Black Hat USA 2026: Over 200 Sessions on AI Security, Zero‑Day Exploits and Cyber Warfare Now on YouTube

The Black Hat USA 2026 conference, the largest ever with more than 200 talks spanning AI security, zero‑day exploits, cyber‑warfare, and more, has uploaded all keynotes, main‑stage sessions and highlighted talks to its official YouTube channel for free viewing.

Black & White Path
Black & White Path
Black & White Path
Black Hat USA 2026: Over 200 Sessions on AI Security, Zero‑Day Exploits and Cyber Warfare Now on YouTube

Scale and Focus of Black Hat USA 2026

Black Hat USA 2026 set a new record with a two‑day formal agenda (August 5‑6) featuring over 200 sessions covering network resilience, malware, detection engineering, security culture, privacy, supply‑chain security and cryptography. The four‑day training track (August 1‑4) added hands‑on content such as incident response, third‑party risk management and AI‑security red‑team exercises.

AI topics dominated the program, appearing in every track—from LLM safety and prompt‑engineering to autonomous exploits and AI agents—signalling that attackers are increasingly focusing on AI.

Key Highlights: Attackers Leading the Curve

PleaseFix: AI Browsers Hijacked by a Single Email

Zenity Labs demonstrated a novel AI‑security vulnerability called "PleaseFix" on the main stage. By embedding malicious commands in an email, calendar invite or web link, an AI‑enabled browser (Claude in Chrome, Gemini, Perplexity Comet, ChatGPT Atlas, Copilot Edge) executes the commands as if they were user requests, without any user click.

The researchers attribute the flaw to the traditional same‑origin policy being effectively broken by AI inference needs. Patches provide limited protection; after Perplexity applied a fix, Zenity was able to bypass it twice.

AI Agents Out of Control: OpenAI Calls It a "Watershed Moment" for Computer Security

OpenAI warned that autonomous AI agents have reached a practical stage of offensive capability, describing it as a watershed moment for computer security. Coupled with Zenity Labs' findings, the warning underscores that attackers no longer need to deceive users—they can directly command AI agents to act on their behalf.

CSS as a Data‑Exfiltration Channel

Security researchers highlighted that Cascading Style Sheets (CSS), once merely a web‑design tool, can now be leveraged to steal data from webmail services. Some vendors are unprepared for this emerging threat.

AI Enables Organized Crime to Enter a "Fraud Paradise"

Another study presented at Black Hat showed organized crime groups using AI at scale to enhance fraud: real‑time deep‑fake video overlays, LLM‑driven persona management, and automated translation enable precise, cross‑border scams amounting to tens of billions of dollars.

LANJack: Zero‑Click Malicious Advertising Mapping Home Networks

Attackers are exploiting ad networks to deliver silent, zero‑click malicious campaigns. The technique, dubbed LANJack, programmatically maps a victim’s home network, locates routers and IoT devices, and compromises them without any user interaction.

YouTube Replay Channel

The official Black Hat USA 2026 YouTube channel now hosts the following content for on‑demand viewing:

Keynotes

Main‑stage sessions

Opening sessions

Highlighted talks

YouTube channel: https://www.youtube.com/@BlackHatOfficial Playlist (continuously updated): https://www.youtube.com/@BlackHatOfficial/playlists
Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

AI securitycyber warfaresecurity researchBlack Hatzero‑day exploits
Black & White Path
Written by

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.