At a glance
Every control in your enterprise rests on one assumption nobody writes down: that crossing a security boundary is hard, and therefore rare. David Weston, who leads the agentic security team at Microsoft, opened day two of Black Hat USA 2026 by putting numbers on the collapse of that assumption. MSRC is now processing nine times the vulnerability volume it handled in March, roughly doubling every six weeks. An internal harness turned loose on Windows on April 1 found more critical and important issues in four months than the entire preceding year. A second harness found about 200 Linux kernel vulnerabilities in Microsoft's own distribution and then automatically generated 182 crash level proofs of concept from them, many of them working root exploits, at an average cost of $3.61 and 21 minutes each.
That is the bad half. The good half is that Weston is, by his own admission, probably the only optimist in the room, and he has a thesis for why. What is happening is not magic, it is productivity, and productivity is available to both sides. The trap is spending it on symmetric fights: vuln for patch, exploit for detection, evasion for detection. Weston calls that hand to hand combat and says defenders lose it. The alternative is to spend the same productivity on things that change the shape of the problem permanently: memory safe rewrites at scale, formal verification of the boundaries that matter, and agent driven prevention across infrastructure that has finally been written down as code.
The evidence he brings for the optimistic half is as specific as the evidence for the pessimistic half. Android went from 76 percent of its patched vulnerabilities being memory safety issues in 2019 to under 20 percent in 2025, after five million lines of Rust that has never shipped a single memory safety bug. Azure rewrote its hypervisor in open source Rust and is running past 1.5 million virtual machines without an incident. Microsoft generated 30,000 lines of Lean proof in a single week, mostly agent driven, formally verifying AES-GCM. And a single wrong shift in a post quantum key encapsulation algorithm survived every test, every fuzzer, and human review, and was caught only by formal verification.
The talk is bracketed by Jeff Moss opening the 29th Black Hat with a short, sharp argument that security is political whether the industry likes the word or not, and by a closing three item homework list that Weston hands the audience: make your highest risk surfaces secure by design, point agents at formal verification of your most critical boundaries, and build an agent army on top of infrastructure as code and graph computation.
The cold open
The lights come up on news audio. A voice warning about "the scope of a massive cyber attack," another saying it is "already believed to be the largest," a third calling it "America under virtual invasion." Then the music, and the president of Black Hat, Susie Pallet, walks out to open day two.
Her first question to the hall is a show of hands: who got less than five hours of sleep last night? Enough hands go up that she laughs. "Yep, that's Black Hat." And then the reason, which is the actual point she is making: you stayed up late because you were in a conversation that mattered, because someone showed you something you had never seen before, because you finally met the researcher whose work you have followed for years, or because you were in your room debugging an idea that would not let you go.
Day one, she says, gave the audience a taste. Day two goes deeper into the research, the hard problems, and the conversations that will shape how the industry thinks about security long after everyone leaves Las Vegas. Her challenge for the day is four words long: don't just attend, discover. Black Hat is more than what happens on the main stage. It is what happens when you step into the convergence and meet someone new, when you sit down at Arsenal and talk to the person who built the tool you did not know you needed, when you ask the question in a briefing that everyone else was thinking but nobody said out loud. Those moments are where the real work happens.
She flags the evening's event before handing off: the world premiere of Midnight in the War Room, a documentary that goes inside the realities of modern cyber conflict and the impossible decisions that shape it. And then she brings out the man who, more than 25 years ago, "saw something that didn't exist and decided to build it. A place where security researchers could share their work without filters, without corporate spin, and without apology. A place where breaking things wasn't just accepted, it was expected." Hacker, founder, CISO, adviser to governments, but at his core a builder. Jeff Moss, founder of Black Hat and president of DEF CON.
Jeff Moss: the 29th Black Hat
Moss opens with a joke about the walk on music. Earlier they had been playing jazz before the room filled, and somebody said no, no, we need the beats.
This is the 29th Black Hat, with the 30th coming next year. He does his usual quick run of the show, and then goes to the number he actually cares about. Black Hat is expensive, especially for people just entering the field, so there is an alternative path in: the scholarship program. You write a white paper, it gets reviewed, and if they like it you get admission for free. This year 131 people attended Black Hat on a scholarship. He asks them to raise their hands, and the room applauds.
Then the part he wants the new people to hear. Some of the keynote speakers from the last two years started out as scholarship attendees. "It is absolutely possible to go from a noob to a badass," he says, "and we're a pretty welcoming community." Attendance this year spans over 103 countries, and he asks everyone not from America, Canada or Mexico to raise a hand, then tells the room to go find them. "Let's get a different perspective. Let's see how security works outside of our bubble."
The four themes, and why three of them are political
Black Hat 2026 is organized around four themes:
- AI and autonomous threats
- Cyber conflict and live operations
- Information operations
- Engineering resilience, identity, trust and control
Moss points out the obvious thing about that list: probably three of the four are political. Which takes him back to something he has been saying from this stage for a decade. Infosec is political. Technology is political. And saying that word out loud makes the whole industry uncomfortable.
"But we have to sort of embrace it. If we don't embrace it, politics will happen to us."
He walks the room through what that looks like right now, at three scales.
Globally. With the conflict in Europe, Russia is all over the giant hyperscalers in multi tenant environments. Why? Because the hyperscalers inherit the risk models of their customers. If your customer is Ukraine, guess what: your opponent is Russia. You just wanted to sell rack space, and now you are in the middle of a power conflict. The same dynamic runs through the great power conflict with China, most visible right now around AI and the open weights debate, and before that around high performance GPU chips trans shipping through countries in Southeast Asia. This stuff is political, and you need a view and an awareness of it to be effective at your job.
Locally and at the state level. What is in the news is Iran hacking rural water districts in the middle of the country. Why rural water? Because a lot of military bases sit on rural water supplies. Take out the water, you take out the military base. And who is going to defend a rural water district? They do not have the budget. So there are defenders from this community donating their time to make it better.
And then the weird one. Moss says he would not quite call it political, but has anyone else noticed the humble brag from some of the frontier model labs? Every time a model breaks out and causes some chaos, there is a piece of humble bragging marketing material attached to it. That is being noticed on Capitol Hill too. There is a political impact to that kind of marketing. And since it is an election year, expect more synthetic personalities and more influence operations.
The people are the cornerstone
Where is this all leading? Moss says the thing that gets lost in an autonomous, agent driven environment is the people. "We are the cornerstone on which all of this is built."
His argument is about coping mechanisms in periods of rapid change. In times of uncertainty, you turn to your community. The most resilient communities in any disaster, natural or man made, are the local ones, because that is where people find both support and direction. So: here you are, in a giant room of peers. Markets are being disrupted, things are moving fast, and everyone in the room will need to lean on each other.
The reason it has to happen in person is one sentence long, and it lands: "you can't inject a fake personality here."
He notes the counterintuitive statistic that when things get extra stressful, attendance at conferences goes up, and not just security conferences. His read on why: people innately know they need to see what is actually going on. You need to talk to your buddy and get the download. And that download might not be happening on a Discord server. So yes, see the technical talks, but take the time to build the connections that carry you through the rest of the year.
AI as a prediction engine, and the abstraction argument
A few years ago on this same stage, Moss said AI is essentially a prediction engine, and that if he were a business leader he would try to turn all of his problems into prediction problems, because a prediction engine only gets faster and cheaper. Then he looks at the last couple of years: "Holy moly. It is a total sea change of what is possible now."
That framing is why there are two keynotes this year, split by direction. Today is defense: how are the hyperscalers, how are we, addressing the risks and opportunities of AI? Tomorrow is offense: what is AI doing to the academic, the reverser, the exploit developer, and is it helping or hurting them?
He closes on the one thought he wants to leave the room with, and prefaces it by saying he is generally a skeptical person, and that skepticism has served his career in security extremely well. The laugh lands. But on AI, listening to developers and to Unix greybeards who go back to VAX/VMS, he sees a trend line. Every improvement in tooling has been an abstraction: the invention of the IDE, higher level languages, object oriented programming. Abstraction, abstraction, abstraction.
"It hasn't been the death of programming jobs. What it's led to is allowing companies and people to think bigger. We can imagine larger things, more complicated systems. We can create newer opportunities."
So his prediction is more disruption and, at the end of it, more jobs, not fewer, because companies everywhere will want to build bigger, and they will build it on the backs of the people in that room, who provide the reassurance and resiliency that lets them take bigger risks.
And with that he introduces the keynote: Dave Weston, who leads the agentic security team at Microsoft, where he builds the AI models, the agents, and the evaluation systems for defense at scale.
Weston takes the stage
"I can't dance as well as Jeff Moss, but I'm trying."
Weston says he was genuinely excited to get asked, because he has a lot pent up. He has been watching the socials fill with AI apocalypse and doomsday content, and he suspects he might be the only optimistic person in the room, maybe at the whole conference. So he sets the format himself:
"I'm going to make this talk a 30 minute high effort social post just live. But you can't block or unfollow me because you're a captive audience."
The subject: what happens when attacks get less rare, and what defenders can do in that environment.
His bias and vantage point, stated up front so the audience can discount him accordingly. Twenty years in the trenches of security. WannaCry, Stuxnet, "I lived it all. I have all the trauma." He built operating system security for Windows and Linux, in Azure and elsewhere, built EDRs, and led vulnerability work and red teams. Then, nine months ago, he switched to the AI world, which he calls switching to the dark side: vulnerability discovery harnesses, training frontier models for cyber capabilities, and building defense. The talk is the nexus of those two vantage points.
The assumption nobody writes down
"Security has this underlying assumption. It's unsaid, and that is that we have these security boundaries, network, process, identity, encryption, and that is extremely hard, and thus attacks that undermine them are scarce. What happens if that changes?"
This is the thesis, and everything after it is either evidence that it is changing or a plan for what to do about it.
The whole cyber house, roof and foundation, is built on those boundaries being rare to break. That is what lets us:
- isolate networks
- separate trust domains in places like the cloud
- build authentication, encryption and data protection policy
- contain failures with hypervisors and process sandboxes
Every control and every policy in your enterprise, your business, your phone, relies on those boundaries not being easy to undermine.
The market has been pricing scarcity for twenty years
You can see the assumption written down in the economics, because bug bounty prices scale with the importance of the boundary. There is no cheap price for undermining a process. A hypervisor bypass goes for roughly 20 times what a process boundary crossing does on the open market. That ratio has been priced in for a long time and it reflects what it is actually like on the ground.
The pricing goes a layer further. A vulnerability is only a potential risk. Actualized risk, meaning exploitation, an implemented attack, costs even more, because now you are pricing in expertise and scarcity for mitigation bypasses and every other technique the exploit needs. That gap is visible in the price difference between vulnerabilities and exploits.
And the outcome of all that scarcity is the number that should anchor the whole discussion: for the tens of thousands of CVEs that scroll past on LinkedIn every day, the industry ends up with only about 90 in the wild exploits a year, as tracked by the Google Project Zero folks. At this point it is genuinely exceptional for a boundary to be undermined.
Which is why most breaches never touch a boundary
Because the assumption has held, real attacks route around it. Verizon's DBIR says most attacks happen at the credential theft level, which is traditionally far cheaper than undermining a boundary, along with phishing and social engineering. And when a vulnerability is exploited, the vast majority of the time it is a known vulnerability, which means there was time to implement the exploit against something already published.
All of today's economics and all of today's strategy rest on that.
The two dominant strategies that quietly depend on scarcity
Weston draws out the two strategies the industry has inferred from the scarcity principle, and then pressure tests each.
Strategy one: deprioritize the SDLC. You can go lighter on static analysis, safer languages, principle of least privilege, and strong identity around the software you build, because you can just patch fast when something becomes known, and vulnerabilities are rarely exploited anyway. The pressure test: what happens if exploits become another commodity? "We lived through this in the 90s. Trivial to exploit. That just patch everything fast strategy carries significant risk."
Strategy two: skip prevention, detect and respond. Less prevention, less investment in the software itself, we will sprinkle some AI on it and detect and respond very quickly. This is what every vendor pitches you. The truth is dwell time is getting longer and detection is getting harder. And the deeper problem is that most detection is based on invariants that do not change. The reasoning goes: attackers are software developers, they cannot afford to rewrite their implants, their C2, and their lateral movement tooling for every single operation, so we can keep detecting them. That reasoning is a supply economics argument, and it breaks in exactly the world where rewriting gets cheap.
So the question for the rest of the talk: what do we do when the scarcity principle no longer has our back, and are we actually there yet?
Assumption one is already breaking: vulnerabilities
The first thing being undermined as we speak is the assumption that vulnerabilities, the potential risk side, are scarce.
The curve Weston puts on screen is a Microsoft number, but he says the trend appears to hold for Google, Apple, and probably every other popular software vendor. MSRC is doubling the number of vulnerabilities it processes and patches roughly every six weeks. The current volume is nine times what it was in March.
He is careful about it in both directions. We do not know if the curve holds. But if it does, we are in deep trouble everywhere we presume vulnerabilities are scarce. The data set is MSRC cases spanning both open source that Microsoft consumes and first party software like Windows and Office, so it is not a narrow slice.
Is it actually AI, or are people just getting better at finding bugs?
Weston anticipates the objection and answers it with the internal data. Microsoft released a new internal vulnerability harness and turned it on against Windows on April 1. His stated result, verbatim: "since then we found 66% of the critical and important issues since April 1st than we did of all of last year."
His conclusion from it is unambiguous: "This is not just a correlation. This is the fact. It is AI that is driving this."
And these are not junk findings. In that data set he saw seven remote TCP/IP vulnerabilities that cross both the kernel and the remote boundary, the two boundaries that matter most for Azure and for every Windows system on the planet.
"These are serious vulnerabilities, the kind that I used to take a year to bespoke craft. They're being spit out at industrial speed."
He is explicit that this is not a Windows story. Look at Linux, look at any other operating system, and he expects a strong correlation.
Assumption two is breaking: exploits
If potential risk is climbing, what about actualized risk? This is where Weston shares what he calls a very unique stat.
Microsoft has an internal vulnerability harness called MDash, which is very good at finding vulnerabilities in agentic systems. It found roughly 200 Linux kernel vulnerabilities in the internal Azure Linux distribution, which Microsoft is working with the community to fix. Then they added a new module to help with triage. What the module does is turn a static analysis result into a proof of concept.
It worked much better than anyone expected. Of the 200 vulnerabilities, 182 crash level PoCs were generated automatically. Many are fully working exploits. Root exploits, spit out from a vulnerability. Average token cost: $3.61. Average wall clock: 21 minutes.
Then he points at what that means. Most of the world runs Linux in some capacity. And when you run Linux, you are relying on the kernel boundary to save you. That boundary is under attack.
And it is not just internal
Public benchmarks tell the same story. On Exploit Gym, the big frontier models are making incredible strides. Weston's slide shows models generating 157 exploits out of roughly 898 real world vulnerabilities, and these are not only Linux kernel bugs, which he concedes are arguably easier to exploit in some ways. The set includes browser vulnerabilities and similar.
He adds a live detail that says everything about the pace: he checked Exploit Gym that morning, and the number on his slide for Mythos had already been roughly doubled by OpenAI.
What is actually holding exploitation back at this point is not the difficulty of reasoning about the bug. It is the nondeterministic mitigations: control flow integrity, address space layout randomization, and friends. Those make things harder. They do not guarantee that a bug cannot be exploited.
"So I would not bet against this curve. I fully believe that if we look at this and we draw a curve here, by the end of the year we'll be looking at automatic exploit generation being pretty commonplace and pretty commodity."
"Won't restricting the frontier models keep it scarce?"
This is the objection Weston most wants to kill, because he thinks a lot of policy is quietly resting on it. The answer is no, and the reason is architectural rather than political.
Go look at CyberGym, a vulnerability discovery benchmark. The top entries are not frontier models. They are harnesses. Harnesses use frontier models, but they also inject context in several other places. Cyber expertise can be encoded into the harness itself and into its tooling.
"There's nothing that says technically that the only place that cyber knowledge can live in an agent is actually in the model. And in a lot of places you don't want to put that in the model. Now that's counter to a lot of business models and other things, but the reality is you can inject that as a markdown file, and it's actually more optimal in many cases."
So the idea that we can restrict our policy way out of this is, in his view, unrealistic. The harnesses on CyberGym from a variety of vendors are strong evidence of that right now, and defenders need to prepare for the restriction strategy not working.
Assumption three is breaking: evasion
The last fallback is detection. Even if all these exploits arrive, we will just detect our way out of it. A large share of the room works in security operations centers and at vendors, and the reasoning behind that confidence is again economic: it is expensive to code a framework or an implant, so operators keep reusing the same tooling with packers and obfuscation, and they keep reusing the same TTPs. So detection stays durable.
That reasoning assumes evasion of detection is a scarce property, because it has been.
The canonical model here is the pyramid of pain, which is really a model of invariants in detection. Hash values, IPs and domains are trivial for an attacker to change. Tools are more expensive. Artifacts are more expensive still. TTPs are the most durable of all, which is why the industry anchors detection there.
What breaks it: previously, changing a TTP meant retraining the operator, which is genuinely expensive in cyber operations. Now you do not retrain an operator, you run autonomous operations. And instead of obfuscating a reused tool, you generate a bespoke set of tools or an entire framework per target.
The real world evidence
Weston walks the receipts.
November of last year, Anthropic's report. The canonical case study: a cyber operator conducting most of an operation against top tier targets essentially using Claude Code with subagents, at somewhere around 80 to 90 percent of the operation automated, with ostensibly good results based on Anthropic's own observations.
May of this year, Dragos. A water utility targeted by an AI assisted group that was building its framework during the operation. The defenders could watch the code being regenerated. It was Python, and the additions had all the hallmarks of being AI generated. In that single operation the attacker generated 17,000 lines of C2 and implant code, just for that op.
Weston's read: that is essentially proof that the assumption of durable artifacts is gone.
The trajectory
To get the direction rather than the snapshot, he points at the UK AI Security Institute, which tests frontier models on their ability to conduct 32 step autonomous breach operations. The current result is 9.8 steps out of 32 at a 10 million token budget, up 59 percent this year alone.
His conclusion: autonomous operations will just be par for the course. And again, do not make assumptions about which models can do this, because the capability can be injected anywhere in the stack.
"So scarcity will not come from restriction."
The ledger so far
| What defense assumes | Why it held | What the talk puts against it |
|---|---|---|
| Vulnerabilities are scarce | Finding a boundary bug takes rare expertise and long timelines, so patch fast is a sufficient strategy | MSRC volume doubling roughly every six weeks, nine times March. A harness on Windows since April 1 producing critical and important issues at a rate measured against the whole prior year, including seven remote TCP/IP bugs crossing kernel and remote boundaries. breaking |
| Exploits are scarcer still | Weaponizing costs expertise on top of the bug, which is why exploits price far above vulnerabilities | MDash converting 182 of about 200 Linux kernel vulnerabilities into crash level PoCs, many working root exploits, at $3.61 and 21 minutes each. Exploit Gym at 157 of about 898 real world bugs and climbing weekly. breaking |
| Evasion is expensive | Attackers are software developers who cannot afford to rewrite implants, C2 and lateral movement per operation, so TTPs stay detectable | Anthropic's November report on an operation run 80 to 90 percent through Claude Code with subagents. Dragos in May on a water utility op with 17,000 lines of framework code generated during the op. breaking |
| Restriction preserves scarcity | Frontier cyber capability lives in the model, so access controls on models control the capability | On CyberGym the leaders are harnesses, not models. Cyber expertise can be injected as tooling or as a markdown file, and often that is the more optimal place for it. does not hold |
| The response is symmetric | Vuln for patch, exploit for detection, evasion for detection | Weston's one prescriptive rule: do not accept the symmetric fight. Spend the same productivity on durability instead. this is the lever |
So why is the optimist still an optimist?
Weston returns to the promise he made at the top. After all of that, how can he be optimistic?
First, because this is not magic, this is productivity. Attackers are more agile, they go asymmetric against defenders, and they have done that since time immemorial. They moved first on AI because defenders have policies, restrictions, auditing, compliance, and token costs slowing them down. But the exact same productivity advantage is available to defenders.
Second, and this is the load bearing claim of the whole talk, because defenders get to choose where to spend it.
Where not to spend it:
"We don't want to go vuln for patch. We don't want to go exploit for detection, evasion for detection. Hand-to-hand combat with attackers will cause us to lose in defense. We will be asymmetric. We don't want to do that."
Where to spend it instead:
"What we want to do is retrain the physics here. We want to figure out where we can use this production advantage to actually turn the tables."
Concretely, three investments in durability rather than in the exchange rate:
- Shift left and make more secure software, which limits vulnerabilities at the source.
- Move from hand to hand detection toward prevention. Detection is still great, it is necessary but not sufficient.
- Use secure by construction and formal methods to get deterministic safety.
If the industry can do that on a realistic timeline, it drives the problem back toward the attacker. The rest of the keynote is the evidence that each of the three is now tractable.
Secure by construction
Weston frames the opening move against the vulnerability curve: about 70 percent of the vulnerabilities patched today, at least by the major vendors, are memory safety issues. Safer system languages, Rust and Go, eliminate that class outright.
The proof point he leads with is Android. In 2019, 76 percent of the vulnerabilities Google patched in an operating system used by billions of people, from cars to phones, were memory safety issues. In 2025 it is under 20 percent. That happened because Google wrote five million lines of Rust, which by their own analysis has a thousand times fewer defects, and which has not shipped a single memory safety issue.
Azure has done the same thing on the containment boundary: the hypervisor was rewritten in Rust in the open, and is now scaling past 1.5 million virtual machines without an incident.
So why isn't everyone doing it?
Because traditionally it is expensive. You need experts who know how. You need people to learn new languages. You need to convert old code bases.
AI is changing exactly those costs, and Weston lists the receipts:
- RustAssistant (Microsoft Research) showed it could take 74 percent of Rust compilation failures and fix them automatically, with no user intervention, with tests passing.
- For existing C code bases, a variant of C called Checked C, similar in spirit to things you see from clang and Apple, let them infer memory safety contracts in a code base and generate 86 percent of the contracts that check for spatial safety vulnerabilities, meaning buffer overflows.
This is productivity driving memory safety, driven by AI. It does not look like automatic vulnerability generation, but Weston calls it absolutely critical.
The real frontier is automatic conversion
The frontier is doing the port automatically, and there is good work happening.
- Sila, a strong paper out of Google and Microsoft, took SymCrypt, the library in Windows that does most of the core encryption and TLS, and converted it automatically to safe Rust. They took a SHA-3 method of a few thousand lines, converted it automatically, and ran the tests. All tests passed and the performance was within 1 percent.
- Rustler is more sophisticated: it works with dependency graph context, generates Rust, then iterates through error checking until it has valid code that passes tests.
- And it is not only the hyperscalers. DARPA, who Weston says arguably showed the industry first where agentic vulnerability discovery was going, is running a program called TRACTOR that sponsors this work and gives out data sets for automatic conversion.
"If we can land this as a community, we can really drive security forward."
But memory safe does not mean safe
Weston stops the momentum himself. Are we done once all of that lands? No.
"Memory safety does not mean security."
You still have logical issues, authentication issues, crypto issues, lots of issues. Most of today's bugs are memory safety, but they will not stay that way forever, and the tail is exactly the part that used to be protected by the scarcest expertise in the field.
His evidence that the tail is falling too comes from Anthropic, which published a blog post and paper on using Claude to analyze HAWK, a post quantum digital signature algorithm, and found a cryptographic attack. Weston's framing matters here: cryptanalysis is, in his view, the most scarce security expertise there is.
The same work showed attacks against AES-128 that drove roughly an 800 times increase in attack performance, plus a forgery bug in wolfSSL. All three are the kind of finding that has traditionally sat at the very top of the scarcity and complexity ladder.
So AI can find logical flaws, not just memory corruption. Which sets up the last technical act of the talk.
Formal methods are having a moment
If memory safety removes bug classes, something has to guarantee the properties, the logic itself.
Weston gives the short history. Formal methods have a rich legacy in computer science going back to the 1960s. Model checking in the abstract form builds a mathematical representation of a program's logic and reasons over it. Symbolic checking compressed the state space further and lets you compute whether a given code base violates a property, and when it does you get a reproduction, which he calls really awesome. High risk safety platforms have adopted it as a result.
So why has it not gone mainstream? Four reasons, and none of them are about whether it works:
- Writing the specifications is hard and takes a lot of expertise.
- Writing the proofs is even harder.
- State space explosion on complicated programs.
- You have to maintain all of it. "Nobody wants to maintain anything."
Every one of those four is a labor cost. Which is why the key question is whether AI can make it scale, and why Weston's analogy is the one he picks:
"Formal methods are having a moment similar to reinforcement learning had with AI. Reinforcement learning has become absolutely critical to modern AI even though it was invented back in the 60s and 70s. Formal methods is perfect. It gives AI generated code an oracle for correctness, both from security but performance, reliability. It's almost tailor made in my opinion."
That is the sharpest idea in the keynote. Generated code has no inherent trustworthiness, and formal verification is precisely a machine checkable oracle for whether a piece of code satisfies a property. The two technologies fit each other's weaknesses.
What the pipeline needs
Weston sketches the loop: you need to be able to specify what must never happen, which can come out of existing specifications. Then you need a model of that specification, a checker that validates the models and proofs, and a way to supply the verdict back.
The tooling exists. CBMC is what Amazon and AWS have used for checking libc and their crypto libraries. But getting good results out of it still takes a lot of maintenance and effort, which is the same labor wall as before.
The bugs only formal verification found
Both Apple and Microsoft have put serious work into this, and both found real bugs in their most scrutinized code.
- Apple formally verified its core crypto and found an error in ML-DSA, the post quantum digital signature standard.
- Microsoft recently found, in a post quantum key encapsulation algorithm, a single shift that was wrong. It had passed all the tests. Passed the fuzzers. Passed human review. Only formal verification found it.
And this is not confined to crypto: AWS is doing it at scale with Cedar for their role based access control policies, which Weston calls amazing.
Scaling the proofs with agents
The remaining question is how to scale formal methods, and here is where the numbers get striking again.
Aeneas can take code bases like Rust, or even specifications, and convert them into Lean proofs. Lean is a functional language for describing the proofs used in formal verification.
Microsoft demonstrated this on real code in SymCrypt: in a single week, mostly driven by agents, they generated 30,000 lines of Lean that formally verified AES-GCM.
What that verification buys is the whole point:
- free of logical issues
- free of cryptographic issues, at least as far as the proofs stand
- free of memory safety issues
Out the other side you have mathematical grounding in the soundness and reliability of that crypto. "If we could have that for all of the boundaries I talked about previously, we'd be in a different game with respect to AI."
The case in point: the OpenAI sandbox escape
Weston connects it to the incident everyone in the hall had been talking about, extrapolating from public information around the OpenAI escape and the Hugging Face incident.
His assessment is that OpenAI did all of the right things. They had a properly isolated, strong boundary around their model evaluation. They gave exactly one proxy out, which was necessary to reach packages.
And that was enough. A capable model found what looks like nine different vulnerabilities on the fly, all of them logical vulnerabilities.
"What that tells us is you can follow the best practice out there, the best boundaries, but if you can't guarantee your code is free from logical issues, which is a tall order today, you're simply not going to be able to guarantee safety."
Then the call to action, which is the reason the incident is in the talk at all: if that package system had been formally verified with the right proofs, we might be talking about something different.
"But what about the meantime?"
Weston voices the objection to himself: Dave, you have talked a big game about prevention, but what happens when we cannot find all the bugs, and we cannot find them all. Everything described so far means taking 20, 30, 40 years of software debt and converting it to memory safe and formally verified software. What do we do while that happens?
The answer starts with an uncomfortable fact about how systems actually fall over today: most infrastructure, cloud and on premises, is owned without exploits at all. It is configuration.
And unfortunately, very little of that infrastructure can be reasoned about by agents, because very little of it has been converted into infrastructure as code or into other persisted, checkable policy. That is the gap. Prevention is the goal, because "we cannot get into a hand to hand combat detection, we will lose." So the job is to reduce attack surface, improve posture and configuration, and shift left on the infrastructure side. The less that reaches production, the less that is reachable in production, and the less there is for attackers to go after.
Give the agents a graph
Agents can reason about infrastructure holistically when it is in the right format. That means building graphs or ontologies of the assets and network flows in your organization, which unlocks a set of things humans cannot do at scale:
- Compute an identity style attack graph and use it to find which accounts are overprivileged.
- Do the same for posture: which devices and infrastructure pieces carry the biggest attack surface, and let agents validate it.
- Use centrality and locality in the graph to focus remediation on the risks that actually matter.
- Once the graph exists, the edges become obvious. If you have a graph of normalized authentication across the organization and a connection suddenly appears from accounting to a domain controller, that is a point of analysis an agent can act on.
- And agents scale out proactive hunting far past what a human team could ever do.
The number he offers as evidence that this is not hypothetical: an analysis of using agents with Checkov, which checks infrastructure as code against various mechanisms, showed that 78 percent of the findings can be resolved by agents.
- 1960sModel checking and formal methods are invented, along with reinforcement learning. Both spend decades waiting for the compute and the labor economics to catch up.
- 201976 percent of the vulnerabilities Google patches in Android are memory safety issues.
- Nov 2025Anthropic reports an operator running an espionage campaign against top tier targets, roughly 80 to 90 percent of it through Claude Code with subagents.
- 2025Android's memory safety share falls under 20 percent after five million lines of Rust that has never shipped a memory safety bug.
- Mar 2026The MSRC baseline that the vulnerability volume curve is measured against.
- Apr 2026Microsoft turns a new internal vulnerability harness on Windows on April 1, including seven remote TCP/IP bugs crossing the kernel and remote boundaries.
- May 2026Dragos reports a water utility targeted by an AI assisted group writing its framework during the operation: 17,000 lines of C2 and implant code for a single op.
- 2026The OpenAI evaluation sandbox escape and the Hugging Face incident. Best practice boundaries, one necessary proxy, and a capable model finds nine logical vulnerabilities on the fly.
- 2026Microsoft generates 30,000 lines of Lean in a single week, mostly agent driven, formally verifying AES-GCM in SymCrypt.
- Aug 2026MSRC volume is nine times March. MDash turns 182 of about 200 Linux kernel bugs into PoCs at $3.61 each. UK AISI measures 9.8 of 32 autonomous breach steps, up 59 percent this year. Weston takes the Black Hat stage.
Figure 6. The chronology of everything the keynote cites, offense and defense on the same rail. The two halves are running at the same speed, which is Weston's entire argument: the productivity is symmetric, only the strategy is a choice.
Three things you can do today
Weston closes with homework, and it is deliberately concrete.
"Attackers have changed the economics of what we're doing today, but as defenders we can choose to change the physics."
- Focus on your highest risk surfaces and make those secure by design. It does not have to be only memory safety. The same move applies to web.
- Figure out what your most critical boundaries are and start using agents to work on formal verification for those. There are many open source tools capable of it now, and you can start preparing yourself.
- Start using infrastructure as code and graph computation to build an agent army that can help with prevention.
"If we invest in this, we change the physics, we change the economics, and we lead the pack. Thank you."
The close
Susie Pallet comes back out. "Great energy." Housekeeping: the next session is in the same room at 10:30, and all of the main briefings start upstairs at 10:15.
Tomorrow's keynote is in the same room, with Yan Shoshitaishvili, team captain of Shellphish, speaking on vulnerability research in the agentic era. That is the offense side of the pairing Jeff Moss described at the top: today the hyperscaler view of defense, tomorrow what all of this does to the reverser and the exploit developer.
And at 6:30 that evening, the premiere of Midnight in the War Room in Oceanside A on level two.
Where it stands
A few honest notes on the talk, kept here at the end rather than threaded through the reconstruction.
The strongest part of the argument is the part that is hardest to argue with. The pessimistic half rests on internal Microsoft telemetry, which the audience cannot audit, but the individual numbers are checkable in kind: public benchmarks like CyberGym and Exploit Gym move in the same direction, the Anthropic and Dragos reports are public, and the UK AISI evaluations are published. The claim that harnesses beat raw frontier models on discovery benchmarks is the most consequential and the most verifiable, because it is the one that kills the "restrict the models" policy answer on technical grounds rather than political ones.
The vulnerability curve is presented with its own caveat, which is to Weston's credit. He says twice that we do not know whether it holds. A doubling every six weeks is not a sustainable rate for anything, and part of the current spike is certainly a backlog being drained by a new capability rather than a permanent new rate. What matters for his thesis is not the exponent but the floor it settles at, and nothing in the talk claims to know that.
The $3.61 number is doing a lot of work and deserves a footnote. It is the token cost of generating a crash level proof of concept from a vulnerability already found, in a kernel Microsoft controls, with a harness built for it. That is not the same as the full cost of a weaponized exploit against a hardened, mitigated target in the wild, which is exactly what Weston says next when he names nondeterministic mitigations as the remaining obstacle. The direction of travel is the point, not the decimal.
The optimistic half is a research agenda, not a product roadmap. Sila, Rustler, Aeneas, TRACTOR and the Lean work are real, and the Android and Azure hypervisor results are shipped and load bearing. But the gap between "30,000 lines of Lean verified AES-GCM in a week" and "your organization's boundaries are formally verified" is the same gap that has kept formal methods out of the mainstream for sixty years. Weston's bet is that the labor cost was the only thing in the way. That is a genuinely plausible bet and it is not yet a proven one.
And the closing homework is the honest test of the talk. Two of the three items, secure by design on your highest risk surfaces and infrastructure as code with graph computation, are things a competent security organization could start this quarter. The middle one, agents doing formal verification of your critical boundaries, is the one that will separate the labs from everyone else for a while.
Key takeaways
- Every security control you own is priced on the assumption that crossing a boundary is rare. Bug bounty prices, patch cadence, detection strategy, and the roughly 90 in the wild exploits a year all encode that assumption. It is not written down anywhere, which is why it is dangerous.
- Vulnerability discovery has already changed. MSRC volume is nine times its March level, doubling roughly every six weeks, driven by an internal harness that has been running against Windows since April 1 and producing kernel and remote boundary bugs at industrial speed.
- Exploit generation is following. MDash converted 182 of about 200 Linux kernel vulnerabilities into crash level PoCs, many of them working root exploits, at $3.61 and 21 minutes each. Public benchmarks show the same curve, and the remaining friction is nondeterministic mitigations, not reasoning.
- Restricting frontier model access will not preserve scarcity. On CyberGym the top entries are harnesses, not models, because cyber expertise can live in tooling or in a markdown file rather than in weights.
- Detection durability was an economic property, not a technical one. TTPs were durable because retraining an operator was expensive. Autonomous operations remove that cost, and a single Dragos reported op generated 17,000 lines of bespoke framework code during the operation.
- The trap is the symmetric fight. Vuln for patch, exploit for detection, evasion for detection. Weston is blunt that defenders lose hand to hand combat and should not enter it.
- Spend the productivity on durability instead. Secure by construction, formal verification of the boundaries that matter, and prevention driven by agents over infrastructure as code.
- Memory safety is the biggest single lever and it is proven. About 70 percent of patched vulnerabilities are memory safety issues. Android went from 76 percent to under 20 percent with five million lines of Rust and a thousand times fewer defects, and Azure's Rust hypervisor is past 1.5 million VMs without an incident.
- AI is what makes the rewrite affordable. RustAssistant fixes 74 percent of Rust compilation failures unattended, Checked C inference generated 86 percent of spatial safety contracts, Sila converted SymCrypt's SHA-3 to Rust automatically with all tests passing and performance within 1 percent, and DARPA TRACTOR is funding the general problem.
- Memory safe is not safe. Claude found a cryptographic attack on the HAWK post quantum signature scheme, an 800 times performance improvement in attacks on AES-128, and a forgery bug in wolfSSL. The scarcest expertise in security is not a moat any more.
- Formal methods are to AI what reinforcement learning was to AI. Generated code needs an oracle for correctness, and formal verification is exactly that. Every barrier to formal methods, specs, proofs, state space and maintenance, is a labor cost, which is the thing that just got cheap.
- Only formal verification catches some bugs. A single wrong shift in a post quantum KEM passed all tests, all fuzzers, and human review. Apple found an ML-DSA error the same way. AWS runs Cedar policy verification at scale.
- In the meantime, configuration is what actually loses. Most infrastructure is owned without an exploit. Convert it to infrastructure as code and graphs so agents can reason about it: 78 percent of Checkov findings can be resolved by agents.
- Jeff Moss's frame around the talk matters too. Security is political whether the industry says the word or not, hyperscalers inherit their customers' adversaries, and in an autonomous agent world the durable resource is still the local community of people. You cannot inject a fake personality into a room.
Chapters
- 0:00 Cold open: "America under virtual invasion"
- 0:18 Susie Pallet opens day two of Black Hat USA
- 1:18 Don't just attend, discover
- 2:34 Introducing the founder: Jeff Moss
- 3:50 Moss takes the stage, the 29th Black Hat
- 4:31 The scholarship program: 131 attendees, 103 countries
- 5:49 The four themes of Black Hat 2026
- 6:40 Security is political: Russia, hyperscalers and inherited risk models
- 7:38 Iran in the rural water districts
- 8:08 The frontier model humble brag, and Capitol Hill
- 8:41 The people are the cornerstone
- 10:33 AI as a prediction engine, and the two keynote directions
- 11:31 Abstraction has never killed the jobs
- 12:54 Introducing David Weston
- 13:17 A 30 minute high effort social post
- 14:05 Twenty years in the trenches, nine months on the dark side
- 14:53 The unsaid assumption: boundaries are hard, so attacks are scarce
- 15:46 The price of a boundary: bug bounty economics and the 20x hypervisor
- 16:44 Roughly 90 in the wild exploits a year
- 17:15 Why most breaches happen above the boundary
- 18:00 Two dominant strategies that quietly depend on scarcity
- 19:31 What do we do when scarcity no longer has our back
- 19:44 The MSRC curve: nine times March, doubling every six weeks
- 20:55 Is it AI? The Windows harness turned on April 1
- 22:13 MDash: 200 kernel vulnerabilities, 182 automatic PoCs, $3.61 each
- 23:27 Exploit Gym: 157 exploits out of 898 real world bugs
- 24:27 Restriction will not save you: harnesses beat models on CyberGym
- 25:51 The pyramid of pain and the collapsing cost of evasion
- 27:22 Anthropic in November, Dragos and the water utility in May
- 28:25 UK AISI: 9.8 of 32 autonomous breach steps, up 59 percent
- 29:03 Why the optimist is still an optimist: this is productivity, not magic
- 29:34 Do not fight hand to hand, retrain the physics
- 30:42 Three levers: secure by design, formal methods, prevention
- 31:27 Secure by construction: 70 percent of patched bugs are memory safety
- 31:53 Android from 76 percent to under 20 percent
- 32:21 The Azure hypervisor in Rust at 1.5 million VMs
- 32:46 Why isn't everyone doing it? RustAssistant and Checked C
- 33:52 Automatic conversion: Sila, Rustler and DARPA TRACTOR
- 35:00 Memory safety does not mean security
- 35:38 Claude, the HAWK cryptanalysis, AES-128 and wolfSSL
- 36:26 Formal methods: model checking, symbolic checking, and four barriers
- 37:34 Can AI make it scale? The reinforcement learning analogy
- 38:07 What the verification pipeline needs, and CBMC
- 38:43 The crypto bugs only formal verification found
- 39:28 Aeneas and 30,000 lines of Lean in a single week
- 40:34 The OpenAI sandbox escape as the case in point
- 41:37 The meantime: infrastructure is owned by configuration, not exploits
- 42:53 Attack graphs, ontologies, and Checkov at 78 percent
- 44:24 Three things you can do today
- 45:20 Closing and housekeeping
Notable quotes
"Technology is political and that makes us all uncomfortable to say that word out loud. But we have to sort of embrace it. If we don't embrace it, politics will happen to us." Jeff Moss, 6:40
"The hyperscalers inherit the risk models of their customers. And if your customer is Ukraine, guess what? Your opponent is Russia. Like, you just want to sell rack space, but now you're in the middle of power conflict." Jeff Moss, 6:40
"Take out the water, you take out the military base." Jeff Moss on Iran targeting rural water districts, 7:38
"You can't inject a fake personality here." Jeff Moss on why the community still gathers in person, 8:41
"It hasn't been the death of programming jobs. What it's led to is allowing companies and people to think bigger. We can imagine larger things, more complicated systems. We can create newer opportunities." Jeff Moss, 11:31
"I might be the only optimistic person in this entire room right now, maybe at this whole conference." David Weston, 13:17
"I'm going to make this talk a 30 minute high effort social post just live. But you can't block or unfollow me because you're a captive audience." David Weston, 13:17
"Security has this underlying assumption. It's unsaid, and that is that we have these security boundaries, network, process, identity, encryption, and that is extremely hard and thus attacks that undermine them are scarce. What happens if that changes?" David Weston, 14:53
"The entire premise of cyber is based on this scarcity and supply economics around this." David Weston, 16:44
"These are serious vulnerabilities, the kind that I used to take a year to bespoke craft. They're being spit out at industrial speed." David Weston on the Windows harness findings, 20:55
"The average cost from a token perspective, $3.61. 21 minutes on average." David Weston on automatically generated kernel exploits, 22:13
"I would not bet against this curve. I fully believe that if we look at this and we draw a curve here, by the end of the year we'll be looking at automatic exploit generation being pretty commonplace and pretty commodity." David Weston, 23:27
"There's nothing that says technically that the only place that cyber knowledge can live in an agent is actually in the model. And a lot of places you don't want to put that in the model. Now that's counter to a lot of business models and other things, but the reality is you can inject that as a markdown file and it's actually more optimal in many cases." David Weston, 24:27
"So scarcity will not come from restriction." David Weston, 28:25
"This is not magic. This is productivity." David Weston, 29:03
"We don't want to go vuln for patch. We don't want to go exploit for detection, evasion for detection. Hand-to-hand combat with attackers will cause us to lose in defense." David Weston, 29:34
"What we want to do is retrain the physics here." David Weston, 29:34
"Memory safety does not mean security." David Weston, 35:00
"Formal methods are having a moment similar to reinforcement learning had with AI." David Weston, 37:34
"Nobody wants to maintain anything." David Weston on the fourth barrier to formal verification, 37:34
"A single shift that was wrong. Passed all the tests, passed fuzzers, passed human review. Only formal verification found it." David Weston on a post quantum key encapsulation bug, 38:43
"You can follow the best practice out there, the best boundaries, but if you can't guarantee your code is free from logical issues, which is a tall order today, you're simply not going to be able to guarantee safety." David Weston on the OpenAI evaluation sandbox escape, 40:34
"Attackers have changed the economics of what we're doing today, but as defenders we can choose to change the physics." David Weston, 44:24
"If we invest in this, we change the physics, we change the economics, and we lead the pack." David Weston, closing line, 44:24
Resources mentioned
The event and the people
- Black Hat USA 2026 and the keynote listing for The End of Rare
- Black Hat scholarship program, the path Moss cited for 131 attendees this year
- Black Hat Arsenal, the tool demo floor Susie Pallet points the audience to
- Jeff Moss, founder of Black Hat and president of DEF CON
- David Weston, agentic security leader at Microsoft Security
- Yan Shoshitaishvili of Shellphish, delivering the following day's keynote on vulnerability research in the agentic era
Data sources and reports cited
- Microsoft Security Response Center, the source of the vulnerability volume curve
- Google Project Zero's 0day In the Wild tracking, the roughly 90 per year figure
- Verizon Data Breach Investigations Report, on credential theft and phishing dominating real breaches
- Anthropic's report on a disrupted AI orchestrated espionage campaign, the 80 to 90 percent automation case study
- Dragos, reporting the AI assisted water utility operation with 17,000 lines of generated framework code
- UK AI Security Institute, the 32 step autonomous breach evaluations
- The pyramid of pain, David Bianco's model of detection invariants
Benchmarks and harnesses
- CyberGym, the vulnerability discovery benchmark where harnesses outrank raw frontier models
- Exploit Gym, the exploit generation leaderboard showing 157 of about 898
- MDash, Microsoft's internal vulnerability discovery and PoC generation harness (internal, no public page)
Memory safety and automatic conversion
- Rust and Go, the safer system languages that eliminate the memory safety bug class
- Google's Android memory safety results, 76 percent in 2019 down to under 20 percent
- OpenVMM, Azure's open source Rust hypervisor now past 1.5 million virtual machines
- RustAssistant, Microsoft Research, fixing 74 percent of Rust compilation failures automatically
- Checked C, the safe C variant used to infer 86 percent of spatial safety contracts
- SymCrypt, the Windows core cryptographic library targeted by both the Sila conversion and the Lean verification work
- DARPA TRACTOR, the program funding automatic C to Rust translation and its data sets
Formal methods and verification
- Lean, the proof language behind the 30,000 line AES-GCM verification
- Aeneas, translating Rust and specifications into Lean proofs
- CBMC, the bounded model checker AWS uses on libc and crypto libraries
- AWS Cedar, formally verified authorization policy at scale
- ML-DSA / FIPS 204, the post quantum signature standard where Apple's verification found an error
- Anthropic research, the Claude cryptanalysis work on HAWK, AES-128 and the wolfSSL forgery bug
Prevention and infrastructure
- Checkov, the infrastructure as code scanner where 78 percent of findings were agent resolvable
- Address space layout randomization and control flow integrity, the nondeterministic mitigations Weston names as the remaining friction on automatic exploitation


