Hacker Summer Camp 2026: A Longitudinal Study of 2,295 Talks

BSidesLV, Black Hat and DEF CON are infotainment at its finest, and there's far too much of it. We researched 2,295 talks across 2025 and 2026 to find what moves the needle in the AI stack.

August 21st, 2026

DEF CON 33 ran 874 sessions across 61 tracks and villages, which is over 900 scheduled hours packed into four days. If you never slept, never waited in line, and never spoke to another human, you still could only catch a tenth of it all at best.

That's just one of three events that makes up Hacker Summer Camp (HSC). Black Hat and BSidesLV run the same week, in the same city, and add another 249 talks between them. So nobody really attends all of HSC. You attend a personal slice of it and then have FOMO after reading other people's takes about the rest on social media.

Semgrep sponsored all three events this year and the question on our mind was: how does anybody keep up with all of this? How do you find what mattered, when you could only be in one room at a time and more than half the program (54%) isn’t even recorded?

That question inspired this project. If you paid close attention in 2025, in hindsight, what trends would have made a substantive difference to your success the rest of the year, and could that insight help us predict what to look for from the 2026 show?

tl;dr

We researched the talks at all three events, in 2025 and again in 2026: 2,295 talks, plus 556 transcripts and 3.2 million words from the 2025 sessions that were captured. Annotating all of them against the same fixed taxonomy list both years is what makes the comparison interesting. The three events sit at different stages of an idea's life, so knowing what is important to you tells you where to look. Year over year, talks discussing AI/ML rose by ten percentage points across all three events.

Treating Hacker Summer Camp 2025 as a Corpus

The first instinct was brute force, it is fun to geek out about cybersecurity talks so why not collect them all? Create a spreadsheet of all the talks, divide them up among the team, and just watch all of them while adding ratings, themes, and other annotations? Could we score them based on engagement metrics and viewing factors to prioritize?

Snippet of spreadsheet showing HSC 2025 talk engagement scores

Some DEF CON 33 talk engagement scores for YouTube recordings

As this approach evolved, we started thinking about 2025 as a training set. Across the three events, 603 talk videos went up over the following year, totalling 352 hours — just about an hour a day for an entire year to view them. We looked at transcripts for 556 of those, which include over 3.2 million words to work with, and ran traditional deterministic Natural Language Processing (NLP) / Machine Learning (ML) text-analysis passes: word and phrase frequency, tool and technology extraction, demo detection, concepts and even sentiment analysis (VADER with NLTK).

BSidesLV filmed almost everything presented at the event, 121 of 124 recording-eligible talks (ie. excluding Skytalks), then dropped all of it at once in December, four months later. Black Hat filmed 101 of 110 Briefings. They are available to pass holders earlier, but it takes seven months for them to be open to the public on YouTube. With DEF CON, villages release at different cadences to media servers, with fastest at a 61-day median and 2/3rds of the program not being available later at all. One of our favorite talks from DEF CON 2025 was Inti De Ceukelaire’s Magical Hacks which was not made available as a recording.

Figure: Release dates on YouTube for talks from Hacker Summer Camp 2025

Figure: Release dates on YouTube for talks from Hacker Summer Camp 2025

Every talk on the schedule was checked against a fixed list of 27 topic categories, which is not dissimilar from the exercise a security researcher runs when reviewing scanner output of a code base and marking what's real or a false positive. The individual labels aren’t critical to understand, what’s relevant is the consistent tagging over every session in both years, so when a trend emerged we’re comparing apples to apples, not changing the definition.

Before looking ahead to the 2026 events, the training set was viewed as a prediction in light of all we’ve witnessed across the industry in the past year: supply chain worms, Mythos and Cyber Models, SAST+LLM, etc. The event schedules are published well before any slides are finished, so annotating them the same way told us what was coming this year while there was still time to catch the talk live. 

Which rooms should we be in for what our customers need to know? Which talks are some of our customers giving themselves? Which stories will we hear at our booth and meeting rooms and point to where the industry is going rather than where it's been?

These events are a big part of how we stay ahead in AI-assisted development and security, because the cheapest way to anticipate the problems security teams will hit six months from now is to start building now.

The Lifecycle of an Idea in Three Acts

Black Hat Briefings passes can be prohibitively expensive for some teams. At 30x the cost of a BSidesLV pass, any representatives sent from a company have different expectations on the ROI when back in the office. The career stage of the audience shapes the complexity of talks so a distinctive trend emerges.

DEF CON shows what people do with technology. At DEF CON, Semgrep sponsored AI Village, but applying AI to security problems has found its way into many villages. AI-assisted OSINT in Recon Village. AI bug hunting in Bug Bounty Village. AI-driven detection in Blue Team Village. AI AppSec tooling in AppSec Village. At DEF CON 33, 105 talks (11%) were listed having AI as a primary theme, often with an emphasis on experimentation.

BSidesLV shares the pragmatic spirit of DEF CON but puts structure to it for those who do it as a profession. The 2025 program had many talks that established vocabulary and threat models we all know today. MCP (Model Context Protocol) showed up as a new attack surface last year, with named attack patterns: tool squatting, line jumping, version drift. Speakers used "vibe coding" not as a productivity buzzword, but as a category of risk in 2025, which was a new framing at the time. One of the most insightful talks may have been on Agentic AI Malware (Candid Wuest, BSidesLV 2025), which described how AI was replacing the planning, not the hacker. We have seen an unprecedented wave of supply chain attacks like the NX compromise using malicious dependencies and AI tooling to target developer credentials.

Black Hat surfaces the problems that are most challenging for the industry. Last year, the field had split between AI as a target and AI as a tool. Some of the fear was felt from targeting AI-assisted development workflows with risks from prompt injection, agent hijacking, and ASCII smuggling. Conversely, the hype behind LLM as the silver bullet was building, using AI for vulnerability discovery, static analysis, and reverse engineering were all major themes last year. One researcher posited that a model that could generate a proof of concept might dramatically reduce false positives. Six months later, Mythos got attention by providing validation of that idea.

Few attend all three events and often group into Black Hat only, Black Hat + BSidesLV, BSidesLV + DEF CON, or DEF CON only depending on their learning- or commercial-intent given the price constraints.

Go to

If you need

Appeals to

2026 Pass Price Range

DEF CON

How do I start experimenting with something new next week?

Enthusiasts

$520 - 600

BSidesLV

What threat models and definitions are most useful for my job?

Professionals

$110

Black Hat

Which problems are hard to solve and worth paying for a solution?

Leadership

$2,495 – 3,399

A >10% Increase in AI Talks, Favoring Offense

To the surprise of nobody, talks with the AI/ML theme increased year over year after already establishing themselves as the leading topic in 2025. This isn’t a zero sum observation though since talks are not one-dimensional and can cover more than one concept. In addition to AI/ML security, vulnerability classes and attack vectors are also consistent themes on the rise in 2026. This suggested to us that AI is not a replacement of other security concepts but is rather a confound. Talks are about vulnerability classes AND the use of LLMs as a tool.

Trend in talks about AI in 2026

Trend in talks about AI in 2026

Each event has its own Call For Papers (CFP) committee, separate review process, culture, and audience, but still converges. The lower percentage of talks about AI at DEF CON is a programming decision, as is BSidesLV adding an AI track, but the overall trend pooled across all three events is a clear signal we’re still trying to understand how AI amplifies security and researchers are anxious to share what they’ve learned.

Using sentiment analysis to look for offensive and defensive terminology, there was a noticeable shift year over year. The increase in AI talks heavily favored offensive attacking. This could be a warning sign for enterprises to shore up their defensive posture for what comes next.

Total Talks

2025

2026

AI + offense

23

47

2.0×

AI + defense

19

17

0.89×

The events themselves also have a leaning along the offense-to-defense axis. BSidesLV is defense-leaning, DEF CON and Black Hat lean toward offense both in 2025 and 2026. Vendor-paid sponsored sessions are scored on sentiment hard toward defense (-0.433) which makes sense. Some vendors do this so that research demonstrates breaking things and then they can sell mitigation. Bucking the trend at Black Hat, our CTO Drew Dennison's talk "Using SAST + Mythos To Shift Right" presented a defense-first counterpoint: using a project code named Mandoline as part of a program analysis toolkit to make agents more effective for defense.

Image of Semgrep CTO Drew Dennison presenting at Black Hat

Semgrep CTO Drew Dennison presenting at Black Hat 2026

Talks about security tools increased at BSidesLV, while decreasing significantly at DEF CON between 2025 and 2026. This showed up in our own plans. Semgrep’s Dr. Katie Paxton-Fear and Milan Williams had a session, "Overcoming the Fear of Security Risk with AI-Assisted Development," looking at the practical side of defense: how teams give developers tools like Cursor, Codex, Claude Code, and Replit without losing organizational visibility into what those agents are doing to their codebase.

Identity and endpoint platforms increased in talks at Black Hat this year while data privacy and IoT/Hardware security talks were down across all three event programs.

Precision Over Recall

Anyone who has pointed a code scanner at a real repository knows why static analysis has the reputation it does. With some tools, you get four hundred findings back and somebody has to work out which ones are real. Many aren't. That triage effort is why "we bought a scanner and then quietly stopped looking at it" is common and why developers distrust security tooling out of hand even though some platforms solve this much better today.

At BSidesLV, Mackenzie Jackson gave an honest take about using LLMs to hunt malicious packages in open source supply chains. He tried pointing an LLM at the problem directly and it didn’t go well: “LLM didn't perform better, actually performed worse than traditional scanners. But then the problem is that the traditional scanners generate huge amounts of false positives for us to look through and we didn't have enough resources to look at it." The solution described was conventional open source scanners run first and produce a flood of findings, then an LLM ingests that output and rates how likely each hit is to be real malware. Only high-confidence ones reach a human which helps focus attention and effort on what counts.

That complaint turns out to be the thing the AI-and-code-security conversation has organised itself around. "False positives" shows up in 64 of the 556 talks (11.5%) with 169 mentions. The raw frequency is not substantial (it ranks 31st at Black Hat but not in the top 100 at BSides or DEF CON). Supply chain appears in more talks. 

What makes this trend interesting is that three separate organizations built entire talks around it suggesting a common problem. 

A startup. AI Agents for Offsec with Zero False Positives — Brendan Dolan-Gavitt. He opened with "there is a spectre haunting AI offensive security, and that spectre is the spectre of false positives," citing curl maintainer Daniel Stenberg drowning in AI-generated fake vulnerability reports. His answer wasn't a better model. It was validation: don't trust what the model claims, make it produce a URL that actually pops an alert() in a headless browser.

A platform vendor's internal lab. More Flows, More Bugs: Empowering SAST with LLMs and Customized DFA — Yuan Luo, Zhaojun Chen, Yi Sun and Rhettxie, all of Tencent Security YunDing Lab. They went after false negatives caused by incomplete source and sink rules, using LLMs to discover sources and sinks instead of hand-writing them. Semgrep talked about this at BSidesSF and RSA, so it is re-affirming to see that others are rallying behind this approach as well.

A university group. Let LLM Learn: When Your Static Analyzer Actually 'Gets It' — Zong Cao and colleagues at Nanyang Technological University and Imperial Global Singapore. They supplied a taxonomy in their talk that is worth considering for best of breed solutions.

  • AI-enhanced: the scanner runs, an LLM filters the results.

  • AI-explorer: LLM drives, the scanner verifies

  • AI-native: the LLM is the scanner

A startup, a vendor lab and a university have very different incentives from their talks but converged on similar ideas. At DEF CON the same problem of preventing false positives surfaces frequently in the talks in Bug Bounty and AppSec villages. Semgrep's own Katie Paxton-Fear and Max vonBlankenburg tackled the bug bounty side of this problem at DEF CON in "Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty." Cris Thomas (aka, Space Rogue) and Pablo Estrada looked at the other end of the same gap in "AI Writes Code. Who Reviews It?"

Semgrep's booth at Black Hat 2026

Semgrep's booth at Black Hat 2026

When across the industry we start discussing precision instead of recall, it is not novel research and becomes security engineering. This lines up with what we’ve been building toward at Semgrep: AI reasoning combined with rule-based analysis. The question these all converge on is pairing a verifier you can trust (such as Semgrep) when evaluating AI-assisted AppSec tooling. Triage and remediation, not detection alone is the impactful work.

Not to Sound Skeptical, But You Can’t Judge a Talk by Its CFP

Is the tone of a talk hyped up for AI or skeptical? Given cynicism is common in the security industry we wanted to test this question.

For the 2026 talks, our results must be anecdotal. With only talk titles, abstracts and a week in the desert to see some talks in person to draw upon there are limits, but for 2025 we have full transcripts of many sessions.

To try and isolate a sub-set, Black Hat sells sponsored sessions along with peer-reviewed briefings. In theory, vendor-paid content should skew to hype. That hypothesis was inconsistent between 2025 and 2026 though, AI marketing content from foundation labs can be very sensational to spur folks to action so the noise from this assessment didn’t provide much insight. This makes sense too because a CFP abstract is a pitch. Any hedging, qualification, promotional cues, or self-doubt are hidden when it comes to the talk abstracts but harder to hide once on stage with a microphone. The titles themselves are typically a clever pun, limiting what conclusions can be drawn.

When looking across the 556 talk transcripts however, the average mean stance was skeptical at all three events. The delivered talks reported the truth masked behind the abstract on what really did or did not work. 

Two talks from 2025 that scored very highly on skeptical terminology were:

Has the tune changed since last year? Roughly one in twenty speakers (5.4%) will appear more than once at Hacker Summer Camp. In 2026, 80 out of 1,480 speakers had encore performances. Semgrep Security Researcher Diptendu Kar is an example of this, he gave a talk at both BSidesLV and DEF CON discussing Cryptography Supply Chain issues that aren’t a problem with the cryptography itself but the code wrapping it. Similarly, Semgrep’s Dr. Katie Paxton-Fear had multiple talks at DEF CON both in 2025 and 2026.

Semgrep Security Researcher Diptendu Kar discussing Cryptography Supply Chain issues

Semgrep Security Researcher Diptendu Kar presenting on Cryptography Supply Chain issues at HSC 2026

There were six speakers who managed the hat trick, sharing their knowledge at all three events in this timespan: 

Speaker

BSidesLV

Black Hat USA

DEFCON

Fred Heiding

ScamBench: Measuring Real-World Risk of AI-Generated Social Engineering

The Good, the Bad, and the Ugly of AI Security

A Framework for Evaluating Ai-Enabled Social Engineering

HD “hdm” Moore

Mind the Gap: Bridges, Backplanes, and BloodHound

Lights Out: BMCs Are Still Broken and Now We Have the Receipts

Lights Out: Out-of-Band, Out of Mind, Out of Control

Christian Dameff

No Water: No Hospitals: Continuity of Care Under Crisis

(2025 co-presentation) Pwning User Phishing Training Through Scientific Lure Crafting

Morbidity and Mortality: Hackers, HIPAA, and a new Prescription for Healthcare Cyber Policy

Ariana Mirian

Victim as a Service: Engaging with Trust Based Scams Using AI

(2025 co-presentation) Pwning User Phishing Training Through Scientific Lure Crafting

Victim as a Service: Engaging with Trust-Based Scams Using AI

Matthew Canham

Putting the CAT in the HAT: Exploring Cognitive Threats in the Context of Human Autonomy Teams

(2025) Evil Digital Twin, Too: The First 30 Months of Psychological Manipulation of Humans by AI

(2025) Using Evil Human Digital Twins for Fun and Profit

Olivier Bilodeau

S.L. Confidential: The Dirty Secrets of InfoStealers

(2025) Hackers Dropping Mid-Heist Selfies: LLM Identifies Information Stealer Infection Vector and Extracts IoCs

(2025) ackers Dropping Mid-Heist Selfies: LLM Identifies Information Stealer Infection Vector and Extracts IoCs

Black Hat and BSidesLV have a tendency to encourage speakers with fresh new ideas, but 29 speakers returned in 2026 (12.2%) and 37 speakers at BSidesLV (17.1%).

Catching Up After Hacker Summer Camp

One of the best parts of an event is the experiential parts and conversations that require follow-ups after the event. One gray beard said that he attends every year and it's worth every penny because one conversation will save him 10x the cost of attending by arriving at a solution faster. It truly is the friends we make along the way.

If you are working on security engineering automation projects right now, contact us to chat. Share with us your use cases, your problems where tooling gets it wrong, and we’ll share what we’ve learned and know about how to achieve code security for builders and agents.

At Black Hat, the badge gets you seven months of lead time. At BSidesLV, four and a half months. At DEF CON, the badge buys you access to the two thirds of the content that never gets filmed. Some of the best and brightest minds in cybersecurity were on-site and many of those talks will be available soon. A few of the BlackHat 2026 keynotes have dropped early including a keynote session from Michael Dalton and Eric Wallace of OpenAI sharing their forensic investigation of the OpenAI-HuggingFace Incident that rocked the industry by escaping its container a few weeks ago. 

Until the rest are available, review some of our favorite talks from 2025 that you may have missed.

Playlist A: Learning Path for AI Meets Application Security

For the novice: Mental models to anticipate the next stages. Mental Models to Anticipate the Next Stages of the AI and Cybersecurity Revolution with Sounil Yu. Describes frameworks for reasoning about where AI capability goes next and vocabulary for scaffolding other knowledge. (BSidesLV)

For the beginner: Conceptual framing of AI’s effect on offense and defense. Thinking Like a Hacker in the Age of AI with Richard Thieme. A popular talk describes the “meta-system” that the hacker mindset is the right tool for navigating AI as a whole. (DEF CON)

For the competent: Assuming some basics are understood. Agentic AI Malware: Why the Cybersecurity Battle Isn't Over with Candid Wuest. This malware talk discusses a PowerShell agent built to generate and execute code with metamorphic obfuscation and telemetry. (BSidesLV)

For the proficient: A grounding in API and agent architecture is a pre-requisite. From Prompts to Pwns: Exploiting and Securing AI Agents with Rich Harang and Rebecca Lynch. Early RAG systems had rigid workflows but modern agentic systems can be attacker-reachable if not cleanly handled. (Black Hat)

For the expert: Apply AI with an understanding of static analysis and dataflows. More Flows, More Bugs: Empowering SAST with LLMs and Customized DFA with Yuan Luo, Zhaojun Chen, et al. This talk analyzed 100+ real vulnerabilities for incomplete source and sink coverage. (Black Hat)

Playlist B: Some of Our Favorite Talks

"AI Agents for Offsec with Zero False Positives" with Brendan Dolan-Gavitt. The clearest articulation of verification of LLM security for benchmarking and analysis. (Black Hat)

"HTTP/1.1 Must Die" with James Kettle. Demonstrates a new technique after years of research across a wide range of live findings. A research talk had a lot of engagement. (Black Hat)

Invitation is All You Need” with Ben Nassi et al. Google already shipped a mitigation for this one which tells you something about how serious this indirect prompt injection technique was in escalating to physical world action. (Black Hat)

Agentic AI Malware” with Candid Wuest. A dose of sanity in a world of hype when it comes to AI malware headlines. (BSidesLV)

My Friend Ben: Solid Employee, DPRK Agent” with Chris Merkel. For fans of the Cuckoo’s Egg, a detection and forensics story. (BSidesLV)

‘Secure AI’ is 20 Years Old” with Sven Cattell. This one isn’t on YouTube but is on the DEF CON media server. (DEF CON AI Village)