The Agentic Age: Why We Can’t Stop the Vulnerabilities | BlackHat USA Conference 2026
Leisure
Why do we keep finding new bugs in code we thought was thoroughly researched? In this Black Hat USA 2026 Keynote, Yan Shoshitaishvili — Associate Professor at Arizona State University and one of the field's most prolific vulnerability researchers — tackles the question head-on. Vulnerability research has always been a pursuit of the elite: deep knowledge of massive codebases, mastery of advanced tooling, grit, and luck. Over 15 years, Shoshitaishvili's research has uncovered thousands of vulnerabilities across IoT devices, web browsers, kernels, and bootloaders — and with each new tool and paradigm, bugs kept appearing in the same "well-researched" code. Now agentic AI vulnerability research is doing it again, surfacing fascinating new bugs in software the community thought was finally understood. Through the lens of his journey, this keynote explores the scientific underpinnings of what our community has long treated as an art form. Speaker: Yan Shoshitaishvili — Associate Professor, Arizona State University What's covered: What vulnerabilities actually are — and why we keep finding them in the same codebases 15 years of lessons from IoT, browsers, kernels, and bootloaders Why AI has revolutionized vulnerability research Where agentic vulnerability research goes from here — and why the road won't be easy Walk away excited about the future… if a little terrified. Recorded Thursday, August 6 at Black Hat USA 2026 — Main Stage, Business Hall START YOUR OWN VULNERABILITY RESEARCH JOURNEY — WITH LUFSEC Agents finding bugs starts with understanding how AI systems break. Get hands-on: Introduction to Prompt Hacking for LLMs — 5 hands-on labs, ~2 hours: https://www.lufsec.com/products/courses/prompt-hacking-for-llms-intro Explore all LufSec hands-on courses — AI/LLM Security, Car Hacking, IoT Hacking: https://www.lufsec.com Subscribe for more cybersecurity deep dives, tutorials, and conference coverage — and hit the bell so you never miss a new video. Has AI changed how you hunt for bugs? Share your experience in the comments. Vulnerability research is changing as agentic systems automate discovery. Learn how security groups manage this new scale. As automated agents begin to dominate threat identification, security groups face a surge in findings that outpaces manual review. This presentation examines the practical challenges of this new era, highlighting how specific methodologies can identify hundreds of vulnerabilities in a single cycle. We review a recent case study where one automated approach successfully isolated 300 vulnerabilities, demonstrating the sheer volume of output that modern teams must now handle. Effective vulnerability testing now requires adapting to these high-frequency inputs. For those working in AI security, the priority is shifting from finding flaws to managing the remediation pipeline effectively. We analyze the shift in defensive strategy needed when the barrier to entry for vulnerability discovery drops significantly. Subscribe for more technical security breakdowns, and let us know in the comments how your team is handling automated findings. 0:00 The Evolution of Capture the Flag 4:45 Research in the Agentic Age 9:41 Three Paths to Autonomous Discovery 14:46 The Fuzzing Renaissance and LLM Integration 19:23 Extracting Properties from Vulnerability Data 23:40 Scaling Workflows to Outperform Benchmarks 30:11 The Limitations of Rewriting in Rust #BlackHat #BlackHatUSA2026 #VulnerabilityResearch #AgenticAI #BugHunting #AISecurity #ExploitDevelopment #IoTSecurity #Cybersecurity #InfoSec #LufSec #EthicalHacking

