Nerdsense

Hacker Summer Camp 2026: This Time the Robots Are Invited

Greg Heffner July 22, 2026
Hacker Summer Camp 2026: This Time the Robots Are Invited

Last Year I Stood in Lines. This Year I'm Chasing Agents.

Last August I wrote about surviving my first DEF CON: the beach ball dodgeball of Line-Con, showing off my hand implant to strangers, failing to pull a Full Art Pokemon card at Toxic BBQ with a crew of Australians, and somehow meeting John Hammond, NetworkChuck, and Jack Rhysider in the same trip. The big technical takeaway then was quantum-safe crypto: get your house in order before the threat arrives.

One year later, the threat that arrived isn't quantum. It's AI, and it's coming in through the supply chain. Attackers are using AI to write phishing that actually reads well, to find vulnerabilities faster, and to automate the boring parts of an intrusion. Meanwhile the biggest breaches of the past year didn't kick down the front door; they walked in through a dependency, a build pipeline, or a trusted vendor. Offense just got cheaper, and defense has to answer. That's the story I'm going to Vegas to learn, and this time I'm bringing it back to the day job.

Why the AI Summit Is the Day I Circled First

Black Hat USA runs August 1 through 6 at Mandalay Bay, and this is my first time attending. The summit day is August 4, and the AI Summit is the one I circled first. The pitch is exactly my problem statement, in both directions: how do we defend the AI we're deploying, and how do we use AI to make detection, triage, and response faster when the other side is using it to scale attacks?

That second half matters most to me professionally. SOC work lives and dies on speed: time to detect, time to triage, time to close. If AI can eat the repetitive tier-one work, enrich alerts before a human ever sees them, and draft the response so an analyst is reviewing instead of writing, that's not a gimmick. That's hours back per shift. I want to hear from the people doing this at scale what actually worked, what fell over in production, and what they'd buy again.

Supply Chain Is the Thread I'm Pulling All Week

The topic I'm chasing hardest across both conferences is supply chain security. Compromised dependencies, poisoned build pipelines, malicious packages, and trusted-vendor breaches have quietly become the most reliable way into an organization. And AI raises the stakes on both ends: models and their training data are now part of the supply chain too, and AI coding tools are pulling in dependencies faster than humans are reviewing them.

My question list for talks and hallway conversations: how are teams actually verifying what they ship and what they consume, what's working in SBOM land beyond compliance checkbox theater, and how do you monitor the AI components in your stack the same way you'd monitor any other third-party risk?

Vendor Floor Mission: Separating AI SOC from AI Sticker

The Business Hall runs August 4 through 6 with hundreds of vendors, including a dedicated AI zone. Every booth this year will say AI on it somewhere. My job is to figure out which ones mean it. I'm going in specifically to hear about new releases, get real-world tips from the engineers working the booths, and come home with a short list worth evaluating instead of a bag of stickers.

Questions I'm bringing to every vendor conversation:

  • What did you ship this year, and what's actually new versus a rebrand of last year's feature?
  • Where exactly does the model sit in your pipeline, and what happens when it's wrong?
  • Can your AI triage explain itself, or is it a black box I'm supposed to trust?
  • How do you defend your own product against prompt injection and model manipulation?
  • How do you help me see into my supply chain, including the AI components in it?

The thing I keep reading about: prompt injection has grown up. Researchers now describe a full "promptware" kill chain: initial access through a poisoned input, privilege escalation through tool access, persistence, lateral movement, and actions on objectives. If you run AI agents anywhere in your stack, that chain is aimed at you.

DEF CON 34: Agency

After Black Hat wraps, DEF CON 34 runs August 6 through 9 at the Las Vegas Convention Center. This year's theme is "Agency," which is almost too on the nose for the year AI agents went mainstream. AI Village is my first stop; the research on adversarial attacks against agents and agentic systems lines up exactly with what I'm chasing at the AI Summit, just from the offense side of the table.

Beyond the villages, the plan is simple: go to events and talk shop. The best parts of last DEF CON weren't scheduled. They were conversations in lines, contests I wandered into, and strangers who turned into friends over trading cards and tin foil hats. This year I'm leaning into that on purpose, because the hallway conversation with another defender who already fought the problem you're about to have is worth more than most sessions.

The Homework I'm Bringing Back to Work

You don't need a badge to act on any of this. The list I'm assigning myself, and would suggest to any defender:

  • Map your supply chain exposure: dependencies, build pipelines, third-party vendors, and now the models and AI services in your stack.
  • Inventory where AI already touches your systems, including assistants and automations nobody thought of as attack surface.
  • Treat any AI agent with tool access like a privileged user: least privilege, logging, and review.
  • Pick one slow, repetitive SOC workflow and pilot AI on it. Measure time to triage before and after, and let the numbers make the case.
  • Assume phishing quality goes way up. Train for the well-written lure, not the typo-riddled one.

Final Thoughts

Last year's lesson was to prepare for quantum before quantum arrives. This year's lesson is to prepare for AI-driven attacks before they arrive, except they already have, and they're coming through the supply chain. So I'm going to the desert to meet the people building the defenses, ask a lot of questions, talk shop with as many like-minded folks as I can find, and stand in some world-class lines while I do it.

If you're going to be at Black Hat, the AI Summit, or DEF CON 34 this year, come say hi. I'm always up for talking SOC tooling, supply chain defense, watching the watchers, or whatever you're hacking on. Then it's straight home, because badges and briefings are great, but my kids start school the week I get back, and that's the one event I'm not missing. Full write-up when I return.

About Me

I served in the U.S. Army, specializing in Network Switching Systems and was attached to a Patriot Missile System Battalion. After my deployment and Honorable discharge, I went to college in Jacksonville, FL for Computer Science. I have two beautiful and very intelligent daughters. I have more than 20 years professional IT experience. This page is made to learn and have fun. If it's messed up, let me know. I'm still learning! :)

Weather Loop

Animated radar loop of Southeast US weather from NOAA