Microsoft Security is preparing an extensive presence at Black Hat USA 2026, centering its messaging around a critical shift in the cybersecurity landscape: adversaries are increasingly exploiting trusted systems rather than simply hunting for vulnerabilities. The company will present keynote addresses, technical briefings, and hands-on demonstrations examining how attackers weaponize legitimate software dependencies, developer tools, and AI systems that enterprises rely upon daily.
Microsoft Security's focus at Black Hat 2026
The tech giant's participation at Black Hat USA 2026, scheduled for August 4 through 6 at Mandalay Bay in Las Vegas, reflects an urgent industry concern. Attackers no longer limit themselves to exploiting weak points in infrastructure. Instead, they infiltrate build pipelines, compromise package managers, and abuse AI agents to access critical code, data, and cloud environments. Microsoft Security's booth 2144 and main stage presentations will address how defenders can identify these trust-based attack vectors before they mature into full-scale breaches.
David Weston, Corporate Vice President of Agentic Security, will deliver the opening keynote titled “The End of Rare: Defending When Offense Is Cheap” at 9:15 AM PT on Wednesday, August 5, 2026. The address will examine how security operations centers must evolve as offensive capabilities become more accessible and scalable.
Later that day at 2:30 PM PT, Aarti Borkar, Corporate Vice President of Microsoft Security, and Tanmay Ganacharya, Vice President of Microsoft Security Research and Threat Intelligence, will present “Poisoned at the Source: Inside the Hunt for Supply Chain Attacks.” This main stage session will detail Microsoft Threat Intelligence's investigations into ongoing npm supply chain attacks affecting software ecosystems and developer workflows globally.
Technical research and expert sessions
Microsoft Security researchers will deliver three peer-reviewed briefings on Wednesday, August 5, 2026. Yossi Weizman, Principal Security Research Manager, presents “GitHub Can Tell You're Being Hacked. You're Just Not Listening: Building EDR for GitHub from Its Own Event Stream” from 10:15 AM to 10:45 AM PT. Dimitrios Valsamaras, Senior Security Researcher, follows at noon with “One Click to System: Exploiting Bixby's Trust Model for Full Device Compromise.” Shay Shavit, Senior Security Researcher, closes the technical track at 4:30 PM PT with “Handle With Care: Chaining Azure Automation Flaws for Cross-Tenant Identity Takeover.”
Additional practitioner-focused sessions will explore topics including AI integration in security operations, forensic defensibility of cloud evidence, and zero trust frameworks for AI systems. The company will also showcase Microsoft Defender Experts Threat Intelligence, a newly launched service providing curated intelligence tailored to organizational needs, alongside Microsoft Defender Experts MDR with expanded third-party and multicloud support.
Community engagement and skilling opportunities
Booth 2144 will operate as a community hub featuring ask-me-anything sessions, lightning talks, partner demonstrations from 13 Microsoft Intelligent Security Association members, and interactive demos spanning AI security and threat response. The booth will remain open Tuesday from 4:00 PM to 7:00 PM PT, Wednesday from 9:00 AM to 6:00 PM PT, and Thursday from 9:00 AM to 4:00 PM PT.
Microsoft Security will host a reception at Swingers at Mandalay Bay on Wednesday, August 5, 2026, from 6:00 PM to 9:00 PM PT, featuring mini golf, food, and networking opportunities with researchers and security professionals.
Remote participants can engage through the Microsoft Black Hat Skilling Challenge, launching July 20, 2026, which offers hands-on training across Microsoft Defender, Microsoft Sentinel, and Microsoft Security Copilot platforms.
Most Read











