Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
July 17, 2026 · Microsoft Security · Severity: MEDIUM
At Black Hat USA 2026, Microsoft Security highlighted the evolving threat landscape where attackers increasingly exploit trust in software, services, and AI systems. Threat actors are targeting trusted tools, developer workflows, and supply chains, such as npm (Node package manager), to scale their attacks. Microsoft emphasized the need for security teams to identify and mitigate these trust paths before they become vulnerabilities. Key sessions included David Weston’s keynote on defending against increasingly accessible offensive capabilities and a presentation by Aarti Borkar and Tanmay Ganacharya on supply chain attacks, focusing on npm-related campaigns. These discussions underscored the urgency for organizations to adapt their security operations to counter threats across software, identity, cloud, and AI systems. Microsoft also showcased new services like Microsoft Defender Experts Threat Intelligence and Microsoft Defender Experts MDR, which provide tailored, expert-led threat intelligence and multicloud coverage. The event, held from August 4 to 6, 2026, at Mandalay Bay in Las Vegas, featured technical research sessions on cloud, mobile, and software supply chain defense. One notable presentation explored GitHub’s event stream as a tool for detecting compromises, while another examined vulnerabilities in Bixby’s trust model. These insights highlighted the critical need for proactive defense strategies in an era where attackers leverage trusted systems to maximize their impact.
Across the threat landscape, in this moment, one pattern sits at the center of the story: threat actors are following trust.
They are not only looking for vulnerable systems, but rather targeting the software, services, identities, tools, developer workflows, and AI systems that organizations already depend on.
A package can become a distribution path. A build pipeline can become an access path. A trusted tool can become or expand an attack surface. An AI agent with the wrong access can become a new way to reach code, data, or infrastructure.
While the surfaces may change, the goal for the majority of threat actors remains the same: find what is trusted, abuse it, and scale the impact.
At Black Hat USA 2026, Microsoft Security will walk through how we are seeing this shift unfold, how security teams can look for it earlier, and how threat intelligence, expert-led response, and security operations need to work together when campaigns move across software, identity, cloud, data, and AI systems.
On Wednesday, August 5, 2026, the day begins with David Weston’s keynote, The End of Rare: Defending When Offense Is Cheap, which looks at what defense requires when offensive capability becomes easier to access, automate, and scale. Later that afternoon, Aarti Borkar and Tanmay Ganacharya will resume the main stage for Poisoned at the Source: Inside the Hunt for Supply Chain Attacks, which offers a closer look at how Microsoft Threat Intelligence is hunting attacks across software ecosystems, developer workflows, and trusted services. This includes details into the ongoing attacks on npm (Node package manager).
Together, these sessions frame the challenge security teams are facing now: when offensive capability becomes easier to scale, security teams need to understand the trust paths threat actors can abuse before those paths become open doors for attacks.
At our booth, we’ll also showcase Microsoft Defender Experts Threat Intelligence, a new expert-led service delivering continuous, curated intelligence tailored to your organization, and Microsoft Defender Experts MDR, now extended with third-party and multicloud coverage.
From August 4 to 6, 2026, at Mandalay Bay in Las Vegas, you’ll find Microsoft Security on the Business Hall floor at booth #2144, and on Wednesday evening, join us at the Microsoft Security reception at Swingers at Mandalay Bay.
Weston on the future of defense
At 9:15 AM PT on Wednesday, August 5, 2026, David Weston, CVP of Agentic Security, will examine what changes for security teams when offensive capability becomes easier to access, automate, and scale.
The keynote sets up one of the central questions security leaders are facing now: how does the security operations center (SOC) and analysts adapt when threat actors can move faster, test more often, and reuse trusted paths across software, identity, cloud, and AI systems? Join the keynote Wednesday, August 5, 2026, then continue the conversation with Microsoft Security at booth #2144.
Our latest intelligence (and response) on npm supply chain attacks
That same intelligence-to-action challenge is at the center of our main stage session at Black Hat.
On Wednesday, August 5, 2026, from 2:30 PM PT to 3:00 PM PT, Aarti Borkar, Corporate Vice President (CVP), Microsoft Security, and Tanmay Ganacharya, Vice President of Microsoft Security Research and Threat Intelligence, will share intelligence and insights into the ongoing supply chain campaigns impacting all areas of the threat landscape. The talk, Poisoned at the Source: Inside the Hunt for Supply Chain Attacks, will walk through Microsoft Threat Intelligence’s investigations into the ongoing npm supply chain attacks targeting software ecosystems, developer workflows, trusted services, and how organizations are handling the challenges associated with npm packages.
Follow the research in the Black Hat Briefings
Microsoft Security researchers will also present peer-reviewed technical research in the Black Hat Briefings. These sessions go deep into cloud, mobile, and software supply chain defense.
GitHub Can Tell You’re Being Hacked. You’re Just Not Listening: Building EDR for GitHub from Its Own Event Stream
- Presented by Yossi Weizman, Principal Security Research Manager
- Wednesday, August 5, 2026, from 10:15 AM PT to 10:45 AM PT
One Click to System: Exploiting Bixby’s Trust Model for Full Device Compromise
- Presented by Dimitrios
Key Takeaways
- This Weston on the future of defense Our latest intelligence (and response) on npm supply chain attacks Follow the research in the Black Ha.
- They are not only looking for vulnerable systems, but rather targeting the software, services, identities, tools, developer workflows, and AI systems.