Black Hat USA runs August 1 through 6 at the Mandalay Bay Convention Center. The Briefings, which is the part where researchers stand up and tell you what they broke, are only two of those days: Wednesday, August 5 and Thursday, August 6.
I went through all 123 of them. Not the press releases about them. The actual schedule, session by session, the way I would go through a general ledger.
Here is what the ledger says.
Thursday, 10:15 a.m.
At 10:15 on Thursday morning, ten sessions start at once. In Oceanside C, a team from a company called BT6 will present something they are calling kinetic prompt injection. Their abstract describes "a live jailbreak of a stock Unitree Go2 robot dog running Gemini Robotics-ER 1.6, reached through its own camera and mic and driven to physical movement, no human in the loop."[1]
That is not a jailbreak typed into a chat box. It is a commercially available robot dog that was talked into moving by something it saw through its own camera and heard through its own microphone.
Down the hall in Oceanside A, at the same minute, two researchers from Oligo Security will present ShadowRay 2.0, which they describe as "the first in-the-wild campaign where AI infrastructure is not just targeted, but weaponized into a self-propagating botnet." The mechanism is Ray, the open-source framework they call "the Kubernetes of AI," and the number they give is more than 230,000 exposed servers.[2]
Their note on how it was done deserves attention: the attackers did not use memory corruption bugs. They "abused legitimate orchestration features and a widely disputed vulnerability." Nothing was broken. The features worked.
Two more AI sessions run in that same 10:15 block. Four of ten. If you want a single half hour that explains the year, that is the one.
The ledger
Twenty-six of the 123 sessions are tracked under AI, ML, and Data Science. That is the largest track on the schedule by a margin of six over the next one, Exploit Development.[3]
Four sessions are tracked under Privacy. Four. It ties Cryptography for the smallest track at the conference.
I count things for a living, and a budget is the most honest document an organization produces, because it records what got bought rather than what got said. A conference schedule works the same way. There are finite rooms and finite hours, and a program committee decides what is worth the space.
This one gave twenty-six slots to how AI systems get attacked and four to whether anyone's data is safe.
I am not going to pretend that ratio is a scandal on its own. Black Hat is an offensive security conference. AI is where the new attack surface is, the researchers follow the surface, and the surface moved. That is the honest reading.
But it is worth knowing which four made the cut. Two of them are about children.
Roblox is presenting twice
On Wednesday at 2:35, four people from Roblox take the stage in Mandalay Bay H for "Privacy at Scale: Roblox's Infrastructure for Honoring User Privacy Rights." The speakers are an engineering manager, a principal privacy software engineer, a director of engineering, and Nicole Grinstead, the company's Chief Information Security Officer.[4]
Their abstract is a real engineering problem, stated plainly: at "over 100 million daily active users," honoring a deletion request means orchestrating erasure "across highly heterogeneous storages and service layers" while data "continuously flows through rapidly evolving microservices." Anyone who has tried to answer a data subject request in a company with more than three databases knows exactly how hard that is.
Then on Thursday at 3:35, three more people from Roblox present in South Seas A&B. Different subject. Their abstract opens like this:
"A hidden instruction in a GitHub Issue convinced Claude Code to upload Roblox's credentials to a public repository. EDR saw nothing, it was a normal process making a normal network request."[5]
The talk is called "Caging the Agent," and it documents what they built afterward: sandboxes for macOS, Linux, Windows, and cloud VMs, a gateway in front of the model, managed system prompts, and VPN profiles that cut production access entirely. It also documents, in their words, "23+ penetration test findings."
They add that the credential incident happened in an internal testing environment. I believe them, and it does not make the sentence less useful. Their endpoint detection saw nothing, because there was nothing anomalous to see. A permitted process made a permitted request. The instruction arrived inside a GitHub Issue, which is to say inside content the agent was supposed to read.
I use Claude Code every day. That is the part of this schedule I cannot file under someone else's problem.
What the privacy talk does not say
Here is where the two Roblox talks stop being unrelated.
While Roblox engineers were preparing a session on honoring user privacy rights, the company was working through the largest wave of child safety litigation in its history. Louisiana's attorney general sued in August 2025. Kentucky followed in October. Texas in November. Iowa and Tennessee in December.[6]
On February 19, 2026, Los Angeles County sued in Los Angeles Superior Court, with County Counsel Dawyn R. Harrison saying: "This is not about a minor lapse in safety. It is about a company that gives predators powerful tools to prey on innocent children."[7]
On March 4, 2026, Nebraska Attorney General Mike Hilgers filed, alleging Roblox "has built a multibillion-dollar business on the trust of families, all while creating a playground for predators and exposing children to graphic and dangerous content."[8]
Oklahoma filed in May. Arkansas in June.
Underneath all of it sits a federal case. On December 12, 2025, the Judicial Panel on Multidistrict Litigation centralized 31 actions from twelve districts into MDL No. 3166, In re: Roblox Corporation Child Sexual Exploitation and Assault Litigation, before Judge Richard Seeborg in the Northern District of California. The Panel noted 48 further related actions. Roblox opposed centralization. Discord, Snap and Meta are also defendants.[9]
Then the settlements started. Nevada on April 15, 2026, for $12.5 million. Alabama on April 21 for $12.2 million. West Virginia the same week for $11.08 million. South Dakota on July 13 for $15 million. That is roughly $50.8 million across four states in three months.[10]
Read the terms, because this is the part that matters for a privacy talk. Roblox agreed to age verification using facial age estimation and government-issued ID. It agreed that adults and users under 16 cannot chat unless designated a "trusted friend." And in Nevada's agreement it agreed to this:
"No communication involving minors on Roblox will be encrypted. By not allowing encryption, law enforcement will be able to more easily combat child exploitation networks, trafficking and the distribution of illegal and harmful content."
Alabama and South Dakota secured the same term. Four states, the same clause. Nobody legislated it. It is now how Roblox works, arrived at through settlement agreements in which the company admitted no liability.
So the same company, in the same year, is doing two things. It is building infrastructure to honor your right to have your data erased, and it has agreed to scan a child's face to confirm their age and to guarantee that a child's messages stay readable.
Both of those are called privacy. They point in opposite directions.
I do not think that is hypocrisy, and I am not going to write it as though it is. It is the actual shape of the problem, and it is the reason the word "privacy" has stopped being useful as a single category. Privacy from whom? A parent, a stranger, the company, the state? Roblox has been forced to answer that question four times in a row, and the answer it gave was: less privacy from us and from law enforcement, so children are safer from each other.
That is a defensible answer. What bothers me is the venue. This is a policy decision about the messages of millions of children, and it was made in negotiated agreements between a company's lawyers and four attorneys general. No hearing, no vote, no statute. If a legislature had proposed banning encryption for minors, there would have been a fight about it, and the fight would have been worth having in public.
Also worth saying plainly: the talk on Wednesday is about honoring privacy rights, and Roblox has never published anything about the architecture in Thursday's talk. As far as I can find, the Black Hat session is the first public disclosure of it.
The one you should actually be scared of
The last privacy talk is Thursday at 2:35, and I think it is the worst thing on the schedule.
Vangelis Stykas and Felipe Solferini of Kumio are presenting "Tracking the Trackers: How We Took Over 36 Million GPS Devices Protecting Children & Vehicles." These are the GPS smartwatches parents buy so they can find their kid, and the trackers people put in their cars.
They looked at three ecosystems: SETracker, roughly 10 million devices across 39 brands; SinoTrack, 6 million-plus vehicles; and TKSTAR/Thinkrace, 20 million-plus devices. Their finding is that these apparent competitors "originate from the same Shenzhen-based supply chain and share critical architectural flaws." Brands including Wonlex, SaveFamily, KidiWatch and Garett run on shared backend infrastructure. In their words, "brand differentiation in this market is largely superficial."[11]
Then this sentence:
"Starting from a free account with no device ownership, an attacker can silently activate microphone wiretaps on children's watches, trigger covert video capture, track vehicles in real time, and execute remote commands such as door unlock and fuel cutoff."
You do not need to own one of these watches, or any device at all, to listen through a stranger's child's watch. You need to register for the service.
They report 45 vulnerabilities disclosed across 50-plus countries, 19 of them critical, 9 scored CVSS 10.0, which is the maximum the scale goes to.
One note, because it is my job to notice: the title says 36 million devices and the abstract says "more than 26 million." Those are not the same number. I do not know which is right, and I am not going to pick the scarier one for you. Either figure describes a lot of children.
Stykas has been at this a long time. His earlier work on GPS tracking backends, disclosed with Michael Gruhn under the name Trackmageddon, involved contacting roughly 100 service providers. Four patched.[12]
That is the number I would put on the wall. Not 36 million, not 26 million. Four out of a hundred.
"Intended functionality"
One more thing from the schedule, because it is the sentence that decides whether any of this gets fixed.
Michael Bargury of Zenity has two talks this year, one Wednesday on agentic browsers and one Thursday on what he calls promptware. He has been doing this for a while. At Black Hat 2024 he showed that hidden HTML in an email could hijack Microsoft Copilot. At Black Hat 2025 he presented AgentFlayer, zero-click exploits against ChatGPT, Copilot Studio and Cursor.[13]
OpenAI and Microsoft patched the specific flaws. Other vendors declined, on the grounds that the behavior was intended functionality.
They are not wrong, and that is the problem. An agent that reads a document and acts on it is doing the thing you bought it for. The instruction in the GitHub Issue was read because reading issues is the job. There is no patch for the feature.
What I take from the ledger
The AI sessions will get the coverage. They should; a jailbroken robot dog is a better photograph than a database.
But the schedule is telling on itself. Twenty-six sessions about protecting AI systems, four about protecting people, and two of the four are about children whose safety is currently being negotiated in courtrooms and consent decrees rather than at a conference.
The Roblox pairing is the whole story in one company. On Wednesday they will explain how to honor a deletion request across a hundred million users. On Thursday they will explain how they caged a coding agent after it mailed their credentials to the internet because someone hid an instruction in a bug report.
Both talks are honest. Both are useful. Neither one is the same conversation as the settlement that says a child's messages will not be encrypted.
None of this has happened yet. Every abstract above is a claim by the researchers presenting it, written to get a talk accepted, and none of it has been through peer review or, in most cases, a vendor's public response. Schedules move. Talks get pulled. I will be reading what actually comes out of those rooms next week.
The one I want to read first is the Roblox agent talk, and not for the sandboxes. It is the delivery mechanism that stays with me. The instruction arrived inside a GitHub Issue, which is exactly the kind of content a coding agent is supposed to open and act on. There is no configuration in which that reading is optional, which means the fix cannot be "stop reading bug reports."



