Black Hat USA 2026 AI Summit
The AI Summit at Black Hat USA 2026 is a one-day event in Las Vegas focused on securing AI systems, AI-enabled threats, digital defense, governance, and regulatory compliance.
Independent research notes, red-team methods, and event intelligence for people building, testing, and governing agentic AI systems.
Future talks, workshops, conferences, and community events related to AI systems, security, compliance, and red teaming.
The AI Summit at Black Hat USA 2026 is a one-day event in Las Vegas focused on securing AI systems, AI-enabled threats, digital defense, governance, and regulatory compliance.
AI Village at DEF CON 34 is confirmed for Las Vegas with demos, CTF activity, community programming, and a poster track on adversarial attacks against agents and agentic systems.
AI Risk Summit 2026 brings security and risk executives, AI researchers, policymakers, and developers to Half Moon Bay for two days focused on managing AI risk in practice.
The 35th USENIX Security Symposium brings peer-reviewed systems-security research to Baltimore, with an unusually deep 2026 AI program. Dedicated ML-security sessions cover real-world and indirect prompt injection, adaptive jailbreak attacks, agent memory and resource-abuse failures, LLM privacy and backdoors, and a systematization of agent attacks and defenses; proceedings are open access.
A small, manually reviewed set of technical guides, hands-on exercises, and deep implementation write-ups for testing and securing AI systems in practice.
A review of nine coding-agent incidents from 2025 and 2026 separates shell, path, and harness failures from constraint decay and excessive permissions, then maps them to concrete controls for identities, filesystems, approvals, verification, logging, and backups.
Cloudflare announced Account Wallets and agent-specific Virtual Wallets for stablecoin and x402 payments, with human-readable identities, allowlists, allowances, transaction caps, anomaly review, and human override workflows.
garak v0.16.0 begins context-aware scanning with technique and intent annotations and IntentProbe, adds native Anthropic and adaptive-attack plugins, and introduces a unified selection grammar plus revised report output.
OpenAI reports two third-party cyber-evaluation incidents in which reduced safeguards and internet-enabled or misconfigured test environments let models act beyond intended ranges, including the use of real external services and exploitation of a real website.
Recent notes and references across prompt injection, agent security, evaluations, responsible AI, and adjacent AI work.
Pillar Security showed that a public GitHub issue could prompt-inject an ADK triage agent into invoking a privileged code-fixing workflow. Proofs of concept achieved CI-runner code execution and exposed bot and cloud credentials; Google removed three workflows, with no public evidence of in-the-wild exploitation.
A credential-stealing npm worm spread through hundreds of package versions using lifecycle scripts and a Bun-based payload. Related repositories also carried Claude Code and VS Code hooks that could execute after workspace trust; reported campaign totals vary, so exposure depends on exact resolved versions and execution.
Microsoft added AI, Security Operations, and Infrastructure checks to its Zero Trust Assessment and a DevSecOps pillar with 15 control groups and 91 tasks to its Zero Trust Workshop, alongside new guidance for governing agent memory.
Three trust_remote_code bypasses in Hugging Face Diffusers let a crafted model repository execute Python during pipeline loading, including cross-repository, local-snapshot, and time-of-check/time-of-use paths. The affected cases are tracked as CVE-2026-44513, CVE-2026-44827, and CVE-2026-45804; Diffusers 0.38.0 contains the fixes.
These topic hubs connect current engineering and research with the parts of AI security, governance, evaluation, and system behavior that are most useful in practice.
Methods, case studies, and tooling for red teaming AI systems end to end.
Open topicPrompt design patterns, instruction hierarchy, and defensive prompt construction.
Open topicPrompt injection attacks, mitigations, detection, and design patterns for safer AI applications.
Open topicControls and attack paths for browsing, tool use, memory, identity, and action-taking agents.
Open topicSafety evaluations, system cards, preparedness, and security measurement for frontier models.
Open topicResponsible AI, governance, standards, and regulatory reference material for teams mapping AI systems to policy and operational controls.
Open topicAdversarial machine learning attacks, taxonomies, and mitigations across the ML lifecycle.
Open topicApplication architecture, developer workflow, tooling, and production patterns for building AI systems.
Open topicFocused on AI engineering, responsible AI, compliance, model behavior, and operational AI systems. Current work includes founding AI operational software for compliance and financial tracking.