As cited
Copy frozen at (site build).
research
Day 2 at Black Hat: Check Point Research Takes the Stage
Check Point Research presented three talks at Black Hat covering a decades-old Windows Defender kernel driver with hardcoded encryption keys that could be repurposed for malicious file and registry operations, prompt injection vulnerabilities across AI agent frameworks like LangChain and Microsoft Agent Framework that stem from unsafe serialization and parsing, and techniques for deobfuscating and analyzing compiled V8 JavaScript bytecode used in the JSCeal cryptocurrency stealer.
Why it matters: Windows administrators and security teams need to understand that a legitimate system driver can be weaponized to bypass Defender protections on every Windows machine; organizations deploying AI agents should audit their framework implementations for unsafe data handling in serialization and caching layers; threat hunters and analysts tracking JavaScript-based malware need approaches to reverse compiled bytecode since standard tools are insufficient.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
research
Day 2 at Black Hat: Check Point Research Takes the Stage
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
research
Day 2 at Black Hat: Check Point Research Takes the Stage
Check Point Research presented three talks at Black Hat 2026, covering a long‑standing Windows Defender driver, security flaws in artificial intelligence (AI) agent frameworks, and analysis of V8 bytecode malware. The Windows Defender driver talk revealed a hard‑coded encryption key that lets an attacker run arbitrary Ring 0 operations without a Common Vulnerabilities and Exposures (CVE) attached and without a pending patch. The audit of four AI agent frameworks uncovered twelve CVEs showing how poisoned inputs can trigger payloads via built‑in serialization and caching, while the V8 malware talk described a deobfuscation pipeline for analyzing compiled JavaScript stealer.
Why it matters: Windows administrators face privilege‑escalation risk from a stealthy Defender driver, AI developers must audit agent frameworks for serialization flaws, and malware analysts need new deobfuscation tools to tackle V8‑bytecode stealers.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
research
Day 2 at Black Hat: Check Point Research Takes the Stage
Check Point Research presented three talks at Black Hat 2026, covering a long‑standing Windows Defender driver, security flaws in artificial intelligence (AI) agent frameworks, and analysis of V8 bytecode malware. The Windows Defender driver talk revealed a hard‑coded encryption key that lets an attacker run arbitrary Ring 0 operations without a Common Vulnerabilities and Exposures (CVE) attached and without a pending patch. The audit of four AI agent frameworks uncovered twelve CVEs showing how poisoned inputs can trigger payloads via built‑in serialization and caching, while the V8 malware talk described a deobfuscation pipeline for analyzing compiled JavaScript stealer.
Why it matters: Windows administrators face privilege‑escalation risk from a stealthy Defender driver, AI developers must audit agent frameworks for serialization flaws, and malware analysts need new deobfuscation tools to tackle V8‑bytecode stealers.
- Source published
- First seen by Cybersecurity Tracker