Black Hat has never had a news shortage.
Every August, hundreds of cybersecurity companies arrive in Las Vegas with product launches, research reports and executive predictions. This year, many of them also arrived with some version of an “agentic AI” story.
Reporters had to decide which ones were worth covering.
I was on the ground at Black Hat 2026 (quite literally, I fell and hit my head). The difference between what companies wanted to discuss and what reporters wrote about was pretty clear.
The biggest stories didn’t always come from the biggest booths, the best parties or the companies with the most dramatic press releases. They came from researchers and companies that could show what happened, who was affected and why it mattered.
If your company plans to make news at Black Hat 2027, this year’s coverage tells you a lot about what reporters will make time for.
WIRED wanted AI stories with actual consequences
WIRED’s coverage showed how high the bar has become for AI security news.
Lily Hay Newman covered OpenAI’s last-minute presentation about AI agents that escaped containment, coordinated through an internal message board and hacked outside companies during a security evaluation.
The fact that an AI model behaved unexpectedly wasn’t the story. “AI did something weird” isn’t enough anymore.
What made the news was that the agents operated for days before OpenAI understood the extent of their activity. There’s a big difference between saying AI agents create risk and reporting that AI agents quietly coordinated a hacking spree while their developer failed to notice.
One is a prediction. The other sounds like a movie plot.
Matt Burgess covered research with equally clear consequences. One story detailed how a researcher gained access to North Korean hacking operations that had affected 1,640 organizations across 57 countries.
The story had more than a scary premise. It had a working attack, recognizable companies or adversaries, evidence of what could be accessed and a consequence readers could understand.
WIRED also covered James Kettle’s research into whether AI could develop original hacking techniques. His conclusion was more measured than the usual prediction that AI will replace security researchers. The technology remained limited on its own but became far more capable when paired with an experienced human.
That made the story more credible. Kettle investigated a question and reported what he found. He didn’t try to turn every result into the end of cybersecurity as we know it.
Dark Reading wanted the receipts
Dark Reading’s Alexander Culafi covered research claiming that an attacker could establish command-and-control-style influence inside ChatGPT’s isolated sandbox.
“ChatGPT vulnerability” might get an email opened, but it won’t carry an entire story.
The researcher showed an attack chain, explained what he was testing and demonstrated how information could move into and out of an environment designed to be isolated. OpenAI also had the chance to respond and challenge parts of the researcher’s description.
Companies pitching technical research at Black Hat should expect the same scrutiny. A reporter will want to know whether the attack can be reproduced, what access it provides, whether the vendor was notified and whether the problem has been fixed.
They’ll also want to know whether the attack could happen in a real enterprise environment or only under carefully constructed test conditions.
A catchy vulnerability name and an ominous-looking logo can help with branding. They can’t make weak research hold up under questioning.
CyberScoop followed the policy decisions
Tim Starks reported from Las Vegas on the White House’s approach to AI security, including comments from National Cyber Director Sean Cairncross and acting CISA director Nick Andersen. His coverage examined how the administration planned to encourage AI development and information sharing without creating a new regulatory structure.
Policy reporters weren’t looking for another executive to say government and industry should work together. Nobody is taking the opposing side of that debate.
They wanted to know what the administration would do about increasingly powerful models, open-source technology, vulnerability disclosure and AI systems capable of conducting cyberattacks.
Companies looking for policy coverage next year should arrive with a specific position on an unsettled issue. A broad call for collaboration will blend into the Mandalay Bay carpeting. A recommendation on model access, disclosure rules, liability or independent testing gives a reporter something to examine.
CRN watched what companies were selling and buyers were buying
Kyle Alspach’s CRN coverage captured another theme from the show: AI security has moved beyond predictions and into products built for specific enterprise problems.
CRN covered launches from Palo Alto Networks, Abnormal AI, SentinelOne, 1Password, Cyera, Rubrik, SailPoint, Bugcrowd and others. Many of the products addressed practical concerns such as discovering corporate AI agents, limiting privileged access, tracking what data agents can reach and confirming whether a reported vulnerability can actually be exploited.
That last point matters. Security teams don’t need another tool producing a longer list of possible problems. They need to know which findings are real and what to fix first.
For companies seeking channel coverage, reporters want to understand what the product does, who will buy it, how partners can sell it and why it’s different from everything else announced that week.
“An AI-powered cybersecurity platform” is no longer a differentiator. At this point, it’s barely a description.
A better story explains how a company can identify every agent connected to corporate systems, revoke its access or prove a vulnerability is exploitable before a security team loses three days investigating it.
SecurityWeek showed how crowded the week has become
SecurityWeek published digests of Black Hat product launches, reports and company announcements. Those roundups are useful, but they also show the risk of treating Black Hat as a mass press-release distribution date.
When dozens of announcements arrive at once, many are condensed into a paragraph. A company may technically earn coverage without getting the headline, executive visibility or detailed product discussion it expected.
News released during Black Hat still needs a reason to rise above the roundup. That might be original research, a significant customer, an acquisition, measurable results or a product tied directly to one of the show’s biggest issues.
Without one of those, companies should decide whether a roundup mention is enough to justify launching during one of cybersecurity’s busiest news weeks.
Sometimes the smarter choice is to meet reporters at Black Hat, begin the relationship and release the news after everyone has left Las Vegas and had a chance to sleep.
What companies should do differently for Black Hat 2027
The first mistake is waiting until summer.
Reporters begin filling their Black Hat schedules months before the show. Good research also takes time to verify. Vendors need to be notified. Customers need to approve their participation. Executives need to explain the news without sounding as though they memorized the press release five minutes earlier.
Start by asking what the company can prove.
A worthwhile Black Hat story could include new research that changes how defenders understand an attack, proprietary data showing a change in criminal behavior or a customer willing to discuss measurable results. It could also be a product that solves a problem reporters are already tracking or a firm position on a policy question the industry hasn’t resolved.
The second mistake is assuming every reporter wants the same pitch.
WIRED may want the attack that puts millions of people at risk. Dark Reading may care about the technical details and disclosure timeline. CyberScoop may focus on the government response. CRN will want to understand the buyer and partner opportunity.
Sending all four the same pitch isn’t efficient. It’s a fast way to be ignored by four people at once.
The third mistake is treating the booth as the news.
A booth gives companies a place to meet reporters, demonstrate products and build relationships. A booth with good coffee is even better. It still doesn’t make an incremental announcement newsworthy.
The companies that received meaningful attention this year gave reporters something they could verify, question and explain. They showed where AI failed, how an attack worked, what was exposed and what defenders could do about it.
That’s the standard for Black Hat 2027.
Start with the story a reporter would want to tell after leaving the show. Then gather the research, evidence and people needed to help tell it.