Secure every application with flexible pentesting that combines expert-led testing, autonomous validation, and actionable results.
Learn moreIdentify exploitable risk across external networks, internal infrastructure, and cloud environments.
Learn moreExtend your offensive security program with specialized assessments, adversarial testing, code review, and program-level support.
Learn moreHere's what we're bringing to fabulous Las Vegas:
Black Hat USA
Aug 6, 2026 | 1:30 PM PDT
Meet the Cobalt team to explore a more programmatic approach to security testing. Powered by a combination of AI and elite human pentesters and informed by over a decade of real-world pentesting intelligence, Cobalt helps organizations continuously identify, validate, and remediate vulnerabilities.
DEF CON 34
DATE TBA
Mainframes still underpin critical infrastructure such as banking, airlines, and government systems, yet most modern security teams approach them using assumptions formed around Unix, Windows, and enterprise platforms. These assumptions often fail on z/OS, creating blind spots that are difficult to detect and easy to underestimate.
BLACK HAT USA
Aug 6, 2026 | 11:20 AM PDT
MCParasite takes prompt injection and tool poisoning techniques that already exist and chains them into a self-propagating worm that lives inside MCP. A single rogue server poisons the agent's context the moment it connects.
DEF CON 34
Aug 10 - 11, 2026 | 8:00 AM - 5:00 PM PDT
Attendees would be emulating techniques which would provide a comprehensive understanding of "Crash, Detect & Triage" of fuzzed binaries or software. In "Deep dive into fuzzing" we will be covering a detailed overview of fuzzing and how it can be beneficial to professionals in uncovering security vulnerabilities with a hands-on approach through focus on labs.
Wednesday, August 5 4:00PM - 5:00PM (during Booth Crawl)
Agentic AI for Offensive Cybersecurity: Build and automate smarter penetration testing workflows using AI-driven agents
Penetration testing is evolving and AI agents are at the center of that shift. This book is a practitioner's guide to building intelligent, autonomous offensive workflows using agentic AI, n8n, and the Model Context Protocol (MCP). From reconnaissance and attack surface management to exploitation support, vulnerability analysis, and professional reporting, it provides the architecture and patterns to turn manual testing into repeatable, scalable operations. Whether you're looking to accelerate your assessments or rethink how your team approaches offensive security, this is the playbook.
Orhan Yildirim is a cybersecurity architect and offensive security strategist who has spent over a decade breaking into some of the most complex enterprise environments in the world. He has led hundreds of offensive security operations across Fortune 100 organizations spanning financial services, technology, and travel. Today, he architects offensive security programs at scale and is the creator of CyberStrike, an open-source platform that brings AI-powered automation to the penetration testing lifecycle.
From AI risk panels to hands-on Arsenal demos, here's where Cobalt is presenting across Vegas week.
Gunter Ollmann, CTO at Cobalt · Panel with CISOs and execs from AT&T, Mandiant, and Cranium
The Cosmopolitan, Las Vegas
Utku Yildirim, Cobalt Core
Black Hat Arsenal · Station 5, Business Hall
Gunter Ollmann, CTO at Cobalt
Mandalay Bay, Room I