August 5-6
Briefings dates
$2,495+
pass price
20,000+
attendees

SponsoredRetool

Retool's new app builder is where AI-generated code ships safely

Building apps with AI is easy. Getting them to production safely is another story.

Start building for free today

Black Hat USA 2026 Briefings run August 5-6 at Mandalay Bay Convention Center in Las Vegas. For practitioners deciding whether the $2,495 pass is worth it, the schedule is the deciding factor. Here is how the Briefings are structured, what the major research areas look like in 2026, why AI security is the dominant track, and how to plan two days of parallel sessions without missing your highest-priority content.

How Black Hat Briefings Are Structured

Briefings run on parallel tracks, typically six to eight simultaneous sessions throughout each day. Each session is 50 minutes, with a short break between presentations. Rooms vary in size from small specialty tracks to the main stage, which holds several thousand people. Popular sessions fill and close before the scheduled start time. Track themes are grouped loosely by domain but the division is not rigid. Day one opens with keynote presentations before tracks begin. Day two follows the same format through the afternoon closing.

The Major Research Areas in 2026

Black Hat 2026 tracks are expected to cover: AI and machine learning security (offensive use, defensive tooling, LLM vulnerability research); vulnerability research (browser, OS, hypervisor, hardware); cloud and identity attacks (OAuth abuse, cloud misconfiguration, SaaS supply chain); network security (carrier-level attacks, protocol abuse, 5G research); and operational technology and critical infrastructure. The AI security track is the largest and most competitive for room space based on trajectory from 2024 and 2025. Practitioners in any domain will find sessions directly relevant to their environment.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

The AI Security Track Preview for 2026

AI security in 2026 is not a novelty track. It encompasses autonomous vulnerability discovery, LLM-assisted exploit development, prompt injection at scale, AI system auditing, and the security of AI supply chains. The research being submitted to Black Hat 2026 reflects a year in which autonomous AI systems demonstrated the ability to find and exploit real vulnerabilities at scale. Attendees should expect live exploit demonstrations, new CVE disclosures, tool releases, and methodology presentations covering both offensive and defensive AI security.

Glasswing and Mythos Set the Context for 2026 AI Research

Anthropic's Project Glasswing, its AI-powered coordinated vulnerability disclosure program, has processed over 10,000 security findings across 200 partner organizations and produced 9 CVEs. The Claude Mythos model achieved 21 out of 41 ExploitBench V8 ACEs, a score no other model came close to. This is the research context Black Hat 2026 presenters are responding to. Talks on autonomous fuzzing, LLM exploit agents, and AI-assisted bug finding will reference or build on work that Glasswing and Mythos-class research established in 2025 and 2026. Understanding that baseline before you walk into Briefings makes every AI security session more useful.

Scheduling Strategy: Parallel Tracks and Arsenal Windows

You can only attend one session at a time. Planning your schedule means accepting that you will miss talks you want to see. The highest-leverage approach: identify your top three sessions per time slot in advance, then attend the first choice and treat the fallbacks as explicit plans if your first-choice room is full. Block at least one Arsenal visit per day. Arsenal demos run on a looser schedule and allow direct conversation with tool creators, which is often more useful than a packed Briefings room. Plan to walk the Business Hall during lower-priority session windows.

Session Priorities by Practitioner Role

SOC analysts and threat hunters should prioritize sessions on active threat actor TTPs, detection engineering, and new malware analysis techniques. Security engineers benefit most from vulnerability research sessions, browser and OS exploit methodology, and cloud architecture attack content. CISOs and security leaders get the most value from the main stage keynotes, CISO Summit sessions (separate track), and vendor Business Hall meetings. For anyone in AI security regardless of role, the AI and ML security track is the clear priority.

How to Access Talks You Miss

Most Black Hat talks are not recorded or publicly distributed during or after the conference. Some researchers post slides, papers, or blog posts independently within days of presenting. Following Black Hat speakers on LinkedIn and social platforms before the conference gives you the best chance of catching post-presentation writeups. The Black Hat conference archive occasionally publishes selected presentations, but coverage is inconsistent. Plan your schedule as if recordings will not exist.

Briefings Planning Resources for Decryption Digest Subscribers

Subscribers get access to curated Briefings planning content including the resources below.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The bottom line

Black Hat 2026 Briefings are two of the highest-signal days available to a security practitioner. The AI security track alone justifies the pass for anyone doing work in that space. Can't make the $2,495 pass work? Enter to win one at decryptiondigest.com/blackhat-2026. Subscribe to Decryption Digest and you are entered automatically.

Frequently asked questions

How many tracks does Black Hat Briefings have?

Black Hat Briefings typically runs six to eight parallel tracks simultaneously throughout each day. Each track is held in a separate room and covers different research domains. You can only attend one track at a time, which means every attendee misses significant content each day.

Are Black Hat talks recorded?

Most Black Hat Briefings talks are not recorded or made publicly available during or immediately after the conference. Some researchers post their slides or papers independently. A small number of talks are later published through official channels. Plan your schedule assuming you will not have a recording to fall back on.

Can I attend both trainings and briefings?

Trainings (August 1-4) and Briefings (August 5-6) require separate passes. A Briefings pass does not include training access, and a training pass does not include Briefings access. Some attendees purchase both, which significantly increases the total cost.

What is Arsenal at Black Hat?

Arsenal is the open-source tool demonstration area included with a Briefings pass. Independent researchers and open-source project contributors demo their tools in a hands-on, conversational format. Arsenal runs alongside the main Briefings sessions and is a high-signal area that many practitioners prioritize over vendor-heavy Business Hall time.

When does the Black Hat 2026 schedule get released?

Black Hat typically releases the full Briefings schedule approximately four to six weeks before the conference. For Black Hat USA 2026 with Briefings on August 5-6, expect the schedule in late June or July. The official app and website are updated simultaneously.

How should practitioners use the Black Hat session abstract summaries to prioritize AI security talks before the schedule drops?

Before the full schedule is published, the call-for-papers accepted abstracts (typically posted to the Black Hat website in the same timeframe as the schedule release) are the highest-signal source for identifying which AI security sessions justify your time. Read the abstract rather than the title: talks titled 'Advanced Exploitation Techniques' may contain significant AI-assisted discovery content, while talks explicitly labeled as AI security may cover introductory survey material. Cross-reference abstracts against the Glasswing CVE list and the Anthropic Exploit Evals benchmarks to identify which talks are building on confirmed production capability versus demonstrating novel but unvalidated techniques. Prioritize talks that cite specific CVE numbers, reference ExploitBench or ExploitGym, name vulnerability classes Glasswing confirmed, or include live demonstration components. These signals reliably distinguish production-validated research from conceptual presentations, which is the distinction that determines whether a session changes your defensive posture or just updates your threat vocabulary.

Sources & references

  1. Black Hat USA 2026 Official Site
  2. Black Hat Briefings Format and Tracks
  3. Anthropic Project Glasswing
  4. Decryption Digest Black Hat Giveaway

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Black Hat Giveaway

Win a $2,495 Black Hat pass.

Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.

Joins Decryption Digest daily briefing. Unsubscribe anytime.

Related Questions: Answer Hub

Giveaway: Black Hat USA 2026 Full-Access Pass ($2,495 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $2,495 Black Hat USA 2026 pass.