Hacker Summer Camp means Black Hat, BSidesLV, and DEF CON, back to back, in one wild week in Vegas. This year, Semgrep is showing up everywhere: people on stage at all three conferences, a booth in the Black Hat Business Hall, and a few sessions worth putting on your calendar if AI-assisted development, LLM-based vuln detection, or crypto failures are your thing. Here's the full rundown, and why you'll want to come find us.
On the Schedule at Hacker Summer Camp
Semgrep at a Glance
Date | Time | Location | Speaker(s) | Talk |
Aug 4 | 10 AM | BSides Las Vegas Proving Ground | Diptendu Kar | Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures |
Aug 4 | 5:30 PM | Black Hat Business Hall Booth 4943 | Drew Dennison Leif Dreizler Katie Paxton-Fear Cathy Polinsky | Fireside Screensaver Chat: Agentically Engineered the Future of AppSec |
Aug 5 | 1:30 PM | Black Hat Business Hall Booth 4943 | Katie Paxton-Fear Milan Williams | Overcoming the Fear of Security Risk with AI-Assisted Development |
Aug 6 | 9:30 AM | Black Hat Business Hall Booth 4943 | Cris Thomas (Space Rogue) Pablo Estrada | AI Writes Code. Who Reviews It? |
Aug 6 | 3:15 PM | Black Hat Business Hall Pulse Stage 4 | Drew Dennison | Using SAST + Mythos To Shift Right |
Aug 7 | 4:30 PM | DEF CON Crypto & Privacy Village Stage 2 | Diptendu Kar | Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures |
Aug 8 | 2:30 PM | DEF CON Bug Bounty Village Stage 6 | Katie Paxton-Fear Max vonBlankenburg | Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty |
Aug 8 | 3:15 PM | DEF CON IoT Village Stage 3 | Katie Paxton-Fear | Beyond Your Bookshelf: Hackable eReaders |
Using SAST + Mythos To Shift Right
Drew Dennison: Paranoid Optimist, Co-founder and CTO of Semgrep, building tools to secure code since 2014.
Black Hat Business Hall, Pulse Stage 4 | Thursday, August 6, 3:15 PM
LLMs are moving the security control point from CI/CD to deep hunts for novel vulnerabilities. Drew's talk covers how combining SAST, LLMs, tooling, and data can surface bugs at scale that have been sitting in codebases for years. If you're skeptical that "SAST + LLMs" is more than a buzzword pairing, this is the talk built to change your mind.
Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty
Katie Paxton-Fear: Security Advocate at Semgrep, API hacker, and host of the InsiderPhD YouTube channel, where she teaches bug bounty hunting to about 100,000 subscribers.
Max vonBlankenburg: Security Researcher at Semgrep, focused on security detection on all fronts and Capture the Flag Lead at Pacific Hackers Association.
DEF CON, Bug Bounty Village, Stage 6 | Saturday, August 8, 2:30 PM
After curl shut down its HackerOne program in January 2026 under a wave of AI-generated reports — some weeks saw seven reports in sixteen hours, none valid — Dr. Katie and Max are introducing Slop Spotting: a lightweight triage method that uses SAST rule generation as a validity signal. The core idea: if a vulnerability is real and well-specified, you should be able to write a SAST rule for it and get a result. If it's slop, even convincing slop, you get a fast no. Anyone who's watched a maintainer drown in obviously-fake reports will recognize the problem immediately.
Beyond Your Bookshelf: Hackable eReaders
Katie Paxton-Fear
DEF CON, IoT Village, Stage 3 | Sat, August 8, 3:15 PM
Kindles, Kobos, Boox, BigMe — eReaders look like the most boring IoT device you own, until you look underneath the eInk display. Dr. Katie digs into the quirks of hacking these devices, from jailbreaking a locked-down Kindle to the xTeink's open-source Crosspoint firmware. Bring your own eReader. She might jailbreak it for you on the spot.
Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures
Diptendu Kar: Security Researcher at Semgrep, previous part-time faculty at Northeastern.
BSides Las Vegas, Proving Ground | Tuesday, August 4, 10 AM
DEF CON, Crypto & Privacy Village, Stage 2 | Friday, August 7, 4:30 PM
Cryptographic failures rarely come from bad math. They come from a skipped validation check, unvalidated input, or the wrong algorithm picked under deadline pressure. Diptendu is giving this talk twice: once at BSidesLV and again at DEF CON's Crypto & Privacy Village, using GitHub Security Advisories data (collected as of January 2026) to walk through the OWASP Cryptographic Failures category. Expect real vulnerable open-source libraries, signature verification bypasses, algorithm confusion bugs, and live demos with CTF-style challenges built in. No cryptography background required to enjoy this talk.
What You’ll Find at the Semgrep Booth (#4943)
Fireside Screensaver Chat: Agentically Engineered the Future of AppSec
Panelists:
Leif Dreizler: AppSec Engineer at Semgrep. Previously helped build and launch Semgrep Secrets; former Engineering Manager at Twilio Segment.
Cathy Polinsky: Co-CTO and VP of Engineering at Semgrep, with 20+ years of engineering leadership at Yahoo!, Salesforce, Stitch Fix, and Shopify.
Drew Dennison
Moderated by Katie Paxton-Fear
Business Hall, Welcome Reception | Tuesday, August 4, 5:30 PM
Kicking off the week with a fireside-style conversation on what it actually looks like when AppSec, CTOs, and software teams try to agentically engineer their way into the future. Grab a drink at the Welcome Reception first. This one's meant to feel like a conversation, not a keynote.
Overcoming the Fear of Security Risk with AI-Assisted Development
Milan Williams: Senior Product Manager at Semgrep, currently overseeing Semgrep Guardian.
Katie Paxton-Fear
Business Hall | Wednesday, August 5, 1:30 PM
70% of engineering leaders list AI adoption as their #1 goal for increasing velocity. 59% of those same leaders say security threats and data control are what's stopping them. Katie and Milan get into how to bring tools like Cursor, Codex, Claude Code, and Replit onto your dev teams without losing the plot on security. Bring your AI IDE questions. Between the two of them, they've probably heard your exact one already.
AI Writes Code. Who Reviews It?
Cris Thomas (Space Rogue): Security Advocate at Semgrep, founding member of the legendary hacker collective L0pht, and author of Space Rogue: How the Hackers Known as L0pht Changed the World.
Pablo Estrada: Head of Product Marketing at Semgrep and one of our most tenured employees. Electrical engineer turned security enthusiast.
Business Hall | Thursday, August 6, 9:30 AM
AI writes code fast but security review still moves at human speed. Space Rogue and Pablo get into what it takes to close that gap without turning review into a rubber stamp. If your team's already shipping AI-generated code faster than anyone can keep up with, come compare notes.
Also at our Black Hat Booth: Partner & Customer Sessions
We're sharing the mic. Visit our booth for quick hits from our partners and customers:
Wednesday, August 5
10:45 AM — Preethi Kumaresan, Sr. Architect, AWS: Zero-Trust AppSec: A Hands-On Semgrep + AWS Platform Tour
2:15 PM — Mark Lambert, Chief Product Officer, ArmorCode: From Detection to Decision: How Semgrep and ArmorCode Close the Loop at Machine Speed
4:45 PM — Gianluca Brindisi, Sr. Security Engineer, Synthesia; Preethi Kumaresan, Sr. Architect, AWS; Milan Williams, Sr. Product Manager, Semgrep: Fireside Chat - How Synthesia Automates AI Code Security Reviews: Built on AWS, Secured by Semgrep
Thursday, August 6
10:45 AM — Eric Carter, Director of Product Marketing, Sysdig: Sysdig + Semgrep: From 10,000 Findings to the 10 That Matter
2:00 PM — Neil Johnson, VP of Security, International Copyright Enterprise Services: Customer Talk
Come Find Us
That's Semgrep's Hacker Summer Camp, top to bottom. But honestly, the best part of Hacker Summer Camp has never been the schedule. It's the conversations that happen in between. Request a meeting in advance or just come find us in person, we'd love to meet you IRL:
See a live look at Semgrep in action and snag some limited edition swag at our booth.
Join Semgrep, ArmorCode, AWS, and Sysdig for a fun night of gaming (no pitches!) at It's All Fun and Games, Thursday, August 6, 7-10 PM. Spots are limited. RSVP Required.
Grab a booster pack of our “Semgrep Threat Dex” stickers at the booth, celebrating(?) the last 12 months in cyber security. From the Shai-Hulud supply chain attacks, to the briefly-banned Mythos, and the OWASP Top 10 2025, there are 22 to collect or (avoid?).
Visit the AWS booth (#1648) Thursday, August 6, 3:30 PM to see a demo presented by Milan Williams: Using Chat Agents Securely Without Losing Company IP.
Need help with the rest of the week? Space Rogue covered how to survive it, and Dr. Katie covered what to do if it’s your first time.
But for now: hydrate, pack smart, and start banking your sleep hours now. See you in Vegas!