kaliel - stock.adobe.com

Black Hat NOC sees AI security failures firsthand

A disturbing trend is unfolding on the ground at Black Hat's elite network operations center: As AI takes off, cyber-risk is rising too. Here's what the NOC wants CISOs to know.

A senior cybersecurity staffer from a Fortune 500 organization learned something alarming and unexpected during a recent training session at Black Hat USA: Because his company's MCP server wasn't secured properly, anyone on the conference's public network could have gained write-access to its EDR system.

"'Somebody on hotel Wi-Fi could have host-isolated all of your endpoints across the entire company,'" James Pope, SOC lead for the Black Hat Network Operations Center, said he told the attendee. "'It also looks like your identity was in there. So, we could have locked out every user in the entire org.'"

The company had apparently set up the MCP gateway and Claude CLI to manage its security stack, which Black Hat NOC analysts could see included CrowdStrike Falcon, Google SecOps, Optiv and Obsidian tools.

We could have locked out every user in the entire org.
James Pope SOC lead, Black Hat Network Operations Center

"They were passing their token in the clear," said Bart Stump, managing principal at Coalfire, during a conference session on the NOC's findings. "And it was a write token, so we could have wiped all of [the security stack]. Or, we could have helped them manage it."

"'Hi, we're the guys from the NOC,'" joked Neil "Grifter" Wyler, senior network operations lead at Black Hat and vice president of defensive services at Coalfire, who presented with Stump. "'Don't worry, we got this. When we're done, we'll close the door on our way out.'"

When Black Hat NOC analysts find a vulnerability or threat on someone's device, they use the IP address to triangulate the device's location to a given conference room, where they then make an impromptu announcement -- never naming names, even when they know them. The team also invites affected users to follow up at the NOC for additional information or support.

After Pope made the notification about the MCP server, the user in question approached him to discuss the exposure. He said the MCP server was recently provisioned by his company -- a Fortune 500 organization that Pope declined to identify but described as a household name. Like many major enterprises, he added, the company seems to have moved quickly to adopt AI for security and inadvertently exposed itself to massive risk in the process.

As vibe coding takes off, encryption rates fall

The MCP server incident reflects a broader trend, according to Pope, who is also senior director of security product research and technical marketing engineer at Corelight. While the Black Hat NOC used to see the percentage of conference traffic that was encrypted climb year over year, that number is now declining. Pope pointed to the rise of AI and vibe coding, with many users shipping applications without proper security.

"AI and vibe coding are great for people building a lot of interesting, good stuff that's impacting the industry," Pope said. "But it's also a lot of people who don't understand how to secure things -- even at a security conference."

As the barrier to entry for vibe coding keeps getting lower, he added, expect to see even less encryption and more risk exposure. While a frontier model could theoretically bake in security by auto-installing TLS in a new application, that would require a certificate authority and a digital certificate -- a level of complexity that vibe coders are often inclined and even incentivized to sidestep. If the proof of concept works on the developer's laptop, the app ships and eventually appears on the Black Hat network in the clear.

"They're just like, 'Make the thing -- I don't care,'" Pope said. "It's all vibes and no encryption."

It's all vibes and no encryption.
James PopeSOC lead, Black Hat Network Operations Center

In another incident at Black Hat, an attendee sitting in a training classroom checked an interior camera feed back at home. The NOC team saw the person's partner and kids in their living room in real time, streaming in the clear. Because the home automation app didn't match any known commercial product, Pope concluded it was likely a DIY vibe-coded project. The NOC team alerted the user, and the traffic fell off.

"That's the best thing in my job," Pope said. "They understood, and they reduced their risk."

Lessons for CISOs from the Black Hat NOC

Pope advised the cybersecurity pro with the vulnerable MCP server to consider gating it behind a VPN and implementing OAuth-based authentication. "And make sure it has some gate for TLS or some encryption where you're not flying that over the wire," he said, adding that the organization's cloud-based EDR tool should also sit behind a VPN.

Cybersecurity still hinges on the "unsexy" fundamentals, Pope added. While he used to see large enterprises incorrectly installing VPNs or SASE, inadvertently putting themselves at risk, he said the same pattern is now playing out with MCP servers. His advice to CISOs is simple: Go look.

"Validate it," Pope said, adding that network visibility is key, regardless of budget. "[We at] Corelight will tell you, 'Buy our stuff, and we'll help your enterprise scale this up.' But Zeek is open source; it's free. Suricata is free. They could stand it up on a single box, and AI is great at this: 'Docker up Zeke.' Connect this one, connect that one, put your SPAN port, your TAP into it. There's no reason to send 50,000 employees out into the world without checking that. So, go check."

Other findings from the Black Hat NOC

Unsecure security products. The Black Hat NOC found a security log collector transmitting endpoint telemetry in the clear, including patch levels, usernames, roles, devices and sites accessed. In 2025, the NOC noticed another established vendor's endpoint log collector sending data over HTTP instead of HTTPS. In a third incident, a VPN encrypted traffic destinations but leaked GPS data, exposing user locations.

"We're saying, 'Fix this for your customers and security people in general. You've got to make this better,'" Pope said, adding that vendors often act on notifications from the Black Hat NOC, but not always. "After multiple years of [a vulnerability] sitting there, sometimes we'll just start dropping companies' names on stage."

Infected rental laptops. The NOC team alerted a vendor on the expo floor that its rental laptops had malware. Further investigation revealed that the rental company's golden image, which it uses to reset devices before loaning them to new customers, was infected. "They got a supply chain attack somewhere, and they're now shipping this to every person who rents a laptop," Pope said. Fortunately, the vendor in question used only demo credentials in a demo environment on the rented devices, so the malware hadn't spread to production.

A personal loan application made public. An attendee contacted their bank about a loan application using a SIP-based calling app, with the audio reconstructible off the wire. Multiple other conference participants also used SIP in the clear. "That's just weird," Pope said. "Come on."

Alissa Irei is senior site editor of TechTarget Cybersecurity.

Dig Deeper on Security Operations & Management