Black Hat USA 2026: Intelligence Briefing

Article · 6 min read

Black Hat USA 2026: autonomous exploits, CYBERCOM's 2,660% bet, the trust supply chain.

Last year AI was the topic on every stage. This year it writes the exploit: Black Hat 2026's keynotes lead with AI-powered exploit generation, CYBERCOM's budget asks for a 2,660 percent AI increase, and the Five Eyes warn the acceleration lands within months.

Context

Black Hat USA 2026 runs August 1 to 6 at Mandalay Bay, the corporate and research pole of the week the industry calls hacker summer camp, with DEF CON 34 opening the same day the Briefings close. It is the room where the AI-versus-cyber question stops being a panel topic and turns into a budget line, and this is the first edition where the exploit-generation loop shows up as procurement reality instead of a demo.

The year's headline: offense went autonomous

Last year the CSO recap said AI "dominated the conversation" at Black Hat: autonomous agents, shadow AI, identity attacks. Conversation is the operative word. This year the machines are doing the work.

Black Hat's own keynote billing, reported by 01net two days ago, leads with "AI-powered exploit generation" and puts U.S. government officials on the stage next to vulnerability researchers to talk about offensive coordination. That is not a trend piece. Read it against CYBERCOM's budget request, a 2,660 percent increase in AI for cyber operations per Breaking Defense, and the Five Eyes joint warning that frontier models could measurably speed up attacks "within months," and the shape is clear. The gap between an AI that can find a bug and an AI that can chain it, weaponize it, and deliver it closed sometime between the 2025 show and this one. Black Hat 2026 is the first major venue where defenders have to answer for it in front of the people writing the checks.

Speakers worth showing up for

The full Briefings schedule and keynote roster were still filling in as of mid-July, the official speakers page listing names without session abstracts. Three confirmed names are worth flagging, plus two roles to watch.

Matt Devost, CEO and co-founder of OODA LLC. Devost's lane is decision-advantage and cyber risk at the geopolitical layer, which is exactly the altitude the AI-offense story needs. The question to ask: if exploit generation compresses from weeks to hours, what breaks first, the patch cycle or the disclosure norms that assume a human timeline?

Paul McCarty, founder of SecurityBreak. McCarty works the software supply chain and CI/CD secret-exposure beat, and that lines up directly with Microsoft's pre-show thesis that "threat actors are following trust." The question: which trust relationship in the build pipeline is the one nobody has instrumented, and why is it still there?

Will McKeen, listed as a senior cybersecurity manager. The speakers page gives no org and no abstract, so treat this as a name to check once the schedule firms up, not a session to plan around.

Watch for the government keynote. 01net reports serving U.S. officials on the AI-offense billing. What one is willing to say on record about offensive coordination tells you whether the 2,660 percent budget line is doctrine or a wish list.

Watch for the vulnerability-research keynote. The tell is whether it treats AI as a research assistant or as an autonomous finder. Those are different threat models, and the framing signals which one the community has actually accepted.

Breakouts with signal density

The keynote stage sets the narrative. The signal lives in the smaller rooms and the after-hours builds.

Tenable's Swarm, a build event announced on Security Boulevard, gathers defenders to build AI agents together on the premise that most teams are building them in isolation. Go for the hallway around it more than the pitch inside it. The interesting question is whose agent framework everyone quietly standardizes on.

The AI-powered exploit-generation track in the Briefings. This is where the keynote abstraction gets a live demo and a CVE number. Sit in the technical sessions if you want to know how far the automation actually reaches versus how far the slide claims.

The supply-chain and "following trust" sessions. Microsoft is seeding this theme hard in its pre-show blog. The density is in the sessions that name a specific trust primitive, a signing key, a package registry, an OAuth scope, rather than the ones that say "supply chain" as a category.

The model-gating discussion. Help Net Security ran Jaya Baloo arguing that gating cyber-capable models slows attackers but starves the defenders who need the same tools. Any panel that touches this is where the real fight sits, because it is a policy question the vendors on the floor cannot answer with a product.

Companies to track at the booths

Microsoft. Says: defending trust in the age of AI and supply chain attacks, anchored by MDASH, a multi-model agentic scanning harness that topped an industry benchmark in May. Actually selling: Security Copilot as the platform of record for defensive AI, with MDASH as proof the platform beats the point tools. The benchmark win is the sales asset.

Tenable. Says: the best defenders build AI agents together, come to Swarm. Actually selling: exposure management repositioned as agent orchestration. As agents multiply, Tenable wants to be the console they all report into, so the community build event doubles as a standards land-grab.

Snyk. Says: Evo Continuous Offensive Security, AI-native pentesting for AI-generated code. Actually selling: an exit from the crowded developer-scanner lane into the pentest budget, which is bigger and stickier. Watch whether "continuous" means genuinely autonomous or scheduled scans with a new label.

Cobalt. Says: human-led, AI-powered offensive security, plus a 2026 Fortress award in continuous exposure management. Actually selling: a defense of the human-led PTaaS moat against fully-autonomous pentest startups. "Human-led" is the hedge, and this show will test how long it holds as a premium.

A Security. Says: fresh out of stealth with 37 million dollars to outpace weaponized AI. Actually selling: the category itself. Defining "weaponized-AI defense" as a distinct budget line before Microsoft absorbs it into the platform is the whole play. Forget the funding round. The number to watch is how many booths borrow the phrase by Thursday.

Conversation patterns

Three things that get argued in the hallway:

Whether "human-led" survives contact with autonomous agents, or becomes varnish on an automated core. Cobalt is betting the premium holds; Snyk's Evo is betting it fades. The pricing on both will tell you who is winning before the keynotes do.

Whether frontier labs should gate cyber-capable models. Baloo's Help Net argument is that gating hands attackers a schedule advantage while defenders lose the tools they depend on. Expect this to split the room along vendor lines, because gating helps whoever already has a model and hurts whoever was going to rent one.

Whether CYBERCOM's 2,660 percent AI request buys capability or contracts. A 138 million dollar line is real money and a rounding error at once. The operators in the room will be quietly asking whether any of it reaches them or evaporates into integration overhead.

One thing nobody is saying out loud: the defensive agent swarms and the offensive exploit generators are being built on the same handful of frontier models. Tenable's Swarm, Microsoft's MDASH, and the attacker tooling the Five Eyes is warning about all rent capability from the same three or four labs. So the real control point for the offense-defense balance is not on the Business Hall floor at all. It sits with the model providers who decide what to gate and for whom, and none of them have a booth. The security vendors are arguing over the allocation of a capability none of them own. That is the conversation the floor is structured to avoid, because admitting it reprices every product in the hall.

The follow-up

Vegas in August is a firehose. Twenty thousand people, two shows if you stay for DEF CON, and a badge holder stuffed with cards from booths, dinners, and the line for coffee. The connections you actually want are a small fraction of that stack, and the window to turn a name into a real follow-up closes fast. By the time you are back at your desk the Monday after, the context has faded and the thread you meant to send never gets sent.

Met is built for that 72-hour window. Capture who someone was and why they mattered while the conversation is fresh, so the follow-up writes itself before the memory decays. It runs on iPhone, and it is free to start. Download it before you fly.

Download for iPhone

Read by operators heading to Black Hat who want the intel before they fly.

Get Met in your inbox

Field notes on conference networking, follow-up timing, and what we ship next. No spam, no AI hype.

No spam. Unsubscribe anytime. Replies go to support@sailquery.com.