Last August I wrote about surviving my first DEF CON: the beach ball dodgeball of Line-Con, showing off my hand implant to strangers, failing to pull a Full Art Pokemon card at Toxic BBQ with a crew of Australians, and somehow meeting John Hammond, NetworkChuck, and Jack Rhysider in the same trip. The big technical takeaway then was quantum-safe crypto: get your house in order before the threat arrives.
One year later, the threat that arrived isn't quantum. It's AI, and it's coming in through the supply chain. Attackers are using AI to write phishing that actually reads well, to find vulnerabilities faster, and to automate the boring parts of an intrusion. Meanwhile the biggest breaches of the past year didn't kick down the front door; they walked in through a dependency, a build pipeline, or a trusted vendor. Offense just got cheaper, and defense has to answer. That's the story I'm going to Vegas to learn, and this time I'm bringing it back to the day job.
Black Hat USA runs August 1 through 6 at Mandalay Bay, and this is my first time attending. The summit day is August 4, and the AI Summit is the one I circled first. The pitch is exactly my problem statement, in both directions: how do we defend the AI we're deploying, and how do we use AI to make detection, triage, and response faster when the other side is using it to scale attacks?
That second half matters most to me professionally. SOC work lives and dies on speed: time to detect, time to triage, time to close. If AI can eat the repetitive tier-one work, enrich alerts before a human ever sees them, and draft the response so an analyst is reviewing instead of writing, that's not a gimmick. That's hours back per shift. I want to hear from the people doing this at scale what actually worked, what fell over in production, and what they'd buy again.
The topic I'm chasing hardest across both conferences is supply chain security. Compromised dependencies, poisoned build pipelines, malicious packages, and trusted-vendor breaches have quietly become the most reliable way into an organization. And AI raises the stakes on both ends: models and their training data are now part of the supply chain too, and AI coding tools are pulling in dependencies faster than humans are reviewing them.
My question list for talks and hallway conversations: how are teams actually verifying what they ship and what they consume, what's working in SBOM land beyond compliance checkbox theater, and how do you monitor the AI components in your stack the same way you'd monitor any other third-party risk?
The Business Hall runs August 4 through 6 with hundreds of vendors, including a dedicated AI zone. Every booth this year will say AI on it somewhere. My job is to figure out which ones mean it. I'm going in specifically to hear about new releases, get real-world tips from the engineers working the booths, and come home with a short list worth evaluating instead of a bag of stickers.
Questions I'm bringing to every vendor conversation:
The thing I keep reading about: prompt injection has grown up. Researchers now describe a full "promptware" kill chain: initial access through a poisoned input, privilege escalation through tool access, persistence, lateral movement, and actions on objectives. If you run AI agents anywhere in your stack, that chain is aimed at you.
After Black Hat wraps, DEF CON 34 runs August 6 through 9 at the Las Vegas Convention Center. This year's theme is "Agency," which is almost too on the nose for the year AI agents went mainstream. AI Village is my first stop; the research on adversarial attacks against agents and agentic systems lines up exactly with what I'm chasing at the AI Summit, just from the offense side of the table.
Beyond the villages, the plan is simple: go to events and talk shop. The best parts of last DEF CON weren't scheduled. They were conversations in lines, contests I wandered into, and strangers who turned into friends over trading cards and tin foil hats. This year I'm leaning into that on purpose, because the hallway conversation with another defender who already fought the problem you're about to have is worth more than most sessions.
You don't need a badge to act on any of this. The list I'm assigning myself, and would suggest to any defender:
Last year's lesson was to prepare for quantum before quantum arrives. This year's lesson is to prepare for AI-driven attacks before they arrive, except they already have, and they're coming through the supply chain. So I'm going to the desert to meet the people building the defenses, ask a lot of questions, talk shop with as many like-minded folks as I can find, and stand in some world-class lines while I do it.
If you're going to be at Black Hat, the AI Summit, or DEF CON 34 this year, come say hi. I'm always up for talking SOC tooling, supply chain defense, watching the watchers, or whatever you're hacking on. Then it's straight home, because badges and briefings are great, but my kids start school the week I get back, and that's the one event I'm not missing. Full write-up when I return.
I served in the U.S. Army, specializing in Network Switching Systems and was attached to a Patriot Missile System Battalion. After my deployment and Honorable discharge, I went to college in Jacksonville, FL for Computer Science. I have two beautiful and very intelligent daughters. I have more than 20 years professional IT experience. This page is made to learn and have fun. If it's messed up, let me know. I'm still learning! :)