Skip to content

Black Hat USA 2026: Five Key Takeaways for CISOs

Bottom line: Black Hat USA 2026 showed that AI agents and their software supply chains are becoming a new attack surface, while existing telemetry sources such as GitHub and expert-led AI research are simultaneously opening up new defensive opportunities.

At the Black Hat and DEFCON conference in Las Vegas, AI as a security tool and autonomous AI agents as a new attack surface took center stage. Five talks offer concrete starting points for evolving security strategies.

Microsoft manager David Weston argued in his keynote that AI is making vulnerability discovery and exploit development increasingly cheaper and faster. This, he said, is undermining the basic assumption that attackers need time and defenders can react afterward. Rather than trying to respond faster than attackers, Weston called for making systems fundamentally more resilient: through the use of memory-safe languages such as Rust, AI-assisted improvement of existing codebases, and automated remediation instead of rigid monthly patch cycles.

Researchers from Zenity uncovered a large-scale supply chain attack: manipulated AI “skills” — instruction and configuration files that tell AI agents how to use tools — were distributed via the marketplace skills.sh. The malicious skills used typosquatting to impersonate the popular services Paperclip and Browser Use and were downloaded more than 1.7 million times in less than a month. Zenity placed the incident within a broader trend of attacks on the AI software supply chain.

Microsoft’s Yossi Weizman and Mor Weinberger of Echo showed that GitHub already provides sufficient telemetry data to detect many supply chain attacks. Incidents such as Shai-Hulud, Trivy, and Megalodon followed recurring patterns: forged commit identities, manipulated tags, abuse of workflows and OIDC tokens, and attempts to cover tracks. These characteristics can be translated into behavior-based detections via GitHub webhooks, APIs, and Git metadata. The researchers released the open-source tool GitHub Threat Detector as part of this work, featuring 30 built-in rules and operating on an EDR-like model, though they note it still has limitations — such as webhooks that can be disabled, rate-limited APIs, and a lack of real-time inspection.

PortSwigger researcher James Kettle demonstrated that AI-assisted security research is most effective when human experts define the methodology, filter out weak results, and use deterministic code for narrowing down findings before letting the AI continue autonomously. Following this approach, his system HTTP Terminator found hundreds of active HTTP request smuggling vulnerabilities (HTTP desync), captured a real API key belonging to a bank, and identified a new vulnerability class called “Shared-Parser Confusion.”

For CISOs, this implies a need to explicitly include AI agents and their supply chains in risk assessments and vendor due diligence, to make more consistent use of existing telemetry sources such as GitHub for detection, and to rely on controlled, expert-led processes rather than fully autonomous systems when using AI in their own security research.


Source: www.csoonline.com · Published August 14, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: