Past eventBlack Hat USA 2026 · Las Vegas · August 4–6, 2026
Let’s meet at Black Hat
See ZeroPath find exploitable vulnerabilities and ship the fix. Come by booth #7908 in the AI Zone to win a Meta Quest.
Agenda
Where you found us at Black Hat 2026
- Tue, Aug 4 4–7 PMBooth
Visit us at booth #7908
We opened the show at booth #7908 on Tuesday evening as the Business Hall doors opened.
AI Zone · Business Hall - Wed, Aug 5 9 AM–6 PMBooth
Visit us at booth #7908
We ran live demos at booth #7908 all day Wednesday, digging into real codebases with the folks who stopped by.
AI Zone · Business Hall - Thu, August 6 3:35–4:15 PMTalk
Briefings: Scanning the Scanners: Turning Security Vendors into Supply Chain Weapons
Co-Founder & CTO Raphael Karger presented his original research on how the security vendors and scanners you trust can be turned into supply-chain attack vectors.
Oceanside B · Mandalay BayView the talk - Thu, Aug 6 9 AM–4 PMBooth
Visit us at booth #7908
We wrapped up at booth #7908 on Thursday — thanks to everyone who came by for a demo and entered the Meta Quest 3S raffle.
AI Zone · Business Hall

Featured Briefings talk
Scanning the Scanners: Turning Security Vendors into Supply Chain Weapons
Raphael Karger · Co-Founder & CTO, ZeroPath
In December 2025, ZeroPath caught a real attacker probing its scan infrastructure with payloads built to be swapped across vendors at scale. Raphael Karger shares what happened when ZeroPath turned that same lens on the rest of the industry — the systemic class of vulnerability it uncovered in widely used security scanners, the responsible-disclosure process that followed, and how the impact reached production databases, cloud credentials, and OAuth tokens at Fortune 100 companies, defense contractors, and government institutions.
What we’ll show you
A vulnerability backlog your team can actually finish.
ZeroPath is AI-native application security: every finding is proven exploitable before it reaches you, and most land with a fix already written. Come see it run against real code at the booth.
Signal
Every candidate finding gets reviewed in context — exploitability, code flow, reachability — so up to 75% of the noise never reaches you. You chase real bugs, not scanner output.
Coverage
Agentic analysis catches what pattern-matching misses — broken auth, authorization gaps, and business-logic flaws — across code, dependencies, secrets, and IaC.
Velocity
Findings show up as ready-to-review fix PRs, verified after patching, with an audit trail behind every call. AppSec stops being the thing that slows everyone down.
This event has ended
Thanks to everyone who joined us at Black Hat USA 2026. We’re no longer collecting signups for this event — but we’d still love to talk.
The details
- Where were you at the show?
- We exhibited at booth #7908 in the AI Zone of the Business Hall at Mandalay Bay throughout Black Hat USA 2026, August 4–6. Thanks to everyone who stopped by — you can still book a demo anytime.
- What was the ZeroPath talk?
- Raphael Karger, Co-Founder & CTO, ZeroPath, presented “Scanning the Scanners: Turning Security Vendors into Supply Chain Weapons” on Thursday, August 6 in Oceanside B — an original-research Briefings session. See the Black Hat schedule for the full abstract.
- Who won the Meta Quest 3S?
- The raffle has closed. We drew our winner after the show and reached out by email — thanks to everyone who entered.
- What happens to my details?
- We use them to follow up after the show. They’re handled per our Privacy Policy, and every email we send has an unsubscribe link.