Summer of Semgrep: Everywhere You'll Find Us at Hacker Summer Camp 2026

Here's the full Semgrep lineup for Black Hat, BSidesLV, and DEF CON 2026: talks, booth sessions, and an exclusive sticker set worth fighting over.

July 22nd, 2026

Hacker Summer Camp means Black Hat, BSidesLV, and DEF CON, back to back, in one wild week in Vegas. This year, Semgrep is showing up everywhere: people on stage at all three conferences, a booth in the Black Hat Business Hall, and a few sessions worth putting on your calendar if AI-assisted development, LLM-based vuln detection, or crypto failures are your thing. Here's the full rundown, and why you'll want to come find us.

On the Schedule at Hacker Summer Camp

Semgrep at a Glance

Date

Time

Location

Speaker(s)

Talk

Aug 4

10 AM

BSides Las Vegas

Proving Ground

Diptendu Kar

Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures

Aug 4

5:30 PM

Black Hat Business Hall

Booth 4943

Drew Dennison

Leif Dreizler

Katie Paxton-Fear

Cathy Polinsky

Fireside Screensaver Chat: Agentically Engineered the Future of AppSec

Aug 5

1:30 PM

Black Hat Business Hall

Booth 4943

Katie Paxton-Fear Milan Williams

Overcoming the Fear of Security Risk with AI-Assisted Development

Aug 6

9:30 AM

Black Hat Business Hall

Booth 4943

Cris Thomas (Space Rogue)

Pablo Estrada

AI Writes Code. Who Reviews It?

Aug 6

3:15 PM

Black Hat Business Hall

Pulse Stage 4

Drew Dennison

Using SAST + Mythos To Shift Right

Aug 7

4:30 PM

DEF CON Crypto & Privacy Village

Stage 2

Diptendu Kar

Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures

Aug 8

2:30 PM

DEF CON Bug Bounty Village

Stage 6

Katie Paxton-Fear

Max vonBlankenburg

Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty

Aug 8

3:15 PM

DEF CON IoT Village

Stage 3

Katie Paxton-Fear

Beyond Your Bookshelf: Hackable eReaders

Using SAST + Mythos To Shift Right

Drew Dennison: Paranoid Optimist, Co-founder and CTO of Semgrep, building tools to secure code since 2014.

Black Hat Business Hall, Pulse Stage 4 | Thursday, August 6, 3:15 PM

LLMs are moving the security control point from CI/CD to deep hunts for novel vulnerabilities. Drew's talk covers how combining SAST, LLMs, tooling, and data can surface bugs at scale that have been sitting in codebases for years. If you're skeptical that "SAST + LLMs" is more than a buzzword pairing, this is the talk built to change your mind. 

Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty

Katie Paxton-Fear: Security Advocate at Semgrep, API hacker, and host of the InsiderPhD YouTube channel, where she teaches bug bounty hunting to about 100,000 subscribers.

Max vonBlankenburg: Security Researcher at Semgrep, focused on security detection on all fronts and Capture the Flag Lead at Pacific Hackers Association.

DEF CON, Bug Bounty Village, Stage 6 | Saturday, August 8, 2:30 PM

After curl shut down its HackerOne program in January 2026 under a wave of AI-generated reports — some weeks saw seven reports in sixteen hours, none valid — Dr. Katie and Max are introducing Slop Spotting: a lightweight triage method that uses SAST rule generation as a validity signal. The core idea: if a vulnerability is real and well-specified, you should be able to write a SAST rule for it and get a result. If it's slop, even convincing slop, you get a fast no. Anyone who's watched a maintainer drown in obviously-fake reports will recognize the problem immediately.

Beyond Your Bookshelf: Hackable eReaders

Katie Paxton-Fear

DEF CON, IoT Village, Stage 3 | Sat, August 8, 3:15 PM 

Kindles, Kobos, Boox, BigMe — eReaders look like the most boring IoT device you own, until you look underneath the eInk display. Dr. Katie digs into the quirks of hacking these devices, from jailbreaking a locked-down Kindle to the xTeink's open-source Crosspoint firmware. Bring your own eReader. She might jailbreak it for you on the spot.

Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures

Diptendu Kar: Security Researcher at Semgrep, previous part-time faculty at Northeastern.

BSides Las Vegas, Proving Ground | Tuesday, August 4, 10 AM

DEF CON, Crypto & Privacy Village, Stage 2 | Friday, August 7, 4:30 PM

Cryptographic failures rarely come from bad math. They come from a skipped validation check, unvalidated input, or the wrong algorithm picked under deadline pressure. Diptendu is giving this talk twice: once at BSidesLV and again at DEF CON's Crypto & Privacy Village, using GitHub Security Advisories data (collected as of January 2026) to walk through the OWASP Cryptographic Failures category. Expect real vulnerable open-source libraries, signature verification bypasses, algorithm confusion bugs, and live demos with CTF-style challenges built in. No cryptography background required to enjoy this talk.

What You’ll Find at the Semgrep Booth (#4943)

Fireside Screensaver Chat: Agentically Engineered the Future of AppSec

Panelists:

  • Leif Dreizler: AppSec Engineer at Semgrep. Previously helped build and launch Semgrep Secrets; former Engineering Manager at Twilio Segment.

  • Cathy Polinsky: Co-CTO and VP of Engineering at Semgrep, with 20+ years of engineering leadership at Yahoo!, Salesforce, Stitch Fix, and Shopify.

  • Drew Dennison

Moderated by Katie Paxton-Fear

Business Hall, Welcome Reception | Tuesday, August 4, 5:30 PM

Kicking off the week with a fireside-style conversation on what it actually looks like when AppSec, CTOs, and software teams try to agentically engineer their way into the future. Grab a drink at the Welcome Reception first. This one's meant to feel like a conversation, not a keynote.

Overcoming the Fear of Security Risk with AI-Assisted Development

Milan Williams: Senior Product Manager at Semgrep, currently overseeing Semgrep Guardian.  

Katie Paxton-Fear

Business Hall | Wednesday, August 5, 1:30 PM

70% of engineering leaders list AI adoption as their #1 goal for increasing velocity. 59% of those same leaders say security threats and data control are what's stopping them. Katie and Milan get into how to bring tools like Cursor, Codex, Claude Code, and Replit onto your dev teams without losing the plot on security. Bring your AI IDE questions. Between the two of them, they've probably heard your exact one already.

AI Writes Code. Who Reviews It?

Cris Thomas (Space Rogue): Security Advocate at Semgrep, founding member of the legendary hacker collective L0pht, and author of Space Rogue: How the Hackers Known as L0pht Changed the World.

Pablo Estrada: Head of Product Marketing at Semgrep and one of our most tenured employees. Electrical engineer turned security enthusiast. 

Business Hall | Thursday, August 6, 9:30 AM

AI writes code fast but security review still moves at human speed. Space Rogue and Pablo get into what it takes to close that gap without turning review into a rubber stamp. If your team's already shipping AI-generated code faster than anyone can keep up with, come compare notes.

Also at our Black Hat Booth: Partner & Customer Sessions

We're sharing the mic. Visit our booth for quick hits from our partners and customers:

Wednesday, August 5

  • 10:45 AM — Preethi Kumaresan, Sr. Architect, AWS: Zero-Trust AppSec: A Hands-On Semgrep + AWS Platform Tour

  • 2:15 PM — Mark Lambert, Chief Product Officer, ArmorCode: From Detection to Decision: How Semgrep and ArmorCode Close the Loop at Machine Speed

  • 4:45 PM — Gianluca Brindisi, Sr. Security Engineer, Synthesia; Preethi Kumaresan, Sr. Architect, AWS; Milan Williams, Sr. Product Manager, Semgrep: Fireside Chat - How Synthesia Automates AI Code Security Reviews: Built on AWS, Secured by Semgrep

Thursday, August 6

  • 10:45 AM — Eric Carter, Director of Product Marketing, Sysdig: Sysdig + Semgrep: From 10,000 Findings to the 10 That Matter 

  • 2:00 PM — Neil Johnson, VP of Security, International Copyright Enterprise Services: Customer Talk

Come Find Us

That's Semgrep's Hacker Summer Camp, top to bottom. But honestly, the best part of Hacker Summer Camp has never been the schedule. It's the conversations that happen in between. Request a meeting in advance or just come find us in person, we'd love to meet you IRL:

  • See a live look at Semgrep in action and snag some limited edition swag at our booth.

  • Join Semgrep, ArmorCode, AWS, and Sysdig for a fun night of gaming (no pitches!) at It's All Fun and Games, Thursday, August 6, 7-10 PM. Spots are limited. RSVP Required.  

  • Grab a booster pack of our “Semgrep Threat Dex” stickers at the booth, celebrating(?) the last 12 months in cyber security. From the Shai-Hulud supply chain attacks, to the briefly-banned Mythos, and the OWASP Top 10 2025, there are 22 to collect or (avoid?). 

  • Visit the AWS booth (#1648) Thursday, August 6, 3:30 PM to see a demo presented by Milan Williams: Using Chat Agents Securely Without Losing Company IP. 

Need help with the rest of the week? Space Rogue covered how to survive it, and Dr. Katie covered what to do if it’s your first time

But for now: hydrate, pack smart, and start banking your sleep hours now. See you in Vegas!