Skip to main content

Cybersecurity

August 11, 2026

 

The bots are teaming up. People should, too.

A dispatch from Black Hat 2026 in Las Vegas, where AI-driven cyberattacks were the talk of the show.

On the show floor at Black Hat 2026.

On the show floor at Black Hat 2026. (Photo credit: Jen Langione, Mastercard)

Bree Fowler

Contributor

When thousands of researchers, security practitioners and business leaders braved the heat of Las Vegas to attend the ​​Black Hat ​​cybersecurity conference ​this past week, the main topic of conversation came as little surprise: Rapidly evolving artificial intelligence technology is supercharging cyberattacks, and the industry must find a way to fight back.

More surprising was the stark warning from one of AI’s pioneers, OpenAI. Earlier this summer, a team of the company’s most advanced AI agents worked together to launch a cyberattack on the developer platform Hugging Face without being prompted to by humans.

OpenAI researcher Michael Dalton urged organizations to invest in better safeguards for AI agent development. He announced that OpenAI is slowing its research to boost security, starting with monitoring its AI agents more closely and enhancing controls for breach prevention, detection and mitigation. 

​​“We believe this is a watershed moment for computer security as an industry, as well as for AI as a whole …  AI-orchestrated, fully automated offensive attacks are real now," Dalton said during a presentation that detailed the Hugging Face hack.​​​​​​​​​​ 

​​​Concerning as the news ​​from OpenAI has been​​, ​​Dalton ​​chose the right venue to rally the ​​industry​​ to action. ​​Annual events like Black Hat offer some of the best opportunities ​for ​companies and industry experts ​to gather together ​to try to find the best solutions for their common problems.

​​Experts at the conference were able to outline ways organizations can protect themselves from this new generation of threats.​

Here are some of the takeaways from Black Hat, including one between leaders from Mastercard and Recorded Future – the threat intelligence ​​company it acquired in 2024 – along with analysts and members of the press. 

Moving at the speed of an AI agent

Organizations have been slow to deploy their own AI agents to fight off agentic AI-based cyberattacks, deterred by concerns about “breaking something” or violating data security and privacy regulations. “But we really don't have a choice,” said Levi Gundert, chief security and intelligence officer at Recorded Future. “That's really what it comes down to. We basically have six to 12 months before defenders are going to be absolutely overwhelmed.”

That’s because AI has the advantage of “velocity,” as Gundert put it. The newest AI agents are zeroing in on vulnerabilities that had gone undiscovered for years. In addition, they can take advantage of multiple minor security gaps at once to infiltrate protected environments.

As a result, cybercriminals are exploiting vulnerabilities at unprecedented speed. And without their own AI defenders, humans can’t find and fix software bugs fast enough to keep up, Gundert said.

He added that now is the time for organizations to advance research and development, test edge cases and figure out how to safely deploy agents into their defenses.

Getting back to security basics

Beyond the social impact that people tend to focus on, the Hugging Face incident lays bare the operational consequences of AI for organizations, according to Alissa Abdullah, Mastercard’s deputy chief security officer. She says technologists need to be ready to both invest in the right technology and design effective guardrails to keep AI in check.

“We're running this race of trying to be first to win the AI battle and say we're doing it,” Abdullah said during the Black Hat press briefing. “But a lot of organizations are still dealing with baseline problems that we still haven't cleaned up.”

As an example, she pointed to long-ago-identified, but ongoing, issues with software-supply chain security.

We basically have six to 12 months before defenders are going to be absolutely overwhelmed.

Levi Gundert, Recorded Future chief security and intelligence officer

Pooling knowledge with partners

To prevent fraud and other kinds of cybercrime, organizations must stay on top of the latest developments in AI. That’s where human intelligence comes in, Gundert said. Security works best when it’s paired with a deep knowledge of the threat landscape, and defenders will need all the help they can get over the next several months, he added. That’s where partnerships come in.

According to the World Economic Forum, 48% of CEOs in what it measured as the most resilient organizations are ramping up their collaborations with government agencies and information-sharing groups, as are 49% of companies with more than 100,000 employees. They are aided by public-private initiatives — such as the Joint Cyber Defense Collaborative and the World Economic Forum Cybercrime Atlas — that allow companies, law enforcement agencies and governments to pool their knowledge to disrupt cybercrime.

Companies look to direct partnerships for cyber ​​intelligence​​​​​​ help, too. For instance, Accenture, which has its own extensive cybersecurity operations, regularly ​relies on​​​ Google Cloud for security intelligence. ​​It’s a partnership ​Ryan Whelan, global head of Accenture Cyber Intelligence,​ views as​​​ key ​to its success ​and ​one that ​has grown over the years.​ ​​​​​​

“We continue to ​​lean into that,” Whelan said during a Black Hat media panel. “We rely on them for a lot of the data that we use and help operationalize that for clients.”

​​Experts from ​Recorded Future help the payments company by looking at the broader online landscape to identify threats before they can become a problem, Gundert said. For example, Record Future’s analysts are identifying scam merchants who use AI to open legitimate-looking online shopping sites. Lured by social media ads, consumers who attempt to buy products from them end up getting ripped off. 

But when analysts spot and flag those sites, Mastercard can ensure the transactions never go through.

“It's not like a silver bullet, but these are two domains that interconnect pretty well,” Gundert said about bringing together cybersecurity insights from both Mastercard and Recorded Future. “In this case, we're not protecting enterprises so much for profit, but consumers.” 

 

Learn more

Cybersecurity experts gathered at Black Hat 2026 to discuss AI-driven threats, fraud, digital trust and emerging risks. Here are the key takeaways.