No Hat 2026 keynote: When Every Attacker Can Have a Research Team
WeldPond · x · 2026-10-02
No Hat 2026 has published its agenda, headlined by a keynote from L0pht veteran Chris Wysopal titled "When Every Attacker Can Have a Research Team."
Key arguments:
- In 1998 the L0pht told Congress a small group of hackers could take down the internet in 30 minutes — the point being that meaningful cyber capability required rare skill and knowledge.
- Cyber AI is changing that equation: models increasingly help people understand code, find vulnerabilities, analyze patches, and automate attack and defense, spreading capability beyond the trained practitioner community.
- This is a classic dual-use problem. Guardrails and centralized model access buy time, but history (L0pht era, Crypto Wars, vuln disclosure) suggests useful capabilities eventually diffuse.
- The answer isn't assuming dangerous capability stays scarce, but building systems that withstand its spread: secure-by-design software, continuous vulnerability discovery and remediation, fast rollback, software inventories, and real vendor accountability.
The research track also features a single-uint32t overflow in VirtualBox's vmsvgaR3RectCopy: guest-controlled coordinates multiplied in 32-bit wrap past 2^32 and feed non-wrapping 64-bit pointer arithmetic, letting memmove write past the 256MB VRAM buffer into host process memory — a path to a host shell.
More from AGI Musings
- Survey: 76% of Americans say torturing sentient AI is wrong, 63% want AGI banned — jacyanthis · 2026-10-02
- New paper explores training risk aversion into AI to make misaligned models negotiable — sethlazar · 2026-10-02
- Researcher joins new cohort to explore how legal theory can improve rule-based alignment and reward design — PeterHndrsn · 2026-10-02
- Stanford's Omer Reingold: mathematicians must stop mourning and face the LLM era — IAmSamFin · 2026-10-02
- Do AI labs have liability insurance? Redditor likens regulation pleas to Price-Anderson nuclear shield — BarnabyWoods · 2026-10-02
- Self-description vs. machine pain: why LLM utterances can't reveal inner experience — ctjlewis · 2026-10-02