Jamf at Black Hat USA 2026
Black Hat USA 2026 highlighted how cybersecurity has fundamentally changed. Here's a peek into what the Jamf team was up to, what we learned, and what we showed at the conference.
At the southern tip of Las Vegas Boulevard in Mandalay Bay Resort and Casino, a global community of cybersecurity leaders convened to learn what’s next (and what is already here) at Black Hat USA 2026. They were joined by red team operators, detection engineers, threat hunters, intelligence analysts and more.
"Cyber Power in the Age of AI"
After a few days of intensive training ranging from AI Cyber Bootcamp to Enterprise Vulnerability Assessments, the conference opened with "Cyber Power in the Age of AI." This set the stage for what would be a common topic of conversation. From how vendors advertised their software and services in the Business Hall to the many briefings throughout the show, one thing was clear: we are in the era of AI. This technology is reshaping how systems are secured, how vulnerability research is conducted and how organizations and security teams operate.
AI is becoming a cornerstone in how many organizations work.
And security leaders are also thinking about how to secure AI itself. At the conference, they asked fundamental questions such as: what new risks does AI introduce (like data exposure, shadow AI, or unauthorized exposure)? How can those risks be mitigated?
Securing AI systems — the data they train on and use and the identities that interact with those systems — is a key tenet of cybersecurity.
Black Hat is the people
Conversations struck up while waiting for a burrito at BBQ Mexicana. New relationships formed at one of the dozens of happy hours. Connection and learning is what drives this community.
As Suzy Pallett, President of Black Hat, said during the opening session, “But the truth, the most important things that happen at Black Hat don't always happen on stage. They happen when a researcher shares a finding that changes how someone thinks about a problem. They happen when states sit down with industry and realize they're solving the same challenge from different angles. They happen in the hallway, in the late-night debates, and the moments when someone says, 'Wait, what if we tried this instead?' That's the power of this community.”
What we experienced at the Jamf booth and in the Network Operations Center (NOC) echoed that sentiment.
Jamf in the NOC
The NOC at Black Hat is one of the buzziest places in the conference. It’s a collaboration of industry leaders who volunteer time and resources to ensure the show runs smoothly. Monitoring and defending Black Hat's network is not a job not for the faint of heart. And at a show which trains attendees to write and deploy malware and exploit vulnerabilities (ethically, of course), that challenge is magnified.
Jamf and partners at the Black Hat NOC
The NOC: a microcosm of Black Hat's community
Here's how it works.
Industry leaders — Cisco, Palo Alto, Corelight, Luman, Arista, and Jamf — work together to solve problems in real time.
The team must distinguish between legitimate conference activity and real malicious behavior. That requires more than simple alerts: it requires context. The NOC team must clearly understand what a "Black Hat positive" is: network activity that is aggressive but normal at a security conference, vs. actual malicious behavior targeting attendees or the conference itself.
Throughout the show, attendees were able to get a first-hand look at the NOC with the NOC Outpost: an open, interactive extension of the main Black Hat NOC. Here, attendees had direct access to the NOC team, the technologies and tools that defend the Black Hat network in real time, and a first-hand view of what goes into securing the conference.
One of Jamf’s roles in the NOC is to ensure Apple devices behave as users expect.
And those devices play a big role. They provide hardware that conference goers are familiar with, making device interactions easy and secure. Black Hat uses iPhones and iPads to register conference goers, scan attendees into briefings and support the operations for vendor booths in the Business Hall.
Jamf at the Black Hat NOC
The Jamf booth
During the show, we explored these topics and more:
- AI governance
- Mac malware
- Threat hunting
- Spyware
- Mobile forensics
We spoke with customers (thanks to all who stopped by!), researchers new to Apple security and others who have focused on the Apple platform for over 20 years.
Live sessions at the Jamf booth
Expanding on what we heard at RSA earlier this year, the use of Mac and mobile devices is accelerating in the enterprise. Mac is becoming the standard, not an exception. Mobile devices are used in more workflows than ever; device and network defense must be layered to be ready for advanced threats.
AI on Mac: from governance to a Mac security assistant
Earlier this year, we surveyed over 650 IT and security leaders about governing AI. The numbers were eye-opening. Nearly three-quarters (72.9%) of respondents have deployed AI in some form, and more than four in five (81.7%) have either dealt with an AI-related incident or expect one.
Four security factors these businesses are facing:
- Shadow AI introduced from employees adopting tools without IT approval
- Agentic and developer AI, including command-line tools, IDE extensions, embedded models and third-party packages — which can generate insecure code
- Vendor sprawl as existing vendors add AI to products already deployed across the fleet faster than teams can vet them
- Cost surprises; usage-based pricing makes spend impossible to forecast
Security leaders expressed similar challenges and questions at the Jamf booth.
Governing AI
Those securing Mac dove deeply into one question: How can we get better visibility into what AI is used on our Mac fleet? There is a real need to surface unsanctioned AI tool usage, enforce governance policies from the operating system level, and apply zero-trust AI access controls using native Apple frameworks.
Network-level controls don't solve this problem; they require endpoint-level controls built natively on Apple's frameworks. This is what provides organizations with the visibility into how to properly govern Mac AI use.
Better yet, how to say yes to AI on Mac.
>> Learn more about AI governance on Mac
Effective AI use with AI Assistant
While teams absolutely need to govern AI, Apple admins also want to use it to improve operations. Jamf's AI Assistant helps admins do just that: ask questions in plain language and receive immediate answers and clear action items based on context.
Our AI team dove deep into AI Assistant: the architecture, design principles and how it works for IT and security administrators. We went into our privacy-by-design principles, such as:
- AI Assistant is off by default and advisory in nature
- Your data is never used for model training
- Jamf customers can restrict access to authorized users
Mac malware and the threat landscape
One of the highlights of the show at the Jamf booth was our conversations on Mac malware and the threat landscape.
Jaron Bradley, Director of Jamf Threat Labs and Patrick Wardle, Founder of Objective by the Sea, offered information-packed sessions.
The expertise of the two speakers gave attendees an inside look into what security researchers and threat hunters think about. They investigate how Mac malware and attacker techniques continue to evolve, why platforms focused on macOS deliver the best tools for defense and where threats to macOS are headed.
One key topic of these presentations: infostealers, often the first stage in a larger attack. These attacks continue to become more popular and evolve. In fact, almost 34% of all malware observed on Mac are now infostealers.
The speakers also talked about their backgrounds, their books on Mac security (which a few lucky attendees went home with), and how Mac malware research and threat hunting go hand-in-hand.
You can read more from Jamf Threat Labs by visiting our blog, and you can hear from Patrick Wardle by reading his blog.
Jaron Bradley of Jamf Threat Labs talks Mac malware and threat hunting at Black Hat 2026.
Mobile risk: from apps to spyware
One of the most notable conversations at the booth centered around securing mobile devices.
These conversations ranged in use cases from data loss prevention and privacy in Bring Your Own Device (BYOD) deployments to the risk that mobile applications introduce to advanced persistent threats and spyware.
IT and security teams alike are responsible for a wide range of devices and use cases in continually distributed workforces. The direction is clear: mobile devices can no longer be a blind spot. AI is more than a downloaded app; visibility cannot stop at the network and cloud layer. Tools must be built for mobile devices and not retrofitted from workstation tools.
Organizations want to create experiences that preserve the native Apple experience and honor user privacy; they need newer tools that go beyond basic Mobile application management. At the same time, security practitioners want visibility that gets to the root of the problem, workflows that are integrated into broader security operations and can support a distributed workforce, and control that goes beyond the application level and works directly on the device.
How to get a real-time view of all mobile apps
During our booth session covering the Mobile Security 360 Report, Jamf and partner NowSecure showed attendees how to get a real-time view of all deployed mobile applications. As documented in the Security 360 Report, and expanded in the session, over 96% of mobile apps contain AI code. Visibility is one of the first steps toward assessing risk and ensuring compliant devices.
Deeper data analysis
Someone was always discussing how to dive deeper into mobile threats, mobile spyware, Advanced Persistent Threats (APTs) and offensive attackers at Jamf's booth throughout the conference.
They all wanted to know this: how can defenders ensure the integrity of the mobile devices in their fleets by gaining deeper data analysis?
These threats — where they happen, to whom they happen, and how they happen — require threat intelligence and automated analysis capabilities that remove the heavy lifting for security teams. Traditional mobile forensics can take weeks to perform, and the teams charged with protecting those devices want better, faster ways to inspect and act on threats. For SOC teams, threat hunters, and security analysts, enhancing digital forensic investigations (for example, remotely scanning a device for inspection) and enabling teams to speed up mitigation and remediation steps (such as using tools to automate and streamline research) is paramount.
The Jamf team diving into mobile APTs and spyware.
Working together to drive better security outcomes
Black Hat USA reinforced that individual tools no longer deliver complete security; the real magic is using platforms such as SentinelOne, NowSecure, Tines and Amplifier Security that integrate and work together as each does what they do best. Jamf and their partners proved this again and again at Jamf booth.
Each partner brought a different solution to today's security challenges, such as how to automate security on Mac or how to investigate mobile application risk in the enterprise. The common thread was integration: connected systems enable deeper visibility, stronger compliance and more effective response.
As the week wrapped up and vendors began dismantling booths, Black Hat USA had made its mark.
We are in a new era of cybersecurity, with new risks, new challenges, but also new opportunities. The best way to secure our systems is by working together so that defenders can stay ahead.
See firsthand how Jamf secures Apple.