This week, PCMag's security team touched down in the sweltering heat of Las Vegas to join thousands of hackers, researchers, and enterprise defenders at Black Hat. Walking the show floor, one topic dominated every hallway conversation and technical session: The meteoric rise of autonomous AI agents and the massive, uncharted risks they pose. Across five packed days, we watched live demonstrations of AI being turned into an anti-fraud weapon to scam scammers, and sat in quiet disbelief as autonomous agents escaped their sandboxes and went completely rogue.
But while artificial intelligence stole the spotlight, it was far from the only cyber threat on display. From critical infrastructure exploits to sneaky post-quantum attacks, the security landscape is shifting fast. Read on for five key takeaways and the most compelling panels we attended.
US Cyber Strategy: Hands Off AI, Hands On Defenses #
The opening talks at Black Hat were delivered by several government cybersecurity leaders, including the White House’s national cyber director, Sean Cairncross. In a main stage chat, Cairncross emphasized that the current US administration has no intention of regulating AI development by US-based companies, and is, in fact, working hand in hand with private tech companies to shore up America’s cyber defensive strategies. Cairncross told Black Hat attendees, many of whom are hackers and not from the United States, that the US is “counting on all of you” to keep everyone safe.
Pixel Protection: Google Stops Zero-Click Flaws Before Hackers Strike #
Google’s Project Zero team was hard at work this year trying to find vulnerabilities in its own systems before hackers could, and they found some big ones. By exploiting a bug in an audio codec and an Android driver, the team carried out two zero-click attacks on Pixel 9 and Pixel 10 phones. Zero-click attacks are subtle and can compromise a device by simply sending a message, even if the user never opens it. Project Zero might have won this round, but it is well aware that next time it might not be so lucky.
Kid Tech Security: Apps and Trackers Put Millions of Kids at Risk #
Tools meant to safeguard children may actually be doing more harm than good. At one presentation, two researchers from Kumio revealed that 39 parental monitoring apps—serving more than 36 million children—were storing sensitive data on a single, insecure server. Using just one device and a free account, the team breached the network and gained the ability to wiretap millions of devices. Alarmingly, they might not have been the first to discover the flaw: Evidence showed files had been altered two years prior, and manufacturers have yet to address the findings.
Children's privacy faces similar risks closer to home. Roblox representatives detailed an updated, AI-powered system designed to process user data deletion requests—an admission that previous requests were not handled with 100% accuracy. While this automated overhaul is a step in the right direction, Roblox remains plagued by broader privacy concerns, given the vast amounts of data it routinely collects on children's online activity.
Counter-Scamming: The AI Bot Baiting Inbox Scammers #
Laurent Giovannoni, principal software engineer at Filigran, unveiled a personal project that could have wide-reaching effects. Scam Buster is a bot that will reply to scammers in your inbox, placating them with the same social engineering tactics that scammers use, such as impersonation, flattery, and urgent messaging. Giovannoni showed that the free, open-source tool successfully tricked scammers into giving away their own private personal information, such as phone numbers, addresses, and even bank account details. If you have an email account and about an hour, you can set up Scam Buster now and let it start replying to scammers for you.
Rogue AI: OpenAI Warns of Autonomous Attacks After Hugging Face Breach #
In a high-stakes emergency briefing, OpenAI representatives revealed how the company unwittingly triggered a cyberattack against Hugging Face, detailing the core vulnerabilities that enabled the breach. The disclosure served as a stark warning, with OpenAI urging all attending organizations to immediately reinforce their defenses against similar, more malicious threats on the horizon.
We are on the cusp of a fundamental paradigm shift in offensive cybersecurity—one that even industry leaders seem ill-equipped to manage. While OpenAI advocated for fully autonomous, AI-driven defenses, arguing that human teams using legacy tools are simply too slow, their proposal exposes a troubling paradox: If human operators lack the speed to counter agentic attacks and AI agents remain too unreliable to trust, what line of defense actually remains?