From Black Hat to DEF CON: 10 Hacker Summer Camp Standouts

Another year, another epic Hacker Summer Camp session. There were stickers galore. There was LineCon. Cliff Stoll took over a threat hunting panel. People decried John Hammond's absence. All in all, a solid week.

Behind it all, Huntress researchers were everywhere, and not just at our Black Hat booth: giving DEF CON talks, lending support to all the villages (Malware, Blue Team, Red Team, and more), and participating in the HacktheBox SOC Showdown. 

Here are 10 highlights from Hacker Summer Camp this year that we loved. 

1. CloudBasher unleashed

At DEF CON, Principal Security Researchers Jenko Hwong and Chris Ryan detailed their research into CloudShell, a browser-based terminal that major cloud providers offer so users can manage their cloud resources without installing anything locally.

The research involved reverse-engineering the private REST and websocket protocols behind AWS, Azure, and GCP CloudShell terminals, along with analyzing browser authentication flows connecting cookies to OAuth tokens. The investigation unearthed significant Identity and Access Management (IAM) design weaknesses, including websocket sessions that outlive API token revocation and default CloudShell access tied to consumer email accounts. 

This all culminated in CloudBasher, a newly released toolkit that automates environment discovery, enumeration, and deployment of distributed workloads with persistent storage and private networking. Jenko and Chris demonstrated CloudBash live during the session across a resilient, large-scale agent network

Jenko Hwong and Chris Ryan crack open CloudShell  

2. All the villages 

DEF CON has almost 40 villages. These community initiatives are focused on tradecraft, offensive security, adversary simulation, emulation, and more across a number of different spaces–whether that's bug bounty, cryptocurrency, lockpicking, IoT, physical security, scambait, car hacking or biohacking. 

You could find us at the Malware Village, where Andrew Brandt, principal threat intelligence incident commander, and Austin Worline, security operations analyst, were helping out.

Austin Worline fixes badges at Malware Village

We were also leading the charge at the Red Team Village (where Logan MacLaren, staff offensive security engineer, was leading the command and conquer workshop), and Blue Team Village (where Christina Parry, staff software engineer, led "The Modern Detection Engineer" panel).

Christina Parry speaks during "The Modern Detection Engineer" panel

3. AI everywhere, and an industry deciding what it all means

Unless you've been living under a rock, you knew AI would be all over Hacker Summer Camp. What stood out this year was less the volume and more the maturity of the conversation. On the Black Hat floor, every vendor claimed to be "agentic," but almost nobody defined it. Autonomous SOC analysts? LLMs with tool access? A chatbot with a scheduler? It felt like the EDR vs XDR debates all over again, the kind of terminology fight that always happens right before a market sorts itself out.

Over at DEF CON, the conversation went a layer deeper. AI safety and policy discussions pulled real crowds, from Policy Village panels with people at frontier AI labs to hallway debates about model guardrails and platform abuse. The question we kept hearing was changing from "can we hack it" to "who owns the problem when it goes wrong." That shift matters, because AI is getting wired into security tooling and attacker tooling at the same time. There is real innovation under the buzzwords, and DEF CON remains one of the only places where the builders, the breakers, and the policymakers all end up in the same room to sort out which is which.

4. Threat actor trial abuse lessons

At Black Hat, Jamie Levy, senior director of Adversary Tactics, gave a recap on a blog that caused quite the stir last year: a threat actor clicked a Huntress ad, started a trial, installed the Huntress agent on their attack machine, and inadvertently exposed their malicious behavior, tooling, workflows, and reconnaissance activity.

The investigation revealed several interesting insights into the threat actor's process, including the type of things they researched, the AI workflows they relied on, and much more. It also led to a conversation on social media around the investigation, what managed endpoint detection and response (EDR) products actually do and what purpose that they serve, and more.

Jamie Levy's Black Hat Pulse Stage presentation on revelations from a trial abuse incident   

5. Public and private, side by side

Federal agencies showed up in force again. CISA, FBI, NSA, and others are fixtures at both cons now, a far cry from the days when "Spot the Fed" was a game people actually played. Conferences like these are one of the best ways to learn what agencies are doing, how to report what you find, and how to get involved, whether through vulnerability disclosure programs or workforce initiatives. If you've never walked up to an agency booth, don't be shy.

What made this year feel different was seeing how much healthier that partnership has become, and how far past the booths it now extends. The relationship between the hacker community and the government used to run on mutual suspicion. Today it runs on shared work. Private sector researchers routinely feed intelligence into joint advisories on active threat campaigns. Ransomware takedowns increasingly pair law enforcement action with telemetry and infrastructure analysis from private security teams, because neither side can pull those operations off alone. When a critical vulnerability drops, the coordination between vendors, researchers, and agencies happens in hours now, not weeks.

That collaboration is built on trust, and trust is built in rooms like these. The conversations happening at a village table or an agency booth in August are the same relationships that get activated in the middle of an incident in November. Watching that partnership keep growing in healthy ways, with the community pushing back where it should and the agencies showing up to listen, was one of the quiet wins of the week.

6. HacktheBox SOC Showdown!

Huntress got to compete in this year's HackTheBox's SOC Showdown Capture The Flag event. Five of our SOC analysts represented their respective regions during this invite-only event.

The event featured a realistic Threat Range scenario, involving a live adversary simulation with logs, alerts, network traffic, and forensic artifacts that was built around the full incident lifecycle. Awesome work to our team: Tanner Filip, Dani Lopez, Adrian Garcia, Jamie Dumas, and Luke Wilkinson!

Huntress SOC analysts hard at work at HackTheBox's SOC Showdown 

7. When "blocked" becomes the attack

AI was everywhere at DEF CON this year, but some of the most interesting research presentations went beyond how adversaries are using AI and focused instead on how the AI systems themselves can be part of the attack path.

The DEF CON talk "Your WAF Blocked Us, That Was the Exploit" demonstrates why Model Context Protocol (MCP) security needs to be part of the conversation as organizations give AI agents access to business systems. The research is a real world example of indirect prompt injection, which falls directly under Open Worldwide Application Security Project (OWASP) Top 10 for Large Language Model (LLM) Applications 2026, LLM01:2026 Prompt Injection. Unlike traditional prompt injection, where an adversary enters malicious instructions directly into a chatbot, indirect prompt injection hides those instructions inside data the AI later consumes, such as logs, telemetry, emails, tickets, documents, or API responses. Tenet demonstrated this with Sentry telemetry. Attacker-controlled instructions were embedded in an error event and later returned to an AI coding agent through the MCP. The agent interpreted this text as instructions and in this case, legitimate remediation guidance that could execute adversary-controlled code. 

What makes this especially concerning is the combination of Prompt Injection (OWASP LLM01:2026) and Excessive Agency (OWASP LLM03:2026). While the MCP does not inherently create the prompt injection vulnerability, it creates the pathway that connects untrusted information to powerful capabilities. If an agent can read external data through the MCP and also execute commands, access credentials, modify infrastructure, or call other tools, an indirect prompt injection can move from manipulating an AI's response to causing real-world actions. 

OWASP specifically identifies direct and indirect prompt injection as potential triggers for Excessive Agency. The Tenet research presented at DEF CON makes that risk tangible. In this case, although the Web Application Firewall (WAF) can successfully block the attacker, the blocked request becomes malicious instructions that an AI agent later reads and acts upon. In an agentic-world, security has to consider not only who can access a system, but what data an agent trusts, what can influence its decisions, and what it is authorized to do as a result.

8. Jen Easterly and Cybersecurity Girl on education hacks 

We hosted a conversation between former CISA Director Jen Easterly and Caitlin Sarian (aka Cybersecurity Girl) on major breaches in the education sector, including the 2024 PowerSchool intrusion that exposed PII for 62 million students and 9.5 million educators, and the 2026 Canvas/Instructure ShinyHunters breach where the attackers claimed they stole 275 million records from nearly 9,000 institutions.

With the school year starting up again, the conversation focused on what parents, educators, and students can do to protect themselves in the wake of these incidents, including: updating devices, using a password manager with complex passwords, inspecting emails for red flags, and turning on MFA.

t

9. Something for everyone: break something, learn something

One of the things that makes DEF CON different is that it doesn't just involve spending the entire conference sitting in a room listening to someone else talk about hacking. Attendees can actually go hack something themselves–and they don't need to have mad skills to participate. At the Evolve Security Cyber Lab, no prior skills or special lab setup is required. The instructors guided the attendees through a deliberately vulnerable environment, starting with basic reconnaissance and then following the breadcrumbs. The participants used tools like nmap, Wappalyzer, OWASP Amass to identify open ports, discover running processes, search for subdomains and login pages and explore where vulnerabilities like SQL injection could be leveraged. The key takeaways went well beyond the tools and commands. It was experiencing the methodology: scan, observe, form a hypothesis, test it and use what you learn to determine where to look next. The hands-on experience provides a much better understanding of how the adversary approaches a target and follows the breadcrumbs from initial discovery to potential compromise.

And the hands-on learning doesn't stop at the keyboard. We learned everything from soldering/assembling badges to how AI is changing attacks against people (thanks to a demonstration and contest using AI-assisted vishing in the Social Engineering Village).

These were very different experiences, but they shared a common thread. Seeing an attack or technology firsthand changes people's understanding of it. Reading about AI-powered social engineering is one thing; seeing how convincingly it can be used in a voice-based attack makes the risk much more tangible. This is what we mean when we say there is something for everyone at DEF CON. In the span of a few days, attendees could hear cutting-edge research on AI and MCP, attack a vulnerable web application, see social engineering in action, pick up a soldering iron for the first time, or wander into a village covering a technology they never touched before. 

You don't have to be an expert to participate. Curiosity is really the only pre-requisite. And sometimes the most valuable thing you bring home is not more knowledge about something you already knew, but an entirely new perspective or way of looking at how technology, adversaries and people intersect.

10. Hacker Jeopardy 

And then, there's Hacker Jeopardy: proof that not every learning experience at DEF CON has to involve a lab, a soldering iron or serious research. It's loud, irreverent, ridiculous and an incredible amount of fun. But somewhere between the jokes and obscure trivia, you realize you're learning, or at least discovering what your brain managed to hang onto for all these years. There's something oddly satisfying about reaching deep into the old memory banks and realizing you still remember a thing (or 20) about obscure HTTP status codes, ancient technology, security history, and other wonderfully useless things until you suddenly need those bits of knowledge.

And then there are those magical moments of community bonding, when a room full of hackers discovers the things that unite use. Apparently, one of those things we all have in common is a pure unadulterated hate of Sony. Hacker Jeopardy captures something that's easy to miss when describing DEF CON purely in terms of talks, villages and technical skills. The community is part of the experience. Sometimes you're learning from a world class researcher, sometimes you're learning by breaking something and sometimes you're laughing with a room full of people who somehow remember the same obscure pieces of internet and technology history that you do.

The community is the con, and the good guys are winning

Talks get recorded. Hallway con doesn't. The real reason tens of thousands of people descend on Las Vegas every August is each other: the mentorship, the reunions, the groups doing year round work like Black Girls Hack and the Consortium of Cybersecurity Clinics, which pairs university students with organizations that could never afford security help on their own. These groups are building the talent pipeline the industry keeps saying it needs, and Hacker Summer Camp is where you see that work pay off.

Cybersecurity headlines skew grim. Breaches, ransomware, burnout. But spend a week watching people you know take the stage for the first time, students landing their first SOC jobs, and veterans teaching lockpicking to twelve year olds in a village, and you walk away with a different picture. This community keeps growing, keeps teaching, and keeps showing up.

To echo what Lintile said from the stage during the Hacker Jeopardy finals: there is so much going on in the world today, and a large portion of the answers to the problems we face are sitting right here in this room. It's hard to argue with that. Thousands of people who take things apart for a living, who teach for free, who show up year after year to make each other better. If the answers are anywhere, they're here.

We always leave Hacker Summer Camp inspired and hopeful for the future. This year is no different. That's a wrap on Hacker Summer Camp 2026. See you next year.