📣 Send us your press release
Site updates every 15 minutes
Technology

AI aids and complicates cybersecurity at Black Hat conference

At the Black Hat cybersecurity conference, AI served as both a tool for threat detection and a source of new vulnerabilities. Network Operations Center staff used AI to manage alerts, but also identified security flaws in AI-generated code.

14 August 2026
AI aids and complicates cybersecurity at Black Hat conference

The annual Black Hat cybersecurity conference in Las Vegas saw artificial intelligence (AI) play a dual role this year: assisting security professionals in identifying threats while simultaneously creating new vulnerabilities. The Network Operations Center (NOC) staff leveraged AI to manage the influx of network activity and potential issues.

AI proved beneficial in spotting suspicious network behavior and distinguishing it from legitimate activity. James Pope, a NOC administrator and senior director of security product research at Corelight, explained the process of combining alerts into detections and then into "agentic triage." This system helped automate the handling of many identified issues.

During the conference, 8,892 network issues were observed, leading to 2,593 cases. The AI-powered triage system successfully handled 2,543 of these automatically, significantly reducing the manual workload for the NOC team.

However, the event also highlighted concerns regarding AI-generated software. Many applications, often created through rapid "vibe coding," lacked essential security measures like Transport Layer Security (TLS) for data transmission, leaving information exposed. This trend presents a democratization of development but introduces significant risks.

Pope advised attendees to use tools like Wireshark to analyze their own applications for data leaks upon returning home. He stressed that while AI can enhance network security, code generated by AI requires thorough scrutiny. The NOC team also focused on educating users about the risks associated with insecure applications beyond immediate network threats.

Original source: fastcompany.com