Black Hat Asia 2026 | Mobile Track Spotlight
Mobile security professionals report a surge in AI-generated code bloat, creating massive workloads for manual code review and forcing a shift toward unified cross-platform frameworks like React Native and Hermes. While AI tools effectively identify low-hanging fruit and automate pattern matching, they struggle with complex business logic and undocumented API endpoints, necessitating human expertise for critical P1 vulnerabilities. Experts warn that despite hardware advancements like secure enclaves and strong boxes, the radio stack remains a legacy vulnerability, and hardware security is frequently compromised by implementation flaws rather than protocol failures. The industry is moving away from Progressive Web Apps toward native or hybrid solutions to manage security risks, yet the sheer scale of AI-injected code requires a hybrid approach where automation handles coverage and humans focus on heat maps and unique attack paths.
Teaching Hardware Hacking at Black Hat & DEF CON (Vlog)
A security team delivered two-day fault injection training at Black Hat and a self-paced workshop at DEF CON, leveraging Hextry to teach hardware hacking techniques. The operation involved complex logistics, including international travel from Germany and the deployment of local workstations with a new kiosk mode for attendees. While the team managed to successfully execute these high-stakes educational events, they also navigated significant physical challenges such as extreme heat and jet lag. The experience highlighted the intense preparation required to maintain performance standards while running a profitable booth in a demanding environment.