Tag: usa
-
That’s a wrap: Mend.io at Black Hat USA 2026
Tags: usaMend.io at Black Hat USA 2026: keynote, podcasts, awards, and a hit booth game. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/thats-a-wrap-mend-io-at-black-hat-usa-2026/
-
China-Linked Surveillance Platform Spans at Least 117 Servers, Targets Routers
LightSpy, a China-linked surveillance platform, has grown into an operation using at least 117 servers with verified router infections. At Black Hat USA, Arctic Wolf researchers Dmitry Bestuzhev and Dmitry Melikov said LightSpy has been identified in more than 13 countries, growing well beyond the spyware, active since at least 2018 and publicly documented in…
-
Why ‘America First’ in AI Shouldn’t Mean ‘America Only’
Former US Cyber Director on Cooperation, AI Supply Chains and National Security. U.S. leadership in AI requires more than protecting domestic technology. Former U.S. National Cyber Director Chris Inglis says national security will depend on outperforming competitors, strengthening global supply chains and working with allies against shared AI risks. First seen on govinfosecurity.com Jump to…
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and First seen on…
-
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices First…
-
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own coding-agent repositories. On OpenAI’s, it was enough to hijack the next agent run.Novee Security ran the attack against each vendor’s agent in the configuration that the vendor ships by default,…
-
Contrast Security Launches CVE Shield for Runtime Exploit Protection
Contrast Security has launched CVE Shield, a runtime control that detects, monitors and blocks exploitation of known vulnerabilities in production applications and APIs while teams work on permanent fixes. Announced July 29 ahead of Black Hat USA 2026, CVE Shield operates inside running applications and uses a microsandbox for each supported CVE. Contrast said the..…
-
Check Point Puts AI Traffic Controls Into Its Existing Firewalls
Check Point has launched an AI Network Firewall that brings visibility and enforcement for AI applications, agents and Model Context Protocol traffic into the physical and virtual firewalls organizations already operate. Introduced July 30 ahead of Black Hat USA 2026, the product is delivered through Check Point’s AI Defense Plane and firewall software release R82.20……
-
1Password Adds Privileged Access Controls for Human and AI Identities
1Password has launched Privileged Access, extending its Unified Access platform into privileged access management with controls designed to remove standing permissions from human and AI identities. The July 28 launch came ahead of Black Hat USA 2026, where identity security and AI-agent controls are major themes. 1Password said Privileged Access provisions permissions when they are..…
-
Sophos, OpenAI Partner to Bring Frontier Models to Managed Service Providers
Sophos said it is partnering with OpenAI to bring OpenAI frontier models to managed service providers through Sophos Fusion, the company’s connected cyber defense system. Announced Aug. 6 during Black Hat USA 2026, the partnership is intended to give MSPs a way to deliver AI security services and build offerings around detection, investigation and response……
-
BeyondTrust Extends Pathfinder to AI Agents and Other Nonhuman Identities
BeyondTrust is extending its Pathfinder platform to cover AI agents, workloads and other nonhuman identities that can hold or exercise privileged access. The company announced the first wave of native Pathfinder capabilities at Black Hat USA 2026 on Aug. 3. The package includes PathfinderAI and a new MCP Server, AI Agent Security, NHI Governance and..…
-
Black Hat USA 2026: Solving insider risk in the agentic AI era
First seen on scworld.com Jump to article: www.scworld.com/perspective/black-hat-usa-2026-solving-insider-risk-in-the-agentic-ai-era
-
Researcher Claims Control of ChatGPT Secure Sandbox
A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT’s isolated sandbox during a session at Black Hat USA 2026. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/researcher-claims-control-chatgpt-secure-sandbox
-
Black Hat 2026: Barracuda Details AI-Powered BEC Attack
Barracuda’s Black Hat USA 2026 research shows how AI email assistants can accelerate business email compromise attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/black-hat-2026-barracuda-details-ai-powered-bec-attack/
-
Why Open-Weight AI Models Are Key to US Strategy
Rain Capital’s Chenxi Wang on Why Closed AI Models Risk US Competitiveness. Machine-scale AI attacks demand machine-scale defenses, says Rain Capital’s Chenxi Wang. She says America’s edge depends on backing open-weight models and using the world’s top AI researchers, not retreating behind closed systems that cede ground to competitors. First seen on govinfosecurity.com Jump to…
-
Photos: Black Hat USA 2026, part two
Tags: usaRound two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/black-hat-usa-2026-business-hall-photos/
-
Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera feeds. First seen on hackread.com Jump to article: hackread.com/black-hat-usa-tp-link-flaws-omada-credentials-camera-risk/
-
Photos: Black Hat USA 2026
Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors: Stellar Cyber, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/black-hat-usa-2026-photos/
-
Zenity Labs Finds Zero-Click Attack Chains Across Agentic Browsers
Zenity Labs released research at Black Hat USA 2026 showing zero-click PleaseFix exploit chains across Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge. The attacks demonstrated paths to silent data theft, credential theft, account takeover and remote control of a victim’s machine. PleaseFix abuses the way agentic browsers combine information..…
-
Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows
At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines. First seen on hackread.com Jump to article: hackread.com/black-hat-usa-2026-github-compromise-ai-coding/
-
Photos: Black Hat USA 2026 Arsenal
Tags: usaThis week Help Net Security is at the Mandalay Bay, where Arsenal is running alongside the Briefings. If you’ve never been, it’s the corner of Black Hat that feels … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/black-hat-usa-2026-arsenal-photos/
-
VanishID Previews AI Exploitability Management at Black Hat USA 2026
VanishID has unveiled AI Exploitability Management, a capability designed to measure what frontier AI could build from publicly exposed information about an organization’s people. The company is demonstrating the capability publicly for the first time at Black Hat USA 2026. VanishID said the system evaluates more than 40 AI-powered attack scenarios, including executive impersonation, real-time..…
-
Novee Brings Continuous AI Pentesting to Mobile Applications
Novee has expanded its AI penetration testing platform to mobile applications, extending continuous testing across mobile, web, APIs, desktop software and AI-enabled applications. The company announced the update ahead of Black Hat USA 2026. Novee said users can upload a mobile application package and receive results within hours, alongside findings from their other application assets……
-
Phoenix Security Launches Exploit Hunt to Validate Vulnerabilities With AI-Generated Exploits
Phoenix Security has launched Exploit Hunt, an AI red-team capability that works from a live threat model and reports a vulnerability only after generating and validating a runnable proof-of-concept exploit. Announced Aug. 5 and timed to Black Hat USA 2026, Exploit Hunt is available now in Phoenix Purple. It can run continuously, on every pull..…
-
Intel 471 Adds MCP Connector and Native AI Analyst to Verity471
Intel 471 has added two AI capabilities to its Verity471 cyber intelligence platform: MCP471, a connector for Model Context Protocol workflows, and Agent471, a native AI analyst. The capabilities are being demonstrated at Black Hat USA 2026 from Aug. 4 to 6. Intel 471 said the additions are designed to bring pre-attack intelligence and threat-hunting..…
-
Stairwell Launches Backstory to Map Malware Blast Radius Beyond the First Alert
Stairwell has launched Backstory, an agentic investigation platform designed to trace related malware variants, identify affected systems and map an incident’s full blast radius. The platform was announced July 29 as Stairwell prepared to showcase it at Black Hat USA 2026. Backstory is built to answer what happened, where an incident spread and what needs..…
-
BlackCloak Expands Impersonation Protection to Executives’ Trusted Circles
BlackCloak is expanding its Impersonation Protection service with a “circle of trust” feature designed to help executives verify communications from the people closest to them. The company announced the capability ahead of Black Hat USA 2026 in Las Vegas. Impersonation Protection lets members authenticate phone calls, video meetings, emails, WhatsApp and Slack messages, texts, and..…
-
7AI Launches Federated SIEM and Build Tools Ahead of Black Hat USA 2026
7AI has launched 7AI Federated SIEM and 7AI Build, two capabilities designed to give security teams a distributed foundation for AI-assisted operations. The company said both will be showcased at Black Hat USA 2026. 7AI Federated SIEM connects to security data across existing SIEMs, data lakes and cloud platforms. It lets teams query, investigate and..…

