Black Hat USA 2026, set for August 5-6 at Mandalay Bay in Las Vegas, shifts cybersecurity’s spotlight firmly onto AI agent vulnerabilities. For the first time, the conference dedicates an unprecedented number of sessions to the security challenges posed by autonomous AI systems, signaling that these threats have moved beyond academic curiosity into real-world danger.
With over seven briefings in the AI, ML, & Data Science track alone, experts will dissect how AI agents integrated into critical enterprise workflows expand the attack surface in unexpected ways. Topics range from credential theft via “The CoreBreak Attack” to exploiting AI frameworks after code injection. Presentations like “Trusted Enough to Run” and “Cost-Effective, Private, Frontier-Grade” reveal practical risks across proprietary and open-source AI implementations.
From Sandbox Escapes to Self-Propagating Botnets
The evolution of AI threats is striking. It started with controlled lab exploits, such as the OpenAI ExploitGym’s sandbox breakouts and Anthropic’s evaluation system breaches. The danger crossed into operational territory as documented by Unit 42’s DeepSeek report, revealing weaponized AI in real scenarios. The conference’s lineup addresses this trajectory, including defenses like multi-layer sandboxing used by Roblox to secure enterprise-scale AI code and alarming cases of botnets built on compromised AI infrastructure that attack other AI agents.
This surge in research responds directly to how quickly AI agents have woven into business processes, forcing security leaders to rethink protections and anticipate more sophisticated attacks ahead.
This material is for informational purposes and does not constitute financial advice.



