BLACK HAT 2026 | CONFERENCE
11 min read

Black Hat 2026 Keynote Speakers: What to Expect from This Year's Opening Sessions

Keynotes open the Briefings days and set the industry agenda; in 2026, AI vulnerability discovery is the dominant story

August 5
Morning keynotes open Black Hat Briefings 2026
1997
Year Jeff Moss founded Black Hat
10,000+
Glasswing findings expected to shape 2026 keynote themes
21/41
ExploitBench V8 ACE challenges solved by Mythos; zero by all other models

SponsoredRetool

Retool's new app builder is where AI-generated code ships safely

Building apps with AI is easy. Getting them to production safely is another story.

Start building for free today

Black Hat keynotes are among the most-watched moments in the security industry calendar. They open the Briefings days, they set the tone for the conference's two hundred-plus technical sessions, and they often deliver the most consequential public statements on the state of security that any major platform produces in a given year. The 2026 keynotes open on the morning of August 5 at Mandalay Bay Convention Center in Las Vegas. Specific speakers have not been announced as of this writing, but the themes those speakers will address are already clear. AI-powered vulnerability discovery is the dominant story of 2026, driven by Project Glasswing's demonstration that an autonomous AI system can find 10,000+ vulnerabilities in 90 days, including a 17-year-old FreeBSD bug and working exploits for V8 challenges that no other system could solve. The question for the 2026 keynotes is not whether AI will be the central theme. It is how the security industry's most prominent voices will frame the implications of what has already been demonstrated. This guide covers how Black Hat keynotes are structured, who typically delivers them, the history of landmark moments in the keynote program, and what 2026 practitioners and CISOs should expect to take from the opening sessions.

How Black Hat Keynotes Are Structured

Black Hat Briefings opens with a keynote block on the morning of August 5, 2026. The keynote program typically spans two to three hours and includes two to four keynote addresses delivered sequentially in the main auditorium. All Briefings pass holders are invited to attend the opening keynotes, which are held in the largest conference hall available at Mandalay Bay to accommodate the full conference attendance. Each keynote address runs 30-50 minutes. Unlike Briefings session talks, which are allocated strict time slots with a moderator managing Q&A, keynotes have a more variable format. Some keynote speakers take questions from the audience; others deliver their address without Q&A. The tone of keynotes is different from research talks: keynotes are expected to frame big-picture themes and deliver perspective on the industry's direction, while research talks are expected to deliver specific findings with evidence. A keynote that fails to offer a compelling perspective on where security is heading is considered a disappointment regardless of the speaker's technical credentials. After the keynote block, the main Briefings session tracks open simultaneously in multiple rooms across the convention center.

Who Typically Delivers Black Hat Keynotes

The Black Hat keynote roster follows a pattern that has remained relatively consistent across recent conferences. Government keynotes: the Director of CISA has become a fixture in the Black Hat keynote program. The CISA Director's keynote is significant because it represents the U.S. government's most direct public engagement with the practitioner security community. These addresses have covered specific threat actor activity, policy initiatives, and calls to action for the private sector. NSA officials and senior Department of Defense cybersecurity leaders have also appeared in keynote slots in recent years. Research and industry keynotes: major security researchers who have produced significant findings, industry executives whose perspective on the field commands broad attention, and technology leaders addressing the intersection of business and security all appear in the keynote program. Jeff Moss: the Black Hat founder typically participates in the opening program. His addresses often have a conversational quality different from formal keynotes, and they frequently include his assessment of where the security community's values and priorities stand relative to the industry's commercial and governmental pressures.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

History of Landmark Black Hat Keynotes

Several Black Hat keynotes have shaped the security industry in ways that extended beyond the conference itself. The annual CISA Director appearances have been used to publicly attribute specific attacks to nation-state actors, announce new public-private partnership programs, and direct the practitioner community's attention toward specific threat categories. These policy announcements, delivered to a practitioner audience, often receive broader coverage than equivalent announcements made through government press releases. Jeff Moss's addresses over the years have tracked the evolution of the security community's relationship with government, industry, and technology. His framing of the security researcher as a legitimate professional, rather than a liability, has contributed to the normalization of vulnerability disclosure, bug bounty programs, and the practitioner's public role in the security ecosystem. Keynotes that have addressed specific major incidents (including major nation-state campaigns) at their first public acknowledgment at a major security conference have defined entire conference cycles. In 2026, the keynote most likely to achieve similar significance will engage most directly with the AI-powered discovery and exploitation capabilities that Project Glasswing has demonstrated.

Why Keynotes Set the Industry Agenda

The Black Hat keynote audience is not primarily the researchers and practitioners in the room. It is the much larger audience that watches the recordings, reads the coverage, and absorbs the industry's reaction to what is said. When the CISA Director says at Black Hat that a specific threat category is a priority, that statement reaches security teams at organizations that never send anyone to Las Vegas. When a major researcher delivers a keynote framing a new attack class, that framing becomes the vocabulary the industry uses to discuss the issue for the next year. The keynotes are industry-agenda-setting in a way that individual Briefings sessions, however technically excellent, typically are not. For practitioners, this makes keynotes more useful as strategic orientation than as technical instruction. A keynote will not teach you how to implement a specific defensive control. It will tell you which defensive challenges the security leadership class has decided matter most right now. That context is useful for understanding which Briefings sessions to prioritize, how to frame security investments to leadership, and what the threat landscape is expected to look like in the next 12-18 months.

The 2026 Likely Themes: AI Vulnerability Discovery and the Defensive Obligation

The 2026 Black Hat keynotes will address the AI-powered vulnerability discovery landscape that Project Glasswing has placed at the center of the security conversation. The specific themes most likely to dominate include the following. AI as an adversary capability: the demonstration that Claude Mythos solved 21 of 41 ExploitBench V8 arbitrary code execution challenges while every other model scored zero represents a capability threshold that the security industry cannot ignore. Keynote speakers will frame what this means for the defensive community's obligations and timelines. The collapse of patch windows: Glasswing's demonstration that AI can find 17-year-old bugs and develop working exploits without human-written code compresses the timeline from 'vulnerability exists' to 'exploit in the wild.' Keynotes will address whether the security industry's current patch management practices are adequate for the AI era. Regulatory response to AI security: the SEC disclosure rules and emerging AI-specific regulatory frameworks intersect with the AI security capability question. Keynotes from government officials will likely address how regulators are thinking about AI-era security disclosure and compliance obligations. The defensive use of AI: keynotes will also address the other side of the equation, specifically how organizations are deploying AI for defensive purposes, and what the evidence shows about AI's effectiveness as a security tool.

How to Follow Speaker Announcements

Black Hat 2026 keynote speakers will be announced in the months before the conference. To follow announcements as they are made, use the following channels. The official Black Hat website at blackhat.com is the authoritative source. The Briefings and keynote schedule pages are updated as speakers are confirmed. The official Black Hat Twitter/X account announces speakers and agenda updates and is typically the fastest channel for breaking announcements. The Black Hat email newsletter, available via the website, sends direct announcements to subscribers as major speakers and sessions are confirmed. Security journalism from outlets including Dark Reading, The Register, Wired Security, and Ars Technica covers major Black Hat announcements, including keynote speaker confirmations, as they are made. Following these sources is the most reliable way to track the 2026 keynote lineup as it develops.

What Practitioners and CISOs Should Take from Keynotes

Practitioners and CISOs consume Black Hat keynotes differently. For practitioners, the keynotes provide strategic context for interpreting the technical sessions. When a keynote speaker identifies AI-discovered Linux privilege escalation as a priority defensive challenge, that context helps practitioners prioritize which Briefings sessions to attend, which Arsenal tools to investigate, and which defensive improvements to propose to their organizations after the conference. For CISOs, the keynotes provide board-room language for security investment justification. A CISA Director statement about AI-era patch management timelines, delivered at the largest practitioner security conference in the world, is a more compelling external reference for a board conversation about patch management investment than an internal security team recommendation. The keynotes give security leaders external validation and vocabulary for discussions that might otherwise be treated as internal security team opinion. Both audiences benefit from watching keynotes not as isolated presentations but as the opening move in a multi-day conversation: the keynotes frame the themes that the Briefings sessions, Arsenal demonstrations, and hallway conversations will all engage with across the two Briefings days.

Watching Live vs. Recorded

Attending keynotes in person provides the full conference experience: the energy of the room, the ability to observe the audience's reaction, and the context of being in the same space as the security community's most significant annual gathering. For practitioners who are already attending Black Hat Briefings, attending the opening keynotes in person on August 5 morning is strongly recommended. The keynote auditorium fills quickly for high-profile speakers, so arrive early. For those who cannot attend in person, Black Hat publishes keynote recordings on its official YouTube channel in the weeks following the conference. The recordings are the full presentation without audience interaction, which is generally the most valuable part. Some keynotes from high-profile government speakers are livestreamed during the conference; check the Black Hat website for any 2026 livestream announcements. Following the conference hashtag on Twitter/X in real time during keynotes provides a community reaction layer that the recordings do not capture.

Keynote Preparation Resources for Subscribers

The complete Black Hat 2026 keynote preparation guide, including the AI vulnerability discovery briefing materials, a framework for translating keynote themes into board-ready language, and a post-keynote debrief template for security team discussions, is available in the Mythos Brief for Decryption Digest subscribers.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The bottom line

Black Hat 2026 keynotes open August 5 morning at Mandalay Bay Convention Center. Specific speakers have not been announced, but the 2026 themes are already clear: AI-powered vulnerability discovery, the compression of patch windows, autonomous exploit development, and the defensive community's obligations in an era when AI systems like Claude Mythos solve V8 exploit challenges that no other tool can approach. The keynotes will frame these themes in ways that shape the industry conversation for the next 12-18 months. Prepare for those conversations with the Mythos Brief at decryptiondigest.com/mythos-brief. And if you are not yet registered for Black Hat 2026 Briefings, enter to win a full Briefings pass at decryptiondigest.com/blackhat-2026.

Frequently asked questions

Who are the Black Hat 2026 keynote speakers?

Specific Black Hat 2026 keynote speakers have not been announced as of this writing. Black Hat typically announces keynote speakers in the months leading up to the conference. To follow announcements as they are made, check the Black Hat USA 2026 website at blackhat.com, follow the official Black Hat Twitter/X account, and subscribe to the Black Hat newsletter. Historically, keynote speakers have included the CISA Director, senior NSA officials, prominent security researchers, technology industry leaders, and Jeff Moss (the founder of Black Hat), who typically delivers an address that frames the state of the industry.

When are Black Hat 2026 keynotes?

Black Hat 2026 keynotes open the Briefings conference on the morning of August 5, 2026, at Mandalay Bay Convention Center in Las Vegas. The exact keynote schedule will be published in the conference agenda as it is finalized. Keynotes typically run in the first two to three hours of the morning before the main Briefings session tracks begin. All Briefings pass holders can attend the opening keynotes, which are held in the largest available auditorium space at Mandalay Bay.

Are Black Hat keynotes recorded?

Yes, Black Hat keynotes are typically recorded and made available after the conference. Black Hat publishes recordings of keynotes and many Briefings sessions on its official YouTube channel (youtube.com/c/BlackHatOfficialYT) in the weeks following the conference. Some sessions are released within days; others take longer to process and publish. If you cannot attend Black Hat 2026 in person, following the official Black Hat YouTube channel and social media accounts will allow you to access the keynote content after the conference.

Who is Jeff Moss?

Jeff Moss, also known as 'Dark Tangent,' is the founder of Black Hat and DEF CON, the two most significant security conferences in the world. He founded Black Hat in 1997 and DEF CON in 1993. Moss served on the U.S. Department of Homeland Security Advisory Council and has been an influential voice in shaping the relationship between the security research community and government agencies. At Black Hat, Moss typically delivers a keynote or participatory address that offers his perspective on the state of the security industry. His commentary tends to be candid and historically significant in framing how the practitioner community interprets the year's most important developments.

What was the most important Black Hat keynote of recent years?

Several Black Hat keynotes have been historically significant. The annual address from the CISA Director has become a major moment at Black Hat, with directors using the platform to announce policy initiatives, acknowledge specific threats, and engage directly with the practitioner community. Former NSA Director Keith Alexander's 2013 keynote, which addressed the Snowden revelations directly, was a defining moment in the conference's history. Keynotes that introduced major industry-shifting concepts, such as those addressing the early development of bug bounty programs as a government procurement mechanism, have had lasting policy impact. In 2026, the keynote most likely to have lasting significance is whatever address engages most directly with AI-powered vulnerability discovery and its implications for the security industry's defensive obligations.

How can practitioners extract maximum operational value from Black Hat 2026 keynotes rather than treating them as passive industry theater?

Treating keynotes as passive industry theater is the most common Black Hat mistake, particularly for practitioners who have limited conference time and competing session priorities. Extract operational value by preparing a specific hypothesis before each keynote: based on the speaker's background and announced topic, write down one prediction about what the address will recommend and one gap in your current security program that you want the keynote to inform. Evaluate each against what the speaker actually says. This active framing converts keynote attendance from passive consumption to a structured assessment exercise. During the keynote, note every external reference, government data point, or benchmark figure the speaker cites -- these become defensible anchors for internal risk conversations and board presentations. Immediately after the keynote (before the first parallel session begins), spend five minutes writing down the single most actionable implication for your organization. The keynotes that change defensive posture are the ones where a practitioner leaves the auditorium with a specific action rather than a general sense of urgency.

Sources & references

  1. Black Hat USA 2026 Official Site
  2. Black Hat Briefings Schedule
  3. Anthropic Project Glasswing 90-Day Report
  4. CISA Cybersecurity Advisories
  5. Informa Tech, Black Hat Organizer

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Black Hat Giveaway

Win a $2,495 Black Hat pass.

Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.

Joins Decryption Digest daily briefing. Unsubscribe anytime.

Related Questions: Answer Hub

Giveaway: Black Hat USA 2026 Full-Access Pass ($2,495 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $2,495 Black Hat USA 2026 pass.