
Black Hat USA
- August 4-6, 2026
- Las Vegas, Nevada
The premier cybersecurity event of the year returns to Mandalay Bay with a re‑engineered program built to ignite innovation, push boundaries, and bring the global security community together like never before.
Connect with Team Cymru at Black Hat USA to gain actionable intelligence on emerging cyber threats, uncover adversary infrastructure impacting your organization, and learn how security teams worldwide are using our data to accelerate investigations and strengthen defenses.


The Cyber Lounge
Connect, Network and Unwind at The House of Blues
- August 4-5, 2026
- 10:00am – 10:00pm PT
- The House of Blues at Mandalay Bay
The Cyber Lounge is making its fifth appearance at The House of Blues in Las Vegas, and we invite you to join us in this exclusive space designed for cybersecurity professionals to unwind, connect, and elevate industry collaboration.
Book a 1:1 meeting with a Team Cymru expert, or join us for happy hour featuring live music that sets the mood without interrupting the conversation.
US CYBERCON
Train. Compete. Win.
- August 6, 2026
- 10:00am – 5:00pm PT
- HyperX Arena Las Vegas
The US Cyber Games program invites the community to gather for an unforgettable day of cyber competition and games, networking, and celebration in the heart of Las Vegas at the iconic HyperX eSports Arena Las Vegas.
Taking place on Thursday, August 6, between Black Hat USA and DEF CON, US CyberCON is where cybersecurity professionals, competitors, students, educators, sponsors, innovators, and enthusiasts meet to compete, connect, and support the next generation of cyber defenders.

Our ElevateExpo speakers
We're a passionate team of marketing professionals dedicated to creating an unforgettable and impactful event for our community


Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker
![BH - Header[3200x500]Dark BH - Header[3200x500]Dark](https://event.team-cymru.com/hs-fs/hubfs/BH%20-%20Header%5B3200x500%5DDark.png?width=2000&height=312&name=BH%20-%20Header%5B3200x500%5DDark.png)

Will Thomas
Senior Threat Intelligence Advisor
Nation State Obfuscation Networks
Location: DEF CON Telecom Village
State-sponsored threat actors from China, Russia, and North Korea have fundamentally shifted their intrusion playbooks away from endpoint compromise and toward edge devices (routers, NAS devices, IP cameras, and consumer VPNs) as their primary obfuscation layer. This session draws on Team Cymru's Pure Signal NetFlow telemetry to expose how each hostile nation state operationalizes this strategy through distinct means: Chinese ORB networks, North Korean laptop farms, and Russian botnets. Attendees will leave with concrete detection and mitigation strategies grounded in external network visibility.
The APT OSINT Challenge
Date: Friday, August 7th
Time: 11:00-12:55 PDT
Location: DEF CON Adversary Village
This hands-on workshop places participants in the role of a threat intelligence analyst, tasked with attributing real-world cyber intrusions to Advanced Persistent Threat (APT) groups using only open-source intelligence. Working from publicly available breach reports drawn from my own Breach-Report-Collection repository, attendees will practise pivoting through OSINT sources, from MITRE ATT&CK and vendor threat blogs to DOJ indictments and IoC databases, to answer the fundamental questions of threat attribution: Who did this? Who sent them? And are they still out there? No prior threat intelligence experience is required; curiosity is the only entry ticket.
Threat Actors: Gotta Catch 'Em All
Date: Friday, August 7th
Time: 12:40-3:10 PDT
Location: DEF CON Recon Village
Your mission: Stop chasing single indicators and start profiling the actual behavior of the adversary. From cybercriminals to state-sponsored actors, every threat group leaves a unique operational blueprint. Whether you are an OSINT hobbyist or an experienced cyber intelligence analyst, come ready to dissect real-world attack behaviors, translate data into actionable insights, and master the art of OSINT-powered TTP research.
This hands-on workshop explores the world of cyber threat actors and the open-source intelligence (OSINT) methodologies used to unmask their behavioral patterns. Rather than focusing strictly on fleeting indicators of compromise (IoCs) like file hashes or IP addresses, participants will learn how to extract, analyze, and profile an adversary's true Tactics, Techniques, and Procedures (TTPs).

Eli Woodward
Senior Threat Intelligence Advisor
MCPwned: How Exposed AI Agents Became the Internet’s New Recon Toy
Date: Friday, August 7th
Location: DEF CON Adversary Village
This talk examines how exposed AI infrastructure is becoming a new adversary playground, as attackers and internet-scale scanners and bruteforcing target LLM gateways, MCP servers, local inference APIs, and AI developer tooling faster than defenders have built threat models for them.
Eli ran a purpose-built AI honeypot that simulated 16 LLM and AI infrastructure personas across 16 ports, returning framework-authentic responses, headers, errors, and protocol behaviors. In one 48 hour window, the system captured 3,993 requests from 327 unique source IPs, including 155 MCP probes and 344 AI API key probes. What emerged was not generic internet noise, but a repeatable playbook against the emerging AI stack: LiteLLM model-registration abuse, MCP resource enumeration, framework-aware credential brute forcing, and coordinated scanning for exposed local inference services.
Threatmaxxing Your Stakeholders while Mogging Your Threat Actors: What is Cyber Threat Intel?
Location: DEF CON n00b Village
This is a 15 minute lightning talk with an intro/brief overview of the Cyber Threat Intelligence discipline. Topics covered include why it's so hard to identify and define what CTI is in the current industry, the different aspects of what can be expected from CTI, and the typical backgrounds of CTI practitioners.
Having been a part of CTI teams at organizations with a wide variety of resources and maturity levels, this talk provides a realistic, ground-level view of the industry and what your average CTI experience is like, not the curated experiences of Fortune 500 CTI teams we all see presenting on the main stage.
Cl0p ^_- Til You Drop - 6 Years, 9 Campaigns, 7 0-Days
Location: Recon Village
For over half a decade now, Cl0p repeatedly targeted file‑transfer and middleware platforms that temporarily store the highest‑value organizational data in plaintext, operating as if these systems were Tier‑0 assets while defenders treated them as routine infrastructure utilities. This session presents a timeline of major Cl0p campaigns (2019–2025) and demonstrates consistent patterns in malicious infrastructure, reconnaissance, exploit selection, and target choice. We then map these behaviors to underlying architectural flaws across commonly deployed MFT and middleware systems. Attendees will leave with concrete design corrections—encrypting before ingestion, eliminating static staging folders, re‑classifying middleware as privilege boundaries, and building breach‑survivability into data‑movement workflows. This talk looks at structural fixes, not just IOCs, and offers practical guidance to reduce recurrence of MOVEit‑class events.
![BH - Form Header[3200x500]Dark BH - Form Header[3200x500]Dark](https://event.team-cymru.com/hs-fs/hubfs/BH%20-%20Form%20Header%5B3200x500%5DDark.png?width=2000&height=312&name=BH%20-%20Form%20Header%5B3200x500%5DDark.png)
