Fresh off their trip to scorching Las Vegas earlier this month, three cybersecurity reporters — TechTarget’s Alissa Irei, Cybersecurity Dive’s Eric Geller, and Dark Reading’s Becky Bracken — talk through the highlights and themes of Black Hat USA 2026.
Undeniably, cybersecurity has reached an inflection point, thanks to artificial intelligence (AI). And this year’s conference was where many of the greatest cybersecurity minds came together to propose their strategies for grappling with defending against AI. Experts arrived in the desert armed with frameworks, research, observations, and revelations all intended to shore up traditional defenses against threat actors armed with weapons that are anything but traditional.
The turmoil within the CVE program, OpenAI’s “mind blowing” revelations about its rogue agents, the future of VulnOps, and AI regulation were just a few of the top-line concerns on the minds of defenders milling around the halls of the Mandalay Bay in 2026, and these reporters were there to ask questions and find as many answers as possible.
Here’s what they know.
Learn more in the video, and also check out our Reporters’ Notebook full series, available here, which is designed to bring together insights and coverage from across Informa TechTarget’s network of cybersecurity sister sites.
Eric Geller, Alissa Irei & Becky Bracken: Full Video Transcript
This transcript has been edited for clarity, readability, and length by Informa TechTarget’s internal AI assistant and human editors. For the full experience, please watch the video.
TechTarget Cybersecurity’s Alissa Irei: Welcome back to another Reporter’s Notebook. I’m Alissa Irei, Senior Site Editor at TechTarget Cybersecurity, and I’m here with Eric and Becky. I’ll let you introduce yourselves.
Cybersecurity Dive’s Eric Geller: Hi, I’m Eric Geller, senior reporter at Cybersecurity Dive.
Dark Reading’s Becky Bracken: I am Becky Bracken, Senior Editor with Dark Reading and happy to be here with you guys.
TTC’s Alissa Irei: We’re here to talk Black Hat, where we all were in lovely, cool, temperate Las Vegas and two letters, unsurprisingly, were top of mind for everybody: AI, AI, AI. What did you guys see and hear in terms of artificial intelligence this year?
CD’s Eric Geller: Well, for me, there were a couple of big themes. The first was there’s a lot of concern about what’s going to happen to the CVE program, which assigns numbers to vulnerabilities and has kind of been tracking the vulnerability ecosystem for decades now. There’s a lot of concern about what happens in the AI era when people are using these tools to discover bugs and report them at a rate that is completely unprecedented. I think probably the No. 1 most common theme for the sessions I attended was the CVE program, people talking about it from all different angles, including: Do we need to reform the program so that it can keep up with the onslaught of vulnerability reports that we’re seeing right now?
And I would say there was a mix of opinions. You have folks who say that the program can scale. It scaled in the past, like when fuzzing became a thing and people started finding a lot more bugs because of fuzzing. And then there’s other folks who say that this is categorically different and we need a different approach to cataloging vulnerabilities because we’re going to see so many more of them and so many of them are going to be inaccurate because the AI tool is going to hallucinate a bug where one doesn’t exist or it’s going to describe it poorly. We need a new way of dealing with bug reports in an era where so many of them come from an automated system. So that’s got to be one of the big things for me.
And then the other one was governance. And I mean that in mostly a policy context. There was not a lot of folks there from the government, senior folks, but the few people who were there really made a point of saying the government right now believes that AI can be left to mostly govern itself, but they’re going to be watching to make sure that we don’t have a crisis spawned by a really powerful tool that gets out and does something really bad. And of course you have all these conversations happening against the backdrop of the OpenAI and Anthropic disclosures about how their models went rogue, escaped their test environments, and hacked into real organizations.
I would say one of the most interesting sessions was the OpenAI talk where they kind of pulled back the curtain a little bit on what went wrong. So policy and governance of AI, that was a huge theme, with the government mostly saying, “We’re not going to be very hands-on for now, but we’re going to be watching to make sure that nothing goes wrong.”
TTC’s Alissa Irei: And Eric, I want to call out there was a quote in one of your articles that I loved. I think you were talking to somebody from the federal government about the government not letting you create a Terminator factory. Am I remembering that correctly?
CD’s Eric Geller: Yeah, that was during a Q&A when I asked at the end of a panel if there was any reason to think that the government would step in because so far the administration has taken a very hands-off approach. And this official from the Department of Homeland Security basically said, “That’s right, we do take a hands-off approach, but at the same time, we’ve made it clear to the industry that we’re not going to let you build a Terminator factory.” And I thought that was a very evocative quote.
TTC’s Alissa Irei: But then I think you followed up with how does the government prevent a Terminator factory? And, you know, there are good reasons that they might not be transparent about that, but it seemed ambiguous. The answer seemed ambiguous. So I guess that’s a lingering question: What is the mechanism for preventing a Terminator, the birth of Terminators among us?
CD’s Eric Geller: And they don’t really have a good answer at this point.
DR’s Becky Bracken: There was one piece of research that sort of attempted to answer that question. And that was from Fred Heiding and Chris Inglis, who was the former NSA director. And they put forth … Fred Heiding has done a lot of looking at how nation-states deal with these threats over the years. And Chris Inglis obviously brings deep government expertise. And they presented a framework. And there are discussions going on about this, but like you say, they are still pretty vague, but capture really sort of the basics of what people think the government should protect against. It’s going to be interesting to see it evolve.
TTC’s Alissa Irei: Another thing that I thought was interesting from that OpenAI session was that one of the folks from OpenAI said that the capabilities of AI have to … aid the defensive side more than they aid the offensive side. But again, the question is how, because it seems like, you know, attackers have a lot of advantages, even pre-AI, against cyber defenders. It’s easier to attack than it is to defend. So that’s a little worrisome as well, I suppose.
CD’s Eric Geller: Yeah, and think about the fact that it’s an employee of OpenAI, the biggest AI company, saying, if we are not making sure that defense benefits more than offense, then we are failing as an industry. This is unsustainable. Think about the fact that the person saying that works for a company that is leading the charge in this unsustainable industry. There’s a huge disconnect between what frontline employees are saying and what CEOs are actually steering their companies toward, at least right now.
TTC’s Alissa Irei: And there is tension between, you know, at a societal level that we see with the federal government. It seems like that tension between allowing innovation and also managing risk that we’re seeing at an enterprise level is being played out across the industry as well as across our society and our regulatory framework.
DR’s Becky Bracken: I didn’t get to attend the OpenAI session itself, but I started at the News Desk where I was sort of perched. I got the waves of experts coming in and their minds were blown by it for a couple of reasons. One, just how open they were about a lot of their intelligence. But I want to say, too, some really specific solutions to that problem you are asking about have been posed on the defensive side.
I don’t want to mess it up. Ed Skoudis from SANS is big on something called VulnOps, which takes SecDevOps and applies it to vulnerability management, which I think is a path forward to speeding up the patching in the AI era. And Heather Barnhart, also from SANS, talked about this need to slow down offensive AI agents. And a researcher named Jake Williams, who is a regular contributor and source of mine, just released something called a custody framework. This is a new framework available to anybody, and it is specifically to keep AI agents in their environment.
You know, traditional defenses are architected around keeping bad things out. So these are just a few different ways that this problem is being attacked, but there is a lot of emphasis from what I’ve heard — because I asked the same question. What about blue teaming? I don’t hear about that. And I’m like, no, it’s purple teaming now, but don’t think that any of the defensive stuff has been ignored in any way. So it’s just a few of the things I overheard.
TTC’s Alissa Irei: One thing that was interesting, I took a tour of the NOC and spoke with a couple of different guys.
DR’s Becky Bracken: I saw your cool article on that, too. It was great.
TTC’s Alissa Irei: Thank you. So they were saying, you know, obviously they’re using AI for defensive use cases in really interesting, innovative ways. But in terms of the AI-driven attacks, it sounds like what they’re seeing currently is that the AI-driven attacks are really loud, they’re really noisy, they’re really — they have the subtlety of a Mack truck, which is great for defenders.
And that raises a couple of questions. I guess one is, are all of the vendors on the show floor that are selling products to defend against AI attacks, are they solving for a problem that doesn’t exist? But then, of course, the other question is how quickly does that change on the ground? Also talked to a ServiceNow threat researcher who said that in the last couple of weeks they’ve started seeing quiet, low-and-slow AI attacks. So a couple of conflicting, you know, narratives or experiences there.
But I’m curious for the typical organization, did you get a sense of, you know, on the one hand, we have these frontier model accidents, for lack of a better word, the OpenAI situation, etc. But then how worried do you think CISOs are or should be in terms of actual real-world AI attacks? Did either of you get a sense of that on the show floor, at sessions or otherwise?
DR’s Becky Bracken: I asked that question in almost all of my interviews. It’s specifically what you said about the hype and solving for a problem that doesn’t exist. And the very down-to-earth, very technical, practical people that I respect say it really doesn’t matter how much of it is hype and how much of it isn’t. Because if it’s real, it’s still something you have to account for. Would you agree with that, Eric?
CD’s Eric Geller: Yeah, I do think that a lot of the threat conversation fails to distinguish between what you’re likely to experience and what you could experience in a worst-case scenario. I do think that there are ways that AI can allow people who don’t have sophisticated tools or a lot of experience to do really dangerous things that they used to not be able to do.
But the question is, for the average organization, which probably has a lot of default passwords, a lot of public-facing infrastructure with perhaps no passwords, are they even going to bother using some exquisite AI capability to get into your network? And usually the answer is no. Think about how many of the water utilities that were hacked recently were using insecure public-facing infrastructure years after these warnings about how you should disconnect these things from the Internet.
Human failures that leave these simple weaknesses exposed inside your organization are right there for exploitation by hackers who don’t need to use AI. So as much as these tools can do really powerful things, every threat actor wants to do the simplest thing possible if they can. And usually the simplest thing possible is readily available to them in the form of a default password. They don’t have to go to AI.
I think it’s like thinking about your threat model. If you’re a defense contractor, you need to be thinking about those really sophisticated AI-powered techniques, and maybe they’re going to find a vulnerability that a human would never have found. On the other hand, if you’re the average company or even a large Fortune 500 company with a ton of different arms spread across the world, there’s a good chance that your biggest weakness has nothing to do with an exquisite vulnerability that AI can find and has a lot more to do with a default password than anybody can try to exploit.
DR’s Becky Bracken: Preach!
TTC’s Alissa Irei: That’s a great point. Yeah. One of the guys in the NOC actually, when TechTarget Cybersecurity took the tour and then followed up with them afterwards, he did say that there was a Fortune 500 organization that had set up an MCP server to enable their internal AI use cases. They didn’t protect the MCP server with any sort of authorization. So it was just sitting there wide open, passing its token in the clear.
They were sitting in the NOC and said they had full access to their complete security stack. They could have erased everything. They were joking that they could have jumped in and helped manage it, which, you know, would have been nice. But that, to your point, I think it’s just an old problem with higher stakes.
CD’s Eric Geller: Right. I mean, that’s really a great example because in that case, the failure was a traditional security failure of setting up controls. It just so happens that the failure involved an AI tool, which meant that if you got in, you could do a lot more damage because the company has connected the AI tool to everything else in a way that other tech platforms, for the most part, except for like your identity database, they’re not typically as far-reaching across your organization. But now everybody wants to connect their AI tools to everything.
Which means if you have a traditional security governance failure, it’s a lot more dangerous if you have that failure with an AI tool. But that isn’t an AI risk per se. That is a traditional security failure. That’s not an AI failure.
DR’s Becky Bracken: And the remedies all seem to be the same old, same old, you know. Asset inventory, you know, segmentation. These are the basics. Basics don’t seem to change regardless of the AI intervention.
TTC’s Alissa Irei: Which is good and bad because the basic — we know how the basics work, we know what it’s supposed to look like, but the bad news is that the basics are hard and, you know, I don’t — I think it was the rare organization that had really mastered the basics pre-AI.
DR’s Becky Bracken: But it’s such a good example of your earlier question where sometimes the vendor landscape gets everybody way over their skis, you know, looking at all this tricky stuff when the truth of the matter is an honest assessment of what actually they have on their network would probably be the best. You know, people aren’t usually ready for a pen test, they’re ready for a tabletop, you know. And so I think that’s worth keeping in mind here.
Did anybody see any really cool merch? I’d like to talk about the merch just while we have a second because I really liked the on-demand screen printing that everybody had going on. I thought that was cool.
I saw one Formula One car, which was disappointing because usually there’s at least three or four. So, you know, we’re in tough times.
CD’s Eric Geller: Yeah. I thought the vendor hall was once again an unbelievably bizarre experience as somebody who’s not involved in purchasing any of this technology. The fact that all these companies can be in business, at least for now, is still mind-blowing to me.
TTC’s Alissa Irei: It’s true.
DR’s Becky Bracken: Did you guys see the Oak booth? That was the one that I thought was the showstopper. It looked like a real tree. It was real. It was cool. Somebody must have spent a fortune, but —
TTC’s Alissa Irei: Did anybody see goats?
DR’s Becky Bracken: No.
CD’s Eric Geller: I heard that there were goats; I did not see goats.
DR’s Becky Bracken: You probably would have smelled them if they were in the house, though.
TTC’s Alissa Irei: That’s true. Maybe they were uninvited. Not really a Mandalay Bay type of guest.
CD’s Eric Geller: Yeah.
DR’s Becky Bracken: Anyway, it was really good to see both of you in Las Vegas, and it was good to have the chance to catch up today for sure.
TTC’s Alissa Irei: Absolutely.
CD’s Eric Geller: Yeah, definitely.
DR’s Becky Bracken: Well, should we tell folks where they can continue to find our work?
CD’s Eric Geller: Well, for me, you can follow all of our coverage at Cybersecurity Dive.
TTC’s Alissa Irei: And you can follow TechTarget Cybersecurity‘s work.
DR’s Becky Bracken: And as always, Dark Reading is where you’ll find me and my colleagues. So please check us out.


