Black Hat

Black Hat

Creator
0 followers

Cutting-edge enterprise security research talks

Black Hat USA 2025 | China's 5+ Year Campaign to Penetrate Perimeter Network Defenses
VideoMar 13, 2026

Black Hat USA 2025 | China's 5+ Year Campaign to Penetrate Perimeter Network Defenses

The Black Hat talk detailed a multi-year, state-linked campaign by Chinese threat actors aimed at compromising perimeter firewalls and the networks they protect. Presenter Andrew Brandt, a principal threat researcher formerly at Sophos, walked through the evolution of the operation,...

By Black Hat
Black Hat USA 2025 | How to Secure Unique Ecosystem Shipping 1 Billion+ Cores?
VideoMar 11, 2026

Black Hat USA 2025 | How to Secure Unique Ecosystem Shipping 1 Billion+ Cores?

At Black Hat USA 2025, Nvidia’s offensive security director Adam Zabrai and system software manager Marco Midik outlined how the company secures a sprawling ecosystem that now ships more than one billion processor cores across data‑center GPUs, consumer graphics, Jetson...

By Black Hat
Black Hat USA 2025 | Breaking Control Flow Integrity by Abusing Modern C++
VideoMar 10, 2026

Black Hat USA 2025 | Breaking Control Flow Integrity by Abusing Modern C++

The Black Hat talk explains how modern C++ coroutines undermine traditional control‑flow‑integrity (CFI) defenses. While CFI has become standard in operating systems and compilers, the presenter shows that coroutine‑generated frames and indirect resume calls open a novel attack surface. CFI works...

By Black Hat
Black Hat USA 2025 | Vulnerability Haruspicy: Picking Out Risk Signals From Scoring System Entrails
VideoMar 10, 2026

Black Hat USA 2025 | Vulnerability Haruspicy: Picking Out Risk Signals From Scoring System Entrails

The talk at Black Hat USA 2025 explored the limits of traditional vulnerability scoring, focusing on CVSS, the emerging EPSS exploit‑prediction model, and newer frameworks such as Pipeline VSS and AI‑VSS. Todd used the ancient haruspex analogy to illustrate how...

By Black Hat
Black Hat USA 2025 | Advanced Bypass Techniques and a Novel Detection Approach
VideoMar 10, 2026

Black Hat USA 2025 | Advanced Bypass Techniques and a Novel Detection Approach

The Black Hat USA 2025 presentation by Itai Ravia of AIM Security highlighted a growing crisis in AI supply‑chain security: third‑party models can execute malicious code during loading or inference, and back‑door inputs can be silently injected by model authors. Ravia explained that model...

By Black Hat
Black Hat USA 2025 | How Tree-of-AST Redefines the Boundaries of Dataflow Analysis
VideoMar 9, 2026

Black Hat USA 2025 | How Tree-of-AST Redefines the Boundaries of Dataflow Analysis

At Black Hat USA 2025, researchers presented Tree-of-AST, a novel dataflow-analysis approach that adapts tree-based generative reasoning techniques (inspired by Tree-of-Thoughts) to program ASTs to more effectively trace sources to sinks and reason about sanitizers. The presenters — including a...

By Black Hat
Black Hat USA 2025 | Digital Dominoes: Scanning the Internet to Expose Systemic Cyber Risk
VideoMar 8, 2026

Black Hat USA 2025 | Digital Dominoes: Scanning the Internet to Expose Systemic Cyber Risk

The Black Hat USA 2025 talk introduced a novel method for measuring systemic cyber risk, branding it as a "digital domino" problem where failures in a single vendor can topple entire industry chains. Morgani, head of cyber catastrophe modeling at...

By Black Hat
Black Hat USA 2025 | Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Apps
VideoMar 8, 2026

Black Hat USA 2025 | Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Apps

The Black Hat USA 2025 talk introduced MCAN, a novel framework for detecting taint‑style vulnerabilities in microservice‑structured web applications. The presenters highlighted how modern architectures replace monoliths with independent services behind a gateway, creating new attack surfaces where malicious input...

By Black Hat
Black Hat USA 2025 | Reinventing Agentic AI Security With Architectural Controls
VideoMar 6, 2026

Black Hat USA 2025 | Reinventing Agentic AI Security With Architectural Controls

At Black Hat USA 2025, David Brockle III of NCC Group opened his briefing by framing AI security as a modern parallel to the early web’s reliance on firewalls. He argued that today’s AI guardrails function like statistical heuristics—useful but...

By Black Hat
Black Hat USA 2025 | Use and Abuse of Palo Alto's Remote Access Solution
VideoMar 5, 2026

Black Hat USA 2025 | Use and Abuse of Palo Alto's Remote Access Solution

The presentation examined Palo Alto’s GlobalProtect remote‑access solution, focusing on its split‑tunnel feature that lets administrators whitelist domains such as *.zoom.us to bypass the VPN. The speaker, a security engineer with pentesting background, demonstrated how the feature intertwines DNS resolution...

By Black Hat
Black Hat USA 2025 | Turning Camera Surveillance on Its Axis
VideoMar 5, 2026

Black Hat USA 2025 | Turning Camera Surveillance on Its Axis

At Black Hat USA 2025, Noam Moshe of Claroty Team82 exposed a critical flaw in Axis Communications’ Access Remoting protocol, the encrypted channel used by enterprises to manage fleets of IP cameras remotely. The protocol, built on MTLS and NLMSSP authentication,...

By Black Hat
Black Hat USA 2025 | Lost & Found: The Hidden Risks of Account Recovery in a Passwordless Future
VideoMar 3, 2026

Black Hat USA 2025 | Lost & Found: The Hidden Risks of Account Recovery in a Passwordless Future

The Black Hat USA 2025 presentation warned that account‑recovery mechanisms—intended as a safety net for forgotten passwords—are rapidly becoming the most exploitable entry point in a passwordless ecosystem. Speakers Sidra, Gabby, and their research team outlined how recovery flows...

By Black Hat
Black Hat USA 2025 |  Pwning User Phishing Training Through Scientific Lure Crafting
VideoMar 2, 2026

Black Hat USA 2025 | Pwning User Phishing Training Through Scientific Lure Crafting

A new eight‑month field study of over 20,000 employees reveals that conventional phishing awareness training fails to meaningfully reduce click rates. The research, presented at Black Hat USA 2025, shows that the success of phishing lures is erratic, with some...

By Black Hat
Black Hat USA 2025 | If Google Uses It to Find Webpages, We Can Use It to Find Fraudsters
VideoFeb 28, 2026

Black Hat USA 2025 | If Google Uses It to Find Webpages, We Can Use It to Find Fraudsters

The session at Black Hat USA 2025 introduced a surprisingly simple technique—term‑frequency inverse‑document‑frequency (TF‑IDF)—as a powerful tool for spotting fraudsters, positioning it as an alternative to the sophisticated AI browsers and agents that dominate today’s web search. Speakers argued that generative...

By Black Hat
Black Hat USA 2025 | Let LLM Learn: When Your Static Analyzer Actually 'Gets It'
VideoFeb 27, 2026

Black Hat USA 2025 | Let LLM Learn: When Your Static Analyzer Actually 'Gets It'

The Black Hat presentation explored how large language models (LLMs) can be fused with traditional static analysis tools to create a new generation of vulnerability scanners. The speaker outlined three integration patterns—AI‑enhanced, where a static scanner filters LLM output; AI‑explorer,...

By Black Hat
Black Hat USA 2025 | Conjuring Hardware Failures to Breach CPU Privilege Boundaries
VideoFeb 25, 2026

Black Hat USA 2025 | Conjuring Hardware Failures to Breach CPU Privilege Boundaries

The Black Hat talk spotlights machine‑check exceptions (MCEs) – hardware‑level fault signals that fire when a CPU detects catastrophic errors such as cache corruption, thermal trips, or external interference. Christopher Domas demonstrates that, unlike ordinary interrupts, MCEs cannot be masked,...

By Black Hat
Black Hat USA 2025 | Enhancing Command Line Classification with Benign Anomalous Data
VideoFeb 25, 2026

Black Hat USA 2025 | Enhancing Command Line Classification with Benign Anomalous Data

Sophos researchers presented a novel pipeline that pairs anomaly detection with large language models to harvest benign command‑line examples for supervised classification. Instead of relying on unsupervised anomaly detection to flag malicious inputs, the approach uses the detector to surface...

By Black Hat
Black Hat USA 2025 | FACADE: High-Precision Insider Threat Detection Using Contrastive Learning
VideoFeb 24, 2026

Black Hat USA 2025 | FACADE: High-Precision Insider Threat Detection Using Contrastive Learning

Google unveiled Facade, a self‑supervised AI system that detects insider threats by analyzing contextual patterns in corporate logs. Leveraging contrastive learning on exclusively benign data, Facade achieves unprecedented accuracy, reporting false‑positive rates below 0.01% and as low as 0.0003% for...

By Black Hat
Black Hat USA 2025 | Breaking Out of The AI Cage: Pwning AI Providers with NVIDIA Vulnerabilities
VideoFeb 23, 2026

Black Hat USA 2025 | Breaking Out of The AI Cage: Pwning AI Providers with NVIDIA Vulnerabilities

Researchers from Wiz uncovered a critical vulnerability in the NVIDIA Container Toolkit, the software that isolates AI workloads on NVIDIA hardware. The flaw permits a container escape to the host OS, potentially compromising entire Kubernetes clusters and exposing cross‑tenant data....

By Black Hat
Black Hat USA 2025 | Autonomous Timeline Analysis and Threat Hunting: An AI Agent for Timesketch
VideoFeb 23, 2026

Black Hat USA 2025 | Autonomous Timeline Analysis and Threat Hunting: An AI Agent for Timesketch

At Black Hat USA 2025, Google engineers unveiled an AI‑powered agent that autonomously performs digital forensic timeline analysis and threat hunting within Timesketch. The system ingests heterogeneous log streams, reconstructs attack chains, and surfaces compromise evidence without relying on pre‑written...

By Black Hat
Black Hat USA 2025 | Vaulted Severance: Your Secrets Are Now Outies
VideoFeb 22, 2026

Black Hat USA 2025 | Vaulted Severance: Your Secrets Are Now Outies

The Black Hat USA 2025 talk, titled “Vaulted Severance: Your Secrets Are Now Outies,” examined critical weaknesses in modern secret‑management systems, using HashiCorp Vault as a case study. The presenters, from SIATA, framed the discussion around how vaults serve as...

By Black Hat
Black Hat USA 2025 | Exploiting DNS for Stealthy User Tracking
VideoFeb 20, 2026

Black Hat USA 2025 | Exploiting DNS for Stealthy User Tracking

The Black Hat USA 2025 presentation by Bitdefender researchers Yangabella and Yan Pedrian revealed how DNS traffic from smartphones can be weaponized to create persistent, cross‑network device fingerprints. By acting as a curious DNS resolver, they collected 985 million DNS events...

By Black Hat
Black Hat USA 2025 | From Prompts to Pwns: Exploiting and Securing AI Agents
VideoFeb 20, 2026

Black Hat USA 2025 | From Prompts to Pwns: Exploiting and Securing AI Agents

The Black Hat USA 2025 session titled “From Prompts to Pwns” examined how modern AI agents—especially those powered by large language models—can be both powerful assistants and vulnerable attack surfaces. Speakers Becca and Rich from NVIDIA’s AI Red Team introduced a three‑tier...

By Black Hat
Black Hat USA 2025 | Advanced Active Directory to Entra ID Lateral Movement Techniques
VideoFeb 17, 2026

Black Hat USA 2025 | Advanced Active Directory to Entra ID Lateral Movement Techniques

The presentation at Black Hat USA 2025 detailed how attackers can move laterally from a fully compromised on‑premises Active Directory into Microsoft Entra ID in hybrid environments. Speaker Dian of Outsider Security explained that once domain‑admin rights are obtained on‑prem,...

By Black Hat