ARTICLES 2026 AUGUST  2026  January(387) February(431) March(447) April(451) May(495) June(499) July(647) August(623) September(0) October(0) November(0) December(0) | YEARS(3 234)  STATISTICS (0)

DATE

NAME

Info

CATEG.

WEB

8.8.26

XSS2Shell (CVE-2026-64638): Patch WordPress Now XSS2Shell (CVE-2026-64638): Patch WordPress Now A new WordPress Core vulnerability chain called XSS2Shell turns a login page XSS bug into a much more serious risk for exposed WordPress sites. The issu... Vulnerebility blog SOCRADAR

8.8.26

Cracking Kynx: The Stealer Hunting for Your Wallets, Games, and AI Tools Infostealers are a rapidly evolving threat, enabling various adversaries, ranging from ransomware groups and hacktivists to nation-state actors, to exploit stolen credentials for unauthorized access to sensitive resources. In today’s threat landscape, identity is a primary target, with attackers seeking diverse credentials including usernames, passwords, tokens, and seed phrases.  Malware blog SOCRADAR

8.8.26

Snowflake Hacker Pleads Guilty, Faces 32 Years Snowflake hacker Connor Riley Moucka pleaded guilty on August 5, 2026, in the U.S. District Court for the Western District of Washington, admitting to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count tied to the 2024 breaches of Snowflake customer accounts. CyberCrime blog SOCRADAR

8.8.26

Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) AhnLab SEcurity intelligence Center (ASEC) recently confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. Xctdoor was disclosed through the ASEC blog in 2024, and In March 2026, Hauri disclosed an attack case in which the malware was disguised as an integrated security program. Malware blog AHNLAB

8.8.26

CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker who lures an authenticated user to a malicious site perform unauthorized actions through Zeppelin’s REST and WebSocket endpoints. Vulnerebility blog OX

8.8.26

IBM report sees deep fakes emerging as top AI attack threat IBM study finds deepfake attacks now account for nearly half of AI-enabled breaches as organizations grapple with rising costs and expanding cyber risks. AI blog BARRACUDA

8.8.26

sMalware signing: When trust becomes an attack surface How cybercriminals use stolen, fraudulent, and commercialized code-signing certificates to make malware appear legitimate and bypass traditional trust controls. Malware blog BARRACUDA

8.8.26

Dark Web Market: Vortex Market Vortex Market describes itself as a “classic wallet escrow market,” and that self-description is accurate. It is a general-purpose Dark Web marketplace built around anonymous trade, vendor reputation levels, and cryptocurrency payments held in market-controlled wallets. Reporting on mirror directories places the launch of the Vortex darknet market in October 2023 with full public access during 2024. CyberCrime blog SOCRADAR

8.8.26

Formula 1 Phishing Campaign & Kit Analysis SOCRadar Threat Research Unit (STRU) has identified and analyzed a sophisticated, multi-stage phishing campaign that exploits the high-intensity demand for Formula 1 Grand Prix tickets. The attackers use highly convincing replicas of official ticketing platforms to deceive victims, tricking them into providing payment information and two-factor authentication (2FA) tokens. Phishing blog SOCRADAR

8.8.26

Free tokens for sale: How fake signups drive AI fraud As AI models have become vastly more capable, these multifunctional tools are being used for a wide range of tasks—from coding and analysis to software testing, research, and vulnerability hunting. AI blog OKTA

8.8.26

QuickFox Supply Chain Attack Used to Deploy FDMTP Implant The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting, and an evolving FDMTP implant Hacking blog FORTINET BLOG

8.8.26

Inside Greatness: Telegram-Distributed M365 AiTM PhaaS ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. Social blog ZEROBEC BLOG

8.8.26

Sorting the Agentic AI Hype From Black Hat 2026: 4 Things to Look For At the Mandalay Bay Convention Center, you could measure how fast the market is moving by counting the signs that read "Agentic AI" over the booth. The label was everywhere. What it actually meant changed booth to booth—and that is the problem you carry home. AI blog RELIAQUEST

8.8.26

Agentic AI Security: The Chatbot Era Is Already Over There is a diagram most security teams still carry in their heads when they think about AI. A user talks to a chatbot. The chatbot talks to a large language model. The model talks back. Put an inspection point in the middle, and the problem is solved. AI blog IMPERVA

8.8.26

Wallet-depleting macOS malware wants your crypto During a retrospective threat hunt in June 2026, a Huntress analyst found components of a Mac-specific stealer malware on a monitored system that had been infected three months earlier. Malware blog Huntress

8.8.26

Fake Bank of America "Action Needed" Phishing Email Deposits ScreenConnect Instead We recently came across a fake Bank of America message that closely imitates the targeted bank's visual style, layout, and branding – from the initial phishing email, to the eventual webpage that victims are redirected to. Phishing blog Huntress

8.8.26

Toolkit Installation via SQL Injection Shows the Classics Still Hit Huntress recently observed an incident that started with a "simple" SQL injection bug in an organization's vulnerable public-facing web app, and ended with OS-level remote code execution Hacking blog Huntress

8.8.26

Living off the coding agent: Two tales of tunnels and LaunchAgents Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware. AI blog ELASTIC

8.8.26

Benchmarking the Agentic SOC: How we evaluate LLMs for security workflows Public leaderboards can't tell you which LLM to trust in your SOC, so Elastic built an evaluation framework that grades models on the work (tool calls, execution traces, blind judging) across Agent Builder, Attack Discovery, and automatic migration. Security blog ELASTIC

8.8.26

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads. Malware blog ELASTIC

8.8.26

Payroll Pirates: Strange New Tides in Business Email Compromise Key Takeaways Arctic Wolf is tracking an active, widespread email-driven phishing campaign that uses adversary-in-the-middle (AiTM) techniques to compromise Microsoft 365 accounts, identify personnel involved Phishing blog ARTICWOLF

8.8.26

Ransomware Moves up the Org Chart: Managers Are Prime Targets When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. Ransom blog Zscaler

8.8.26

Targeted Attack on Government Entities in the Middle East | Part 2 This is Part 2 of our two-part technical analysis on new tools used by an East Asia-linked threat actor targeting government entities in the Middle East. After ThreatLabz published Part 1 on the TELESHIM backdoor and MIXEDKEY loader, Kaspersky highlighted a related campaign in recent reporting. Hacking blog Zscaler

8.8.26

ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness It was 9:14 AM when the CISO's VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn't see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his Director of Security Operations, and authenticated through a trust chain that never questioned traffic originating from VPN infrastructure. AI blog Zscaler

8.8.26

Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery The conversation about AI in cybersecurity has recently centered on capabilities like vulnerability discovery, exploit generation, and automated proof-of-concept development. It’s easy to see why: These tasks produce binary outcomes; a vulnerability either exists or it doesn't. That makes them useful for measuring model progress and demonstrating increasingly sophisticated cybersecurity capabilities. AI blog CROWDSTRIKE

8.8.26

CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates Real-world case studies and observations demonstrate an increase in attacks on trusted relationships and adversarial use of AI. Exploit blog CROWDSTRIKE

8.8.26

Secure Agent Harness Execution: Preventing Escape CrowdStrike uses a defense-in-depth architecture, consisting of seven independent control layers, to prevent autonomous AI agents from taking unintended actions. Vulnerebility blog CROWDSTRIKE

8.8.26

N-able N-central exploitation results in RMM tool deployment After compromising systems via CVE-2026-18577, threat actors use the additional RMM tools and network tunnels to establish persistent remote access Vulnerebility blog SOPHOS

8.8.26

Interlock ransomware gang creates volatile situation Multiple legitimate DFIR tools abused by GOLD EMBRACE double-extortion specialists Ransom blog SOPHOS

8.8.26

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the following developments: AI blog GTI

8.8.26

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. Cyber blog GTI

8.8.26

Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs (CRIL), the region experienced 866 documented… Ransom blog Cyble

8.8.26

From Stolen Credentials to Full Breach: The 72-Hour Timeline The 72-hour Timeline reveals how stolen credentials can escalate into a cyberattack, showing key attack stages and detection opportunities. CyberCrime blog Cyble

8.8.26

The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem Discover why continuous asset discovery is the foundation of attack surface management and how visibility helps reduce cyber risk and exposure. Hacking blog Cyble

8.8.26

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide  A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. Malware blog Microsoft blog

8.8.26

ChainDrop supply chain compromise: Anatomy of a self-propagating worm A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. Malware blog Microsoft blog

8.8.26

MythStealer: Browser and Discord Credential Theft with HTTPS Exfiltration to Operator-Notified C2 The Sonicwall Threats research team have recently been tracking an information-stealer malware family known as Myth. The sample we analyzed is a 43.8 MB Windows executable combining browser credential theft, Discord session token extraction, Firefox cookie harvesting, and HTTPS exfiltration into a single binary. Malware blog SonicWall

8.8.26

AI Meets Ransomware : Open‑Weight AI Models Fueling Ransomware Evolution This week, the SonicWall Capture Labs Threat Research team analyzed an interesting ransomware sample discovered about an year ago, that leverages AI capabilities in its attack workflow. Unlike conventional ransomware that embeds its malicious logic directly within the binary, PromptLock adopts a fundamentally different approach. Ransom blog SonicWall

8.8.26

No File, No Trace: How a Fake Invoice Hides a Formbook Loader in Plain Sight This week, the SonicWall Capture Labs Threat Research Team identified an ongoing campaign distributing Formbook malware through phishing emails disguised as routine business documents, purchase orders, shipping notices, and request-for-quote attachments targeting unsuspecting users and businesses. Cyber blog SonicWall

8.8.26

Langflow AI Untrusted Control Sphere Remote Code Execution The SonicWall Capture Labs threat research team became aware of an unauthenticated remote code execution vulnerability in Langflow AI, assessed its impact and developed mitigation measures. Langflow AI is a Python-based web application that provides a visual interface to build AI-driven agents and workflows. AI blog SonicWall

8.8.26

ChainDrop: Inside a Self-Propagating npm Worm A self-propagating npm worm nicknamed ChainDrop infected over 400 packages that are collectively downloaded hundreds of millions of times each week. This includes malicious versions of widely used packages such as keyv and cacheable-request. Unit 42 has unique observations of this attack. Malware blog Palo Alto

8.8.26

The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software Frontier AI is fundamentally shifting the dynamics of cybersecurity — accelerating both how vulnerabilities are discovered and how quickly they can be exploited. AI blog Palo Alto

8.8.26

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. AI blog Palo Alto

8.8.26

“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we've seen bad actors leveraging cloud-based AI. AI blog CISCO TALOS

8.8.26

Why metaphor may dictate your security strategy In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat. Cyber blog CISCO TALOS

8.8.26

[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2. Incident blog CISCO TALOS

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34

2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34

2026

The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

CONGRESS

DEFCON 34
2026 The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest.

CONGRESS

DEFCON 34
2026

Mnoho z úèastníkù na DEF CONu se øadí mezi bezpeènostní experty, novináøe, právníky, crackery, kyber-kriminálníky, a hackery se spoleènými zájmy jako zdrojové kódy, poèítaèová architektura, phreaking, úprava hardwaru, a vše ostatní, co mùže být "hacknuto".

CONGRESS

DEFCON 34

2026

BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0—without exploits, vulnerabilities, or memory corruption?

CONGRESS

BLACKHAT 2026 USA

2026 Can AI Do Novel Security Research? Meet the HTTP Terminator We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it.

CONGRESS

BLACKHAT 2026 USA

2026

GPUBreach: Privilege Escalation Attacks on GPUs Using Rowhammer Rowhammer attacks have been extensively studied on CPUs, where they have enabled powerful exploits, including privilege escalation. In contrast, Rowhammer on NVIDIA GPUs, despite recently demonstrated by GPUHammer attacks, has largely been viewed as low impact, limited to inducing random bit flips that merely degrade machine learning accuracy. In this Briefing, we will overturn that assumption and show that GPU Rowhammer can be weaponized into a full-system compromise.

CONGRESS

BLACKHAT 2026 USA

2026 One Click to System: Exploiting Bixby's Trust Model for Full Device Compromise During the 2025 Mobile Pwn2Own competition, we identified a series of vulnerabilities affecting Samsung devices. Chained together, these issues resulted in remote system-level compromise triggered by a single user interaction.

CONGRESS

BLACKHAT 2026 USA

2026

Scambuster: Social Engineering Scammers at Scale Most security teams get a scam email and delete it. That's the standard move. Block it, move on, forget it.

CONGRESS

BLACKHAT 2026 USA

2026

The CoreBreak Attack: Turning AI Agents into Credentials Exfiltration Vectors Building an AI agent? We all do.
Struggling to figure out how to make it secure? You're not alone.
Counting on your cloud provider's AI agent platform to handle security for you? It's time to think again.

CONGRESS

BLACKHAT 2026 USA

2026 The Good, the Bad, and the Ugly of AI Security Artificial intelligence is fundamentally reshaping cybersecurity for both attackers and defenders, but the uplifts in capabilities are asymmetrical. Our research presents a comprehensive analysis of how AI is removing long-standing operational bottlenecks across offensive and defensive cyber operations, revealing where the resulting capability gains are greatest and why they are inherently asymmetric.

CONGRESS

BLACKHAT 2026 USA

2026 The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI In this talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, and alignment. Throughout the session, they will share insights that address key topics raised by the Black Hat Review Board, including model safeguards, evaluation and containment practices, defensive use cases for AI, and the broader implications of increasingly autonomous systems for the cybersecurity community.

CONGRESS

BLACKHAT 2026 USA

2026

Anatomy of a Takedown: Inside the Operation That Broke LockBit LockBit was the most prolific ransomware-as-a-service operation the world has seen. For four years, it operated as if law enforcement could not touch it. It accounted for one in four ransomware attacks globally, victimized over 2,500 organizations across 120 countries, collected more than $500 million in ransom payments, and built a 194-affiliate operation whose leader went out of his way to project invincibility. Operation Cronos, led by the FBI and UK NCA with partners from ten countries, took it apart in phases over the course of a year, and the operation is not over.

CONGRESS

BLACKHAT 2026 USA

2026 Apple macOS Kernel Exploitation with MIE: Building on the Ashes of 100 Vulnerabilities On modern Apple systems, the AI-powered flood of vulnerabilities does not immediately lead to a flood of Apple exploits. This Briefing walks through a modern XNU kernel chain targeting macOS with MIE, showing how kalloc_type, MTE, PAC, and SPTM reshape every step from memory disclosure to read/write to privilege escalation.

CONGRESS

BLACKHAT 2026 USA

2026

gpwn: Wiretapping Fiber ISP Deployments From the Comfort of Your Home GPON is the fiber-to-home protocol that carries traffic for hundreds of millions of subscribers worldwide (and climbing). Although actively updated, the threat model in the ITU-T's Recommendation has remained nearly unchanged since original publication in 2004, and no longer reflects the realities of real world deployment by ISPs. Additionally, with 4G and 5G networks now carrying backhaul traffic over the same residential PON trees, this means the scope has grown to include the traffic of all customers who are connected to nearby cell towers as well.

CONGRESS

BLACKHAT 2026 USA

2026 No Tools Required: Post-Injection Exploitation Across AI Agent Frameworks Prompt injection was first understood as a behavioral problem: make the agent misbehave, leak hidden context, or bypass guardrails. Then came tool abuse, where injected content caused agents to misuse APIs, shells, browsers, databases, and file systems. Our research shows a deeper failure: in many agentic frameworks, prompt-controlled content can cross the boundary into trusted framework logic itself.

CONGRESS

BLACKHAT 2026 USA

2026

Privacy at Scale: Roblox's Infrastructure for Honoring User Privacy Rights Modern online platforms operate complex distributed systems that store user data across hundreds of services and datastores. At the scale of platforms such as Roblox, serving over 100 million daily active users, honoring user privacy rights under regulations requires infrastructure capable of orchestrating data access and erasure requests across highly heterogeneous storages and service layers. As user data continuously flows through rapidly evolving microservices, ensuring that privacy requests are executed reliably, securely, and within reasonable timeframes becomes a significant engineering challenge.

CONGRESS

BLACKHAT 2026 USA

2026

Rules for Neural Traffic: A New Defensive Layer for LLMs For decades, defenders have used rule-based systems like Snort and YARA to express, share, and enforce precise security logic over network and file activity. LLM security, by contrast, is still dominated by opaque safeguards such as RLHF, moderation APIs, and judge models that monitor mostly surface-level text and are brittle against obfuscation, jailbreaks, and prompt injection. In this Briefing, we will introduce GAVEL, a rule-based detection framework that operates over a model's neural activations and that enables the community to collaborate on a shared rule ecosystem for AI security, much like signature sharing in traditional detection engineering.

CONGRESS

BLACKHAT 2026 USA

2026 The Cost of Obscurity: Exploiting the ATM Supply Chain ATMs represent a critical, high-stakes target within the global financial infrastructure. While manufacturers like Diebold Nixdorf employ security measures, their reliance on a proprietary software supply chain introduces systemic risk that remains an under examined attack surface.

CONGRESS

BLACKHAT 2026 USA

2026 Transformers: Dark Side of the Type - Weaponizing the Conversion Layer In 2017, we presented "Friday the 13th: JSON Attacks" and forced the industry to confront Insecure Deserialization. We demonstrated that Java and .NET serialization libraries are vulnerable to Remote Code Execution (RCE) when an attacker can control the type of object being instantiated. Developers responded by hardening the configurations of complex parsers and serializers: disabling TypeNameHandling, implementing strict binders, and restricting polymorphic binding. That hardening worked for the parsers and serializers we highlighted in 2017. But it created a dangerous blind spot. Developers and security reviewers now assume that simpler code patterns, those that do not involve complex parsers, are inherently safe. We demonstrate that they are not.

CONGRESS

BLACKHAT 2026 USA

2026

Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks An increasing number of network vendors offer Zero-Touch Provisioning (ZTP) to conveniently provision and configure devices with little-to-no manual intervention. A ZTP ecosystem includes provisioning servers (local or cloud-based controllers) that push configurations and updates to client devices: routers, switches, gateways and wireless access points. It is often taken for granted that there is a strong chain of trust between these two parties and that the networking protocols used in ZTP are securely implemented.

CONGRESS

BLACKHAT 2026 USA

2026 A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox OpenAI designed ChatGPT's container sandbox as a secure runtime environment, enforcing full network isolation, strict execution timeouts, and an AI supervisor to filter every command. Under this model, owning the container and extracting sensitive data seemed impossible. However, we demonstrate that by chaining file-parsing abuse for persistent execution, reasoning-channel hijacking for data extraction, and shared infrastructure manipulation, an attacker can establish a Cross-tenant data exfiltration.

CONGRESS

BLACKHAT 2026 USA

2026

Breaking the Seal: Static Deobfuscation of Compiled V8 JavaScript Bytecode Malware Compiled V8 JavaScript bytecode (.jsc) is an emerging format that gives attackers an unusual advantage. Threat actors can assemble capable malware using the rich Node.js ecosystem, apply an off-the-shelf JavaScript obfuscator, and then compile the prepared code. While the payload is relatively easy to build, it is much harder to analyze. From the defender's perspective, it falls in an uncomfortable gap: above the native-level instrumentation, but below the standard JavaScript analysis tooling.

CONGRESS

BLACKHAT 2026 USA

2026 Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover Active Directory remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gaining Domain Admin privileges. This level of privilege effectively grants full control over the environment.

CONGRESS

BLACKHAT 2026 USA

2026

Lights Out: BMCs Are Still Broken and Now We Have the Receipts Baseboard management controllers (BMCs) are embedded into every modern enterprise server. These devices run their own OS, have their own network interfaces, and are network-reachable even when the server is powered off. The devices speak a protocol called IPMI that was thoroughly trashed by Dan Farmer's ground-breaking research in 2013. Since Farmer's original research into Cipher Zero authentication bypass and RAKP password hash disclosure, dozens of new vulnerabilities have been identified in these devices, but none of this research revisits the IPMI protocol itself.

CONGRESS

BLACKHAT 2026 USA

2026

Pass-the-Passkey Family of Attacks Coming from the field of enterprise security, performing privilege escalation and lateral movement by attacking Windows Integrated Authentication is our bread and butter. But as more and more companies are adopting cloud services, we decided to shift our attention to Passkeys, which are slowly but steadily becoming the norm.

CONGRESS

BLACKHAT 2026 USA

2026 Policy Meetup: Fireside Chat with Kirsten Davies, CIO at DOW This exclusive fireside chat with the Hon. Kirsten Davies, the Department of War CIO, explores the military's shifting IT landscape, efforts to create an enduring digital foundation, hardened cybersecurity capabilities, and essential partnerships. The session provides firsthand insights into tackling legacy technical debt, accelerating modern software delivery, and operationalizing systems for warfighter dominance.

CONGRESS

BLACKHAT 2026 USA

2026

Surveillance as a Service: LightSpy's 72 Servers, Router Implants, and Operators Eating Out for Fried Chicken Forensics LightSpy is an actively developed surveillance framework with 70+ plugins targeting iOS, Android, macOS, Windows, Linux, and routers. While previous reporting focused on individual platform variants, no research has mapped the full operational scope of LightSpy's infrastructure, its live operator workflows, or its router infection capabilities.

CONGRESS

BLACKHAT 2026 USA

2026

Time for ACKrobatics: Abusing TCP Timestamps to Improve Remote Timing Attacks Exploiting timing side-channel leaks over the Internet is known to be challenging due to variations in the round-trip time, i.e., network jitter. Timing attacks have become especially challenging as processors become faster, resulting in smaller timing differences, systems become more complex, making it more difficult to collect consistent measurements, and networks become more congested, amplifying the network jitter.

CONGRESS

BLACKHAT 2026 USA

2026 Trusted Enough to Run: Breaking AI Agents in Official Workflows Official AI-agent workflows increasingly run as trusted, unattended automation. These workflows are not a single decision point: they are built from internal stages that decide what is approved, sanitized, and safe to reuse during execution. Our research identifies a distinct failure class inside those official workflow paths: the product marks state as safe, and a later component in the same workflow interprets or consumes that state more powerfully than the earlier decision accounted for.

CONGRESS

BLACKHAT 2026 USA

2026 Vulnerabilities Assembled! The Vulnerability Factory Inside the Windows Kernel As a fundamental part of the Windows networking stack, AFD (Ancillary Function Driver) has undergone years of security hardening and is often considered a well-investigated target whose attack surface would be expected to steadily reduce over time. But is that actually true? Actually, vulnerabilities are not just found, but assembled. By looking at AFD through a cross-layer composition perspective and piecing drivers and components together, we uncovered more than 30 vulnerabilities, just like playing the LEGO.

CONGRESS

BLACKHAT 2026 USA

2026

Beam Me Up, Luke: A Review of Teleport Attack Scenarios Traditional network perimeters are disappearing with the increased adoption of cloud infrastructure, SaaS applications, and remote workforces. As a result, solutions such as Teleport have emerged to provide secure access to distributed infrastructure and services, including emerging AI-driven access patterns. But what happens when a threat actor targets the very technology responsible for guarding remote access?

CONGRESS

BLACKHAT 2026 USA

2026

CRLF-Powered Desync Attacks: Beheading HTTP Streams Have you ever discovered a header injection vulnerability and settled for little more than an open redirect or XSS? In this Briefing, we will introduce a battle-tested "header injection" powered desync methodology, enabling you to perform HTTP request smuggling attacks against even strictly RFC-compliant proxy chains.

CONGRESS

BLACKHAT 2026 USA

2026 Deny. Disrupt. Dismantle. Breaking the Business Model of Cybercrime in the Gray Zone Ransomware networks and cyber-enabled fraud syndicates, from ransomware-as-a-service (RaaS) ecosystems to pig-butchering scam compounds - are not separate problems requiring separate policy responses. They are converging nodes in a single gray-zone threat landscape: transnational criminal organizations that have industrialized to state-level consequence-generation capacity, often operating with explicit or tacit state patronage. The dominant U.S. policy response has been a law-enforcement-first model. It has produced some real wins, but it is also structurally insufficient, unsustainable, and not scaled in timeliness or efficacy to the threat.

CONGRESS

BLACKHAT 2026 USA

2026

Forgotten but Not Gone: Unauthenticated RCEs and LPEs in Legacy Linux Services The cybersecurity industry constantly chases the greatest risks in the latest tech, while old components developed with outdated security principles gather dust. Companies rush to secure their latest AI-based product, while their network remains the same. Do attackers really need prompt injections, malicious IDE extensions, or cloud vulnerabilities to take you down? Or maybe legacy services hiding right under our noses are as big a threat?

CONGRESS

BLACKHAT 2026 USA

2026

Handle With Care: Chaining Azure Automation Flaws for Cross-Tenant Identity Takeover In modern cloud architecture, the integrity of tenant isolation is the ultimate safeguard. However, when the very logic intended to manage identity and automation is flawed, those boundaries become transparent.

CONGRESS

BLACKHAT 2026 USA

2026 PLaTypus: Eliminating Code-Reuse at the Module Boundary Numerous techniques have been proposed to thwart code reuse attacks, yet practical adoption remains limited due to compatibility and deployment challenges. In the current and foreseeable Intel architecture landscape, the main line of defense against such attacks is Intel CET, a hardware-enforced control-flow integrity (CFI) mechanism integrated into recent Intel x86-64 CPUs. However, despite its hardware-backed protections and widespread adoption, CET still provides only partial security: it continues to allow hijacked function pointers to invoke arbitrary functions across module boundaries, a capability that remains fundamental to many modern exploits.

CONGRESS

BLACKHAT 2026 USA

2026

Prompt2Own: Real-World Kernel Exploit Development with LLMs Operating system kernel exploit development is a high-effort, expert-driven process: beyond identifying a memory corruption flaw, developers must build a bug-triggering proof-of-concept (PoC), tame non-determinism from races and allocator noise, determine which exploit primitives are available from the crash context, and compose them into an end-to-end exploit, achieving local privilege escalation (LPE) while overcoming modern mitigations.

CONGRESS

BLACKHAT 2026 USA

2026

Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover Atlas breaks Same-Origin Policy (SOP). Gemini and Edge add untethered localhost access. Comet opens up your filesystem. Claude executes scripts on any website, giving you XSS as a service. Their main mitigation is model safety training. These are design choices, not vulnerabilities. Subsequently, XSS, sandbox escapes, and drive-by exploitation are making a comeback!

CONGRESS

BLACKHAT 2026 USA

2026 Running Untrusted Code: An Empirical Study of Developer Compromise and Its Blast Radius Developer-targeted attacks, particularly those using trojanized coding assessments, are a known threat vector. What has been missing is empirical data on what these attacks actually yield at scale, and how far downstream the impact extends.

CONGRESS

BLACKHAT 2026 USA

2026

Breaking Trust Boundaries: Exploiting Design Assumptions in Network Infrastructure Most modern network infrastructure relies on design assumptions that have remained unchallenged for decades since their original development. While these assumptions historically held under cooperative network environments, some no longer withstand adversarial conditions.

CONGRESS

BLACKHAT 2026 USA

2026

Cracking the Chains: Accelerating Ransomware Recovery via LLM-Assisted Engineering and Verification In the high-stakes world of ransomware incident response, organizations are often forced into a binary choice: pay the ransom or face permanent data loss. However, even the most aggressive threat actors make fatal implementation errors.

CONGRESS

BLACKHAT 2026 USA

2026

Bring Your Own COM - Session Pivoting and Lateral Movement via Ephemeral COM Registration Modern Endpoint Detection and Response (EDR) systems heavily rely on process lineage and telemetry tracking to identify malicious behavior. To bypass these checks, advanced threat actors have historically turned to Component Object Model (COM) hijacking — specifically Living off the Land (LotL) techniques that abuse known, trusted binaries like MMC20.Application.

CONGRESS

BLACKHAT 2026 USA

2026 Cost-Effective, Private, Frontier-Grade: AI Agent Exploitation with a Fine-Tuned OSS Model Large Language Models (LLMs) have transitioned from isolated chat interfaces to autonomous agents, shifting the attack surface from output generation to active, multi-step execution. Modern agents execute critical business logic through tool-calling capabilities, yet current security defenses lag: current LLM scanners, even with multiturn capabilities, primarily judge prompts and responses in isolation and fail to account for the dynamic, execution-based nature of agentic loops, where risk accumulates over time across iterative steps without human intervention.

CONGRESS

BLACKHAT 2026 USA

2026

Cracking the Chains: Accelerating Ransomware Recovery via LLM-Assisted Engineering and Verification In the high-stakes world of ransomware incident response, organizations are often forced into a binary choice: pay the ransom or face permanent data loss. However, even the most aggressive threat actors make fatal implementation errors.

CONGRESS

BLACKHAT 2026 USA

2026

Cyberspace Pirates: Outsourcing Cyberwar in the Age of AI and Ransomware Four days ago, the White House publicly declared it is "not interested in fighting pirates with pirates." Congress disagrees. H.R. 4988 - the Scam Farms Marque and Reprisal Authorization Act - would invoke one of the Constitution's oldest war powers to deputize private actors to hack foreign criminal enterprises, disrupt infrastructure, and seize illicit cryptocurrency. Meanwhile, the Trump administration's March 2026 national cyber strategy calls for "destigmatizing and normalizing" offensive cyber operations and leveraging the private sector "at scale" - while simultaneously insisting that doesn't mean hack-back.

CONGRESS

BLACKHAT 2026 USA

2026 Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius Prompt injection is usually treated as a text problem contained on a screen: a bad output, leaked data, a rogue tool call. This one isn't. A live jailbreak of a stock Unitree Go2 robot dog running Gemini Robotics-ER 1.6, reached through its own camera and mic and driven to physical movement, no human in the loop. Underneath the demo is a measurement problem: agents behave differently when they know they're being tested, so a clean evaluation score doesn't mean the unsafe behavior is gone. The talk covers the attack live, a taxonomy of how these systems fail, why current testing misses it, and what defenders should change. Live hardware, on stage.

CONGRESS

BLACKHAT 2026 USA

2026

Sift or Get Off the PoC: Applying Information Retrieval to Vulnerability Research You bought an IoT device, extracted the firmware, and dropped the main runtime binary into your favorite reverse engineering tool. Now you're staring at thousands of decompiled functions with no source, no symbols, and no obvious place to start bug hunting. How might an LLM help find signal in the noise, even before you've clearly established what "signal" looks like?

CONGRESS

BLACKHAT 2026 USA

2026

Tractor ECU RE: When a Noise Triggered Recall is Also a Security Patch Tractor brake controllers are assumed to be isolated from the trailer's noisy powerline network. This research proves that assumption false. In 2024, a major North American recall was issued for Bendix EC80 brake controllers, citing "memory corruption from power-line noise" as the cause.

CONGRESS

BLACKHAT 2026 USA

2026 When AI Attacks AI: Inside the Self-Propagating Botnet Built on Compromised AI Infrastructure ShadowRay 2.0 is the first in-the-wild campaign where AI infrastructure is not just targeted, but weaponized into a self-propagating botnet. In this Briefing, we will present concrete evidence of a global operation exploiting Ray, an open-source framework often referred to as the "Kubernetes of AI", to autonomously spread across more than 230,000 exposed servers.

CONGRESS

BLACKHAT 2026 USA

2026

Blind Trust in the 6 GHz Band: Weaponizing Wi-Fi Automated Frequency Coordination (AFC) Driven by rapid device growth and congestion in legacy bands, the 6 GHz spectrum is critical for next-generation Wi-Fi, but it is shared with mission-critical incumbents such as fixed microwave links and cellular backhaul. To enable safe sharing of the band and prevent interference, the FCC mandates Automated Frequency Coordination (AFC), a cloud-based control plane that dictates allowed channels and transmit power to standard-power 6 GHz access points based on their geolocation. With vendors already shipping AFC-capable 6 GHz Wi-Fi hardware, deployments are expected to scale to millions of devices by 2030. Yet the entire system rests on an untested assumption: that the AP is a trusted endpoint reporting truthful data over a secure channel.

CONGRESS

BLACKHAT 2026 USA

2026 ChatMate: Remote Prompt Execution on AI Assistants through Sandbox Escaping Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim.

CONGRESS

BLACKHAT 2026 USA

2026

Closed Loop: From Autonomous Exploit to Deployed Defense in Under 5 Minutes The median time-to-exploit for actively targeted vulnerabilities is now measured in hours, not weeks. CVE-2026-33017 went from advisory to confirmed exploitation in 20 hours. React2Shell saw state-sponsored exploitation within hours of disclosure. When I ran the security programs at Updater, ezCater, and CLEAR, we were following industry standards, patching criticals on 14-to-30-day cycles. But experience and industry benchmarks show that the gap is not closing fast enough, even as AI-accelerated exploit development is improving and moving faster.

CONGRESS

BLACKHAT 2026 USA

2026

Could a Pattern on Your Clothing Fool Facial Recognition? Facial recognition evasion research has a costume problem. Masks, infrared LEDs, real-time face swaps, adversarial makeup. Every approach either requires active electronics, makes you look like a Batman villain, or replaces your face with someone else's. None of them scale. None of them are subtle. And none of them actually attack the model.

CONGRESS

BLACKHAT 2026 USA

2026 One Percent of the Tokens, All of the Strategy: LLM-Assisted Vulnerability Discovery in IoT and Embedded Firmware Progression of IoT and embedded devices is still outpacing security community's assessment capabilities, despite many standards being raised in recent years. Due to the volume of distinct software and hardware stacks, proprietary protocols and heterogenous platform design, it is economically infeasible to manually analyze every device at the rate devices ship. An analysis of 48,174 CVEs published in 2025, classified by exploitation difficulty using CWE-based tiered-mapping, reveals 64.4% falls into categories where the primitive directly provides capability of device compromise: amenable to pattern recognition over decompiled code, which is precisely where frontier LLMs excel.

CONGRESS

BLACKHAT 2026 USA

2026

Policy Meetup Join fellow policy professionals for this interactive meetup session, an informal, semi-structured conversation on national and international cyber policies, all those hard problems which span more than just a single enterprise. Whether you want to ask what is next for cyber in the Trump administration or the EU, what's in store for regulatory harmonization, or how to improve deterrence or disruption of adversaries, this session is for you. This meetup offers a unique opportunity to exchange insights on emerging challenges, share effective approaches, and build valuable connections within the policy community. Whether you're a seasoned policy veteran or new to the cybersecurity policy landscape, hope to see you at this policy meetup.

CONGRESS

BLACKHAT 2026 USA

2026

Render Safe: Reverse Engineering and Exploiting an EOD Robot Remotely operated systems are increasingly integral to modern operations, with explosive ordnance disposal (EOD) robots serving as some of the earliest pioneers of deployed robotics. This Briefing provides a deep technical analysis into the architecture, attack surface, and 25-year evolution of iRobot's PackBot. Originally developed by iRobot, creators of the Roomba vacuum, the PackBot saw extensive use since its creation. However, beneath its ruggedized exterior lies a fragile ecosystem built on legacy open-source software, commercial off-the-shelf hardware, and significant technical debt.

CONGRESS

BLACKHAT 2026 USA

2026 Root From Kilometers Away: Ubiquiti AirMax RCE You don't realize it until you see them; they are everywhere. From Wireless ISPs links, to the frontline of modern warfare. But no one found anything?

CONGRESS

BLACKHAT 2026 USA

2026

You Can't Patch a Mental Model: How Agentic Systems Expose our Hidden Security Assumptions Agentic security is not hard because it is new. It is hard because it violates the assumptions our security models are built on.

CONGRESS

BLACKHAT 2026 USA

2026 !secure: A Single Wrong Negation to Root Linux and Escape Managed Containers A single-line logic error in the Linux kernel's networking stack -- present for years and reachable without privileges -- results in a use-after-free that gives any unprivileged local user a deterministic path to root on Ubuntu 24.04, and from a default Kubernetes pod to full node compromise on managed cloud services -- demonstrated on 2 cloud providers. Turning this into a working exploit on Ubuntu 24.04 meant bypassing every mitigation the kernel currently ships: RETHUNK (return thunks that eliminate ROP gadgets), RANDOM_KMALLOC_CACHES (16 randomized sub-caches per slab size class), AppArmor unprivileged user namespace restrictions, KASLR, SMAP, and SMEP. We developed techniques for each, including a code-reuse approach that achieves privilege escalation without a single ROP gadget on post-RETHUNK kernels.

CONGRESS

BLACKHAT 2026 USA

2026

A 0-Click Exploit Chain for the Pixel 10 Attackers are often reported to target mobile devices with 0-click exploits, but limited information is available about how such exploits work on modern Android devices. This Briefing will explain how Project Zero exploited two vulnerabilities to compromise a Google Pixel 9 remotely, without user interaction. It will then explain how we chained a different privilege escalation vulnerability to exploit the Pixel 10.

CONGRESS

BLACKHAT 2026 USA

2026

Batch Me If You Can: Breaking With the State‑of‑the‑Art of Fuzzing Cryptographic Architectures BGP routing underpins the entire Internet and RPKI is supposed to keep it safe. We found 21 new vulnerabilities across every major RPKI vendor, including critical RCE and DoS bugs. We received 8 CVEs so far with CVSS of 7.5 - 9.8. Each vulnerability can downgrade routing protection or worse, expose the server running the validator to hostile takeover.

CONGRESS

BLACKHAT 2026 USA

2026 Beyond Detection: What We Learned Testing Every AI Approach to Vulnerability Classification There has been considerable discussion on how to use AI to find vulnerabilities, but very little discussion on how to use it to _classify_ vulnerabilities. Given the huge backlog of vulnerabilities in our systems, and the agentic coding revolution which will 100x them, a new approach is needed to accurately cull and rank issues.

CONGRESS

BLACKHAT 2026 USA

2026

Born Corrupted: How We Backdoored Trusted Language Binaries I know. You can audit your dependencies, pin your versions, verify signatures, and stick to trusted downloads. But what happens when you're pwned before you even start?

CONGRESS

BLACKHAT 2026 USA

2026

Breaking Recently Deployed Spectre v2 Mitigations: A Novel Attack Primitive Recently deployed Spectre v2 mitigations neutralize branch predictor state through domain isolation or sanitization. Neutralization occurs when switching privilege contexts, or immediately prior to indirect branch execution. Once neutralized, the predictor state is assumed to remain free from attacker influence until it is used.

CONGRESS

BLACKHAT 2026 USA

2026 Catch Me If You Can: AI Investigators Hunting Autonomous Attackers as a Benchmark Attackers are already using AI agents in their workflows. Defenders are still evaluating theirs against stale benchmarks that profile yesterday's attackers. These evaluations do not capture a battle at machine speed where AI agents go toe-to-toe. We propose a new methodology in which blue and red agents fight it out on live infrastructure.

CONGRESS

BLACKHAT 2026 USA

2026

One Key to Rule Them All: Taking Over a Flagship Cloud Service In this Briefing, we'll break down how we took over a major cloud provider's managed database service. We'll walk through the entire attack chain: escaping a custom .NET sandbox, moving laterally through internal infrastructure, and ultimately extracting a master key that granted admin access to every customer database on the platform.

CONGRESS

BLACKHAT 2026 USA

2026 Pedal to the Bare Metal: Rehosting and Fuzzing the Tesla Wall Connector to Start a Worm Bare-metal embedded systems are notoriously difficult to secure, which is worrying, as exploits in this domain can blow things up and shut things down. So far, research on this type of embedded system has been rare because automated security analysis techniques were unavailable. Now, after our seven-year-long research on rehosting-based firmware fuzzing, a technique that allows firmware to run in an auto-generated execution environment, finding security vulnerabilities in bare-metal firmware has become feasible at scale.

CONGRESS

BLACKHAT 2026 USA

2026

Render Safe Live: EOD PackBot Demonstration Remotely operated systems are increasingly integral to modern operations, with explosive ordnance disposal (EOD) robots serving as some of the earliest pioneers of deployed robotics. This live demonstration (following the Briefing - Render Safe: Reverse Engineering and Exploiting an EOD Robot) will showcase the robot and its interface after the main talk. Come see how a bomb disposal robot is controlled and get a chance to have a live Q &A with the original researchers and speakers for this talk.

CONGRESS

BLACKHAT 2026 USA

2026

Can't Touch This: Attacking Fingerprint Systems from Sensor to OS Three years ago, we demonstrated full authentication bypasses against the top three fingerprint sensors used in Windows laptops, exposing fundamental flaws in various vendor-specific implementations. That research showed that match-on-chip biometric sensors, which are widely held to be the most secure approach because of resistance to host-side attacks, could be reliably defeated through hardware, protocol, and software abuse.

CONGRESS

BLACKHAT 2026 USA

2026 CSS: The Bomb Inside Your Inbox You might think it's safe to open an email in 2026. After all, it's only HTML, right? Turns out, we forgot about CSS. In this Briefing, I'll introduce multiple novel techniques for compromising email accounts by ripping apart trust boundaries, using nothing but CSS and HTML.

CONGRESS

BLACKHAT 2026 USA

2026

If the Adversary Lives Off Your Land, So Should You Modern defenders are expected to detect and respond to adversaries who increasingly "live off the land," blending into enterprise environments by abusing legitimate tools, credentials, and infrastructure. Traditional detection approaches, often reliant on signatures, expensive tooling, or low-fidelity deception, struggle to distinguish malicious activity from normal operations, leading to delayed detection, high false positives, and limited ability to shape adversary behavior.

CONGRESS

BLACKHAT 2026 USA

2026

Invisible Threads: Remote Building Surveillance Through Encrypted Thread Traffic Analysis Thread has rapidly become the backbone of modern building automation systems, powering critical infrastructure in offices, hospitals, manufacturing facilities, and smart buildings worldwide. What if an attacker could map your entire building's automation infrastructure without ever setting foot inside, simply by exploiting Matter's predictable packet sizes?

CONGRESS

BLACKHAT 2026 USA

2026 Policy Meetup: Panel Discussion on Policy Perspectives on AI Security AI security policy is being written right now- in federal agencies, standards bodies, European cybersecurity institutions, and the enterprises trying to put all of it into practice. This session brings those four vantage points into one room.

CONGRESS

BLACKHAT 2026 USA

2026

The 0-Day Engine: Finding 100+ Vulns with LLMs in Chrome and Android Scaling logic vulnerability discovery in high-value targets like Android and Chrome is difficult: traditional fuzzing is blind to non-crashing logic defects, while known LLM approaches fail on large-scale codebases due to context hallucination.

CONGRESS

BLACKHAT 2026 USA

2026 The Crypto Caper: Exposing a Sophisticated Multi-Cloud Bandit Attackers had just made off with tens of millions of dollars in cryptocurrency. The victim had no clue how this could have happened. Step by step, the ensuing investigation revealed a remarkable sprawling campaign which spanned months and compromised every part of the target's multi-cloud infrastructure. From simple help-desk phishing calls to Identity Provider access, attackers methodically expanded their foothold to reach GitHub and production AWS environments, successfully evading detection while repeatedly executing malicious transactions right under the victim's nose.

CONGRESS

BLACKHAT 2026 USA

2026

ThreatForest: Automated Attack Trees from Source Code Everyone agrees that threat modeling is important. Almost nobody does it. Today's threat modeling tools still require a human to draw architecture diagrams, enumerate every threat, and manually map findings to MITRE ATT&CK. For a cloud-native app with dozens of microservices and hundreds of IAM policy statements, that process takes days and goes stale with the next deployment. So teams skip it, and the attack surface goes unanalyzed.

CONGRESS

BLACKHAT 2026 USA

2026

Tiny Chips, Big Leaks: Breaking TrustZone-M with Single-Stepping Attacks Trusted execution environments (TEEs) provide confidential-computing guarantees by running sensitive code inside hardware-enforced enclaves that remain isolated even when the operating system is compromised. However, despite this strong architectural isolation, TEEs remain vulnerable to software-based microarchitectural side-channel attacks.

CONGRESS

BLACKHAT 2026 USA

2026 Tracking the Trackers: How We Took Over 36 Million GPS Devices Protecting Children & Vehicles We analyzed three of the largest GPS tracking ecosystems: SETracker (~10M devices across 39 brands), SinoTrack (6M+ vehicles), and TKSTAR/Thinkrace (20M+ devices). Despite appearing as competing products, all three originate from the same Shenzhen-based supply chain and share critical architectural flaws.

CONGRESS

BLACKHAT 2026 USA

2026

Beyond Normalization: The Expanding Unicode Attack Surface Modern web applications process input through layered pipelines: URL decoding, UTF-8 validation, WAF transformations, framework parsing, surrogate handling, database collation, HTML entity decoding, and increasingly, LLM preprocessing. Each layer implements subtly different assumptions about character validity and equivalence. When those assumptions diverge, security boundaries fail. Building off our popular Black Hat USA 2025 Unicode Briefing, we have continued our research into the complex world of Unicode processing.

CONGRESS

BLACKHAT 2026 USA

2026 Breaking Hardware CFI with Sigreturn Modern hardware-assisted Control Flow Integrity (CFI) is increasingly deployed across mobile devices and cloud infrastructure. On ARM64 systems, backward-edge protections such as Pointer Authentication (PAC) protect return addresses, while forward-edge defenses such as Branch Target Identification (BTI) restrict indirect branches to compiler-inserted landing pads. Together, these mechanisms are intended to prevent traditional code-reuse attacks such as ROP and JOP.

CONGRESS

BLACKHAT 2026 USA

2026

Caging the Agent: How Roblox Built Multi-Layer Sandboxes to Secure Claude Code at Enterprise Scale A hidden instruction in a GitHub Issue convinced Claude Code to upload Roblox's credentials to a public repository. EDR saw nothing, it was a normal process making a normal network request. The good news, it happened in an internal testing environment.

CONGRESS

BLACKHAT 2026 USA

2026

Inside Coruna and DarkSword - iOS Exploits Caught in the Wild Prior to 2026, iOS Malware and Exploits were seen as a problem only targeting a few individuals. 2026 changed this. Coruna and DarkSword were both deployed as watering hole attacks impacting hundreds of millions of iPhones at the time. Watering hole attacks are specifically evil as they don't include any device targeting or even social engineering. Combined, they supported iOS 13 - 18.7. Both tools were leaked and quickly proliferated. In the case of Coruna, it was the first time we had seen iOS Exploit being used by organized crime groups.

CONGRESS

BLACKHAT 2026 USA

2026 Promptware EOD: Skillful Agent Detonation The AI agent supply chain has become a fertile ground for malware. It lurks in skill markdown files, rug-pulled MCP servers, misaligned models, and weaponized moltbook posts. In a blink of an eye, we find ourselves with an outdated supply chain security model. Intelligence gathering based on build-time static scanning has been sidestepped by agents pulling, writing, and executing code at runtime.

CONGRESS

BLACKHAT 2026 USA

2026

Scanning the Scanners: Turning Security Vendors Into Supply Chain Weapons Every security scanner promises to protect your supply chain. We submitted malicious repos to 20 of them through free-tier signups and compromised 5, gaining access to production databases, cloud credentials, third-party service credentials, and OAuth tokens associated with Fortune 100 companies, defense contractors, and government institutions. All from a single config file, in under an hour, with no zero-days. One vendor awarded their maximum bug bounty payout.

CONGRESS

BLACKHAT 2026 USA

2026 The 12th Annual Black Hat USA Network Operations Center (NOC) Report Back with another year of soul-crushing statistics, the Black Hat NOC team will be sharing all of the data that keeps us equally puzzled and entertained, year after year.

CONGRESS

BLACKHAT 2026 USA

2026

The Intent Gap: Where Every AI Regulation Falls Short and What Security Leaders Need Instead Every major AI regulation from the NIST AI Risk Management Framework, the EU AI Act, the U.S. AI Action Plan, and CISA's December 2025 OT guidance was designed for a world where software executes instructions. None of them adequately address the security challenge created by AI systems that autonomously form plans, make decisions, and take actions: systems that have INTENT. S

CONGRESS

BLACKHAT 2026 USA

2026

When Agentic Glue Melts: Exploiting Cloudflare CodeMode and Workers We began this research with a narrow goal: break Cloudflare Code Mode. What we found was much broader.

CONGRESS

BLACKHAT 2026 USA

2026 Breaking the Unbreakable: Dismantling the Myth of "Trusted" Cryptographic Libraries (ON-DEMAND ONLY) "Don't roll your own crypto." We follow this rule religiously — and in doing so, transfer absolute trust to libraries we never inspect. But how would you actually answer the question: is your cryptographic dependency secure?

CONGRESS

BLACKHAT 2026 USA

2026

Deterministic Chaos - Exploiting and Securing Predictable Timing in TSN Industrial Networks (ON-DEMAND ONLY) Time-Sensitive Networking (TSN) is rapidly becoming the backbone of modern industrial automation. By enabling deterministic, low-latency communication over standard Ethernet, TSN supports safety-critical control loops, synchronized robotics, and real-time industrial processes where reliability and availability are essential.

CONGRESS

BLACKHAT 2026 USA

2026

Exploring the EL2 Attack Surface: From Vulnerability to Full System Compromise (ON-DEMAND ONLY) AVF (Android Virtualization Framework) was introduced with Android 13 to provide underlying data-isolation capabilities that surpass traditional application sandboxing. Its core objective is to ensure the confidentiality and integrity of sensitive data within virtual machines (VMs), even if the host Android kernel is compromised. Currently deployed in commercial scenarios, AVF is positioned as a foundational pillar for privacy computing and confidential AI processing according to Android's long-term roadmap.

CONGRESS

BLACKHAT 2026 USA

2026 From 8 Bytes to Full Compromise: AI-Assisted Exploitation of a Widespread USB Flaw in a Multi-SE Hardware Wallet (ON-DEMAND ONLY) Hardware wallets and secure embedded devices are heavily marketed on their "defense-in-depth" architectures: multi Secure Elements (SE), MPU-protected OTP/fuses, and cryptographic key sharding. This Briefing examines what happens when the software foundation connecting these defensive layers is compromised.

CONGRESS

BLACKHAT 2026 USA

2026

Ghost Credentials: Hunting and Exploiting NonHuman Identities Across Cloud Environments (ON-DEMAND ONLY) In 2026, the ratio of Non-Human Identities (NHIs) to human identities reached a staggering 144:1. While organizations have invested heavily in phishing-resistant MFA, passwordless authentication, and Zero Trust for human users, an invisible ecosystem of service accounts, API keys, OAuth applications, CI/CD secrets, Kubernetes identities, and AI agent credentials continues to operate with persistent privileges, fragmented ownership, and little to no lifecycle management. These machine identities have quietly become one of the highest-return attack surfaces for adversaries targeting modern cloud environments.

CONGRESS

BLACKHAT 2026 USA

2026 Inside the Screen: Deep-Diving into North Korean IT Workers' Live Infrastructure (ON-DEMAND ONLY) North Korean IT workers have infiltrated companies worldwide, generating revenue for the regime while posing significant security risks to employers. In 2025, we exposed their reality—organizational structure, workflows, and tradecraft. This time, through a two-year collaboration with a confidential source, we successfully obtained complete forensic images of VPS systems actively used by North Korean operators.

CONGRESS

BLACKHAT 2026 USA

2026

Medical Device Kill Chain: From Debug Port to Patient Impact (ON-DEMAND ONLY) Connected medical devices such as infusion pumps, patient monitors, imaging systems, implantables, and other cyber-physical healthcare technologies increasingly form the backbone of modern clinical care. Despite growing connectivity and cloud integration, the security community still lacks a practical, end-to-end methodology for understanding how weaknesses across hardware, firmware, protocols, and backend systems combine to create patient safety and operational risk.

CONGRESS

BLACKHAT 2026 USA

2026

Spaghettifying DRAM: Breaking Everything with Memory Collision Exploitation (ON-DEMAND ONLY) In this Briefing, we will take a fundamental invariant of computing - that an address identifies a variable's location - and break it at the hardware level.

CONGRESS

BLACKHAT 2026 USA

2026 Trust No Deputy: Breaking Azure and GCP Through Managed Identity Chains (ON-DEMAND ONLY) Cloud platforms delegate sensitive operations to managed identities, trusting that Azure RBAC and GCP IAM boundaries contain blast radius. This trust is misplaced.

CONGRESS

BLACKHAT 2026 USA

2026

When BPF Blinding Goes Dark: Smuggling Raw Gadgets into the Linux Kernel (ON-DEMAND ONLY) bpf_jit_harden=2 is supposed to be the last word on JIT spray in the Linux kernel. Every immediate value in a BPF program gets masked with a random XOR key before the JIT ever sees it. Attacker-controlled bytes cannot land in kernel executable memory. The defense has been in place since 2016 and, until now, it worked.

CONGRESS

BLACKHAT 2026 USA

2026 Attacking and Defending AI Browsers Implementing Kubernetes namespace-based multi-tenancy is challenging, and its isolation is generally considered less effective than control-plane isolation. That's why the latter is often recommended ... and also implemented? Not really, as workloads such as machine learning, pipelines, and scripting capabilities are increasingly common in enterprise environments. And they can introduce unobvious multi-tenancy in clusters.

CONGRESS

BLACKHAT 2026 USA

2026

BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0—without exploits, vulnerabilities, or memory corruption?

CONGRESS

BLACKHAT 2026 USA

2026 Can AI Do Novel Security Research? Meet the HTTP Terminator We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it.

CONGRESS

BLACKHAT 2026 USA

2026

GPUBreach: Privilege Escalation Attacks on GPUs Using Rowhammer Rowhammer attacks have been extensively studied on CPUs, where they have enabled powerful exploits, including privilege escalation. In contrast, Rowhammer on NVIDIA GPUs, despite recently demonstrated by GPUHammer attacks, has largely been viewed as low impact, limited to inducing random bit flips that merely degrade machine learning accuracy. In this Briefing, we will overturn that assumption and show that GPU Rowhammer can be weaponized into a full-system compromise.

CONGRESS

BLACKHAT 2026 USA

2026 One Click to System: Exploiting Bixby's Trust Model for Full Device Compromise During the 2025 Mobile Pwn2Own competition, we identified a series of vulnerabilities affecting Samsung devices. Chained together, these issues resulted in remote system-level compromise triggered by a single user interaction.

CONGRESS

BLACKHAT 2026 USA

2026

Scambuster: Social Engineering Scammers at Scale Most security teams get a scam email and delete it. That's the standard move. Block it, move on, forget it.

CONGRESS

BLACKHAT 2026 USA

2026

The CoreBreak Attack: Turning AI Agents into Credentials Exfiltration Vectors Building an AI agent? We all do.
Struggling to figure out how to make it secure? You're not alone.
Counting on your cloud provider's AI agent platform to handle security for you? It's time to think again.

CONGRESS

BLACKHAT 2026 USA

2026 The Good, the Bad, and the Ugly of AI Security Artificial intelligence is fundamentally reshaping cybersecurity for both attackers and defenders, but the uplifts in capabilities are asymmetrical. Our research presents a comprehensive analysis of how AI is removing long-standing operational bottlenecks across offensive and defensive cyber operations, revealing where the resulting capability gains are greatest and why they are inherently asymmetric.

CONGRESS

BLACKHAT 2026 USA

2026 The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI In this talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, and alignment. Throughout the session, they will share insights that address key topics raised by the Black Hat Review Board, including model safeguards, evaluation and containment practices, defensive use cases for AI, and the broader implications of increasingly autonomous systems for the cybersecurity community.

CONGRESS

BLACKHAT 2026 USA

2026

Anatomy of a Takedown: Inside the Operation That Broke LockBit LockBit was the most prolific ransomware-as-a-service operation the world has seen. For four years, it operated as if law enforcement could not touch it. It accounted for one in four ransomware attacks globally, victimized over 2,500 organizations across 120 countries, collected more than $500 million in ransom payments, and built a 194-affiliate operation whose leader went out of his way to project invincibility. Operation Cronos, led by the FBI and UK NCA with partners from ten countries, took it apart in phases over the course of a year, and the operation is not over.

CONGRESS

BLACKHAT 2026 USA

2026 Apple macOS Kernel Exploitation with MIE: Building on the Ashes of 100 Vulnerabilities On modern Apple systems, the AI-powered flood of vulnerabilities does not immediately lead to a flood of Apple exploits. This Briefing walks through a modern XNU kernel chain targeting macOS with MIE, showing how kalloc_type, MTE, PAC, and SPTM reshape every step from memory disclosure to read/write to privilege escalation.

CONGRESS

BLACKHAT 2026 USA

2026

gpwn: Wiretapping Fiber ISP Deployments From the Comfort of Your Home GPON is the fiber-to-home protocol that carries traffic for hundreds of millions of subscribers worldwide (and climbing). Although actively updated, the threat model in the ITU-T's Recommendation has remained nearly unchanged since original publication in 2004, and no longer reflects the realities of real world deployment by ISPs. Additionally, with 4G and 5G networks now carrying backhaul traffic over the same residential PON trees, this means the scope has grown to include the traffic of all customers who are connected to nearby cell towers as well.

CONGRESS

BLACKHAT 2026 USA

2026 No Tools Required: Post-Injection Exploitation Across AI Agent Frameworks Prompt injection was first understood as a behavioral problem: make the agent misbehave, leak hidden context, or bypass guardrails. Then came tool abuse, where injected content caused agents to misuse APIs, shells, browsers, databases, and file systems. Our research shows a deeper failure: in many agentic frameworks, prompt-controlled content can cross the boundary into trusted framework logic itself.

CONGRESS

BLACKHAT 2026 USA

2026

Privacy at Scale: Roblox's Infrastructure for Honoring User Privacy Rights Modern online platforms operate complex distributed systems that store user data across hundreds of services and datastores. At the scale of platforms such as Roblox, serving over 100 million daily active users, honoring user privacy rights under regulations requires infrastructure capable of orchestrating data access and erasure requests across highly heterogeneous storages and service layers. As user data continuously flows through rapidly evolving microservices, ensuring that privacy requests are executed reliably, securely, and within reasonable timeframes becomes a significant engineering challenge.

CONGRESS

BLACKHAT 2026 USA

2026

Rules for Neural Traffic: A New Defensive Layer for LLMs For decades, defenders have used rule-based systems like Snort and YARA to express, share, and enforce precise security logic over network and file activity. LLM security, by contrast, is still dominated by opaque safeguards such as RLHF, moderation APIs, and judge models that monitor mostly surface-level text and are brittle against obfuscation, jailbreaks, and prompt injection. In this Briefing, we will introduce GAVEL, a rule-based detection framework that operates over a model's neural activations and that enables the community to collaborate on a shared rule ecosystem for AI security, much like signature sharing in traditional detection engineering.

CONGRESS

BLACKHAT 2026 USA

2026 The Cost of Obscurity: Exploiting the ATM Supply Chain ATMs represent a critical, high-stakes target within the global financial infrastructure. While manufacturers like Diebold Nixdorf employ security measures, their reliance on a proprietary software supply chain introduces systemic risk that remains an under examined attack surface.

CONGRESS

BLACKHAT 2026 USA

2026 Transformers: Dark Side of the Type - Weaponizing the Conversion Layer In 2017, we presented "Friday the 13th: JSON Attacks" and forced the industry to confront Insecure Deserialization. We demonstrated that Java and .NET serialization libraries are vulnerable to Remote Code Execution (RCE) when an attacker can control the type of object being instantiated. Developers responded by hardening the configurations of complex parsers and serializers: disabling TypeNameHandling, implementing strict binders, and restricting polymorphic binding. That hardening worked for the parsers and serializers we highlighted in 2017. But it created a dangerous blind spot. Developers and security reviewers now assume that simpler code patterns, those that do not involve complex parsers, are inherently safe. We demonstrate that they are not.

CONGRESS

BLACKHAT 2026 USA

2026

Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks An increasing number of network vendors offer Zero-Touch Provisioning (ZTP) to conveniently provision and configure devices with little-to-no manual intervention. A ZTP ecosystem includes provisioning servers (local or cloud-based controllers) that push configurations and updates to client devices: routers, switches, gateways and wireless access points. It is often taken for granted that there is a strong chain of trust between these two parties and that the networking protocols used in ZTP are securely implemented.

CONGRESS

BLACKHAT 2026 USA

2026 A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox OpenAI designed ChatGPT's container sandbox as a secure runtime environment, enforcing full network isolation, strict execution timeouts, and an AI supervisor to filter every command. Under this model, owning the container and extracting sensitive data seemed impossible. However, we demonstrate that by chaining file-parsing abuse for persistent execution, reasoning-channel hijacking for data extraction, and shared infrastructure manipulation, an attacker can establish a Cross-tenant data exfiltration.

CONGRESS

BLACKHAT 2026 USA

2026

Breaking the Seal: Static Deobfuscation of Compiled V8 JavaScript Bytecode Malware Compiled V8 JavaScript bytecode (.jsc) is an emerging format that gives attackers an unusual advantage. Threat actors can assemble capable malware using the rich Node.js ecosystem, apply an off-the-shelf JavaScript obfuscator, and then compile the prepared code. While the payload is relatively easy to build, it is much harder to analyze. From the defender's perspective, it falls in an uncomfortable gap: above the native-level instrumentation, but below the standard JavaScript analysis tooling.

CONGRESS

BLACKHAT 2026 USA

2026 Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover Active Directory remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gaining Domain Admin privileges. This level of privilege effectively grants full control over the environment.

CONGRESS

BLACKHAT 2026 USA

2026

Lights Out: BMCs Are Still Broken and Now We Have the Receipts Baseboard management controllers (BMCs) are embedded into every modern enterprise server. These devices run their own OS, have their own network interfaces, and are network-reachable even when the server is powered off. The devices speak a protocol called IPMI that was thoroughly trashed by Dan Farmer's ground-breaking research in 2013. Since Farmer's original research into Cipher Zero authentication bypass and RAKP password hash disclosure, dozens of new vulnerabilities have been identified in these devices, but none of this research revisits the IPMI protocol itself.

CONGRESS

BLACKHAT 2026 USA

2026

Pass-the-Passkey Family of Attacks Coming from the field of enterprise security, performing privilege escalation and lateral movement by attacking Windows Integrated Authentication is our bread and butter. But as more and more companies are adopting cloud services, we decided to shift our attention to Passkeys, which are slowly but steadily becoming the norm.

CONGRESS

BLACKHAT 2026 USA

2026 Policy Meetup: Fireside Chat with Kirsten Davies, CIO at DOW This exclusive fireside chat with the Hon. Kirsten Davies, the Department of War CIO, explores the military's shifting IT landscape, efforts to create an enduring digital foundation, hardened cybersecurity capabilities, and essential partnerships. The session provides firsthand insights into tackling legacy technical debt, accelerating modern software delivery, and operationalizing systems for warfighter dominance.

CONGRESS

BLACKHAT 2026 USA

2026

Surveillance as a Service: LightSpy's 72 Servers, Router Implants, and Operators Eating Out for Fried Chicken Forensics LightSpy is an actively developed surveillance framework with 70+ plugins targeting iOS, Android, macOS, Windows, Linux, and routers. While previous reporting focused on individual platform variants, no research has mapped the full operational scope of LightSpy's infrastructure, its live operator workflows, or its router infection capabilities.

CONGRESS

BLACKHAT 2026 USA

2026

Time for ACKrobatics: Abusing TCP Timestamps to Improve Remote Timing Attacks Exploiting timing side-channel leaks over the Internet is known to be challenging due to variations in the round-trip time, i.e., network jitter. Timing attacks have become especially challenging as processors become faster, resulting in smaller timing differences, systems become more complex, making it more difficult to collect consistent measurements, and networks become more congested, amplifying the network jitter.

CONGRESS

BLACKHAT 2026 USA

2026 Trusted Enough to Run: Breaking AI Agents in Official Workflows Official AI-agent workflows increasingly run as trusted, unattended automation. These workflows are not a single decision point: they are built from internal stages that decide what is approved, sanitized, and safe to reuse during execution. Our research identifies a distinct failure class inside those official workflow paths: the product marks state as safe, and a later component in the same workflow interprets or consumes that state more powerfully than the earlier decision accounted for.

CONGRESS

BLACKHAT 2026 USA

2026 Vulnerabilities Assembled! The Vulnerability Factory Inside the Windows Kernel As a fundamental part of the Windows networking stack, AFD (Ancillary Function Driver) has undergone years of security hardening and is often considered a well-investigated target whose attack surface would be expected to steadily reduce over time. But is that actually true? Actually, vulnerabilities are not just found, but assembled. By looking at AFD through a cross-layer composition perspective and piecing drivers and components together, we uncovered more than 30 vulnerabilities, just like playing the LEGO.

CONGRESS

BLACKHAT 2026 USA

2026

Beam Me Up, Luke: A Review of Teleport Attack Scenarios Traditional network perimeters are disappearing with the increased adoption of cloud infrastructure, SaaS applications, and remote workforces. As a result, solutions such as Teleport have emerged to provide secure access to distributed infrastructure and services, including emerging AI-driven access patterns. But what happens when a threat actor targets the very technology responsible for guarding remote access?

CONGRESS

BLACKHAT 2026 USA

2026

CRLF-Powered Desync Attacks: Beheading HTTP Streams Have you ever discovered a header injection vulnerability and settled for little more than an open redirect or XSS? In this Briefing, we will introduce a battle-tested "header injection" powered desync methodology, enabling you to perform HTTP request smuggling attacks against even strictly RFC-compliant proxy chains.

CONGRESS

BLACKHAT 2026 USA

2026 Deny. Disrupt. Dismantle. Breaking the Business Model of Cybercrime in the Gray Zone Ransomware networks and cyber-enabled fraud syndicates, from ransomware-as-a-service (RaaS) ecosystems to pig-butchering scam compounds - are not separate problems requiring separate policy responses. They are converging nodes in a single gray-zone threat landscape: transnational criminal organizations that have industrialized to state-level consequence-generation capacity, often operating with explicit or tacit state patronage. The dominant U.S. policy response has been a law-enforcement-first model. It has produced some real wins, but it is also structurally insufficient, unsustainable, and not scaled in timeliness or efficacy to the threat.

CONGRESS

BLACKHAT 2026 USA

2026

Forgotten but Not Gone: Unauthenticated RCEs and LPEs in Legacy Linux Services The cybersecurity industry constantly chases the greatest risks in the latest tech, while old components developed with outdated security principles gather dust. Companies rush to secure their latest AI-based product, while their network remains the same. Do attackers really need prompt injections, malicious IDE extensions, or cloud vulnerabilities to take you down? Or maybe legacy services hiding right under our noses are as big a threat?

CONGRESS

BLACKHAT 2026 USA

2026

Handle With Care: Chaining Azure Automation Flaws for Cross-Tenant Identity Takeover In modern cloud architecture, the integrity of tenant isolation is the ultimate safeguard. However, when the very logic intended to manage identity and automation is flawed, those boundaries become transparent.

CONGRESS

BLACKHAT 2026 USA

2026 PLaTypus: Eliminating Code-Reuse at the Module Boundary Numerous techniques have been proposed to thwart code reuse attacks, yet practical adoption remains limited due to compatibility and deployment challenges. In the current and foreseeable Intel architecture landscape, the main line of defense against such attacks is Intel CET, a hardware-enforced control-flow integrity (CFI) mechanism integrated into recent Intel x86-64 CPUs.

CONGRESS

BLACKHAT 2026 USA

2026

Prompt2Own: Real-World Kernel Exploit Development with LLMs Operating system kernel exploit development is a high-effort, expert-driven process: beyond identifying a memory corruption flaw, developers must build a bug-triggering proof-of-concept (PoC), tame non-determinism from races and allocator noise, determine which exploit primitives are available from the crash context, and compose them into an end-to-end exploit, achieving local privilege escalation (LPE) while overcoming modern mitigations.

CONGRESS

BLACKHAT 2026 USA

2026

Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover Atlas breaks Same-Origin Policy (SOP). Gemini and Edge add untethered localhost access. Comet opens up your filesystem. Claude executes scripts on any website, giving you XSS as a service. Their main mitigation is model safety training. These are design choices, not vulnerabilities. Subsequently, XSS, sandbox escapes, and drive-by exploitation are making a comeback!

CONGRESS

BLACKHAT 2026 USA

2026 Running Untrusted Code: An Empirical Study of Developer Compromise and Its Blast Radius Developer-targeted attacks, particularly those using trojanized coding assessments, are a known threat vector. What has been missing is empirical data on what these attacks actually yield at scale, and how far downstream the impact extends.

CONGRESS

BLACKHAT 2026 USA

2026

Breaking Trust Boundaries: Exploiting Design Assumptions in Network Infrastructure Most modern network infrastructure relies on design assumptions that have remained unchallenged for decades since their original development. While these assumptions historically held under cooperative network environments, some no longer withstand adversarial conditions.

CONGRESS

BLACKHAT 2026 USA

2026

Cracking the Chains: Accelerating Ransomware Recovery via LLM-Assisted Engineering and Verification In the high-stakes world of ransomware incident response, organizations are often forced into a binary choice: pay the ransom or face permanent data loss. However, even the most aggressive threat actors make fatal implementation errors.

CONGRESS

BLACKHAT 2026 USA

2026

Bring Your Own COM - Session Pivoting and Lateral Movement via Ephemeral COM Registration Modern Endpoint Detection and Response (EDR) systems heavily rely on process lineage and telemetry tracking to identify malicious behavior. To bypass these checks, advanced threat actors have historically turned to Component Object Model (COM) hijacking — specifically Living off the Land (LotL) techniques that abuse known, trusted binaries like MMC20.Application.

CONGRESS

BLACKHAT 2026 USA

2026 Cost-Effective, Private, Frontier-Grade: AI Agent Exploitation with a Fine-Tuned OSS Model Large Language Models (LLMs) have transitioned from isolated chat interfaces to autonomous agents, shifting the attack surface from output generation to active, multi-step execution.

CONGRESS

BLACKHAT 2026 USA

2026

Cracking the Chains: Accelerating Ransomware Recovery via LLM-Assisted Engineering and Verification In the high-stakes world of ransomware incident response, organizations are often forced into a binary choice: pay the ransom or face permanent data loss. However, even the most aggressive threat actors make fatal implementation errors.

CONGRESS

BLACKHAT 2026 USA

2026

Cyberspace Pirates: Outsourcing Cyberwar in the Age of AI and Ransomware Four days ago, the White House publicly declared it is "not interested in fighting pirates with pirates." Congress disagrees. H.R. 4988 - the Scam Farms Marque and Reprisal Authorization Act - would invoke one of the Constitution's oldest war powers to deputize private actors to hack foreign criminal enterprises, disrupt infrastructure, and seize illicit cryptocurrency.

CONGRESS

BLACKHAT 2026 USA

2026 Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius Prompt injection is usually treated as a text problem contained on a screen: a bad output, leaked data, a rogue tool call. This one isn't. A live jailbreak of a stock Unitree Go2 robot dog running Gemini Robotics-ER 1.6, reached through its own camera and mic and driven to physical movement, no human in the loop. Underneath the demo is a measurement problem:

CONGRESS

BLACKHAT 2026 USA

2026

Sift or Get Off the PoC: Applying Information Retrieval to Vulnerability Research You bought an IoT device, extracted the firmware, and dropped the main runtime binary into your favorite reverse engineering tool. Now you're staring at thousands of decompiled functions with no source, no symbols, and no obvious place to start bug hunting. How might an LLM help find signal in the noise, even before you've clearly established what "signal" looks like?

CONGRESS

BLACKHAT 2026 USA

2026

Tractor ECU RE: When a Noise Triggered Recall is Also a Security Patch Tractor brake controllers are assumed to be isolated from the trailer's noisy powerline network. This research proves that assumption false. In 2024, a major North American recall was issued for Bendix EC80 brake controllers, citing "memory corruption from power-line noise" as the cause.

CONGRESS

BLACKHAT 2026 USA

2026 When AI Attacks AI: Inside the Self-Propagating Botnet Built on Compromised AI Infrastructure ShadowRay 2.0 is the first in-the-wild campaign where AI infrastructure is not just targeted, but weaponized into a self-propagating botnet. In this Briefing, we will present concrete evidence of a global operation exploiting Ray, an open-source framework often referred to as the "Kubernetes of AI", to autonomously spread across more than 230,000 exposed servers.

CONGRESS

BLACKHAT 2026 USA

2026

Blind Trust in the 6 GHz Band: Weaponizing Wi-Fi Automated Frequency Coordination (AFC) Driven by rapid device growth and congestion in legacy bands, the 6 GHz spectrum is critical for next-generation Wi-Fi, but it is shared with mission-critical incumbents such as fixed microwave links and cellular backhaul. To enable safe sharing of the band and prevent interference, the FCC mandates Automated Frequency Coordination (AFC), a cloud-based control plane that dictates allowed channels and transmit power to standard-power 6 GHz access points based on their geolocation

CONGRESS

BLACKHAT 2026 USA

2026 ChatMate: Remote Prompt Execution on AI Assistants through Sandbox Escaping Imagine a user asks an LLM a question about a document. An attacker then gains an interactive prompt on the user's chat session, enabling the attacker to instruct the AI assistant to take actions on behalf of the victim.

CONGRESS

BLACKHAT 2026 USA

2026

Closed Loop: From Autonomous Exploit to Deployed Defense in Under 5 Minutes The median time-to-exploit for actively targeted vulnerabilities is now measured in hours, not weeks. CVE-2026-33017 went from advisory to confirmed exploitation in 20 hours. React2Shell saw state-sponsored exploitation within hours of disclosure. When I ran the security programs at Updater, ezCater, and CLEAR, we were following industry standards, patching criticals on 14-to-30-day cycles.

CONGRESS

BLACKHAT 2026 USA

2026

Could a Pattern on Your Clothing Fool Facial Recognition? Facial recognition evasion research has a costume problem. Masks, infrared LEDs, real-time face swaps, adversarial makeup. Every approach either requires active electronics, makes you look like a Batman villain, or replaces your face with someone else's. None of them scale. None of them are subtle. And none of them actually attack the model.

CONGRESS

BLACKHAT 2026 USA

2026 One Percent of the Tokens, All of the Strategy: LLM-Assisted Vulnerability Discovery in IoT and Embedded Firmware Progression of IoT and embedded devices is still outpacing security community's assessment capabilities, despite many standards being raised in recent years. Due to the volume of distinct software and hardware stacks, proprietary protocols and heterogenous platform design, it is economically infeasible to manually analyze every device at the rate devices ship.

CONGRESS

BLACKHAT 2026 USA

2026

Policy Meetup Join fellow policy professionals for this interactive meetup session, an informal, semi-structured conversation on national and international cyber policies, all those hard problems which span more than just a single enterprise.

CONGRESS

BLACKHAT 2026 USA

2026

Render Safe: Reverse Engineering and Exploiting an EOD Robot Remotely operated systems are increasingly integral to modern operations, with explosive ordnance disposal (EOD) robots serving as some of the earliest pioneers of deployed robotics. This Briefing provides a deep technical analysis into the architecture, attack surface, and 25-year evolution of iRobot's PackBot.

CONGRESS

BLACKHAT 2026 USA

2026 Root From Kilometers Away: Ubiquiti AirMax RCE You don't realize it until you see them; they are everywhere. From Wireless ISPs links, to the frontline of modern warfare. But no one found anything?

CONGRESS

BLACKHAT 2026 USA

2026

You Can't Patch a Mental Model: How Agentic Systems Expose our Hidden Security Assumptions Agentic security is not hard because it is new. It is hard because it violates the assumptions our security models are built on.

CONGRESS

BLACKHAT 2026 USA

2026 !secure: A Single Wrong Negation to Root Linux and Escape Managed Containers A single-line logic error in the Linux kernel's networking stack -- present for years and reachable without privileges -- results in a use-after-free that gives any unprivileged local user a deterministic path to root on Ubuntu 24.04, and from a default Kubernetes pod to full node compromise on managed cloud services -- demonstrated on 2 cloud providers.

CONGRESS

BLACKHAT 2026 USA

2026

A 0-Click Exploit Chain for the Pixel 10 Attackers are often reported to target mobile devices with 0-click exploits, but limited information is available about how such exploits work on modern Android devices. This Briefing will explain how Project Zero exploited two vulnerabilities to compromise a Google Pixel 9 remotely, without user interaction. It will then explain how we chained a different privilege escalation vulnerability to exploit the Pixel 10.

CONGRESS

BLACKHAT 2026 USA

2026

Batch Me If You Can: Breaking With the State‑of‑the‑Art of Fuzzing Cryptographic Architectures BGP routing underpins the entire Internet and RPKI is supposed to keep it safe. We found 21 new vulnerabilities across every major RPKI vendor, including critical RCE and DoS bugs. We received 8 CVEs so far with CVSS of 7.5 - 9.8. Each vulnerability can downgrade routing protection or worse, expose the server running the validator to hostile takeover.

CONGRESS

BLACKHAT 2026 USA

2026 Beyond Detection: What We Learned Testing Every AI Approach to Vulnerability Classification There has been considerable discussion on how to use AI to find vulnerabilities, but very little discussion on how to use it to _classify_ vulnerabilities. Given the huge backlog of vulnerabilities in our systems, and the agentic coding revolution which will 100x them, a new approach is needed to accurately cull and rank issues.

CONGRESS

BLACKHAT 2026 USA

2026

Born Corrupted: How We Backdoored Trusted Language Binaries I know. You can audit your dependencies, pin your versions, verify signatures, and stick to trusted downloads. But what happens when you're pwned before you even start?

CONGRESS

BLACKHAT 2026 USA

2026

Breaking Recently Deployed Spectre v2 Mitigations: A Novel Attack Primitive Recently deployed Spectre v2 mitigations neutralize branch predictor state through domain isolation or sanitization. Neutralization occurs when switching privilege contexts, or immediately prior to indirect branch execution. Once neutralized, the predictor state is assumed to remain free from attacker influence until it is used.

CONGRESS

BLACKHAT 2026 USA

2026 Catch Me If You Can: AI Investigators Hunting Autonomous Attackers as a Benchmark Attackers are already using AI agents in their workflows. Defenders are still evaluating theirs against stale benchmarks that profile yesterday's attackers. These evaluations do not capture a battle at machine speed where AI agents go toe-to-toe. We propose a new methodology in which blue and red agents fight it out on live infrastructure.

CONGRESS

BLACKHAT 2026 USA

2026

One Key to Rule Them All: Taking Over a Flagship Cloud Service In this Briefing, we'll break down how we took over a major cloud provider's managed database service. We'll walk through the entire attack chain: escaping a custom .NET sandbox, moving laterally through internal infrastructure, and ultimately extracting a master key that granted admin access to every customer database on the platform.

CONGRESS

BLACKHAT 2026 USA

2026 Pedal to the Bare Metal: Rehosting and Fuzzing the Tesla Wall Connector to Start a Worm Bare-metal embedded systems are notoriously difficult to secure, which is worrying, as exploits in this domain can blow things up and shut things down. So far, research on this type of embedded system has been rare because automated security analysis techniques were unavailable. Now, after our seven-year-long research on rehosting-based firmware fuzzing, a technique that allows firmware to run in an auto-generated execution environment, finding security vulnerabilities in bare-metal firmware has become feasible at scale.

CONGRESS

BLACKHAT 2026 USA

2026

Render Safe Live: EOD PackBot Demonstration Remotely operated systems are increasingly integral to modern operations, with explosive ordnance disposal (EOD) robots serving as some of the earliest pioneers of deployed robotics. This live demonstration (following the Briefing - Render Safe: Reverse Engineering and Exploiting an EOD Robot) will showcase the robot and its interface after the main talk. Come see how a bomb disposal robot is controlled and get a chance to have a live Q &A with the original researchers and speakers for this talk.

CONGRESS

BLACKHAT 2026 USA

2026

Beyond Seccomp: Breaking and Rebuilding Syscall Filtering for Microservices

In cloud-native environments, system calls serve as both the primary attack surface and the last line of defense for containers. However, widely deployed commercial container security tools still inherit structural design limitations that create critical blind spots when protecting microservices.

CONGRESS

BLACKHAT 2026 USA

2026 Bye Bye AI: How We Hacked the AI Shopping Assistant of a Top 3 US Retailer AI agents have become powerful digital touchpoints in retail, guiding product discovery, influencing purchases, and acting as the front door to the customer experience. For major retailers, these assistants are a core marketing and sales channel used by millions of shoppers daily. Unfortunately, they are also far easier to compromise than most organizations realize.

CONGRESS

BLACKHAT 2026 USA

2026

Detection Engineering Beyond the Inbox Email gateways fail to detect 63% of targeted phishing in operationally-constrained environments, from our 18-month deployment processing 2.3M+ daily emails. Every industry has structural operational requirements creating email security blind spots gateways cannot solve.

CONGRESS

BLACKHAT 2026 USA

2026 GitHub Can Tell You're Being Hacked. You're Just Not Listening: Building EDR for GitHub from Its Own Event Stream Open-source repositories are critical infrastructure, yet GitHub - where supply chain attacks often originate - remains largely unmonitored. We studied dozens of real-world supply chain attacks spanning 2018–2026 and built a behavioral anomaly scoring model to determine what defenders can detect from GitHub platform telemetry combined with direct Git object-level inspection.

CONGRESS

BLACKHAT 2026 USA

2026

Hunting LANDFALL: From Overlooked Images to State-Linked Mobile Spyware In mid-2024, a set of malformed DNG image files carrying a fully-featured Android spyware were uploaded to VirusTotal from Iraq, Iran, and Morocco.

CONGRESS

BLACKHAT 2026 USA

2026 LANJack: Turning Ads into IoT Recon Tools You visit a legitimate website. A trusted brand advertisement loads. Nothing looks suspicious. No phishing page, no exploit kit, no visible signs of an attack. Meanwhile, your browser is silently scanning your internal network, mapping your LAN and identifying connected devices.

CONGRESS

BLACKHAT 2026 USA

2026

Policy Meetup: Government Panel Discussion on AI and the New Era of Cyber Resilience Agentic AI has moved the security conversation past scale and speed.

CONGRESS

BLACKHAT 2026 USA

2026 Thinking Beyond the Code: Contrarian Thinking to AI and Lessons From a Life in Discovery In an era increasingly defined by the algorithmic logic of Large Language Models, the true frontier of security isn't just about better code—it's about seeing the world differently. This Briefing explores the "Mudge" philosophy: a focus on understanding the belief systems and incentive structures that underpin our environment to find the hacks others miss.

CONGRESS

BLACKHAT 2026 USA

2026

Turning Enterprise Update Servers Into Backdoor Factories (0_o) Windows Server Update Services (WSUS) sits at the heart of enterprise patch management, responsible for distributing updates across thousands of endpoints. Its privileged position in the network makes it a high-value target.

CONGRESS

BLACKHAT 2026 USA

2026 When Queues Become Vulnerabilities: Reverse Engineering GCD, XPC Races, and macOS Detection Engineering While many macOS services rely on Grand Central Dispatch (GCD) for concurrency, the underlying kernel integration is often treated as a black box, even by experienced engineers.

CONGRESS

BLACKHAT 2026 USA

2026

A Front-Row Seat to APT Operations: How OPSEC Failures Exposed a Malware Supplier We have spent years tracking adversaries across the Asia-Pacific region. This Briefing presents what may be our most revealing case: a single OPSEC failure by a malware supplier that didn't just expose one campaign — it exposed an entire ecosystem.

CONGRESS

BLACKHAT 2026 USA

2026 AI and the Future of Cyber Defense Panel AI and Cyber from Frontier AI models are crossing capability thresholds that reshape both the offensive and defensive sides of cybersecurity.

CONGRESS

BLACKHAT 2026 USA

2026

Burning Tears of PHP's Memory Hardening PHP introduced new heap hardening measures for its heap allocator, ZendMM, in April 2024. This Briefing asks a simple question: how much protection do these latest mitigations really buy against a determined attacker?

CONGRESS

BLACKHAT 2026 USA

2026 C and Its Consequences: The Source Is Just a Suggestion int x = k; if (x == 1 && x == 2) { printf("this is possible"); } Modern compilers don't mindlessly translate your code - they entirely rewrite it. By the time C reaches machine code, it's been reshaped by frontend lowering, IR optimizations, register allocation, and backend codegen - a deep, multi-stage pipeline making decisions you can't see.

CONGRESS

BLACKHAT 2026 USA

2026

Defensive V Offensive? - How Do We Balance The Needs Of The Many The UK like many countries must balance the offensive and the defensive. Since 2016, the NCSC has worked to make the UK the safest place to live and work online, where we counter cyber threats from adversaries planning to do us harm.

CONGRESS

BLACKHAT 2026 USA

2026 From Prompts to Pipelines: Building Agentic Detection Engineering and Threat Hunting Detection engineering and threat hunting remain bottlenecked by the gap between threat intelligence and deployed defenses.

CONGRESS

BLACKHAT 2026 USA

2026

Managing Security Culture Half Life This Briefing pairs two consecutive CSOs from the same high-profile organization — the Democratic National Committee, breached by two Russian intelligence services in 2016 — to examine what the security industry almost never gets to see: an honest succession.

CONGRESS

BLACKHAT 2026 USA

2026 Pre-auth RCE in Enterprise Java: When Middleware Becomes the Exploit Enterprise Java platforms still expose critical pre-authentication attack paths through middleware features that were never designed to handle untrusted input.

CONGRESS

BLACKHAT 2026 USA

2026

Threat Modeling LLMs: The PHANTOM-B model Security engineers shipping LLM products face a painful mismatch: the threat landscape is complex and evolving, the boss wants it deployed yesterday, and existing resources — MITRE ATLAS, NIST AI RMF, hundreds of academic papers — are built for thoroughness, not speed.

CONGRESS

BLACKHAT 2026 USA

7.8.26

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since Vulnerebility The Hacker News

7.8.26

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) Attack The Hacker News

7.8.26

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle Phishing The Hacker News

7.8.26

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle , generated and proved new HTTP AI The Hacker News

7.8.26

Cracking Kynx: The Stealer Hunting for Your Wallets, Games, and AI Tools Infostealers are a rapidly evolving threat, enabling various adversaries, ranging from ransomware groups and hacktivists to nation-state actors, to exploit stolen credentials for unauthorized access to sensitive resources. Virus SOCRADAR

7.8.26

Snowflake Hacker Pleads Guilty, Faces 32 Years Snowflake hacker Connor Riley Moucka pleaded guilty on August 5, 2026, in the U.S. District Court for the Western District of Washington, admitting to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count tied to the 2024 breaches of Snowflake customer accounts. CyberCrime SOCRADAR

7.8.26

Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) AhnLab SEcurity intelligence Center (ASEC) recently confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. Xctdoor was disclosed through the ASEC blog in 2024, and In March 2026, Hauri disclosed an attack case in which the malware was disguised as an integrated security program. Hack AHNLAB

7.8.26

CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker who lures an authenticated user to a malicious site perform unauthorized actions through Zeppelin’s REST and WebSocket endpoints. Vulnerebility OX

7.8.26

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables. Virus The Hacker News

7.8.26

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's AI The Hacker News

7.8.26

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating Hack The Hacker News

7.8.26

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts Zapscape , a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM Vulnerebility The Hacker News

6.8.26

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of Vulnerebility The Hacker News

6.8.26

New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel Hack The Hacker News

6.8.26

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan ICS The Hacker News

6.8.26

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains . Introduced in Cryptocurrency The Hacker News

6.8.26

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. OS The Hacker News

6.8.26

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post- Attack The Hacker News

6.8.26

AWS, Google, and Vercel Patch Agent Flaws That Let Tool Calls Skip the Model Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of Vulnerebility The Hacker News

6.8.26

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. Virus The Hacker News

6.8.26

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel , the Ransom The Hacker News

6.8.26

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild , according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The Exploit The Hacker News

6.8.26

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related CyberCrime The Hacker News

6.8.26

IBM report sees deep fakes emerging as top AI attack threat IBM study finds deepfake attacks now account for nearly half of AI-enabled breaches as organizations grapple with rising costs and expanding cyber risks. AI BARRACUDA

6.8.26

Malware signing: When trust becomes an attack surface How cybercriminals use stolen, fraudulent, and commercialized code-signing certificates to make malware appear legitimate and bypass traditional trust controls. Virus BARRACUDA

6.8.26

Dark Web Market: Vortex Market Vortex Market describes itself as a “classic wallet escrow market,” and that self-description is accurate. It is a general-purpose Dark Web marketplace built around anonymous trade, vendor reputation levels, and cryptocurrency payments held in market-controlled wallets. CyberCrime SOCRADAR

6.8.26

Formula 1 Phishing Campaign & Kit Analysis SOCRadar Threat Research Unit (STRU) has identified and analyzed a sophisticated, multi-stage phishing campaign that exploits the high-intensity demand for Formula 1 Grand Prix tickets. Phishing SOCRADAR

6.8.26

Free tokens for sale: How fake signups drive AI fraud As AI models have become vastly more capable, these multifunctional tools are being used for a wide range of tasks—from coding and analysis to software testing, research, and vulnerability hunting. AI OKTA

6.8.26

QuickFox Supply Chain Attack Used to Deploy FDMTP Implant The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting, and an evolving FDMTP implant Hack FORTINET BLOG

6.8.26

Inside Greatness: Telegram-Distributed M365 AiTM PhaaS ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. Phishing ZEROBEC BLOG

6.8.26

Fake Bank of America "Action Needed" Phishing Email Deposits ScreenConnect Instead We recently came across a fake Bank of America message that closely imitates the targeted bank's visual style, layout, and branding – from the initial phishing email, to the eventual webpage that victims are redirected to. Phishing Huntress

6.8.26

Toolkit Installation via SQL Injection Shows the Classics Still Hit Huntress recently observed an incident that started with a "simple" SQL injection bug in an organization's vulnerable public-facing web app, and ended with OS-level remote code execution Hack Huntress

6.8.26

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads. Virus ELASTIC

6.8.26

The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 An exposed open directory at 193.233.202[.]17 caught an operator tied to The Gentlemen ransomware mid-intrusion, setting up a Windows domain for persistent access, credential theft, and lateral movement. The files left behind trace the full operation, from privileged account creation and LSASS dumping to security-product tampering and reverse tunnels. Virus HUNT.IO

6.8.26

Targeted Attack on Government Entities in the Middle East | Part 2 This is Part 2 of our two-part technical analysis on new tools used by an East Asia-linked threat actor targeting government entities in the Middle East. After ThreatLabz published Part 1 on the TELESHIM backdoor and MIXEDKEY loader, Kaspersky highlighted a related campaign in recent reporting. Virus Zscaler

6.8.26

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had Virus The Hacker News

6.8.26

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide AI The Hacker News

5.8.26

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) AI The Hacker News

5.8.26

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source AI The Hacker News

5.8.26

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Vulnerebility The Hacker News

5.8.26

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the Virus The Hacker News

5.8.26

77 evil twin Open VSX extensions Between July 26 and August 1, 2026, our monitoring systems identified 77 Open VSX extensions that beacon to the same newly registered domain. Each one republishes the name, namespace and description of a real, unrelated extension at a low version number, almost always 0.0.1, under an account that does not own the namespace and does not belong to the original author [example 1, example 2, example 3]. Hack MANIFOLD

5.8.26

A Massive Shai-Hulud Campaign Hits npm: +440 Packages Compromised, Over 2B Monthly Downloads A massive Shai-Hulud campaign hit npm, affecting over 2 billion monthly downloads of packages, the code contains the classic infostealer logic, and self propagating code. Virus OX SECURITY

5.8.26

ChainDrop supply chain compromise: Anatomy of a self-propagating worm Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others. Hack Microsoft blog

5.8.26

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default- Vulnerebility The Hacker News

5.8.26

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled Phishing The Hacker News

5.8.26

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup An unauthenticated attacker can read any file the service account can access on Gitea , the self-hosted Git platform, in versions 1.22.1 through Vulnerebility The Hacker News

5.8.26

Leaked n8n API Tokens Exposed Live Instances to Credential Theft GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers Vulnerebility The Hacker News

5.8.26

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were Virus The Hacker News

5.8.26

New DOUBLECUP ClickFix service hides malware in browser cache images A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. Virus BleepingComputer

5.8.26

Fake Roblox Xeno script launcher pushes infostealer, RAT malware Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. Virus BleepingComputer

5.8.26

N-able warns of N-central auth bypass flaw exploited in attacks N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. Vulnerebility BleepingComputer

5.8.26

ExfilSquad hackers leak info of over 100,000 UK police officers, staff A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. Incindent BleepingComputer

5.8.26

Inside the Underground Business of the Android BTMOB RAT malware Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. Virus BleepingComputer

5.8.26

OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. AI BleepingComputer

5.8.26

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. Vulnerebility BleepingComputer

5.8.26

Google Chrome may soon block New Tab hijacker extensions by default Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. Hack BleepingComputer

5.8.26

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber AI The Hacker News

5.8.26

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities ( Exploit The Hacker News

5.8.26

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. Virus The Hacker News

5.8.26

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code Phishing The Hacker News

4.8.26

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 Virus The Hacker News

4.8.26

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe Hack The Hacker News

4.8.26

How legitimate cloud platforms enable phishers to bypass MFA We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. Phishing SECURELIST

4.8.26

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue AI The Hacker News

4.8.26

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege Vulnerebility The Hacker News

4.8.26

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in Virus The Hacker News

4.8.26

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to Exploit The Hacker News

4.8.26

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. Virus The Hacker News

3.8.26

An analysis of incidents at Brazilian educational institutions Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe. Incindent SECURELIST

3.8.26

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or Hack The Hacker News

3.8.26

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Ransom The Hacker News

3.8.26

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. APT The Hacker News

3.8.26

PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and BigBrothers The Hacker News

3.8.26

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered Vulnerebility The Hacker News

3.8.26

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems Exploit The Hacker News

3.8.26

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily Vulnerebility The Hacker News

2.8.26

Rails patches critical Active Storage flaw with RCE potential A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). Vulnerebility BleepingComputer

2.8.26

Amgen says cloud data breach exposed patient health, proprietary info Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. Incindent BleepingComputer

2.8.26

Arch Linux disables AUR package adoption to stop malware flood Arch Linux disables AUR package adoption to stop malware flood Virus BleepingComputer

2.8.26

Online ad firm Adform’s script compromised to steal cryptocurrency Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. Cryptocurrency BleepingComputer

2.8.26

OpenAI says its new GPT 5.6 models are becoming more cost-efficient OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. AI BleepingComputer

2.8.26

Hacker uses DeepSeek AI to autonomously attack vulnerable servers A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. AI BleepingComputer

2.8.26

CISA warns of cyberattacks disrupting U.S. water utilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. BigBrothers BleepingComputer

2.8.26

ESET tracks rise in malicious AI skills and adaptable malware Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software AI BleepingComputer

2.8.26

Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. AI BleepingComputer

2.8.26

South Korea fines telco giant KT $39 million for customer data breach South Korea fines telco giant KT $39 million for customer data breach Incindent BleepingComputer

2.8.26

Network Anomaly Detection in KATA Once the attacker has breached the corporate network, subsequent stages of the attack often involve leveraging standard domain infrastructure protocols: using Kerberos, running DNS queries, accessing internal services, opening network shares, and other common networking actions. Security SECURELIST

2.8.26

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Cryptocurrency The Hacker News

2.8.26

JetBrains warns of critical TeamCity remote code execution flaw JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. Vulnerebility BleepingComputer

2.8.26

Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. APT BleepingComputer

2.8.26

VMware fixes three critical flaws allowing auth bypass, VM escapes Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. Vulnerebility BleepingComputer

2.8.26

Google says AI helped Chrome fix 1,072 security bugs in two releases Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. AI BleepingComputer

2.8.26

ShinyHunters claims Brinks Home breach, threatens to leak stolen data Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. Incindent BleepingComputer

2.8.26

Microsoft Teams vishing attacks lead to Chaos ransomware attacks Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. Ransom BleepingComputer

2.8.26

Analog Devices discloses data breach, says operations unaffected Analog Devices discloses data breach, says operations unaffected Incindent BleepingComputer

2.8.26

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. APT BleepingComputer

2.8.26

Anthropic confirms Claude is down worldwide Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to fail with a "529 Overloaded" message, including in Claude and tools that rely on its API. AI BleepingComputer

2.8.26

Cisco warns of FMC static credential flaw exploited in zero-day attacks Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. Vulnerebility BleepingComputer

2.8.26

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. CyberCrime BleepingComputer

1.8.26

OpenAI agent used exposed credentials at 4 services in Hugging Face breach In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. AI BleepingComputer

1.8.26

Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." Incindent BleepingComputer

1.8.26

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. AI BleepingComputer

1.8.26

Windows 11 KB5101684 update released with 42 changes and fixes Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. OS BleepingComputer

1.8.26

These near-mint ASUS Chromebook refurbs are only $145 Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade "A" rating, but it still only costs $144.97 (reg. $369.99) on sale. Security BleepingComputer

1.8.26

CubePilot drone software dev hit by DNS hijacking to intercept traffic CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. AI BleepingComputer

1.8.26

OpenAI models used Artifactory zero-days to escape to the internet JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. AI BleepingComputer

1.8.26

CISA shares advice on isolating vital systems during cyberattacks The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. ICS BleepingComputer

1.8.26

vBulletin fixes critical pre-auth RCE flaw with public exploit A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. Vulnerebility BleepingComputer

1.8.26

Is Your SSO Protected Against Modern Credential Attacks? A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. Security BleepingComputer

1.8.26

Over 24,000 exposed server BMCs leak password hash via decades-old flaw More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. Incindent BleepingComputer

1.8.26

Data breach at medical billing firm MCBS affects 1.26 million people Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. Incindent BleepingComputer

1.8.26

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites Attackers modified a JavaScript file served by advertising technology company Adform , turning it into a browser-side tool that rewrites Cryptocurrency The Hacker News

1.8.26

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing Vulnerebility The Hacker News

1.8.26

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake , a remote access trojan (RAT) that can capture webcam Virus The Hacker News

1.8.26

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in APT The Hacker News

1.8.26

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based Virus The Hacker News

1.8.26

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo Hack The Hacker News

1.8.26

[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups” issued by the Republic of Korea’s National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI). Ransom blog AHNLAB

1.8.26

Not Every Fox is Silver: Inside an AtlasRAT loader chain AtlasRAT is a Windows-based remote access malware. This report analyzes a four-stage in-memory loader chain—which begins with a Delphi executable that is disguised as AGE Flash Player—and its final RAT functionality. Malware blog AHNLAB

1.8.26

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner. Hacking blog AHNLAB

1.8.26

June 2026 Threat Trend Report on APT Attacks (South Korea) AhnLab monitored domestic APT (Advanced Persistent Threat) attacks—which are conducted covertly and persistently—using its own infrastructure. This report summarizes the classification and statistics on domestic APT attacks identified in June 2026 and describes the capabilities of each type of APT attack. APT blog AHNLAB

1.8.26

Bitdefender Threat Debrief | July 2026 This edition of the Bitdefender Threat Debrief covers the latest developments in the ransomware threat landscape, including Qilin’s fall from the number one rank in Top Groups. Other events featured in this release include the arrest of a Scattered Spider operator, the criminal act of ransom negotiation, and an update on the FortiBleed campaign. Cyber blog BITDEFENDER

1.8.26

Operation BlueDash: Multi-RMM Workplace Phishing ZeroBEC investigated a live Microsoft Teams-themed phishing operation that began with a "secure document" email and ended with the silent enrollment of the victim endpoint into attacker-controlled remote monitoring and management environments. Phishing blog ZEROBEC BLOG

1.8.26

Kali365 Ringer: Targeting Financial and Insurance Sectors ZeroBEC prevented a Kali365 device-code phishing attack targeting a financial, regulated customer environment. The lure used a missed-call notification and a trusted Google Sites wrapper before redirecting through Google redirector, OCI API Gateway, and a Cloudflare-protected Kali365 host. Phishing blog ZEROBEC BLOG

1.8.26

Inside JIVS PhishKit: A Domain-Adaptive Credential Harvester ZeroBEC prevented a coordinated mailbox credential-harvesting campaign targeting multiple users within the same Microsoft 365 organization. The messages used an authenticated but unrelated external sender, warned that each recipient mailbox had violated policy, and directed users to a live PHP phishing page on corychase[.]org. Phishing blog ZEROBEC BLOG

1.8.26

Apple Libnotify/notifyd Stack Overflow (CVE-2026-64739) — Discovered by ThreatBook XGPT On July 27, 2026, Apple released security updates for iOS 26.6 and iPadOS 26.6, fixing vulnerabilities across several components — Accessibility, Kernel, Libnotify, and WebKit. Among them is CVE-2026-64739, a stack-based buffer overflow in Libnotify/notifyd found and reported to Apple by ThreatBook XGPT. Vulnerebility blog THREATBOOK

1.8.26

Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection & Mitigation A remote code execution vulnerability in Fastjson affects every version up to and including 1.2.83. A remote attacker can run arbitrary code on a vulnerable server by sending it specially crafted JSON — no user privileges, no victim interaction, and no third-party libraries required. Exploit blog THREATBOOK

1.8.26

Threat Coverage Digest: New TI Report, Threat Research and 750+ Detection Rules July brought another set of threat coverage updates designed to help security teams work faster and with more confidence. ANY.RUN added 42 behavior signatures, 11 YARA rules, and 703 Suricata rules, giving SOCs broader visibility across files, malware behavior, and network activity. Security blog ANYRUN BLOG

1.8.26

The US CFO’s Playbook: How to Reduce Cyber Risk Without Scaling SOC Team in a Tight Labor Market Cyber risk is increasing, but so is the cost of managing it. More than 514,000 cybersecurity job listings appeared in the US between May 2024 and April 2025, while the mean annual wage for an information security analyst reached $132,510. Cyber blog ANYRUN BLOG

1.8.26

Building Resilience Against AiTM Phishing: What SOC Leaders Should Know Email gateways, endpoint controls, and file-centric sandboxing remain essential layers of defense. But many of today’s phishing attacks unfold in ways they weren’t designed to fully expose. Phishing blog ANYRUN BLOG

1.8.26

Infrastructure Health, Now Agentic: The IT Engineer Teammate Is Here Technology and infrastructure health is the foundation of the SOC. Investigations, threat hunts, and detection engineering all assume the same thing: the tools underneath are up, generating telemetry, and functioning as intended. Security blog RELIAQUEST

1.8.26

DNS Poisoning Tactics Expand to Hospitality Wi-Fi Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Hacking blog RELIAQUEST

1.8.26

The Five Questions Every Security Team Should Be Asking After the OpenAI–Hugging Face Incident On Tuesday, July 21, OpenAI reported that its own AI models were behind an unprecedented cyber incident against the open-source developer platform, Hugging Face. A combination of GPT-5.6 Sol, and a more capable, unreleased model broke out of a sandboxed testing environment, reached the public internet, and exploited a vulnerability to access Hugging Face's systems. AI blog RELIAQUEST

1.8.26

Fake Claude Install Guide Leads to MacSync Stealer and RAT: What We Pulled From the Attacker’s Servers Huntress recently investigated an incident where the victim searched Google for how to install Claude on a Mac, clicked a sponsored result, and landed on a weaponised claude.ai/share conversation dressed up as an Apple Support install guide. Malware blog Huntress

1.8.26

Huntress Threat Advisory: Widespread SonicWall Credential Stuffing Campaign Starting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins. These logins originated from a suspicious Autonomous System Number (ASN). Cyber blog Huntress

1.8.26

Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT Between July 21 and July 22, 2026, Huntress' Security Operations Center (SOC) lit up with a swathe of unusual executable installs, Defender exclusions, and anomalous persistence across 29 organizations, all coming from ClaudeDesktop.exe. Malware blog Huntress

1.8.26

Iran War’s Secondary Effects Shape 2026 US Violent Extremism Explore the 2026 US violent extremism threat landscape. This report analyzes rising risks from HVEs, DVEs, and Iran-nexus actors to public and BigBrother blog Recorded Futures

1.8.26

Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend Every stage of the Hugging Face breach maps to Elastic Defend and SIEM rules already shipping, from worker RCE and credential harvest to self-migrating C2 and GenAI detection. AI blog ELASTIC

1.8.26

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth. Cyber blog ELASTIC

1.8.26

What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support Elastic Defend automatically generates and instantly deploys vulnerable driver YARA rules from VirusTotal, LOLDrivers and Microsoft's blocklist, closing the gap BYOVD attacks depend on. Plus a new troubleshooting skill and ARM endpoint protection. Safety blog ELASTIC

1.8.26

Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here Elastic's first automatic migration from a modern SIEM. Translate your Sentinel detection rules into Elastic Security without rebuilding them. Security blog ELASTIC

1.8.26

Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called While conducting routine open-source research, NetAskari identified a malicious Android APK impersonating a Chinese Provincial Public Security Bureau service app. Analysis of the malware led to a Telegram channel distributing the source code for an undocumented Android application builder and device control framework called Flying Eagle (飞鹰). Malware blog HUNT.IO

1.8.26

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades NGINX sits in front of a large share of the internet's web traffic and Ghost CMS powers well over 100,000 publishing sites. Within months of each other earlier this year, critical vulnerabilities were found in both: NGINX Rift (CVE-2026-42945), a long-standing heap overflow in the rewrite module, and a blind SQL injection in the Ghost Content API (CVE-2026-26980). Exploit code for both became public quickly. AI blog HUNT.IO

1.8.26

Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Financ Disclosure note: This research was conducted jointly by Hunt.io and Bob Diachenko, security researcher and journalist. Thailand's national CERT and NCSA were notified on July 15, 2026, and acknowledged receipt the same day. Publication was held for the standard 7-day disclosure window. Exploit blog HUNT.IO

1.8.26

Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection Summary Arctic Wolf Labs has been tracking a cluster of campaigns built around CastleLoader, a multi-stage shellcode loader that has served as the backbone of Malware blog ARTICWOLF

1.8.26

Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit On 22 July 2026 (the day prior to Proofpoint’s joint release with the NSA), TA488 initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). APT blog PROOFPOINT

1.8.26

Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. Malware blog Zscaler

1.8.26

The AI era of cybercrime has arrived: The 2026 Cybercrime in the age of AI report New research reveals how AI is rewiring cybercrime today, and how you can prepare for what’s coming tomorrow. AI blog THREATDOWN

1.8.26

XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys Forensic Smokescreens Dive into a covert Linux XMRig campaign exploiting trusted access, weaponizing PAM to create forensic smokescreens, and deploying self-unlinking payloads. Exploit blog GROUP-IB

1.8.26

Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks In February 2026, Socket.dev published research on a multi-stage npm supply chain worm operating under the internal flag SANDWORM_MODE. The campaign spanned 19 malicious packages in total across two unique publisher aliases and demonstrated a new class of supply chain attacks that targeted AI-augmented development workflows. AI blog CROWDSTRIKE

1.8.26

CrowdStrike Joins the Open Secure AI Alliance to Advance AI Safety and Security CrowdStrike is an inaugural partner in the Open Secure AI Alliance, a new industry coalition built on a simple premise: securing the AI era requires open models, shared tools, and a massively distributed community of defenders. AI blog CROWDSTRIKE

1.8.26

Inside Astaroth's New Spambot Component Operators of the Astaroth botnet introduced a new spambot component, a sign of their evolving operations and an expanding LATAM eCrime ecosystem. BotNet blog CROWDSTRIKE

1.8.26

Falcon AIDR Now Protects Copilot Studio Agents and Claude Code New feature releases extend AI visibility, detection, and response capabilities to Microsoft Copilot Studio and Claude Code. AI blog CROWDSTRIKE

1.8.26

Chaos in Teams vishing Sophos analysts investigated a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas to gain remote access to victims’ systems. Phishing blog SOPHOS

1.8.26

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. APT blog GTI

1.8.26

Announcing InfraTrust, the source of intelligence on security risks across hardware infrastructure Today we’re excited to announce InfraTrust, a global hardware infrastructure security knowledgebase making mission critical infrastructure security data available faster, so you have it when you need it to defend your enterprise. InfraTrust is a searchable, continuously updated source of security advisories and risk data from major enterprise hardware infrastructure vendors. Cyber blog Eclypsium

1.8.26

APTs Top the List of Most Active Threat Actors in H1 2026 These are the most active threat actors in H1 2026 as APT groups lead global cyber operations, followed by ransomware and hacktivist campaigns. APT blog Cyble

1.8.26

Inside the Underground Economy: 5 Dark Web Trends Shaping the 2026 Threat Landscape Cyble breaks down how dark web ecosystems are evolving in 2026 with ransomware, initial access brokers, AI-driven attacks, and underground threat activity. CyberCrime blog Cyble

1.8.26

Fake invoices are moving from inboxes to shopping apps Scammers are using order-tracking apps to place fake receipts where users expect to see real purchases, then pushing them to call fake support numbers. GENDIGITAL

1.8.26

Email threat landscape: Q2 2026 trends and insights  In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains. Cyber blog Microsoft blog

1.8.26

Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to strengthen cyber defense. AI blog Trend Micro

1.8.26

Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave Between January and June 2026, TrendAI™ tracked more than 35,000 fake sites exploiting the 2026 FIFA World Cup, spanning counterfeit merchandise shops, cloned ticket pages, and bogus free-streaming sites, which together drew roughly 1.48 million visits from Japan. Hacking blog Trend Micro

1.8.26

The Signs Were There: What the First Autonomous Ransomware Case Confirms An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction. The autonomous attacks TrendAI™ Research predicted are beginning to arrive, and defending against them shifts from blocking known indicators to detecting behavior. AI blog Trend Micro

1.8.26

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan We analyzed a sustained tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets. Spam blog Trend Micro

1.8.26

Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It OpenAI’s own models broke out of a test sandbox and into Hugging Face’s servers to solve an evaluation, with no human attacker involved. The incident showed how keeping agentic AI safe now depends on how it’s contained, not just on how it’s trained. AI blog Trend Micro

1.8.26

Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure TrendAI™ Research breaks down what changed in CISA’s updated advisory on an ongoing PLC exploitation, why this activity might be more dangerous than a similar campaign in 2023, and how organizations can take action now to protect themselves. ICS blog Trend Micro

1.8.26

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement. Phishing blog Trend Micro

1.8.26

DbGate JSON Script Runner Unauthenticated Remote Code Execution SonicWall Capture Labs threat research team became aware of the threat CVE-2026-47668, assessed its impact, and developed mitigation measures. Vulnerebility blog SonicWall

1.8.26

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version After months of dormancy, the attackers behind the XCSSET malware released version 40 (v40), targeting the macOS ecosystem. This version’s advanced architecture hides its core logic in memory space, reducing its digital footprint. Malware blog Palo Alto

1.8.26

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact. AI blog Palo Alto

1.8.26

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses. Cyber blog CISCO TALOS

1.8.26

Black Hat special: Rewind and revisit Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence. Cyber blog CISCO TALOS

1.8.26

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN. Ransom blog CISCO TALOS

1.8.26

Preview: Cisco Talos at Black Hat USA 2026 Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk. Cyber blog CISCO TALOS

1.8.26

You were onto something with “It’s the Climb,” Miley Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar. Cyber blog CISCO TALOS

1.8.26

Don’t swing at everything Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever. Cyber blog CISCO TALOS

1.8.26

Begun, the Patch Wars have Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story. Cyber blog CISCO TALOS

1.8.26

The Hunter's Paradox: Is it time to embrace automated threat hunting? Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like. Cyber blog CISCO TALOS

1.8.26

Beyond the screenshot: Why you should verify what you see The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine Cyber blog Eset