Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Education & Training

Hacker Summer Camp Is a Defender’s Education

By Len Noe
Laptop with coding
Arnold Francisca via Unsplash
August 19, 2026

Every August, tens of thousands of people fly into a desert running north of a hundred degrees in the shade so they can sit in windowless ballrooms and talk about how things break. We call it Hacker Summer Camp. This year it stretched across one week and four venues: BSides Las Vegas at the Tuscany, August 3 through 5; Black Hat USA at Mandalay Bay, August 1 through 6; the Cognitive Security Conference back at the Tuscany, August 6 and 7; and DEF CON 34 at the Las Vegas Convention Center, August 6 through 9.

I have been going for years. As I walked the venues, I watched the same misunderstanding play out, in the press and in boardrooms back home: the assumption that a hacker conference is a gathering of criminals. Let me put that one down early, because it is the reason a lot of good security work never leaves the building.

The Reputation, and Where it Came From

The reputation is not made up out of nothing. DEF CON started in 1993 as a going-away party an 18-year-old named Jeff Moss, his handle “Dark Tangent”, threw for a friend leaving the country. The name is a nod to WarGames. For most of its life the event carried an outlaw air. Federal agents from the FBI and Defense Department showed up to watch the crowd, and the crowd turned that into a game called Spot the Fed. After the 2013 surveillance disclosures, organizers publicly asked the feds to sit a year out. In 2005, a researcher was pressured off a stage for detailing a router flaw before the vendor was ready. Hollywood did the rest, and the hoodie-wearing villain stuck.

Here is what that reputation misses entirely. That same week is, by any honest measure, the single largest concentration of practical cybersecurity knowledge on the planet. Government cyber leadership from CISA, the NSA, and the FBI come to talk national strategy alongside the people they spend the rest of the year chasing and hiring.

This year the government was in the room for the same reason everyone else was: to understand what is coming. That is not a criminal underworld. That is a professional field doing its continuing education in public.

Hacking Is not Illegal. What and How You Hack Is the Whole Game.

The word "hacking" does a lot of unfair work. Hacking is not a crime. It is a discipline of understanding a system well enough to make it do something its designers did not intend. The technique that dumps credentials out of memory during a sanctioned engagement is the exact same technique an adversary runs on a Tuesday. What separates the two is authorization and intent, not skill and not tooling.

That is precisely why defenders need to be in the room. You do not learn to defend a lock by reading the manufacturer's brochure. You learn by watching someone pick one, in front of you, slowly, while they explain what the lock’s designer got wrong. Strip away the parties and the branded socks and that is the actual product of the week: defenders getting measurably better by watching offense operate up close, at a depth no vendor webinar will ever match.

What the Offense Pointed at this Year

If you wanted one theme, agentic AI took the week across all four venues. DEF CON’s own theme was "Agency", which is fitting, because when you strip the AI demos down to what actually moved an attacker from outside a system to inside it, you land on something far older and far more boring than a large language model. You land on identity. Credentials. Privilege.

That is not a hunch. The 2025 Verizon Data Breach Investigations Report (DBIR) puts the human element in roughly 60 percent of breaches, found compromised credentials serving as the initial access vector in 22 percent of breaches, and watched ransomware climb into 44 percent of the breaches it reviewed.

Read those numbers the way an operator does. Attackers overwhelmingly are not breaking down the wall. They are logging in. MITRE catalogs it plainly as Valid Accounts, technique T1078: legitimate credentials, legitimate access, illegitimate hands. Once they are in with a valid identity, privilege is what decides whether the incident is a contained annoyance or a company-ending event. Standing privilege is the difference between an attacker owning one mailbox and an attacker owning the domain.

Identity Is Infrastructure. Privilege Is Risk.

This is where the agentic AI conversation stops being futuristic and starts being a mirror. Every autonomous agent you deploy is a new non-human identity holding real, standing privilege, often over-provisioned because provisioning it correctly was slower than shipping it. The uncomfortable takeaway from the show floor is that we are rolling out AI agents with the same over-permissioned, implicitly trusted, standing-access mistakes we have spent two decades making with human accounts, only faster and at machine scale.

Human identities, machine identities, and now AI agent identities are all the same problem wearing different clothes. Each one is a path to privilege. The DBIR’s other finding this year, that third-party involvement in breaches doubled to 30 percent, is the same lesson from a different angle: your trust boundaries now run straight through identities you do not directly control. 

None of this calls for a moonshot. It calls for the unglamorous discipline the best people at that conference already practice. Enforce least privilege and mean it, so a compromised identity inherits as little as possible. Kill standing privilege where you can and move to access that is granted, scoped, and taken back. Push toward phishing-resistant MFA, which CISA has been telling everyone to adopt for years for exactly the reasons the DBIR keeps re-proving. Validate trust continuously instead of once at login. Actually map your paths to privilege, human and machine and AI, and treat that map as live infrastructure. And extend every bit of that governance to your non-human identities, because the agents do not get tired, do not get suspicious, and will use every permission you forgot to take away.

I am not going to pretend this is easy. Legacy systems will not cooperate. Budgets are finite, change management is real friction, and someone always needs that one over-scoped service account to keep the lights on. Maturity here is not a switch. It is a direction. The organizations that walk out of a week like this and reduce standing privilege by any measurable amount are ahead of the ones that walk out with a new logo on a slide and nothing changed.

What the Camp Is Actually For

The reputation says Vegas in August is where hackers go to break things. The people who go know it is where defenders go to become harder to break. The checkered history is real, but it was never the point. The point is a week where the offense shows its hand in the open, and anyone paying attention can take that knowledge home and turn it into a control.

This year the hand it showed was identity and privilege, dressed up in the language of AI. The tools change every August. The lesson underneath them has not moved in years: identity is the terrain modern attacks are fought on, and privilege is the prize. You do not need to fly to the desert to act on that. But it helps to have watched, up close, exactly how someone takes it from you.

KEYWORDS: Black Hat credentials hacking identity identity challenges

Share This Story

Len Noe is a Solutions Architect at BeyondTrust, Transhuman, Podcaster, International Cyber Security Speaker, Author, Technical Evangelist, and Biohacker with 11 implanted microchips. A former blackhat with more than 30 years in technology, he has presented in over 70 countries and is featured in the documentary I Am Machine, which premiered at DEF CON 2025.

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Photograph of apartment complex patios

Enhancing Residential Building Security

Handcuffs and cash

Mass Kidnapping Increased 154% from 2020 to 2025

security

6 Crisis Response Best Practices (That Actually Hold Up When Things go Sideways)

Northland Controls sponsored content

The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Trust

Building Public Trust in AI‑Enabled Security

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing