Skip to content

Adventures at Hacker Summer Camp - 2026 Edition

I'm out in vegas this week, attending BSides Las Vegas and Black Hat (no DEF CON for me this year). I'll be documenting who I talk to on this post.

It's time for the annual adventure to Hacker Summer Camp. I'm only able to attend 2 of the 3 parts of Summer Camp (BSides Las Vegas and Black Hat - no DEF CON for me this year), so this will fell a bit incomplete. But I'll make the most of it.

8/3/2026: BSides Las Vegas

BSides Conferences are for the community, full stop. And BSides Las Vegas is one of the best of them. You get representation from all across the spectrum of info/cyber security. Straight up hacker types to CISOs to vendors to analysts. It's a wide umbrella at BSides, and it's a great place to see friends and meet new ones.

I talked to a few sponsors of the event while I was there. First out of the gate: Cognitive Security Institute. I asked Barry Suskind if he would do a quick video about their mission, and he delivered big time. Here are some key points, and then you can watch Barry describe it himself:

  • Incident responders and security professionals face rising stress due to increasing incident volume.
  • The volume and diversity of information overwhelms the brain.
  • They are teaching cybersecurity professionals how to secure and protect their minds.
0:00
/2:52

Checkmarx

Next, I talked to Zach Johnston at Checkmarx. I've always known Checkmarx as an application security company, and they still are. But in the "Age of AI", they are pivoting a bit to help secure code created by AI. Here's Zach:

0:00
/0:47

Flare

Next is Eric Boivin from Flare. Eric talks quickly about Flare's Cyber threat Intelligence (CTI) platform helps their customers discover exposed data, especially credentials like passwords and other sensitive information.

0:00
/0:54

White Knight Labs

Up next, White Knight Labs, who offers "customized penetration testing services to safeguard your business from cyber threats." I had to pull that description from LinkedIn, because John Stigerwalt talked more about why they support BSides Las Vegas. And I thought that was awesome. Always good to see a company more interested in talking about why they support the community than telling people what they do. Here's John' quick video.

0:00
/0:31

Sublime

Then I moved over to chat with Brian Baskin, threat researcher at Sublime, where they provide agentic email security tailored to your organization. They combine AI-driven threat detection with autonomous investigation and response. Their AI agents adapt detections to each organization's environment, helping stop sophisticated phishing attacks while reducing manual email triage.

Brian also focused more on why they are at BSides. Here he is.

0:00
/0:32

Nudge

For the final one, I talked to Nudge Security, which provides SaaS and AI security by discovering unmanaged applications, identities, and AI tools, then automating governance and risk remediation through policy-driven workflows and user guidance. The platform helps organizations control shadow IT, SaaS sprawl, and AI adoption while improving overall security posture.

Vince Lucier let us know why they support BSides and provided a quick overview of what they do (with a clever shout out of the reasoning behind their name). You'll hear me a little bit in the video because I needed to get a shot of the neon sign in their booth that was both awesome and blinding.

0:00
/0:45

8/4/2026: Black Hat Conference 2026

On to Black Hat! Today, I spoke with three cybersecurity companies. Of the three, only one of them could be called a pure vendor. I'll start with them since they were also the first company I spoke with.

Jazz Security

I had a great conversation with at Danielle Guetta, VP of Marketing, and Sagi Chen, Product Manager, at Jazz Security. Their tagline is clear: DLP Sucks. And I couldn't agree more. We talked about Jazz’s shift away from static rules and all those false positives toward contextual DLP that is focused on classifying data as it moves, tries to determine user intent, and doesn't make the CEO come after you with a knife because you blocked legitimate business activity.

The data-as-it-moves way of classifying data is very interesting, and the ease of use Danielle and Sagi noted from customer testimonials is powerful. Yes, DLP does suck. I've done a lot with DLP over the years, and I've never seen even a good implementation. But that is many times because classification and location of data was hard to build.

Then Jazz tells me you don't even need that. Jazz is pushing back on the old DLP model that says you have to discover and classify all your data at rest before you can protect it. Instead, it classifies data as it moves, which means it can also look at who moved it, where it was going, and what happened before and after. That can make a HUGE difference in the objection handling of why data security programs never get off the ground, or slow to halt after they launch.

Definitely worth your time to take a look if you're struggling in the data security area (and most companies are).

Here's Danielle and Sagi with their send off, staying true to their tagline!

0:00
/0:18

Suzu Labs

A lot of cybersecurity folks are veterans. Michael Bell, CEO of Suzu Labs is no exception to that, and he hires a bunch of veterans on his team. Being a veteran myself, that policy means a lot to me.

In addition to the military conversations, Mike and I talked about AI and it's role - both good and bad - in cybersecurity. But what I really loved was the conversation we had around how AI has affected cybersecurity consultancies (Suzu Labs is primarily a consultancy with a focus on AI advisory services, but they also develop their own products in the space). here are the main points:

  • Secure AI adoption is primarily an architecture and modernization problem: Organizations can deploy AI securely without buying a completely new security stack. Existing controls can provide the required guardrails, but older infrastructure (we talked about AS/400s!) can cause serious problems and should be addressed before deciding to deploy AI.
  • AI is changing the economics of consulting: Mike told me that Suzu Labs uses internal AI workflows and reusable automation to cut down on the manual work involved in research, documentation, analysis and delivery. That means clients can get more bang for their buck, while Suzu consultants can handle more engagements without simply adding more people.
  • The competitive advantage is accumulated knowledge, not one-off AI output: Mike argues that consultancies shouldn't use AI like a generic chatbot that starts from scratch on every engagement. The real value comes from capturing what you've learned from previous projects and feeding that knowledge back into repeatable AI workflows. Without that context and human oversight, you run the risk of AI-generated deliverables containing hallucinations, bad references or unsupported conclusions. Suzu Labs is using that approach to continually improve its internal workflows and bring lessons learned from one engagement into the next.

Great conversation all around. Here's Mike for a wrap up!

0:00
/0:16

Black Hills Information Security

This next conversation was a lot of fun. If you've never had a chance to sit down and talk with John Strand from Black Hills information Security, I highly recommend it. He's high energy, and he's a wealth of knowledge.

We talked about Black Hills, of course. As a high level business-focused description, Black Hills Information Security is a cybersecurity services company offering everything from penetration testing and incident response to defensive security, SOC and AI security services. But BHIS is also part of a larger group of companies built around giving back to the cybersecurity community through affordable training, free educational content, open-source tools and hands-on events like Wild West Hackin’ Fest. In short, their making a big difference.

As a company providing penetration testing services, the conversation went to AI-automated pentesting quickly. Let's get into the main points:

  • Security companies must adopt AI, but the current investment cycle is unlikely to last: Strand sees AI as mandatory for offensive-security firms: companies that fail to use it will be slower and less competitive. But he was also very clear that the model will have a ton of issues if third-party models are used primarily due to rising costs (can you say tokenmaxxing?). Essentially, if agentic/automated pentesting companies don't differentiate, their funding will dry up.
  • AI will commoditize automated penetration testing, making trust the real differentiator: Despite that potential future funding problem, Strand expects more, not less, of automated pentest companies to pop up in the near future. So who will we see start coming out on top? Strand says that customers will determine the winners based on the quality, judgment and credibility of the people interpreting the results—not the automation itself.
  • AI is strengthening both attackers and defenders—but offense currently has an advantage: While Strand believes there is something of an equilibrium in offensive and defensive AI, he believes offensive AI is advancing faster than defensive AI. That is primarily because offensive AI it can automate reconnaissance, vulnerability discovery and exploitation more readily than defenders can use AI to automate reliable protection.

Here's John giving an amusing send off.

0:00
/0:14

8/5/2026: Black Hat Conference 2026

Floor Time!

August 5 was the day I reserved for more floor time. Here's a video of Andy Ellis and me running around the floor a bit. Technically this was on the opening evening on on the 4th, but it pretty much shows what the 5th was like. Go read the story Bill Brenner wrote around Andy's big takeaways from the floor.

0:00
/0:53

8/6/2026: Black Hat Conference 2026

Black Hat NOC/SOC and Corelight

This was my last day in Vegas, and I had more interviews planned. But alas, CEO work called and I got held up on getting some admin work done. However, I did manage to interview James Pope at Corelight and have him run through a tour of the Black Hat NOC and SOC.

One point Pope made is that none of the companies in the NOC and SOC buy their way in. These are partnerships with Black Hat. Obviously it's good for these companies to be in the mix of providing infrastructure and security, the mix of companies (Corelight, Arista Networks, Cisco Systems, Lumen Technologies, jamf, and Palo Alto Networks) is impressive.

The stories James Pope told me about some of the issues they have found over the years on the Black Hat network should have been unsurprising. But it still raised my eyebrows when he told me about a compromises found on a major news outlet's journalist's machine (he didn't tell me which outlet), a large well-known corporation (he also didn't divulge which company), and others. These are firms that had no idea they had been hacked, and it took the information gathered from network traffic (obviously they can't put endpoints agents on attendee machines) to find out. Really wild stuff.

Here are some stats from their presentation at Black Hat:

  • 285.9 million threat detections were recorded while the network was live for roughly nine days. Removing informational events left 17.1 million detections with some severity, which the NOC ultimately narrowed to 323 blocked threats
  • Black Hat’s general Wi-Fi infrastructure transferred more than 33 terabytes of data across 66 switches and 156 access points. It recorded 22,500 unique clients beaconing, 11,751 connecting, and a peak of 3,000 concurrent connections
  • 14,451 different suspicious samples were submitted for sandbox analysis. Not all of those were confirmed to be malicious

Here's a quick video of the NOC to wrap up this part of the post. Thanks to the NOC/SOC team for doing the hard work of protecting the Black Hat infrastructure an attendees!

0:00
/0:19

Anomali

And finally, we end with Anomali. I was really excited for this final interview because I got to meet up with my good friend, Chris (CV) Vincent! CV and I go back to the old pre-Optiv Accuvant days (yes, we're old), so it was great to catch up. But once we got done with the hugs and the "how are things" talk, we got down to talking about serious matters.

I have worked with Anomali many times in the past as a threat intel platform (TIP) to help customers get their threat intelligence under control. But as I discussed what Anomali is with CV, and as I dug in with my own research, I've seen that TIP is really not a standalone product that CISOs are looking for these days. That's why our conversation focused on how threat intelligence can give AI the context it needs to make better security decisions, improve detections and safely automate more of the response.

The ThreatStream TIP is still there, but Anomali has broadened its capabilities to stay relevant in the agentic AI era. Today, I would describe Anomali as a security operations platform that brings security telemetry, threat intelligence and agentic AI together. It has always been difficult to operationalize threat intel into security operations, but Anomali is using AI to cut through some of the noise while making threat intelligence more operational. That results in giving analysts and AI agents better data to work with when detecting, investigating and responding to threats.

The three main points I took away from the conversation are:

  • Threat intelligence must become operational, not just informational: threat intelligence platforms and traditional SIEM products are losing relevance because they largely aggregate data and generate reports without directly improving security outcomes. The next generation of platforms must automatically normalize, deduplicate, enrich and correlate telemetry with threat intelligence—then use that context to accelerate decisions, improve detections or trigger defensive actions.
  • Threat intelligence is the missing context layer for security AI: AI agents, detection-engineering systems and automated threat-hunting tools are only as effective as the context they receive. High-fidelity intelligence can act as a guardrail, helping AI distinguish meaningful threats from benign activity and reducing the risk of unreliable autonomous decisions. Anomali sees intelligence—not storage, pipelines or generic AI capabilities—as the key differentiator that many competing platforms lack.
  • Security agents need a centralized, isolated data environment: Agents can analyze historical and real-time data in an isolated cybersecurity “data brain” or data plane environment without placing operational infrastructure at unnecessary risk. High-confidence findings can be automated, while lower-confidence activity can be escalated to analysts or existing SIEM workflows. The objective is to augment security teams, reduce alert noise and improve resilience—not replace human decision-makers.

Unfortunately, I didn't get a video or picture with CV, but it was still great catching up and talking about the Anomali solutions and mission.

My Takeaways from Hacker Summer Camp 2026

AI is everywhere, but we're starting to get past the “AI because AI” phase. Almost every conversation I had touched AI in some way, but the interesting discussions weren't about just adding an LLM to a product. They were about where AI can actually change security, whether that's contextual DLP, faster consulting and modernization, automated pentesting, threat intelligence, or detection and response.

Context is becoming just as important as detection. This came up over and over again. Jazz talked about understanding the context around data movement and user intent. Anomali talked about using threat intelligence to give analysts and AI better context. Suzu Labs talked about feeding what they've learned from previous engagements back into their AI workflows. AI without context is really just faster automation, and potentially a way to make mistakes faster.

AI isn't replacing people anytime soon, but it is changing how much one person can do. Suzu Labs is using AI to let consultants handle more work, John Strand sees automated pentesting becoming another tool used by experienced practitioners, and Anomali sees agents taking on more of the reactive security work. I clearly see where leverage lies with AI, but that's not the same as replacing humans.

The fundamentals of security still matter. For all the talk about agents, LLMs and AI, a lot of these conversations came right back to identity, architecture, good data, threat intelligence, visibility and human oversight. The technology is changing quickly, but none of that makes the security fundamentals we've been talking about for years suddenly go away.

Final Thought

The cybersecurity community is still the best part of Hacker Summer Camp: AI may have dominated the technology conversations this year (just like ransomware, spyware, DDoS, etc. have in the past), but the people are still what make the week worth the travel, sore feet (though my HOKAs have almost eliminated that problem), too much rich food, and too little sleep. Whether it was BSidesLV, talking to John Strand about giving back to the community, or just running into people I've known for years, Hacker Summer Camp is still as much about the community as it is about the technology.

See you all again next year!

HOU.SEC.CON CTA

Latest