The Sessions I'm Genuinely Excited About at Black Hat 2026 (Adam's version)
Adam Shostack, Shostack + Associates
The things I'm looking forward to at Black Hat this year.
Every Blackhat, there's a lot to be excited about, and I’m always excited about the Human Factors track.
- Thinking Beyond the Code: Contrarian Thinking to AI and Lessons From a Life in Discovery
- Peiter ‘Mudge’ Zatko has always had a fascinating mix of understanding
systems and unconventional thinking about them, which he combines
to fascinating results.
Wednesday, August 5 | 10:15am-10:45am ( Oceanside A, Level 2 ) - Managing Security Culture Half Life
- Bob Lord and Steve Tran have an incredibly interesting talk lined
up about the changes made at the Democratic National Committee
after the 2016 Russian break ins, and how those changes persisted
- or didn’t - after a leadership transition.
Wednesday, August 5 | 11:05am-11:45am ( Jasmine, Level 3 ) - Scambuster: Social Engineering Scammers at Scale
- This talk offers more Black Hat human factors than I thought you
could stuff into a talk about using LLMs to social engineer
scammers. This isn't just for fun - they are also extracting IoCs to inform other systems, and will share relevant code.
Wednesday, August 5 | 12:00pm-12:40pm ( Mandalay Bay H, Level 2 ) - Could a Pattern on Your Clothing Fool Facial Recognition?
- Bill Swearingen isn’t content with being survielled. None of us
should be, but Bill is fighting back with 61 different attack
techniques against 10 models — all of which can be printed
on the latest in fashion.
Thursday, August 6 | 11:05am-11:45am ( Oceanside B, Level 2 ) - You Can't Patch a Mental Model: How Agentic Systems Expose our Hidden Security Assumptions
- Ben Hanson is using agentic systems as a mirror into the hidden
assumptions that we’ve built into systems. I’m again excited
for the loop between technology, humans and the systems we build.
Thursday, August 6 | 11:05am-11:45am ( Mandalay Bay H, Level 2 ) - Threat Modeling LLMs: The PHANTOM-B model (Bonus!)
- Perhaps unsurprisingly, I’m also excited for my own talk on threat
modeling LLMs. At the heart of threat modeling is the
question “what can go wrong,” and what goes wrong with LLMs
seems to be a little different than attacks. PHANTOM-B tries
to focus on the LLM properties that traditional security models miss.
Wednesday, August 5 | 11:05am-11:45am ( Oceanside C, Level 2 )
I’m also excited by the training we’re offering at Blackhat along with everything else we have planned. (A complete list of my company’s events is being kept up to date.)
Also, my review board colleague Thomas Brandstetter has a linkedin post: What's cool at blackhat USA 2026.