Black Hat USA
- When
- First week of August
- Where
- Las Vegas, NV (Mandalay Bay)
- Format
- In-Person
- Organizer
- Informa Tech (Black Hat)
- Attendance
- 20,000+
- Cost
- $2,000-3,000
What this conference is for
Black Hat USA is the largest vendor-neutral offensive-security research conference in North America, drawing over 20,000 practitioners to Las Vegas each August for a program built around original vulnerability research, red-team methodology, and hands-on training rather than product pitches. It runs alongside DEF CON the same week and functions as the year's biggest venue for disclosing new attack techniques, including the ones that target authentication, passkeys, and non-human identity.
Who should attend
Security researchers and red teamers who want deep technical briefings, and identity and security leaders tracking which attack techniques are moving from research to real-world exploitation. The Business Hall also concentrates a year's worth of identity and access management product launches into two days.
What we cover
Black Hat's program spans the entire security stack, most of it outside identity. Our coverage is narrow and deliberate: the briefings, research disclosures, and vendor launches that are specifically about authentication, identity infrastructure, machine and non-human identity, and access control. See our Black Hat USA 2026 recap for what stood out this year.
Coverage
This is independent community coverage of identity-relevant themes, not an official summary of the conference. Always confirm specific research and product claims with the original researchers, vendors, or the official site.
Related on Start with Identity
- BlogPass-the-Passkey: a Black Hat researcher found the WebAuthn implementation bugs, not the standard
At Black Hat USA 2026, DSInternals researcher Michael Grafnetter presented a family of passkey attacks including cleartext YubiKey signatures readable by any au
- ArticleIdentity for B2B SaaS: Multi-Tenancy, Enterprise SSO, and Admin Control
The identity model B2B SaaS actually needs: multi-tenant organizations, per-customer enterprise SSO and SCIM, delegated administration, and audit logs, plus why
- ArticleIdentity for Gaming: Scale, Social Login, and Child Safety
Identity in gaming has to handle massive spikes, near-zero login friction, cross-platform accounts, anti-cheat and account-takeover defense, and strict child-sa
- ArticleIdentity for Government: National eIDs, Assurance Levels, and Access
How identity works in the public sector: national eID schemes and citizen login, identity assurance levels under NIST 800-63 and eIDAS, workforce credentials li