Black Hat Conference

Black Hat Conference

The Black Hat Conference is one of the world's most important professional events on computer security. Experts publicly demonstrate there how they found security vulnerabilities in software, devices, and now also in AI systems.

The Black Hat Conference is a major professional gathering for everyone who works professionally on the security of computers and networks. It takes place every year, with the best-known edition held in summer in Las Vegas. On stage are people who professionally search for weaknesses in programs and devices. A vulnerability is a flaw that allows an attacker to make a system do things the manufacturer never intended. Exactly these kinds of flaws are presented there, complete with technical details and often a live demonstration. The name is a nod to the old Western convention that the bad guys wear black hats — even though the presenters mostly work on the defenders' side.

The place where security vulnerabilities go public

Security research usually happens out of sight. Whoever finds a vulnerability first reports it to the manufacturer and waits until a patch is ready. The Black Hat Conference is the moment when many of these findings are finally explained publicly. That’s why companies like Microsoft, Apple, or Google often time the release of their updates to coincide with the conference.

For companies, the conference is also an uncomfortable deadline. Anyone who ignores a reported vulnerability for months risks having it discussed on a big stage. This pressure is a key reason why manufacturers take security reports seriously at all.

In recent years, AI has moved to the center of the talks. Topics include, for example, prompt injection — hidden instructions in a website or email that an AI assistant mistakes for a user request. Attacks on AI agents with access to calendars, files, and banking data are also demonstrated there. Anyone who wants to know which AI risks will be in the news a year from now often finds them here a year earlier.

Talks, trainings, and the rules for demos

The core of the event is the so-called Briefings: roughly 40-minute technical talks for which you submit an application beforehand. A selection committee checks whether the finding is new and technically sound. Pure marketing talks from companies get filtered out, which is the basis of the conference’s reputation. Alongside this, there are multi-day, expensive trainings in which participants practice attack and defense techniques themselves.

An important rule concerns how to handle vulnerabilities that are still unpatched. The common practice is responsible disclosure: the manufacturer is informed beforehand and given time for a patch, usually 90 days. Only afterward does the talk follow. Sometimes companies sue over this, or lawyers block a presentation at the last minute. Such conflicts are part of the conference’s history.

The conference also includes an exhibition hall with security companies and an area with competitions. It’s important to distinguish it from DEF CON, which runs right after it in the same city. Black Hat is expensive, business-oriented, and aimed at companies and government agencies. DEF CON is cheaper, more chaotic, and more strongly shaped by the hacker scene itself. Many professionals attend both in the same week.

Why the name shows up in business news

In the news, the term usually appears as a source reference. Sentences like “at the Black Hat Conference, researchers demonstrated that a car can be remotely controlled via radio” come from such talks. Well-known examples involved pacemakers, ATMs, hotel room locks, and vehicle electronics. Such reports sometimes even move stock prices, because they put a manufacturer under pressure.

For companies, the conference is also a recruiting and sales market. Security vendors present new products there, and corporations look for talent. When a company announces a bug bounty program — that is, cash rewards for reported flaws — it often happens to coincide with this event.

A common misconception is that the conference is a gathering of criminals. The opposite is true: those attending are mainly employees of security companies, IT departments, government agencies, and universities. The underlying idea is that you can only protect a system if you thoroughly understand the attacks against it. That’s why attack techniques are openly taught there.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.