Each year, security researchers and white hat hackers converge in Las Vegas for the Black Hat conference to share new discoveries and timely warnings about the tech we use each day. The conference begins with three days of cybersecurity training, including data breach response simulations, a bootcamp for corporate security leaders, and a hands-on demonstration of how to build and sideload malicious browser extensions (for research purposes, of course). After the training is over, the Black Hat briefings begin, bringing light to never-before-seen vulnerabilities, inventive defense tactics, and interesting research.
PCMag’s security team will be on the ground in Vegas to attend the sessions that look the most critical, chilling, or…maybe just fun. We’ll be reporting on everything we see throughout the week on our Black Hat page, so set your bookmarks accordingly! Until then, here’s a look at some of the highlights we’re anticipating.
Attendees at a previous Black Hat rode in simulators on the show floor provided by SentinelOne, a security platform provider (Credit: Black Hat USA)
Security Experts Sour on AI
One interesting trend this year at Black Hat is the cybersecurity industry turning on AI. Most of this year’s briefing descriptions about AI and LLMs approach the technology with caution at best, as presenters highlight how AI can be exploited or used to exploit others.
The sentiment toward AI at Black Hat has changed over the years. For example, here’s Black Hat’s briefing schedule in 2023, which is in pretty stark contrast with briefings in 2026:
A canary in the coal mine in the screenshot above is the presentation about creating a so-called “evil digital twin.” I attended that discussion in 2023, and the follow-up briefing in 2025, titled “Evil Digital Twin, Too: The First 30 Months of Psychological Manipulation of Humans by AI.”
In both presentations, the experts were adamant that generative AI would, very quickly, make it incredibly difficult for humans to discern reality from artificiality. Years later, in an age where NSFW image and video generators are the norm, we can’t say they were entirely wrong.
Surveilling Children Has Privacy Consequences for Everyone
An investigation led by Vangelis Stykas, CTO of Kumio, an AI cybersecurity agent provider, and Felipe Solderini, a senior penetration tester at Lares, a security consulting firm, is set to uncover some startling details regarding third-party parental monitoring apps. The pair mainly claims that 39 seemingly distinct apps all report to the same server in China.
The sheer scale is startling. The investigation is said to have revealed dozens of vulnerabilities that could allow hackers to wiretap all devices on the parental monitoring network across all 39 apps. Sytkas and Solderini claim that an attacker could even activate camera feeds and listen in through device microphones.
Can Fashion Save Us From Surveillance?
Cameras are everywhere these days, and as we’ve noted before, many are connected to each otheris dead. Or is it? According to one researcher, a piece of fabric may become the ultimate defense against facial recognition programs
Bill Swearingen says he has created a scarf that can fool AI. He printed a pattern on the fabric that, when viewed by cameras with facial recognition capabilities, can cause failures. This year at Black Hat, the SecKC founder will demonstrate how the scarf works, along with an exploration of facial recognition technology.
Roblox Talks Privacy, But Is It Enough?
A team of security experts from Roblox will discuss how to protect privacy at a massive scale. With more than 111 million daily active users on the platform, nearly half of whom are minors, Roblox has its hands full. Their proposed solution appears to give users more control over the deletion of personal data. However, such measures feel insufficient considering the platform’s widespread issues around data breaches, child endangerment, and woefully insufficient protections for minors.
Roblox’s privacy policy also keeps a lot of user data indefinitely by default, even after an account is deleted. Whether Roblox has more significant privacy changes slated in this presentation remains to be seen.
Invisible Malware: Google Exposes Zero-Click Mobile Exploit
Google’s “Project Zero” has discovered an exploit chain stemming from Android, this time a zero-click attack that can compromise a device with no user interaction. The attack itself isn’t new; zero-click attacks have been carried out on platforms like WhatsApp and TikTok. However, this exploit highlights vulnerabilities in Android that can impact all smartphone vendors.
Project Zero’s presentation will cover how the exploit was uncovered on Pixel devices and outline how other smartphone vendors can protect their devices against similar attacks.
Recommended by Our Editors
What Are the Best VPN and Online Privacy Tools? Tell Us Your Thoughts for a Chance to Win
The Best Password Managers for 2026
Your ISP Is Watching You. Here’s How a VPN Can Help
Laurent Giovannoni is a principal software engineer at Filigran, a threat intelligence platform, and will present code for ScamBuster, a scam-baiting program designed to waste scammers’ time and energy. Here’s how it works: The AI picks a persona, like, say, a confused tourist or an elderly person, and writes back to a scammer every time they make contact. Giovannoni’s team tested ScamBuster for 60 days and found that different types of human scammers respond differently to the ScamBuster personas.
Giovannoni says the system’s script is not fixed. Instead, it’s a learning algorithm that determines which personas work best against specific scam types and changes strategies quickly.
Your Inbox Could Contain a Ticking Time Bomb
If you’ve ever wanted to hack something, but the last time you used code was in 2006 when you customized your Myspace profile, you’re in luck. Gareth Heyes, a researcher at PortSwigger, a web app security and training company, will teach Black Hat attendees several techniques to attack email accounts using nothing but CSS.
Bot-on-Bot Combat Designed to Settle Our AI Differences
Adaptive Security is collaborating with BattleBots to bring some action to the AI debate by having humanoid bots battle it out on the show floor. Each bot will represent an argument about AI usage, and attendees at Black Hat can step up, take control of a bot that supports their claim, and duke it out with the opposition.
Where to Follow Our Black Hat 2026 Coverage
Black Hat’s briefing schedule is, as always, jam-packed with interesting demonstrations and titillating panel discussions. Follow us as we highlight the year’s most impactful cybersecurity discoveries on our Black Hat page, in our SecurityWatch newsletter, and on our social media feeds. Once the crowds disperse, we’ll follow up with a recap of the most memorable sessions this year, so make sure to tune in for one of our favorite weeks in cybersecurity.
About Our Experts
Kim Key
Senior Writer, Security
Experience
I review privacy tools like hardware security keys, password managers, private messaging apps, and ad-blocking software. I also report on online scams and offer advice to families and individuals about staying safe on the internet. Before joining PCMag, I wrote about tech and video games for CNN, Fanbyte, Mashable, The New York Times, and TechRadar. I also worked at CNN International, where I did field producing and reporting on sports that are popular with worldwide audiences.
In addition to the categories below, I exclusively cover ad blockers, authenticator apps, hardware security keys, and private messaging apps.
Areas of Expertise
Latest By Kim Key
- Traveling Soon? I Never Board a Plane Without This on My Laptop
- The AI Doppelgänger Nightmare: Inside the Unregulated Wild West of Deepfakes
- Freshman Fraud 101: The Digital Scams Targeting College Students (and How to Stop Them)
- Can You Erase Your Digital Footprint? Probably Not, But You Can Do This
- The 10 Things Every Kid on the Internet Should Know
- More from Kim Key
Read Full Bio
Justyn Newman
Senior Writer, Security
Experience
My writing journey started in 2012 and has taken me through various niches, but my main focus has always been on tech. I contributed to several growing PC hardware and software sites, focusing on gaming, peripherals, and privacy.
As the amount of information we put out on the internet has grown, so have the threats and the tools we use to combat them. With VPNs gaining traction in the late 2010s as a tool for the public instead of just an option for business security, I found myself reviewing countless options in this continuously changing landscape.
This led to my role before PCMag over at WizCase, where I honed my knowledge of VPNs and privacy tools and eventually oversaw all of the content produced. I led a talented team of fellow writers and editors to evaluate VPNs, password managers, antivirus, and parental controls.
- VPN
- Security
- Proxies
Latest By Justyn Newman
Read Full Bio
