In 1997, Jeff Moss, founder of Def Con, held a one-off meeting called The Black Hat Briefings, giving engineers and software programmers an internal look at the mystical world of computer security and hackers. The show's press release read ominously:
It's late. You are alone in the office, keeping up with database management. Behind you, your network server hums quietly and reliably. Life is good. Life is safe. Or is it?
A wave of anxiety will wash you away. The air looks cold and scary. Your hands will become tillmie, as the sixth sense is telling you, suddenly, you are not alone. They're there. What's worse, they're trying to get in. And how? And what can you do to stop them?
The meeting promised users to “face today's cutting-edge computer security experts and 'hackers'.
The conference returned in 1998 and has been held annually ever since, expanding worldwide along with Black Hat Europe, Black Hat Asia, Black Hat Middle East and Africa.
The show evolved from targeting “people who implement it.” [CIOs’] Building Network Strategy and Applications “Build applications to portray security practitioners, including IT specialists, intrusion testers, cryptographers, security executives, business developers, CISOs, CEOs, consultants, and venture capitalists with vendors and sponsors who want to showcase their products and services.
Black Hat USA has grown from a two-day session of DOS attacks, two-day sessions of secure programming techniques and security monitoring to a six-day event, including a four-day training followed by a two-day main conference. The sessions will be held with AI, machine learning and agent AI. Supply chain security. Red team and pen test. Ransomware; Quantum Computing; And yes, there is still DOS attacks and security surveillance.
Black Hat is well known for hackers who show proof of concept, new attack techniques, security research and vulnerability disclosure. Below are some highlights from Black Hat USA 2025. In a 1997 press release, “The choice is yours. You can live in fear of them.
Critical vulnerabilities reveal enterprise secret safes
Researchers have discovered 14 zero-day vulnerabilities in Cyberark Congur, a secret management platform used by Hasicorp vaults and thousands of companies. The flaws discovered by Agent AI identity company Cyata allow authentication bypass, root access and remote code execution.
Five Combingur vulnerabilities have formed a single exploit chain that could allow an attacker to redirect authentication checks through the tool's policy factory functionality and execute malicious code. The nine vulnerabilities in Hashicorp could have been combined to bypass security controls and escalate privileges.
Both companies are patching their own key issues.
Read the complete story of Nate Nelson on Dark Reading.
Dell laptops are vulnerable to firmware-level attacks
Cisco researchers have revealed that over 100 Dell laptop models contain important Revault vulnerabilities that affect Controlvault3 firmware, which protects sensitive data, including passwords and biometrics.
Five high-strength flaws allow an attacker to maintain permanent access to withstand system reboots and full OS reinstallation. Vulnerabilities include memory access defects, buffer overflows, and dangerous escape issues that can be exploited remotely after initial access or via physical device access.
Dell has released patches for all vulnerabilities distributed via Windows Update.
Read the full story of Jaivi Jayan in Dark Reading.
Researchers hijack Google Gemini to control smart home devices
Security researchers have demonstrated how Google Gemini hijacked to control Smart Home devices. The attack used a Poisoned Google Calendar invitation with invisible rapid injections that became active when a user asked Gemini to summarize their weekly calendar. When these dormant instructions were triggered, they allowed Bennasy at Tel Aviv University, Stav Cohen at Israeli Institute of Technology, or Yair from the security company Safebreach to operate connected lights, shutters and even boilers.
To ensure that no technical knowledge is required and virtually anyone can access it, it highlighted the real-world consequences of compromised AI systems as large-scale language models are increasingly integrated into everyday life.
The researchers identified 14 indirect rapid injecting attacks against Gemini and reported their findings to Google.
Read the complete story from Kristina Beek's Dark Reading.
Editor's Note: The editors used AI tools to help generate this news brief. Our expert editors should always review and edit content before publishing.
Sharon Shea is the executive editor of Informa TechTarget's SearchSecurity site.
