The End of Rare: Defending When Offense Is Cheap | David Weston Keynote | Black Hat USA 2026

Share:

LufSec Cyber Security

The End of Rare: Defending When Offense Is Cheap | David Weston Keynote | Black Hat USA 2026

Leisure


What happens to cybersecurity defense when AI makes finding and exploiting vulnerabilities cheap? In this Black Hat USA 2026 Keynote, David Weston, Agentic Security Leader at Microsoft, argues we're entering "the end of rare" — an era where vulnerability-finding agents have driven discovery costs to record lows and exploit development is cheaper than it's been since the '90s. When that happens, the two strategies defenders have leaned on for years stop holding: wait-and-patch-fast (which assumed exploits took time to build) and detect-and-respond (which assumed attacker tradecraft stayed stable long enough to become a signal). When tooling is generated on demand, both assumptions weaken at once. In this keynote: Why AI-driven vulnerability discovery breaks the assumptions behind modern defense Memory-safe languages in the AI era — removing whole vulnerability classes before code ships The resurgence of formal methods, now that AI can scale proof-writing Automated patching to shorten the disclosure-to-remediation window at massive scale Rethinking detection when the implant changes every run — which signals stay stable Real examples from large-scale defensive software projects, plus the open problems still unsolved This isn't doom and gloom: AI also creates asymmetries that can favor defense — if we invest in the right strategy. Essential viewing for cloud providers, OS and platform vendors, and SecOps teams defending large networks. Speaker: David Weston — Agentic Security Leader, Microsoft Recorded Wednesday, August 5 at Black Hat USA 2026 — Main Stage, Business Hall LEVEL UP YOUR SECURITY SKILLS WITH LUFSEC Offense is getting cheap — learn how attackers manipulate AI systems so you can defend them: Introduction to Prompt Hacking for LLMs — 5 hands-on labs, ~2 hours: https://www.lufsec.com/products/courses/prompt-hacking-for-llms-intro Explore all LufSec hands-on courses — AI/LLM Security, Car Hacking, IoT Hacking: https://www.lufsec.com Subscribe for more cybersecurity deep dives, tutorials, and conference coverage — and hit the bell so you never miss a new video. Do you think AI ultimately favors attackers or defenders? Drop your take in the comments. 0:00 Celebrating Two Decades of Security Innovation 2:08 The Political Reality of Modern Cybersecurity 5:05 The Human Element in an Autonomous World 6:47 The Evolution of Prediction Engines 9:42 An Optimistic View on the AI Frontier 25:02 Retraining the Physics of Defense 40:25 Final Logistics and Upcoming Highlights #BlackHat #BlackHatUSA2026 #Cybersecurity #AISecurity #DavidWeston #Microsoft #MemorySafety #FormalVerification #ExploitDevelopment #InfoSec #LufSec #PromptHacking #LLMSecurity