5 key priorities for your Black Hat agenda — and what to avoid

Two major conferences loom large on the US cybersecurity events calendar: The RSA Conference and Black Hat.

RSA was launched in 1991 by then CEO Jim Bidzos of RSA Data Security, the encryption company founded by Ron Rivest, Adi Shamir, and Leonard Adleman. Originally, the conference had a cryptography focus, but that all changed in 2005 when Bill Gates, then CEO of Microsoft, gave a keynote presentation. With that one presentation, RSA broadened its focus to include all things enterprise security. In 1991, a few dozen people attended RSA. This year, nearly 44,000 showed up.

Black Hat also started with a practitioner’s perspective, back in 1997. It seemed that the true “hacker” spirit of Defcon was antithetical to corporate sensitivities, even though the no-nonsense technical discussions were extremely valuable for infosec pros. To bridge this gap, Defcon founders spun off Black Hat as a more “buttoned down” cybersecurity fiesta. Similar content with a tamer atmosphere.

Like RSA, Black Hat also changed in 2005 but for a completely different reason. The conference was sold to CMP Media that year for $14m (CMP is now part of Informa).

Since the CMP acquisition, Black Hat has had a bit of an identity problem. It retains its role as a cybersecurity summer camp, but it also moved in a simultaneous aspirational direction as an RSA wannabe. It got more corporate, sprinkling blatant sales pitches in with its traditional content. So much so that Black Hat is now perceived by some as a jack-of-all cybersecurity trade and a master of none. Practitioners were turned off by corporate hyperbole, while vendors felt alienated by an anti-establishment hacker vibe. I’ve heard that Informa hired a high-priced New York City branding company to conduct research and help it through this Black Hat identity morass.

To be clear, the authentic content presented by researchers, threat analysts, reverse engineers, and now AI experts always was, and still is, exceptionally valuable, and the Black Hat team does a respectable job vetting signal from noise. That said, there are all kinds of conference sponsors who pay big dough for prime real estate. Given this, I highly advise security professionals to resist the temptation to “wing it.” Avoid the shiny lights, silly themed cocktail parties, and the casino and focus your attention on the meaty conference content.

Here are a few topics that should be on the top of every cybersecurity professionals’ agenda at this year’s Black Hat.

1. Agentic AI framework exploitation

As organizations deploy autonomous AI agents with access to APIs, databases, and enterprise pipelines, adversaries are intent on riding shotgun, targeting execution chains and autonomous logic.

A successful attack could then mess with agent logic, corrupt underlying data, or allow agent-based lateral movement. Security practitioners need to understand these threat vectors so they can pinpoint vulnerabilities, monitor anomalous behavior, and create initiative-taking compensating controls.

2. Advanced APT infrastructure and threat intelligence

Modern APTs include edge device compromises, consumer-based command-and-control (C2) servers, identity/session hijacking, and criminal/state-sponsored adversary coordination.

With these changes, security pros must bolster network traffic analysis, familiarize themselves with adversary infrastructure and tools (i.e., think of the top layers of the “pyramid of pain”), and transform threat indicators into automated detection rules and security control configurations. Cybersec pros should cast a wide net and include these topics on their Black Hat to-do lists.

3. Automated vulnerability discovery and AI-powered exploitation

Alarmingly, there is little to no time anymore between vulnerability discovery and adversary weaponization. As a result, periodic scanning, patch windows, and CVSS scoring methodologies are now obsolete.

Organizations must shift to AI-driven defensive pipelines that leverage automated code-fixing agents, accommodate business-centric risk scoring, deploy real-time virtual patching and runtime application self-protection (RASP) at the execution layer. Security teams will need to cooperate with IT operations and software development teams to get this right. As such, look for comprehensive case studies and success stories at Black Hat.

4. Threat hunting in the AI era

The days of relying on static indicators of compromise (IP addresses, file hashes, etc.) are over. Rather, practitioners must learn to act by implementing continuous anomaly detection, configuring deterministic runtime guardrails, and using automated toolsets to rapidly operationalize threat intelligence.

AI automation must then be balanced against human experience and knowledge of business context and cyber defenses. Black Hat can provide ideas and training in these areas.

5. Real use of AI by cyber adversaries

Beyond scale and speed, cyber adversaries are using AI for things like just-in-time malware injection, technical reconnaissance, debugging operational code, parsing sensitive documents, creating lifelike virtual personas, and generating automated scripts for wiping forensic evidence and event logs.

Static alerts and detection rules are no match for this level of intelligence. Rather, security teams must rely on behavioral anomaly detection, collaborative reasoning AI agents, and engineered workflows. Before approaching vendors for solutions, cybersecurity professionals must fully understand AI-based kill chain advances and the appropriate agentic countermeasures. An open mind and Black Hat can help.

Additional agenda priorities

If cybersecurity leaders and their teams have enough bandwidth to move beyond these areas, there will also be great discussions around AI-threat modeling, cloud-based exploits, multitenancy hacks, and much, much more. Good stuff!

When people who’ve never been to Las Vegas ask me to describe the city, I tell them that Las Vegas can be what you want it to be. If you love live music, ignore the “sin city” façade, and seek out the great live music all over Vegas. The same philosophy holds true if your passion is food, shows, gambling, and other sordid activities.

Black Hat should be approached with a similar viewpoint. If you conscientiously avoid the vendor and venture capital embellishment and seek out the true intellectual substance, you’ll leave Vegas much smarter than when you arrived. Given how fast AI is changing applications, IT, security defenses, and business tactics, it’s worth pursuing this strategy.