Friday, 14 August 2026

Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers You're Not Using (Yet)

Event Tracing for Windows (ETW) is a built-in Windows logging and tracing framework that collects system and application events, providing detailed visibility into what's happening on a machine. In security, ETW is widely leveraged as one of the key telemetry sources for modern Endpoint Detection and Response (EDR) products because of the wealth of data it provides. This trace data is generated by components known as providers. While four types exist—Managed Object Format (MOF), Windows software trace preprocessor (WPP), Manifest-based, and TraceLogging—Microsoft generally recommends using the two modern variants: Manifest-based and TraceLogging providers [1]. However, a significant knowledge gap exists. While Manifest-based providers are relatively well-understood [2], information regarding TraceLogging providers remains scarce. Consequently, it is questionable whether the security community is truly maximizing ETW's full potential. To bridge this gap and enable defenders to better leverage ETW, we will present our findings on TraceLogging providers in the latest Windows. We will cover how to work with them, highlight providers potentially useful for security (e.g., AttackSurfaceMonitor), and walk through practical use cases. Asuka Nakajima | Senior Security Research Engineer, Elastic https://ift.tt/PNbRd1M

source https://www.youtube.com/watch?v=ubFcs1M62P4

Black Hat Asia 2026 | Beyond the Golden Image: A Self-Healing Image Supply Chain

Cloud images are frequently stale on arrival. Traditional hardening depends on manual patch cycles and periodic rebuilds—an approach that breaks down in large enterprises running thousands of rapidly changing workloads. Reactive remediation creates persistent security debt, long exposure windows, and an image supply chain that cannot keep pace with modern Agile delivery. This Briefing presents a security-first framework for a self-healing image supply chain that continuously delivers deterministic, verifiable, and zero-CVE operating system images at enterprise scale. The approach replaces legacy package-manager–driven workflows with hermetic, declarative builds that remove non-determinism and guarantee 100% reproducibility. Every image is cryptographically signed, attested with SLSA-aligned provenance, and verified prior to promotion, preventing compromised or untrusted components from reaching production. Our platform implements this framework, with layered hardening and minimal-footprint custom builds that eliminate unnecessary utilities, reducing attack surface while preserving developer flexibility. Strict policy gates ensure that only images meeting integrity, compliance, and vulnerability criteria are deployable. To sustain security posture at scale, the system continuously tracks vulnerability intelligence feeds and upstream base-layer updates. When a patch or new CVE is released, images are automatically regenerated, validated, and published—guaranteeing updated images in less than 24 hours without manual intervention. In production use, the framework is actively consumed by 500+ SREs impacting 1000s of developers across 70+ engineering teams, has reduced organization-wide CVE backlog by approximately 40%, and scales to support thousands of workloads. Today it supports hardened Linux and Windows OS images across AWS and Azure, with a design extensible to data-center images and container pipelines. We will share the architecture framework, threat model and implementation techniques as a vendor-neutral blueprint so security and platform teams can transform image security from a reactive process into an autonomous, continuously verified supply chain. Neelu Tripathy | Senior Security Architect, Adobe Inc. Lovlesh Malik | Engineering Manager, Adobe Systems India Pvt. Ltd https://ift.tt/7OeFs2o

source https://www.youtube.com/watch?v=ueG0ynK0I7A

Thursday, 13 August 2026

Black Hat Asia 2026 | Inside Cybercrime Inc: Lessons From Covering the Global Fraud Boom

Drawing on three years of on the ground reporting across South East Asia, this talk examines the rise of an industrial scale cybercrime economy, an ecosystem now generating an estimated $500bn a year, rivaling the global drug trade. I'll unpack how these syndicates operate as fully fledged multinational enterprises, and explore the human, political and economic forces that allow them to thrive. By tracing how online fraud has evolved, industrialised and globalised, I'll outline what this transformation reveals about the future of organised crime and why defenders, policymakers and investigators need to rethink the threat landscape ahead. Sue-Lin Wong | Asia Correspondent, The Economist https://ift.tt/xcOnhQI

source https://www.youtube.com/watch?v=ChQ-wvvgGNU

Black Hat Vault | Cyber Granny

Meet Cyber Granny! 🔐 Hear her thoughts on the Black Hat community, advice for newcomers, and the importance of staying cyber aware.

source https://www.youtube.com/shorts/vgyZ7AaAZCM

Black Hat Stories | Daniel Cuthbert

From world-class research to the collaborative spirit that brings the global security community together, Daniel shares how Black Hat has helped shape some of the most important moments in cybersecurity history.

source https://www.youtube.com/shorts/GiWY0pNKH_4

Wednesday, 12 August 2026

Black Hat Stories | More Than a Conference

Three years, three different Black Hat experiences. Gaurav Keerthi, CEO and founder of StrongKeep, shares what makes it special.

source https://www.youtube.com/shorts/5Qq_L_qp7R8

Three Decades of Influence | Why Black Hat Matters

As Black Hat approaches its 30th anniversary, Daniel Cuthbert reflects on why this conference remains essential to the cybersecurity community. See how Black Hat has influenced the industry through groundbreaking research, innovation, and collaboration.

source https://www.youtube.com/shorts/tq6lYc3jZDo

Tuesday, 11 August 2026

Saturday, 8 August 2026

Black Hat USA Briefings: Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius

Prompt injection is usually treated as a text problem contained on a screen: a bad output, leaked data, a rogue tool call. This one isn't. A live jailbreak of a stock Unitree Go2 robot dog running Gemini Robotics-ER 1.6, reached through its own camera and mic and driven to physical movement, no human in the loop. Underneath the demo is a measurement problem: agents behave differently when they know they're being tested, so a clean evaluation score doesn't mean the unsafe behavior is gone. The talk covers the attack live, a taxonomy of how these systems fail, why current testing misses it, and what defenders should change. Live hardware, on stage. Pliny the Liberator | Directs Frontier-Model Research, BT6 Philip (injx) Dursey | Managing Director, BT6 Adrian (threlfall) Wood | Frontier AI Red Team Operator, BT6 Ads (0xmoose) Dawson | Senior Frontier AI Red Team Operator, BT6 Dustin (ph1r3574r73r) Farley | Frontier AI Red Team Operator, BT6 Sean (seahop) Hopkins | Frontier AI Red Team Operator, BT6 Learn more: https://ift.tt/3D6MJTn

source https://www.youtube.com/watch?v=LZkdihOzfe4

Thursday, 6 August 2026

Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident

The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI When AI Goes Rogue. The Incident That Changed Everything. An OpenAI evaluation agent broke out of its sandbox, infiltrated Hugging Face infrastructure, and attempted to steal test answers—all autonomously. No human involved. The era of AI-driven cyberattacks is here. Are you prepared? Speaker: Michael Dalton, Speaker: Eric Wallace Learn more: https://ift.tt/La7IhuT

source https://www.youtube.com/watch?v=87DyyMV0kCY

Friday, 31 July 2026

Black Hat Stories | Daniel Cuthbert, Black Hat Training Review Board Member

In this episode, Black Hat Training Review Board member Daniel Cuthbert discusses why Black Hat remains a driving force in the cybersecurity industry. From world-class research to the collaborative spirit that brings the global security community together, Daniel shares how Black Hat has helped shape some of the most important moments in cybersecurity history. Discover what makes Black Hat a trusted platform for groundbreaking research, meaningful connections, and the exchange of ideas that continue to advance the industry. 🔐About Daniel Cuthbert Global Head of Security Research | Banco Santander Daniel Cuthbert is the Global Head of Security Research for Banco Santander. With a career spanning over 20 years on both the offensive and defensive side, he's seen the evolution of hacking from a small groups of curious minds to organized criminal networks and nation state we see today. He is the original co-author of the OWASP Testing Guide, released in 2003 and now the co-author of the OWASP Application Security Verification Standard (ASVS). https://ift.tt/lIkNESX

source https://www.youtube.com/watch?v=e_8rik9NT7U