Get ready for Black Hat USA 2026 

Join Endor Labs and XBOW at Libertine Social in Mandalay Bay
Sponsors
Our Black Hat sponsors
Thank you to our partners supporting Endor Labs’ Black Hat activities.
Major Sponsor
Party Sponsors

Base camp at Libertine Social

Meet with fellow researchers, defenders, and builders
Anonymized: Exclusive Wine Tasting
Monday, 3rd August 4:30pm-6pm
The best rooms at Black Hat don't have signs on the door. Anonymized is an evening of tasting fine wines hosted by Endor Labs, Terra Security and Dell Technologies Capital for the security leaders who are building what comes next.

No keynotes. Just good drinks, honest conversation, and the people from all sides of the table.
Secure your Seat
Mythos Brunch
Wednesday, 5th August 10am-12pm
The Mythos era broke the assumptions AppSec was built on: infinite bugs, maintainers underwater, triage that can't keep pace with shrinking mean-time-to-exploit.

The answers don't exist yet so we're writing them together. A working session for security and engineering leaders. No panels, no slides. You won't be talked to; you'll help define the problems that define this era.
Save your Seat
Building Effective AI Security Agents: Beyond "Just Ask the AI"
Wednesday, 5th August 3pm-3:45pm
Stop relying on clever prompts and start building reliable AI security tools.In this interactive Q&A, Jason Haddix cuts through the hype: testing tradecraft over prompt tricks, proven ways to cut hallucinations and false confidence, and how to structure agents for consistent, actionable results.
Register Now
Code, Conversations & Cocktails 
Wednesday, 5th August 5pm-9pm
After a busy day on the show floor clocking up that step count, attending sessions and having meetings, it's time to relax and enjoy some off the clock conversations over great food, drinks and a live DJ. 

Join Endor Labs alongside Averlon, OLIGO, Token Security, Witness AI and XBOW as we bring the party to you. 
Register Now
Schedule a meeting with our team
Curious about how we help security teams stay ahead of application security in the AI era? Our experts will be on hand for casual conversations and hands-on demos.
Schedule a Meeting

Lightning sessions

9:30 am PT
5th
Wednesday
Anatomy of a Modern Software Supply Chain Attack
Malware in open source ecosystems surged 14x in the past year, largely driven by compromises of trusted packages and maintainers. 88% of engineering and security teams know the first days after a release are the highest-risk window, yet most struggle to identify and contain until too late. We'll break down how modern package attacks actually work, and how to move from reactive detection to proactive prevention.
11:30 am PT
5th
Wednesday
Offensive Security Without Human Bottlenecks — What Breaks and What Scales
Maury Cupitt, Head of Solutions Architecture, XBOW
Open source malware is no longer rare: 51% of organizations found malicious packages in 2025. Yet the gap is striking — 88% know new releases are the riskiest window, but only 21% enforce a cooldown. New data from 605 security professionals shows where defenses are falling short.
  • Identifying which defenses break down first against machine-speed attacks
  • Adopting nonstop, automated security testing at scale
  • Scaling security to meet the new magnitude and speed of AI‑generated software
12:15 pm PT
5th
Wednesday
Engineering the Security Harness for AI Coding Agents
Agents are powerful tools for coding tasks, but many teams still use them as blunt instruments for security tasks, burning time and tokens. Agents shouldn't have to reconstruct your security posture from scratch on every task; they need direct access to vulnerability details, upgrade paths, package impact analysis, and remediation guidance specific to your codebase. This is the role of harness engineering. We'll show how building specialized agents cut cost, improve outcomes, and give you visibility into what your agents are actually doing.
12:45 pm PT
5th
Wednesday
AI Pentesting Trivia Showdown
Andy Dennis, Head of Field Engineering, XBOW
Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. 
Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.
1:30 pm PT
5th
Wednesday
Autonomous Pentesting in a Live AWS Environment
This session will showcase a learning lab walking through the XBOW/AWS integration - how XBOW discovers, enumerates, and tests an example customer's AWS org end to end, from asset discovery to validated findings.
2:15 pm PT
5th
Wednesday
Following the Flow to a 22x Memory-Amplification DoS
Pointed at buffa, Anthropic's Rust protobuf library, Endor Labs flagged a data flow that's easy to skim past: an unknown-field decoder that allocates heap in proportion to attacker-controlled input. The obvious sink amplifies a modest ~2x, but one branch further sits a second sink that turns a tiny input into a ~22x allocation, enough to OOM-kill a process (now CVE-2026-55407). A frontier model reasons well about the code it surfaces but leaves most of the repo unexamined, while a pattern scanner matches everywhere but is blind to behavior; we'll walk through how following the data flow catches what both miss.