Hacker Summer Camp 2026

August 3-9, 2026

Code Security for Builders
Redefining AppSec for the AI Era

Semgrep is the leader in code security for builders.

AI has changed how code is written. Traditional SAST misses business logic. Pure AI tools can feel inconsistent and noisy.

We'll be at BSides LV, Black Hat (Booth #4943), and DEF CON this summer. Stop by to see the next generation of AppSec and get a first look at what we've been building since RSA.

BSides Las Vegas

location icon The Tuscany
time icon Aug 3, 2026 - Aug 5, 2026

"Using SAST + Mythos To Shift Right"

location icon Pulse Stage 2 | Black Hat Business Hall
time icon Aug 6, 2026

It's All Fun and Games Party

location icon Level Up | MGM Grand
time icon Aug 6, 2026

DEF CON 34

location icon LVCC West Hall
time icon Aug 6, 2026 - Aug 9, 2026
Schedule

Aug 3 | BSides Las Vegas

8:30am - 7:00pm • The Tuscany

Semgrep is heading to BSides Las Vegas to connect with builders and security leaders shaping the future of AppSec.

Stop by our table to learn more about our latest product launch to help developers reduce noise and ship secure code faster.

Aug 4 | BSides Las Vegas

8:30am - 7:00pm • The Tuscany

Semgrep is heading to BSides Las Vegas to connect with builders and security leaders shaping the future of AppSec.

Stop by our table to learn more about our latest product launch to help developers reduce noise and ship secure code faster.

Aug 4 | "Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures"

10:00 am - 10:30am • BSides LV, Proving Ground

Cryptographic failures rarely come from bad math. They come from a skipped validation check, unvalidated input, or the wrong algorithm picked under deadline pressure. Diptendu is giving this talk twice: once at BSidesLV and again at DEF CON's Crypto & Privacy Village, using GitHub Security Advisories data (collected as of January 2026) to walk through the OWASP Cryptographic Failures category. Expect real vulnerable open-source libraries, signature verification bypasses, algorithm confusion bugs, and live demos with CTF-style challenges built in. No cryptography background required to enjoy this talk.

Aug 4 | PBC Connect

11:00am - 3:00pm • Mandalay Bay

PBC Connect events bring together CISOs, AppSec, infrastructure security, product security, AI security, and cyber resilience leaders for high-value discussion, networking, and community-building.

This year's Black Hat gathering will focus on the future of AI security, vulnerability management, product security, and frontier AI risk, anchored by a featured fireside chat with Jason Clinton and Phil Venables on how security leaders should prepare for the risks from advanced AI capabilities.

Register here!

Aug 4 | Black Hat Welcome Reception

4:00pm - 7:00pm • Mandalay Bay Convention Center

Unwind while you network in The Business Hall before the first full day of Black Hat kicks off at the Welcome Reception. Meet fellow Attendees, Speakers, Exhibitors (check us out, booth #4943), and Staff over appetizers and refreshments.

Aug 4 | Fireside Screensaver Chat: "Agentically Engineered the Future of AppSec"

5:30pm - 5:45pm • Booth #4943, Mandalay Bay Convention Center

Kicking off the week with a fireside-style conversation on what it actually looks like when AppSec, CTOs, and software teams try to agentically engineer their way into the future. Grab a drink at the Welcome Reception first. This one's meant to feel like a conversation, not a keynote.

Aug 5 | BSides Las Vegas

8:30am - 2:00pm • The Tuscany

Semgrep is heading to BSides Las Vegas to connect with builders and security leaders shaping the future of AppSec.

Stop by our table to learn more about our latest product launch to help developers reduce noise and ship secure code faster.

Aug 5 | Black Hat Business Hall

9:00am - 6:00pm • Mandalay Bay Convention Center

Visit us in booth #4943 for custom live demos and to learn how Semgrep’s low-noise results and AI guidance across SAST, SCA, and Secrets can help you fix vulnerabilities early, speed up releases, and reduce risk.

Aug 5 | Partner Demo

10:45am - 11:00am • Booth #4943, Mandalay Bay Convention Center

AWS Partner Demo

Aug 5 | "Overcoming the Fear of Security Risk with AI-Assisted Development"

1:30pm - 1:45pm • Booth #4943, Mandalay Bay Convention Center

70% of engineering leaders list AI adoption as their #1 goal for increasing velocity. 59% of those same leaders say security threats and data control are what's stopping them. Katie and Milan get into how to bring tools like Cursor, Codex, Claude Code, and Replit onto your dev teams without losing the plot on security. Bring your AI IDE questions. Between the two of them, they've probably heard your exact one already.

Aug 5 | Partner Talk

2:15pm - 2:30pm • Booth #4943, Mandalay Bay Convention Center

"From Detection to Decision: How Semgrep and ArmorCode Close the Loop at Machine Speed"

Aug 5 | Partner Talk

4:45pm - 5:00pm • Booth #4943, Mandalay Bay Convention Center

Fireside Chat: "How Synthesia Automates AI Code Security Reviews: Built on AWS, Secured by Semgrep"

Aug 6 | Black Hat Business Hall

9:00am - 4:00pm • Mandalay Bay Convention Center

Visit us in booth #4943 for custom live demos and to learn how Semgrep’s low-noise results and AI guidance across SAST, SCA, and Secrets can help you fix vulnerabilities early, speed up releases, and reduce risk.

Aug 6 | "AI Writes Code. Who Reviews It?"

9:30am - 9:45am • Booth #4943, Mandalay Bay Convention Center

AI writes code fast but security review still moves at human speed. Space Rogue and Pablo get into what it takes to close that gap without turning review into a rubber stamp. If your team's already shipping AI-generated code faster than anyone can keep up with, come compare notes.

Aug 6 | Partner Talk

10:45am - 11:00am • Booth #4943, Mandalay Bay Convention Center

"Sysdig + Semgrep: From 10,000 Findings to the 10 That Matter"

Aug 6 | Partner Talk

2:00pm - 2:15pm • Booth #4943, Mandalay Bay Convention Center

International Copyright Equipment Services

Aug 6 | Sponsored Speaking Session

3:15pm - 3:35pm • Pulse Stage 2, Business Hall

Join Semgrep Co-Founder & CTO, Drew Dennison, as he breaks down "Using SAST + Mythos To Shift Right." Learn how using SAST + LLMs + tools + data to find bugs at scale.

Aug 6 | It's All Fun and Games

7:00pm - 10:00pm • Level Up, MGM Grand

Whether you’re coming from Black Hat sessions, hanging with the BSides crew, or gearing up for DEF CON madness, join us for a night of fun and games.

No pitches. No slide decks. Just a good food and good people.

Aug 7 | "Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures"

4:30pm - 5:00pm • DEF CON, Crypto & Privacy Village, Stage 2

Cryptographic failures rarely come from bad math. They come from a skipped validation check, unvalidated input, or the wrong algorithm picked under deadline pressure. Diptendu is giving this talk twice: once at BSidesLV and again at DEF CON's Crypto & Privacy Village, using GitHub Security Advisories data (collected as of January 2026) to walk through the OWASP Cryptographic Failures category. Expect real vulnerable open-source libraries, signature verification bypasses, algorithm confusion bugs, and live demos with CTF-style challenges built in. No cryptography background required to enjoy this talk.

Aug 8 | "Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty"

2:30pm - 3:00pm • DEF CON, Bug Bounty Village, Stage 6

After curl shut down its HackerOne program in January 2026 under a wave of AI-generated reports — some weeks saw seven reports in sixteen hours, none valid — Katie and Max are introducing Slop Spotting: a lightweight triage method that uses SAST rule generation as a validity signal. The core idea: if a vulnerability is real and well-specified, you should be able to write a SAST rule for it and get a result. If it's slop, even convincing slop, you get a fast no. Anyone who's watched a maintainer drown in obviously-fake reports will recognize the problem immediately.

Aug 8 | "Beyond Your Bookshelf: Hackable eReaders"

3:15pm - 3:45pm • DEF CON, IoT Village, Stage 3

Kindles, Kobos, Boox, BigMe — eReaders look like the most boring IoT device you own, until you look underneath the eInk display. Katie digs into the quirks of hacking these devices, from jailbreaking a locked-down Kindle to the xTeink's open-source Crosspoint firmware. Bring your own eReader. She might jailbreak it for you on the spot.

Request a meeting

Leading engineering organizations rely on Semgrep to embed security into the development workflow without sacrificing speed or scale.

Connect with us at BSides LV and Black Hat, attend a live demo, and join our community event.

Your privacy matters to us. By submitting this form, you agree to our Privacy Policy