The top highlights from Black Hat, Def Con, and BSides Las Vegas 2026, if you couldn't make it in person
Hacker summer camp is over, everyone go home! Black Hat, Def Con, and BSides Las Vegas sounded like they were all pretty great this year... if you were there. I was not, and so I missed out on some incredible talks — but escaped the awful Las Vegas heat. Not all bad, then.
Instead, I was living vicariously through the week of live streams, the incredible reporting from the show, and what people on the ground were telling me. (Thank you for all the tips, and keep them coming by email or via Signal at zackwhittaker.1337.)
Pour yourself some coffee (or alternative) and catch up with some of my choice highlights from the week.
Former Justice Department prosecutor Leonard Bailey talks about U.S. hacking laws and bridging the divide between DOJ and security researchers.
Told over three acts, Leonard Bailey goes back more than a decade to detail the years-long effort to reform America's computer hacking laws from within the Department of Justice. It was in large part thanks to security researchers who wanted to see changes and sought out prosecutors to figure out how to make that happen. Bailey's talk concludes that the Computer Fraud and Abuse Act (CFAA), which governs much of the law around hacking and unauthorized access, is unlikely to change any time soon, conceding that Congress is broken, but why the battle for legal rights continues on. Stick around for the excellent question and answer session afterwards, where he discusses the potential for accountability when AI goes on the attack.
Former EFF director Cindy Cohn wants you to join the fight for privacy and encryption.
Cindy Cohn does the last round on the Las Vegas cyber conference circuit as the outgoing director of the Electronic Frontier Foundation, with a plea for everyone involved in cybersecurity: Privacy and encryption are good, and we need to fight to keep them. Cohn speaks about privacy as a check on the powerful and those with money, and how privacy protects people with less power. Cohn runs through stories covering the three big battles for privacy and encryption that she headed while at the EFF, including the fight for strong cryptography, secrecy orders like national security letters; and the long-running privacy battle against NSA surveillance after a whistleblower turned up on the EFF's door in 2005 and revealed NSA spying long before Edward Snowden. In this talk, Cohn explains and empowers the audience about what you can do to join in.
Adrian Sanabria explores why perhaps surprisingly few companies go under following cybersecurity failures.
A common statistic has floated around for years: Some 60% of small businesses go under six-months after a breach. But this is bunk. The actual number is only a tiny fraction: Only a few dozen businesses have shut down due to a cyberattack. In some cases, an exposure of data — no outside malicious activity — was enough to end some business altogether. Adrian Sanabria digs into this bunk statistic and explains the reasons why these companies sank and how much cybersecurity failings had to do with it. Sanabria also sprinkles a little mythbusting, from cyber-insurance payouts through to how much a company's reputation ultimately matters. This was a good talk that touches on this note: "The most important lesson is in how the breach is handled, not how the breach happens."
Cliff Stoll takes everyone down memory lane of hunting a hacker in his legendary book, The Cuckoo's Egg
Take a few to enjoy this animated talk by Cliff Stoll, the legendary author of The Cuckoo's Egg, who 40 years ago to the day discovered a 75¢ accounting error in his university's supercomputer that ultimately led him on a months-long trail to hackers working for Soviet intelligence. It is such a joy to see someone with so much love, excitement, and energy about something they care deeply about. If you've read the book, you'll be glad to know that he brought the viewgraphs that he used to brief the NSA. You are genuinely in for a treat.
OpenAI breaks down how its unreleased AI model autonomously hacked Hugging Face.
For the first time since the ChatGPT maker admitted it one of its unreleased AI models hacked into Hugging Face, two of the company's top technical leaders, Eric Wallace and Michael Dalton, walk us through how the AI models began laying the groundwork for their attacks back in May. The talk is technical, but also breaks down the attack — probably for the first time — in pretty understandable logic that explains how the AI models broke through its sandbox, reached out to the internet, and eventually hacked into Hugging Face. It's a fascinating talk (even if AI isn't your thing) about how the models found and exploited security vulnerabilities with the aim of solving the technical challenge it was given.
~this week in security~ is my weekly cybersecurity newsletter and blog supported by readers like you. Please consider signing up for a paid subscription starting at $10/month for access to exclusive articles, analysis, and more.
Or, you can submit a one-time tip or gift a paid subscription to show your support!
Recent blogs include: When AI chatbots and LLMs get legal, check your privilege | Most fitness wearables lack end-to-end encryption and don't disclose government data demands | U.S. judge denied feds a month-long warrant to snoop on the phones of thousands of Ohio residents | Why ad blockers are a top security and privacy defense for everyone | A beginner's guide to analyzing the network traffic of apps and websites
Joe Slowik dives into residential proxy networks and the risk they pose to critical infrastructure
Hot off the presses with news of hackers targeting water providers and facilities in Minnesota, Michigan, and beyond in ongoing cyberattacks, Dataminr's Joe Slowik dives into one major threat that faces critical infrastructure today: Many industrial control systems, like water providers and energy systems, are connected to the internet. Sure, you can pull these devices and systems offline but practically it's not so simple, and it's easier said than done, especially in rural communities where an important sensor might be miles away. This opens up critical infrastructure to attacks. Slowik uses his talk to dive into residential proxy networks, which give outsiders access to your internet connection, and are being abused by hackers to target critical infrastructure.
Mansoor Ahmad reveals how easy it can be to hack into a ton of internet-connected sex toys.
Any educational sex-tech talk that shouts-out the great security researcher Render Man, who has pioneered much of the work in internet-connected sex toy research to date, you know it's going to be a good talk. This talk by Ahmad does not disappoint. Ahmad found that around four-out-of-five popular intimate sex toys sold on Amazon are vulnerable to remote attacks over the internet because they share a common, buggy back-end and app. Ahmad shows how vulnerable these apps are to attacks carried out over the internet, and how these apps can publicly spill users' private information, passwords, and ultimately allow access to outsiders. This work raises important questions about the security and privacy of users of internet-connected sex toys.
Alexis Hancock and other EFF staff discuss why age verification laws make everyone less safe online.
This was a great discussion with the EFF's Alexis Hancock, who leads the organization's awareness efforts about age verification, and others from the EFF with questions from the audience. Age verification (which I've written about how these laws threaten the open internet) has erupted around the world over the past year. Critics argue that these systems have become a slippery slope of government authoritarianism. The EFF researchers do a great job of highlighting how these laws are aimed ostensibly at protecting children but instead put everyone at risk of security lapses, data breaches, and misuse.
Bill Swearingen developed an "adversarial" pattern that can defeat surveillance camera detections.
An absolutely brilliant talk by Kansas City local Bill Swearingen, who spent the past year developing adversarial patterns that can defeat the detection capabilities of surveillance cameras. This was a thorough, deep-dive talk explaining why he worked on developing these patterns over the past year, and why they mathematically work better than anything else out there today. Now with a Kickstarter launched, it's only a matter of time before we can buy merch with patterns that can defeat facial, object, and person recognition. (Disclosure: I wrote this story for TechCrunch!)
Vangelis Stykas and Felipe Solferini discover how millions of GPS smart watches can be easily hacked.
Kumio's top security researchers are back in Las Vegas to reveal new security risks with popular GPS smart watches. Much like Ahmad's sex toy app talk, Vangelis Stykas and Felipe Solferini found some of the more popular smart watches were white-labeled from the same China-based electronics maker that all rely on the same back-end web platform. By digging into the platform and the flaws, the researchers were able to hijack any of the millions of smart watches around the world. Instead, they asked Wired's Andy Greenberg to try out a vulnerable watch as proof that their bugs worked — with alarming results — including the ability to track people's location.
Bonus: The Pwnie Awards acknowledge the best and worst in cybersecurity this year.
Probably to little surprise, tech giants Microsoft and Meta took the top awards for their respective screw-ups earlier this year.
Thank you so much for reading ~this week in security~! I hope you enjoyed and found this article helpful. If you like it, please share a link on your social media! Please email me with any feedback, questions, or comments about this article: this@weekinsecurity.com.