- Published on
BlackHat USA 2026 (1–6 August) and DEF CON 33 (6–9 August) closed the hottest two weeks of the year for industrial security experts. Three presentations genuinely change the threat map for European MES: automated OPC UA break-in through poisoned certificates, AI model theft from edge Jetson servers via side-channel, and a supply-chain attack through the open-source Python ecosystem in SCADA environments. This article walks through each of the three vectors without marketing, plus a concrete list of changes to deploy within 30 days.