Black Hat USA

  • August 4-6, 2026
  • Las Vegas, Nevada

The premier cybersecurity event of the year returns to Mandalay Bay with a re‑engineered program built to ignite innovation, push boundaries, and bring the global security community together like never before.

Connect with Team Cymru at Black Hat USA to gain actionable intelligence on emerging cyber threats, uncover adversary infrastructure impacting your organization, and learn how security teams worldwide are using our data to accelerate investigations and strengthen defenses.

Mandalay___W_Las_Vegas___Night_Hero

71b3f18c-f85f-4f41-b0c0-7949722d2638-ps

The Cyber Lounge

Connect, Network and Unwind at The House of Blues

  • August 4-5, 2026
  • 10:00am – 10:00pm PT
  • The House of Blues at Mandalay Bay

The Cyber Lounge is making its fifth appearance at The House of Blues in Las Vegas, and we invite you to join us in this exclusive space designed for cybersecurity professionals to unwind, connect, and elevate industry collaboration.

Book a 1:1 meeting with a Team Cymru expert, or join us for happy hour featuring live music that sets the mood without interrupting the conversation.


US CYBERCON

Train. Compete. Win.

  • August 6, 2026
  • 10:00am – 5:00pm PT
  • HyperX Arena Las Vegas

The US Cyber Games program invites the community to gather for an unforgettable day of cyber competition and games, networking, and celebration in the heart of Las Vegas at the iconic HyperX eSports Arena Las Vegas.

Taking place on Thursday, August 6, between Black Hat USA and DEF CON, US CyberCON is where cybersecurity professionals, competitors, students, educators, sponsors, innovators, and enthusiasts meet to compete, connect, and support the next generation of cyber defenders.

Screenshot 2026-06-03 at 4.02.29 PM

Our ElevateExpo speakers

We're a passionate team of marketing professionals dedicated to creating an unforgettable and impactful event for our community

Speaker

Role & company

Speaker

Role & company

Speaker

Role & company

Speaker

Role & company

Speaker

Role & company

Speaker

Role & company

Speaker

Role & company

Speaker

Role & company
BH - Header[3200x500]Dark
will t

Will Thomas
Senior Threat Intelligence Advisor

Nation State Obfuscation Networks

Location: DEF CON Telecom Village

State-sponsored threat actors from China, Russia, and North Korea have fundamentally shifted their intrusion playbooks away from endpoint compromise and toward edge devices (routers, NAS devices, IP cameras, and consumer VPNs) as their primary obfuscation layer. This session draws on Team Cymru's Pure Signal NetFlow telemetry to expose how each hostile nation state operationalizes this strategy through distinct means: Chinese ORB networks, North Korean laptop farms, and Russian botnets. Attendees will leave with concrete detection and mitigation strategies grounded in external network visibility.

 

The APT OSINT Challenge

Date: Friday, August 7th

Time: 11:00-12:55 PDT

Location: DEF CON Adversary Village

This hands-on workshop places participants in the role of a threat intelligence analyst, tasked with attributing real-world cyber intrusions to Advanced Persistent Threat (APT) groups using only open-source intelligence. Working from publicly available breach reports drawn from my own Breach-Report-Collection repository, attendees will practise pivoting through OSINT sources, from MITRE ATT&CK and vendor threat blogs to DOJ indictments and IoC databases, to answer the fundamental questions of threat attribution: Who did this? Who sent them? And are they still out there? No prior threat intelligence experience is required; curiosity is the only entry ticket.

Link to Session

Threat Actors: Gotta Catch 'Em All

Date: Friday, August 7th

Time: 12:40-3:10 PDT

Location: DEF CON Recon Village

Your mission: Stop chasing single indicators and start profiling the actual behavior of the adversary. From cybercriminals to state-sponsored actors, every threat group leaves a unique operational blueprint. Whether you are an OSINT hobbyist or an experienced cyber intelligence analyst, come ready to dissect real-world attack behaviors, translate data into actionable insights, and master the art of OSINT-powered TTP research.

This hands-on workshop explores the world of cyber threat actors and the open-source intelligence (OSINT) methodologies used to unmask their behavioral patterns. Rather than focusing strictly on fleeting indicators of compromise (IoCs) like file hashes or IP addresses, participants will learn how to extract, analyze, and profile an adversary's true Tactics, Techniques, and Procedures (TTPs).

Link to Session




eli

Eli Woodward
Senior Threat Intelligence Advisor

MCPwned: How Exposed AI Agents Became the Internet’s New Recon Toy

Date: Friday, August 7th

Location: DEF CON Adversary Village

This talk examines how exposed AI infrastructure is becoming a new adversary playground, as attackers and internet-scale scanners and bruteforcing target LLM gateways, MCP servers, local inference APIs, and AI developer tooling faster than defenders have built threat models for them.

Eli ran a purpose-built AI honeypot that simulated 16 LLM and AI infrastructure personas across 16 ports, returning framework-authentic responses, headers, errors, and protocol behaviors. In one 48 hour window, the system captured 3,993 requests from 327 unique source IPs, including 155 MCP probes and 344 AI API key probes. What emerged was not generic internet noise, but a repeatable playbook against the emerging AI stack: LiteLLM model-registration abuse, MCP resource enumeration, framework-aware credential brute forcing, and coordinated scanning for exposed local inference services.

Link to Session

Threatmaxxing Your Stakeholders while Mogging Your Threat Actors: What is Cyber Threat Intel?

Location: DEF CON n00b Village

This is a 15 minute lightning talk with an intro/brief overview of the Cyber Threat Intelligence discipline. Topics covered include why it's so hard to identify and define what CTI is in the current industry, the different aspects of what can be expected from CTI, and the typical backgrounds of CTI practitioners.

Having been a part of CTI teams at organizations with a wide variety of resources and maturity levels, this talk provides a realistic, ground-level view of the industry and what your average CTI experience is like, not the curated experiences of Fortune 500 CTI teams we all see presenting on the main stage.

 

Cl0p ^_- Til You Drop - 6 Years, 9 Campaigns, 7 0-Days

Location: Recon Village

For over half a decade now, Cl0p repeatedly targeted file‑transfer and middleware platforms that temporarily store the highest‑value organizational data in plaintext, operating as if these systems were Tier‑0 assets while defenders treated them as routine infrastructure utilities. This session presents a timeline of major Cl0p campaigns (2019–2025) and demonstrates consistent patterns in malicious infrastructure, reconnaissance, exploit selection, and target choice. We then map these behaviors to underlying architectural flaws across commonly deployed MFT and middleware systems. Attendees will leave with concrete design corrections—encrypting before ingestion, eliminating static staging folders, re‑classifying middleware as privilege boundaries, and building breach‑survivability into data‑movement workflows. This talk looks at structural fixes, not just IOCs, and offers practical guidance to reduce recurrence of MOVEit‑class events.


BH - Form Header[3200x500]Dark