New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
blog

Offense Got Faster at Black Hat 2026. Defense Has to Get Connected.

Published

Aug 17, 2026

Introduction

It was a 116-degree Las Vegas August, “but it’s a dry heat,” as a hilarious sticker memorialized. Nevertheless, there was a breath of fresh air at the indoor forest Black Kite built on the show floor, complete with ranger gear, pine scent, and bird sounds. I'll get to why. It makes even more sense after framing what we all saw and heard at Black Hat and DEF CON.

Two Conferences, One Week, Opposite Conversations

Black Hat 2026 was a referendum on AI. A sizable share of sessions covered it, and the overwhelming majority of vendors were AI-centric, either using AI to solve security or applying traditional security approaches to the problem of AI.

Such heavy saturation invites skepticism. Ekrem Selçuk Çelik of the Black Kite Research Group™ attended his first Black Hat this year and put it plainly: AI was everywhere, "maybe a little too everywhere," and it sometimes felt forced, because it had to be there rather than because the problem needed it.

Then came DEF CON, where across the eight (randomly selected) sessions I attended, not one speaker raised AI at all. They were busy with older technology: hacking BGP, the routing protocol holding the internet together, Windows plug and play, capturing MFA tokens over long-range radio, transit cards, LoRA.

Two conferences, one week, and a gap between them is more important than either agenda. One floor was selling the future. The other was demonstrating that the past is still wide open.

AI is Collapsing the Cost of Finding and Exploiting Vulnerabilities

For twenty years, cybersecurity architecture rested on one assumption: bypassing a security boundary is expensive. Microsoft's David Weston used the Main Stage keynote to show that assumption expiring, with an AI vulnerability harness that surfaced more in three months than manual analysis had in the previous twelve.

Ferhat Dikbiyik, who leads the Black Kite Research Group™, took the Business Hall stage the same day to explain what that means downstream. His session, "The Vulnerability Deluge: How AI and Ransomware Are Reshaping Third-Party Risk," put a number on it: of the 48,000+ CVEs published last year, roughly 800 were exploited in the wild. Black Kite's 2026 Supply Chain Vulnerability Report narrowed it further, to 58 that posed a genuine, discoverable threat to enterprise supply chains.

Finding those 800 was always the job. Cataloging the 48,000 never was. CVSS scores were not built to tell you what is actively being exploited, and the KEV catalog tells you what already happened somewhere else.

As AI pushes discovery past 100,000 CVEs a year, that small stable number of things that actually matter stops being small or stable.

The Back Door Usually Belongs to Someone Else

Strip both agendas down and they point at the same thing. The most dangerous technology in your environment is the technology you didn't pick.

State-sponsored actors spent this summer turning hotel and conference Wi-Fi into malware delivery systems. That is not a hotel problem. Hotels rely on third-party providers for in-house networks, so the exposed supplier is one nobody in the transaction selected, evaluated, or could name.

Invert it and it gets worse. A vendor employee's credentials get compromised, an adversary walks in through a legitimate account, and that vendor becomes the path into every partner it serves. Cascading failure rarely starts with the organization that absorbs the damage.

DEF CON supplied its own case study. This year's badges shipped with a camera for a QR-code game. Someone backdoored it (shocker, at a hacker’s event) and produced identifiable photos from three feet away, at a conference with a strict no-photography policy and 40,000 attendees. A component nobody specified, in a device everyone was handed, doing something no one approved. That is third-party cyber risk management rendered in hardware.

Defense Needs to Evolve

Ekrem asked the question that connects both conferences: if offense is evolving this quickly, how fast does defense need to evolve?

The honest answer is that no single organization can evolve fast enough on its own, and continuing to try is the actual risk.

Prioritization proves it. Knowing which vulnerabilities matter this week requires knowing who is being targeted, what is being weaponized, and how quickly that is changing. None of that context exists inside one company's perimeter. A security team can see its own exposure perfectly and still have no idea which of its 4,000 vendors an active threat actor is working through right now.

Attack surface management stopped being about any one organization a long time ago.

What the Forest Already Solved: Collective Resilience

Nature settled the question of collective defense before anyone thought to ask it.

When pests attack, trees release compounds that summon the predators that eat them. When a hornet threatens a hive, bees coordinate and some of them die so the colony survives. The signal travels through the network, and the network is what survives.

Adversaries have already adopted the model. They share tooling, sell access, and collaborate across groups with more efficiency than most defenders manage inside a single company. Defenders still largely operate as individual trees.

One useful piece of pushback came at the booth from a CEO, who liked the framing with a caveat: everyone is talking about resilience right now, and not everyone agrees on what the word means.

He is right, so here is a definition worth arguing over. Resilience is the ability to reach a minimum level of business and functional viability no matter what happens – to you, or your suppliers. The only route to it runs outside your own organization.

Collective Resilience in Practice

The finger-wagging era of vendor management produced compliance theater and very little security.

Sending a vendor a list of 48,000 CVEs and a deadline was never a strategy. It assumed the vendor understood the sender's risk, had the capacity to act, and would respond to pressure from an organization with no real leverage. Usually none of those held.

Narrowing that list to the 30 or 40 findings that genuinely threaten the relationship changes the exchange entirely. The work has been done. The vendor gets a short list and a reason. That shift from policing to partnering is what collective resilience looks like on a Tuesday.

It already works. A Black Kite customer stopped by the booth (watch the video clip) to describe how his team identified a breach at one of their vendors before the vendor detected it, and then told them. One organization's visibility protected another organization's business, at no benefit to the first except a healthier ecosystem to operate in. 

That is the entire thesis, and it scales. Every organization monitored, every signal contributed, and every finding remediated makes the next compromise harder to land. It is the operating principle behind Black Kite's vendor engagement and cyber risk intelligence capabilities, and the reason a forest made more sense on that show floor than another booth about AI.

Offense got faster this year. Defense has to get connected.