- Blog
- Company News
- Blackhat 2026: Hacking the Past. Hacking the Future.
Blackhat 2026: Hacking the Past. Hacking the Future.
XBOW brought hacking’s past and future together at Black Hat and DEF CON 2026, from a hands-on hacking museum and critical vulnerability research to autonomous pentesting demos, talks, and CTFs.
XBOW’s presence at Black Hat USA this year was big, bold, and retro. From our booth, to our meetings, demos, and talks, we celebrated hacking’s origins, and envisioned its future.
Booth: Our Hacking Museum was a hit, with attendees hacking, playing, reminiscing, and learning about the future of hacking — XBOW’s autonomous offensive security platform.
Research: We showcased a freshly uncovered CVSS score 9.8 flaw in Gitea.
Talks: XBOW Engineering Lead Alvaro Munoz took the stage for Exploitability Is the Ground Truth.
Takeover: XBOW joined Endor Labs for a takeover of Libertine Social, featuring a series of lightning talks.
DEFCON: XBOW showed up in force by sponsoring the Bug Bounty Village and CTF, hosting 400 people at the AI Pentesting Trivia Showdown at the AppSec Village, and taking to the main stage to highlight our research.
Our Black Hat theme this year was Hacking the Past. Hacking the Future. And it was clear from our conversations that the tools might be changing, but the adversarial mindset isn’t.
Read on for full details of what we built, shared, saw, and heard at Black Hat USA 2026 …
—————
Black Hat has always been a special gathering where security practitioners, researchers, and industry leaders come together, not just to showcase technology, but to exchange ideas and shape what's next. And what’s next can seem scary these days. Things are moving fast, and it’s easy to feel nostalgic for a time when things seemed simpler.
In that spirit, when XBOW decided to have a presence at Black Hat this year, we asked: How do we make something with substance, something that will resonate?
The typical trade-show floor can often feel transactional, a cycle of demos, swag exchange, and meetings. We set out to break that mold. We wanted to attract attention, but not just because of a gimmick or a clever giveaway. We wanted attention for the right reasons, and for reasons that tied back to XBOW’s mission and to our customers' challenges.
So we thought, and we talked, and we brainstormed, and, in the end, we built a functioning hacking museum that you can play with.
Our Black Hat theme: "Hack the Past to Hack the Future" reflected a simple belief that understanding where we've been helps us see where we're going. Hacking’s origins were in the 90s, and from day one the mission was to be curious, to figure out how things worked, and, ultimately, to think and operate like the attackers and stay one step ahead. That’s the same today. But now the attackers have AI. Leveraging an AI hacker for offensive security might seem futuristic, but it’s here, it’s the natural evolution of what we started back then, and it’s where we need to go now.
So we built a time machine; we sourced vintage machines, like a Sun Microsystems and even a O2 Silicon Graphics workstation, told their stories, and even baked a collection of zero days on these systems as part of a small CTF around payphones and classic systems.
When attendees stopped by our booth, we asked them, "If you could go back with what you know today, what system would you want to hack?" It’s a fun question, and the nostalgia and reminiscing it encouraged led to some great conversations and connections. People talked about where they came from, and how the industry is changing at a speed that can feel overwhelming, even scary. Ultimately, having real, in-person conversations like these is the true opportunity of these shows.
Please Do Hack the Museum Artifacts
A museum for the curious, we were not satisfied with simply putting vintage computers behind glass. We wanted to hack them, and luckily enough, our very own Brendan Dolan-Gavitt and Nick Gregory have been creating exploits and techniques to hack these older systems and create compelling demonstrations. What began as a wild idea ended up becoming an interactive CTF that helped us remember our first steps in security and how this industry was shaped.
We even had some teams competing for our skateboards doing blueboxing and DTMF decoding over ChatGPT, a true tale of our current times. We will do a more extensive write up in the upcoming days, so stay tuned.
What’s New? Autonomous Testing at Enterprise Scale
We did move beyond the 90s to focus on the present, and the future, as well …
The XBOW team has been hard at work refining our platform, ensuring autonomous offensive security is not just powerful, but also dependable and enterprise-ready. Our latest features focus on making it easier than ever to operationalize testing by integrating directly into your security stack, navigating complex target environments, and maintaining resilient performance even during authentication or availability hurdles, all while scaling safely across the organization.
New capabilities showcased at Black Hat included public API endpoints; customer-controlled finding workflow metadata; external ticket referencing; a simplified safety checker; and preflight WAF, CAPTCHA and bot-detection validation.
Real Demos, Real Vulns
Beyond the museum exhibits and challenges, our space became a hub for live XBOW demonstrations, which happened non-stop, sparking deep technical exchanges with researchers, customers, and industry leaders on the real-world autonomous offensive security. The team spent the event moving from one conversation to the next, running back-to-back demos, answering technical questions, digging into real security problems, and showing people what we have been working on.
In keeping with our commitment to real-world impact, we showcased a freshly uncovered flaw in Gitea, the widely utilized self-hosted Git solution. This finding, identified as CVE-2026-59774, is a critical unauthenticated file-read risk that can be used to escalate a RCE. With a CVSS score of 9.8, it impacts Gitea deployments from version 1.22.1 up to 1.27.0. We demoed the technical details of this finding, which was uncovered by XBOW's autonomous testing, during the event.
Following XBOW's critical RCE discovery within Microsoft Bing, this latest CVE further underscores our commitment to surfacing impactful vulnerabilities. Our growing repository of public security advisories is now available for practitioners to follow and track.
Customers, Community, and Conversations
Black Hat was also about connecting face-to-face. The XBOW team held in-person meetings with customers and prospects throughout the week.
In addition, XBOW Engineering Lead Alvaro Munoz took the stage for Exploitability Is the Ground Truth, exploring why security teams need to move beyond theoretical vulnerability signals and focus on what attackers can actually exploit.
Finally, off the show floor, XBOW joined Endor Labs for a takeover of Libertine Social, featuring a series of lightning talks, a fireside chat with Jason Haddix, and our Code, Cocktails and Conversations happy hour.
And then … DEFCON
The week rolled straight into DEFCON, shifting from the expo floor into an even more community-driven environment of hacking, research, competition, and shared curiosity. Many of us not only enjoy DEFCON but also are heavily involved in the villages and its events.
XBOW supported the Bug Bounty Village at DEFCON as a Platinum Sponsor and CTF Main Sponsor. DEFCON Bug Bounty Village CTF is an official contest, where around 500 hackers participate on a realistic, full-stack web application seeded with real-world vulnerability classes. Ariel Walter Garcia, co-founder of the BBV and a security researcher at XBOW, awarded the CTF winners on the main stage.
kreep and diabl0sec, from Spain were the winners of the CTF by solving 30 of the total 40 flags collecting a total of 22848 points, taking the first position on the leaderboard and beating the runner up team shero4 and hackerbone only for a small point difference earned by quality of report and triager's feedback.
We also brought our perspective on AI offensive security to the AppSec Village, continuing the same theme that had shaped our week in Las Vegas: engaging practitioners through hands-on experiences, technical conversations, and real-world security challenges.
More than 400 people joined us for the AI Pentesting Trivia Showdown, bringing the week to a close with exactly the kind of energy we had hoped for: a room full of people testing their knowledge, challenging assumptions, sharing ideas, and having fun while doing it.
Our technical team also participated in the main track at DEFCON:
Takes a village
To sum it up, it was an intense week. The booth was constantly full. The demo stations ran back-to-back. Meetings turned into deep technical conversations. People came for an old workstation or a payphone and stayed to talk about exploitation, automation, runtime testing, and where security is heading next.
That only happened because of an enormous team effort. From restoring decades-old hardware, to building challenges, preparing research, running demos, booking meetings, designing the space, shipping equipment, and solving countless problems behind the scenes, this really is a company effort which showcases the love and talent we have at XBOW.
In a sea of noise, I think we managed to create a place people wanted to spend time. Things are changing fast, but if you look back at the early days of hacking, it’s pretty clear where we need to go now. For more than 30 years, security has been about learning to think and operate like an attacker. Today, that means hacking with AI.
That is important because the reality is that there are now too many vulnerabilities, too few defenders, and attackers continue to find effective paths through systems faster than organizations can close them. In cybersecurity, we don't just want to describe that reality. We want to change it.
The state-of-the art agents can reason, explore, improvise, and sometimes even play Houdini, finding their way around assumptions and controls just as a real attacker would. Not because evasion is the goal, but because understanding how an attacker can assemble an effective kill chain is one of the best ways to break that chain before it is used against you.
The closer we can get to reproducing real attacker behavior, the better we can identify what is actually exploitable, understand how vulnerabilities are chained, and give defenders the evidence they need to fix what matters.
The tools are changing. The adversarial mindset isn't.
For decades, the answer has been to think like an attacker. Now we have the opportunity to do that at a scale we have never had before.
Until next time …
Keep curious, Keep hacking!