As tens of thousands of cybersecurity professionals, executives, and policymakers descend on the Las Vegas strip for the annual “Hacker Summer Camp”—encompassing Black Hat, DEF CON, and B-Sides conferences—the importance of this gathering is unparalleled. The year 2024 has witnessed a surge in cyber disruptions, from ransomware crippling medical offices and auto dealerships to widespread breaches of federal agencies attributed to Volt Typhoon, a notorious China-based APT group.
Additionally, the recent global outage caused by a CrowdStrike update has highlighted the fragility of the software supply chain. Though not a result of a cyber attack, this incident underscores the potential havoc that malicious actors could wreak on software supply chain security (SSCS).
So, what does this mean for the attendees at Black Hat this week? They are gathering with a sense of urgency and a plethora of issues to tackle. Here are two main themes they will confront at this year’s conference.
[Visit our team to learn more about our plans: RL @ Black Hat 2024]
Spotlight on Software Supply Chain Security
As the cybersecurity community congregates in Vegas, the aftermath of the CrowdStrike Falcon endpoint detection and response software debacle, which caused widespread Windows system crashes, will be a hot topic, despite not being officially on the agenda. This incident, among others, has cast a glaring light on the vulnerabilities within software supply chains.
Even without this outage, software supply chain threats were destined to be a major discussion point, given recent incidents such as the takeover attempt of the xz Utils open-source project, malicious packages on Google Play, and attacks on Ivanti’s Pulse Secure VPN. Various talks at Black Hat will delve deep into the foundational flaws of both open-source and commercial software that power the global economy. Highlights include a high-level talk by Danny Jenkins, CEO of ThreatLocker, on software supply chain risks, and a technical presentation on the vulnerabilities of the Secure Shell protocol by security experts HD Moore and Rob King.
The aged Secure Shell protocol, nearing its third decade, poses significant risks of “code rot,” leading to unexpected vulnerabilities and novel attacks like the recent regreSSHion (CVE-2024-6387) in OpenSSH, affecting millions of Glibc-based Linux systems. Moore and King will introduce an open-source tool, “sshamble,” for further SSH flaw research.
The risk from flawed code isn’t exclusive to open-source software. Other Black Hat presentations will expose severe vulnerabilities in commercial codebases, cloud services, and prominent platforms. Alon Leviev’s presentation will reveal a compromise of Windows Update, enabling forced component downgrades and follow-on attacks. Tenable researcher Liv Matan will discuss a critical RCE vulnerability (‘CloudImposer’) in Google Cloud Platform (GCP), affecting millions of cloud servers.
The Double-Edged Sword of AI
Artificial intelligence (AI) is another prominent theme at this year’s Black Hat, as it is at many tech conferences. In cybersecurity, AI is seen both as a potential savior for overburdened security teams and a new tool for malicious actors, enabling everything from automated vulnerability discovery to advanced phishing campaigns.
Talks like “Threat Hunting with LLM” by researchers at DBAPPSecurity highlight how AI, particularly large language models (LLMs), can aid in detecting advanced threats. Similarly, Bill Demirkapi of Microsoft’s Security Response Center will discuss using LLMs to automate security response workflows.
Conversely, there are significant concerns about the risks of AI-generated code, especially from services like GitHub CoPilot. Chris Wysopal of Veracode will address these issues in his talk “From HAL to HALT: Thwarting Skynet’s Siblings in the GenAI Coding Era,” highlighting the dangers of relying on AI-generated code and the potential for serious flaws.
Another talk by Michael Bargury, CTO of Zenity, will explore vulnerabilities in Microsoft CoPilot, including prompt injection attacks that could bypass data leak prevention measures. Shachar Menashe of JFrog will discuss risks in machine learning operations (MLOps) platforms, showing how features in these platforms can be exploited in real-world attacks.
As AI continues to evolve, the debate over its role in cybersecurity—whether it will be a boon for defenders or a force multiplier for attackers—will unfold in real-time.
Visit ReversingLabs at Booth #2660
Rapid technological innovation, digital transformation, AI, and an expanding threat landscape make for an exciting Hacker Summer Camp. ReversingLabs will be there, ready to discuss our advanced threat hunting and intelligence solutions, as well as our software supply chain security platform. Plus, we’ll have cookies—don’t miss out!



