CYBERSECURITYTRACKER
TRACKING7,218 stories in this site build1,512 vulnerability news stories in this site build
Permanent story citation

Day 2 at Black Hat: Check Point Research Takes the Stage

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4009

As cited

Copy frozen at (site build).

research

Day 2 at Black Hat: Check Point Research Takes the Stage

Check Point Research presented three talks at Black Hat covering a decades-old Windows Defender kernel driver with hardcoded encryption keys that could be repurposed for malicious file and registry operations, prompt injection vulnerabilities across AI agent frameworks like LangChain and Microsoft Agent Framework that stem from unsafe serialization and parsing, and techniques for deobfuscating and analyzing compiled V8 JavaScript bytecode used in the JSCeal cryptocurrency stealer.

Why it matters: Windows administrators and security teams need to understand that a legitimate system driver can be weaponized to bypass Defender protections on every Windows machine; organizations deploying AI agents should audit their framework implementations for unsafe data handling in serialization and caching layers; threat hunters and analysts tracking JavaScript-based malware need approaches to reverse compiled bytecode since standard tools are insufficient.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

research

Day 2 at Black Hat: Check Point Research Takes the Stage

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

research

Day 2 at Black Hat: Check Point Research Takes the Stage

Check Point Research presented three talks at Black Hat 2026, covering a long‑standing Windows Defender driver, security flaws in artificial intelligence (AI) agent frameworks, and analysis of V8 bytecode malware. The Windows Defender driver talk revealed a hard‑coded encryption key that lets an attacker run arbitrary Ring 0 operations without a Common Vulnerabilities and Exposures (CVE) attached and without a pending patch. The audit of four AI agent frameworks uncovered twelve CVEs showing how poisoned inputs can trigger payloads via built‑in serialization and caching, while the V8 malware talk described a deobfuscation pipeline for analyzing compiled JavaScript stealer.

Why it matters: Windows administrators face privilege‑escalation risk from a stealthy Defender driver, AI developers must audit agent frameworks for serialization flaws, and malware analysts need new deobfuscation tools to tackle V8‑bytecode stealers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

research

Day 2 at Black Hat: Check Point Research Takes the Stage

Check Point Research presented three talks at Black Hat 2026, covering a long‑standing Windows Defender driver, security flaws in artificial intelligence (AI) agent frameworks, and analysis of V8 bytecode malware. The Windows Defender driver talk revealed a hard‑coded encryption key that lets an attacker run arbitrary Ring 0 operations without a Common Vulnerabilities and Exposures (CVE) attached and without a pending patch. The audit of four AI agent frameworks uncovered twelve CVEs showing how poisoned inputs can trigger payloads via built‑in serialization and caching, while the V8 malware talk described a deobfuscation pipeline for analyzing compiled JavaScript stealer.

Why it matters: Windows administrators face privilege‑escalation risk from a stealthy Defender driver, AI developers must audit agent frameworks for serialization flaws, and malware analysts need new deobfuscation tools to tackle V8‑bytecode stealers.

VendorsMicrosoftGoogleCheck Point
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary