Hacker Summer Camp Is a Defender’s Education

Every August, tens of thousands of people fly into a desert running north of a hundred degrees in the shade so they can sit in windowless ballrooms and talk about how things break. We call it Hacker Summer Camp. This year it stretched across one week and four venues: BSides Las Vegas at the Tuscany, August 3 through 5; Black Hat USA at Mandalay Bay, August 1 through 6; the Cognitive Security Conference back at the Tuscany, August 6 and 7; and DEF CON 34 at the Las Vegas Convention Center, August 6 through 9.
I have been going for years. As I walked the venues, I watched the same misunderstanding play out, in the press and in boardrooms back home: the assumption that a hacker conference is a gathering of criminals. Let me put that one down early, because it is the reason a lot of good security work never leaves the building.
The Reputation, and Where it Came From
The reputation is not made up out of nothing. DEF CON started in 1993 as a going-away party an 18-year-old named Jeff Moss, his handle “Dark Tangent”, threw for a friend leaving the country. The name is a nod to WarGames. For most of its life the event carried an outlaw air. Federal agents from the FBI and Defense Department showed up to watch the crowd, and the crowd turned that into a game called Spot the Fed. After the 2013 surveillance disclosures, organizers publicly asked the feds to sit a year out. In 2005, a researcher was pressured off a stage for detailing a router flaw before the vendor was ready. Hollywood did the rest, and the hoodie-wearing villain stuck.
Here is what that reputation misses entirely. That same week is, by any honest measure, the single largest concentration of practical cybersecurity knowledge on the planet. Government cyber leadership from CISA, the NSA, and the FBI come to talk national strategy alongside the people they spend the rest of the year chasing and hiring.
This year the government was in the room for the same reason everyone else was: to understand what is coming. That is not a criminal underworld. That is a professional field doing its continuing education in public.
Hacking Is not Illegal. What and How You Hack Is the Whole Game.
The word "hacking" does a lot of unfair work. Hacking is not a crime. It is a discipline of understanding a system well enough to make it do something its designers did not intend. The technique that dumps credentials out of memory during a sanctioned engagement is the exact same technique an adversary runs on a Tuesday. What separates the two is authorization and intent, not skill and not tooling.
That is precisely why defenders need to be in the room. You do not learn to defend a lock by reading the manufacturer's brochure. You learn by watching someone pick one, in front of you, slowly, while they explain what the lock’s designer got wrong. Strip away the parties and the branded socks and that is the actual product of the week: defenders getting measurably better by watching offense operate up close, at a depth no vendor webinar will ever match.
What the Offense Pointed at this Year
If you wanted one theme, agentic AI took the week across all four venues. DEF CON’s own theme was "Agency", which is fitting, because when you strip the AI demos down to what actually moved an attacker from outside a system to inside it, you land on something far older and far more boring than a large language model. You land on identity. Credentials. Privilege.
That is not a hunch. The 2025 Verizon Data Breach Investigations Report (DBIR) puts the human element in roughly 60 percent of breaches, found compromised credentials serving as the initial access vector in 22 percent of breaches, and watched ransomware climb into 44 percent of the breaches it reviewed.
Read those numbers the way an operator does. Attackers overwhelmingly are not breaking down the wall. They are logging in. MITRE catalogs it plainly as Valid Accounts, technique T1078: legitimate credentials, legitimate access, illegitimate hands. Once they are in with a valid identity, privilege is what decides whether the incident is a contained annoyance or a company-ending event. Standing privilege is the difference between an attacker owning one mailbox and an attacker owning the domain.
Identity Is Infrastructure. Privilege Is Risk.
This is where the agentic AI conversation stops being futuristic and starts being a mirror. Every autonomous agent you deploy is a new non-human identity holding real, standing privilege, often over-provisioned because provisioning it correctly was slower than shipping it. The uncomfortable takeaway from the show floor is that we are rolling out AI agents with the same over-permissioned, implicitly trusted, standing-access mistakes we have spent two decades making with human accounts, only faster and at machine scale.
Human identities, machine identities, and now AI agent identities are all the same problem wearing different clothes. Each one is a path to privilege. The DBIR’s other finding this year, that third-party involvement in breaches doubled to 30 percent, is the same lesson from a different angle: your trust boundaries now run straight through identities you do not directly control.
None of this calls for a moonshot. It calls for the unglamorous discipline the best people at that conference already practice. Enforce least privilege and mean it, so a compromised identity inherits as little as possible. Kill standing privilege where you can and move to access that is granted, scoped, and taken back. Push toward phishing-resistant MFA, which CISA has been telling everyone to adopt for years for exactly the reasons the DBIR keeps re-proving. Validate trust continuously instead of once at login. Actually map your paths to privilege, human and machine and AI, and treat that map as live infrastructure. And extend every bit of that governance to your non-human identities, because the agents do not get tired, do not get suspicious, and will use every permission you forgot to take away.
I am not going to pretend this is easy. Legacy systems will not cooperate. Budgets are finite, change management is real friction, and someone always needs that one over-scoped service account to keep the lights on. Maturity here is not a switch. It is a direction. The organizations that walk out of a week like this and reduce standing privilege by any measurable amount are ahead of the ones that walk out with a new logo on a slide and nothing changed.
What the Camp Is Actually For
The reputation says Vegas in August is where hackers go to break things. The people who go know it is where defenders go to become harder to break. The checkered history is real, but it was never the point. The point is a week where the offense shows its hand in the open, and anyone paying attention can take that knowledge home and turn it into a control.
This year the hand it showed was identity and privilege, dressed up in the language of AI. The tools change every August. The lesson underneath them has not moved in years: identity is the terrain modern attacks are fought on, and privilege is the prize. You do not need to fly to the desert to act on that. But it helps to have watched, up close, exactly how someone takes it from you.