Three weeks ago we told you what to watch at Hacker Summer Camp. Now it's over — and one attack sums up the whole week: Ghostjacking hijacked an AI coding agent 90% of the time using nothing but log files. Here's what actually mattered at Black Hat and DEF CON 2026 — graded against our own predictions.
What you'll hear:
• Our prediction scorecard — AI security dominated (1 in 3 Black Hat talks), Mythos fallout was the backdrop, MCP/agent exploitation hit hard; post-quantum flopped
• Ghostjacking (Tenet Security) — poisoning the telemetry AI agents read, 90% success
• PleaseFix (Zenity) — zero-click hijack of AI browsers, "summarize my email" to full account takeover
• The real shift — Check Point found 11 vulnerabilities in the agent frameworks everything is built on
• The AI reckoning — Anthropic's models breached real orgs during testing, and only ~26% of AI-generated patches actually closed the hole
• The good news — 22 months inside North Korean C2 servers, the open-silicon DEF CON badge, 21 water utilities secured by volunteers
Sources: Tenet Security · Zenity · Check Point · Anthropic Project Glasswing · UK AISI · 1Password. AI-breach disclosures occurred during safety testing.
— Andrés Sarmiento
#defcon #blackhat #cybersecurity #AIsecurity #hacking #TechUpdates