CODY KELLER

Hacker Summer Camp wrapped up last week. Black Hat USA 2026 ran August 1-6 at Mandalay Bay, DEF CON 34 followed August 6-9 at the Las Vegas Convention Center, and somewhere north of 50,000 security professionals spent the better part of two weeks in 105-degree heat talking about the things that are going to show up in your incident reports over the next twelve months.

If you attended, you already have your own notes and opinions. If you didn’t, here’s the debrief — not a vendor announcement roundup, but the signal that actually matters for practitioners who have to do something on Monday morning.

Start Here: What Your Program Should Actually Do

Before the context and the conference breakdown, here’s the short list of what comes out of this year’s Hacker Summer Camp that deserves action:

  • Audit your AI workload infrastructure scope. If GPU infrastructure is running AI workloads in your cloud environment, GPUBreach means it belongs in your cloud security program. This is no longer theoretical.
  • Check your macOS patch status immediately. CVE-2026-28860 is a credential extraction vulnerability requiring no elevated privileges. If your Mac endpoints aren’t patched, this is a priority item this week.
  • Review your AI-generated patch process. If your AppSec or development program is using AI to generate fixes, new research shows 54% of those patches don’t fully remediate the vulnerability. Human review before deployment is no longer optional.
  • Add AI browser and agent prompt injection to your threat model. If agentic tools are deployed or being evaluated, the PleaseFix research means your security review of those tools needs to include cross-origin request handling and prompt injection resistance.
  • Socialize the ransomware mortality data with healthcare leadership. Peer-reviewed Medicare claims data now shows in-hospital mortality running 34-38% higher during ransomware attacks. If you’re in healthcare or advising healthcare clients, this changes the board-level risk conversation.
  • Watch the non-human identity vendor space but buy carefully. Every major vendor shipped an agent governance product this week. The problem is real. Most of the solutions are v1 capability at v2 marketing. Evaluate against your actual risk register gaps.

That’s the action list. Here’s the context behind it.

The Federal Government Came to Make a Point

The opening keynote at Black Hat wasn’t a researcher. It was the federal government — and not in a symbolic capacity. White House National Cyber Director Sean Cairncross, CISA Acting Director Nick Andersen, FBI Cyber Division Assistant Director Brett Leatherman, and the Department of War’s principal cyber advisor all took the stage together for the first time in Black Hat’s 29-year history.

That’s a deliberate signal, not a scheduling coincidence. The administration sent its senior civilian cyber leadership to a practitioner conference because the gap between policy and operational reality has become impossible to ignore. The subject was AI’s effect on both offensive and defensive cyber operations — which tells you something about where the policy conversation currently sits. It’s no longer about whether AI changes the threat landscape. It’s about how fast and what to do about it.

Whether the collaborative posture Cairncross described materializes operationally remains to be seen. But the fact that they showed up and made the case in front of that audience matters. Government isn’t just watching this fight anymore.

The Research That Changes What You Defend Against

AI is finding vulnerabilities at a scale humans can’t match — and that cuts both ways.

Unit 42 published results from NOVA, an autonomous vulnerability research system that analyzed 3,915 open source projects over two months and confirmed 14,090 vulnerabilities. Ninety-nine point four percent had not previously been reported, and 39.7% were rated High or Critical under CVSS 4.0.

An autonomous AI system found roughly 14,000 previously unknown vulnerabilities in two months. If offensive researchers — and threat actors — have access to equivalent capability, the window between vulnerability existence and exploitation is compressing in ways that fundamentally challenge traditional vulnerability management programs.

On the flip side: 1Password’s Off-By-1 Labs research found that 54% of AI-generated vulnerability patches do not fully remediate the target vulnerability and sometimes introduce new ones, based on evaluation of over 6,000 patches across recently disclosed, complex vulnerabilities in open source software.

So AI finds vulnerabilities faster than humans can discover them, and AI patches half of them incorrectly. If your development or AppSec program is leaning on AI-generated patches as a shortcut, that research is a direct challenge to that posture.

The attack surface moved to the hardware under AI.

GPUBreach — opening research at Black Hat — demonstrated the first Rowhammer attack capable of escalating from NVIDIA GDDR6 GPU memory to a host root shell, bypassing IOMMU protections. GPU infrastructure is now running AI workloads at scale across cloud environments. What was previously theoretical about Rowhammer at the hardware level is now a documented, working attack chain against the infrastructure most organizations are actively scaling.

AI browsers and agents have a prompt injection problem that guardrails aren’t solving.

Research presented at Black Hat documented the PleaseFix class of vulnerabilities, showing that AI browsers from major vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, highlighting weaknesses in how they handle cross-origin requests. An AI agent that can be manipulated by a malicious web page it visits is not a controlled tool. It’s an attack surface.



What DEF CON 34 Told Us That Black Hat Didn’t

DEF CON and Black Hat cover the same week and share a lot of the same attendees, but they have different DNA. Black Hat is where enterprise security and the research community meet at a professional register. DEF CON is where the most technically aggressive research gets presented, where the villages surface niche threats before they become mainstream, and where the cultural temperature of the security community is most visible.

DEF CON 34 ran under the theme “Agency” and hosted the conference’s first autonomous-only CTF — called HALctf — where AI agents pursue targets without real-time human control. Autonomous offensive AI systems that can run attack chains without a human in the loop are being built and tested right now, in a competitive environment, by the research community. What performs well at DEF CON CTFs tends to show up in threat actor toolkits within 12-18 months.

The macOS Keychain vulnerability (CVE-2026-28860) presented at DEF CON’s main stage demonstrated a technique capable of extracting all passwords stored within the Keychain — requiring neither root privileges, a user password, nor any user prompts. If your organization has Mac endpoints and hasn’t patched this, that’s a current priority.

The DEF CON Cloud Village featured research on Azure MCP vulnerabilities showing attack chains including managed identity token theft, never-expiring write SAS tokens dumped from Microsoft’s own backend, and MCP credential relay delivered remotely through prompt injection with no network access to the target. For organizations running Azure, this documents an attack chain combining managed identity governance failures, SAS token lifecycle gaps, and MCP security weaknesses into a single kill chain.

The ransomware-kills-patients data finally has peer review behind it.

A DEF CON Creator Stage session referenced a peer-reviewed analysis of Medicare claims published in the American Economic Journal showing in-hospital mortality running 34 to 38 percent higher during ransomware attacks on hospitals.

The cybersecurity community has made this argument for years without solid data. Now there’s peer-reviewed, claims-based evidence. For GRC professionals in healthcare — and for anyone managing healthcare vendor risk — this data belongs in your risk register and in your executive briefings. Ransomware in healthcare is not a data breach. It’s a patient safety event with documented mortality impact. That distinction changes how it gets resourced and prioritized.



The Vendor Floor: What to Take Seriously

Every major security vendor shipped an agent governance product this week. Identity vendors launched controls for non-human identities, SOC platforms added agent-specific detection, and endpoint tools built to police AI coding agents — the pattern across vendor announcements was consistent: agentic AI governance is the product category of 2026.

Most of it is v1 capability at v2 marketing. Apply the same filter from the RSA recap in March: does this announcement address a problem documented in your risk register right now? If yes, evaluate it. If not, watch file.

The exception: anything in the identity space tied to non-human identity governance is solving a real problem that exists in your environment regardless of whether it’s in your risk register. We covered this in the May 13 post. The vendor market has now caught up to the problem. That makes procurement conversations more viable — it doesn’t make them less careful.

The research presented at Black Hat and DEF CON doesn’t stay in Las Vegas. It typically takes six to eighteen months to move from conference stage to real incident reports. Programs that adjust now are ahead of the curve. Programs that don’t tend to recognize the research again when they’re writing the postmortem.


Discussion Questions

  1. Does your cloud security program include AI workload infrastructure — GPU instances, model serving environments, AI pipeline components — in its scope? If not, what would trigger adding it?
  2. How does your AppSec program handle AI-generated patches? Is there a human review step before those patches are deployed, or is the AI output treated as production-ready?
  3. If you’re in healthcare or manage healthcare vendor risk, how is ransomware represented in your risk register — as a data breach scenario or as a patient safety scenario? Does that distinction change how it’s resourced?

Further Reading


Leave a Reply

Your email address will not be published. Required fields are marked *