Shostack + Friends Blog

 

The Sessions I'm Genuinely Excited About at Black Hat 2026 (Adam's version)

Adam Shostack, Shostack + Associates

The things I'm looking forward to at Black Hat this year. An image of the Black Hat logo

Every Blackhat, there's a lot to be excited about, and I’m always excited about the Human Factors track.

Thinking Beyond the Code: Contrarian Thinking to AI and Lessons From a Life in Discovery
Peiter ‘Mudge’ Zatko has always had a fascinating mix of understanding systems and unconventional thinking about them, which he combines to fascinating results.
Wednesday, August 5 | 10:15am-10:45am ( Oceanside A, Level 2 )
Managing Security Culture Half Life
Bob Lord and Steve Tran have an incredibly interesting talk lined up about the changes made at the Democratic National Committee after the 2016 Russian break ins, and how those changes persisted - or didn’t - after a leadership transition.
Wednesday, August 5 | 11:05am-11:45am ( Jasmine, Level 3 )
Scambuster: Social Engineering Scammers at Scale
This talk offers more Black Hat human factors than I thought you could stuff into a talk about using LLMs to social engineer scammers. This isn't just for fun - they are also extracting IoCs to inform other systems, and will share relevant code.
Wednesday, August 5 | 12:00pm-12:40pm ( Mandalay Bay H, Level 2 )
Could a Pattern on Your Clothing Fool Facial Recognition?
Bill Swearingen isn’t content with being survielled. None of us should be, but Bill is fighting back with 61 different attack techniques against 10 models — all of which can be printed on the latest in fashion.
Thursday, August 6 | 11:05am-11:45am ( Oceanside B, Level 2 )
You Can't Patch a Mental Model: How Agentic Systems Expose our Hidden Security Assumptions
Ben Hanson is using agentic systems as a mirror into the hidden assumptions that we’ve built into systems. I’m again excited for the loop between technology, humans and the systems we build.
Thursday, August 6 | 11:05am-11:45am ( Mandalay Bay H, Level 2 )
Threat Modeling LLMs: The PHANTOM-B model (Bonus!)
Perhaps unsurprisingly, I’m also excited for my own talk on threat modeling LLMs. At the heart of threat modeling is the question “what can go wrong,” and what goes wrong with LLMs seems to be a little different than attacks. PHANTOM-B tries to focus on the LLM properties that traditional security models miss.
Wednesday, August 5 | 11:05am-11:45am ( Oceanside C, Level 2 )

I’m also excited by the training we’re offering at Blackhat along with everything else we have planned. (A complete list of my company’s events is being kept up to date.)

Also, my review board colleague Thomas Brandstetter has a linkedin post: What's cool at blackhat USA 2026.