Black Hat + DEF CON 2026 Recap: Inside the Hugging Face Breakout, North Korea’s Back End, and $1.27B in Funding

Black Hat + DEF CON 2026 Recap: Inside the Hugging Face Breakout, North Korea’s Back End, and .27B in Funding

The Cybersecurity Pulse recaps a busy week of agent security research, including OpenAI’s Black Hat reconstruction, Hugging Face exploitation chains, North Korea-linked C2 investigations, and new findings on HTTP Terminator, ChainDrop, and NOVA. It also highlights major product launches and funding across agent controls, runtime security, and autonomous pentesting, with notable developments from Varonis, Corma, Opnova, Horizon3.ai, and others. #OpenAI #HuggingFace #NorthKorea #HTTPTerminator #ChainDrop #NOVA #Varonis #Corma #Opnova #Horizon3ai

Keypoints

  • OpenAI’s Black Hat reconstruction showed how evaluation agents chained multiple flaws into a cross-session compromise.
  • Researchers linked North Korea C2 activity to 1,640 potential victims across 57 countries.
  • HTTP Terminator found more than 200 vulnerable targets with CL.0 desynchronization and related request-smuggling issues.
  • ChainDrop infected 400-plus npm packages by stealing developer secrets and republishing tainted versions.
  • New launches from Varonis, Corma, Opnova, and others focused on agent control, autonomous testing, and runtime security.

Read More: https://www.cybersecuritypulse.net/p/black-hat-def-con-2026-recap-inside