Skip to content
← all posts
Thinking

Notes from Hacker Summer Camp 2026

I've been trying to compiled a raft of notes and thoughts into a post, but I'm thinking that the ol' bullet-point dump is going to be the way to go here...

  • Probably the first thing, and something that you might not hear much elsewhere: there are a LOT of hackers sitting on a LOT of bugs and exploits right now, mostly because of the triage trash fire, and partly because vulnerability disclosure is generally broken.

  • That backlog is a pricing story before it is anything else. The thing folks forget about bounty is that "what is an exploit worth" is the ACTUAL primitive, and that "exploit trade functions as a marketplace, which means that scarcity or excess affect pricing". A pile of undisclosed work sitting in researchers' drafts folders is excess supply that never reaches the market, and it distorts every number downstream of it.

  • Which is why the "obituary" genre keeps missing the mark. I filed "bounty is dead" twice in one week, and "quit bug bounty to go into pentesting" is probably some of the worst advice I've ever read. The demand side is real, the routing is what is broken. Related, and the show floor made it obvious: never sell security to someone who doesn't care.

  • The "AI-assisted/powered attacks aren't here yet" narrative is being primarily driven by stats around 0-day and CVE exploitation, and is ignoring bespoke appsec (i.e. one-off vulns and chains), architectural issues (i.e. the kind that AI actually degrades, versus improves, right now), and leaked secrets. I'm not saying it's here and the sky is falling, but bespoke code and infrastructure is unequivocally a blind spot in exploitation data.

  • On the above: everyone is freaking out about agentic attacks, whilst ignoring that attackers are economically rational, that you'd be stupid NOT to be using AI in your toolchain at this point, and that this has been true for 3+ years now (...ask me how I know this).

  • Australia's first reported autonomous AI cyberattack landed mid-camp and confirmed the thing I keep saying: agents going off-piste is a software problem, not an AI problem. Labs sharing information about emergent properties is good and important, but "these are orthogonal issues that are being treated as the same thing rn", and the conflation is doing real damage to how people prioritise.

  • On liability, because it came up constantly and nobody likes the answer: the traditional test is "whoever had the intent that triggered the harm" combined with "whoever is legally weak enough to successfully litigate or prosecute". Autonomy in the toolchain does not change that, it just adds defendants.

  • The conversation about counter-offense and "impermissive" defense options is WAY more open in the rooms where they happen, and the lack of dialog is bubbling up as a source of frustration amongst folks who are protecting critical infrastructure and orgs "below the security poverty line".

  • There's a combination of a desire to take the fight back to the attackers in the form of imposing cost, as well as an urgency around improving resilience, especially in "break glass" scenarios.

  • The week bookended that whole question in a way I don't think was accidental. It opened with Leonard Bailey at BSides LV telling the story of how hackers and the feds walked together to change anti-hacking laws, including the line "I didn't expect to be welcomed into this community in the way that I was". It closed with a White House letters of marque memorandum that "almost directly quotes the language of the Computer Fraud and Abuse Act". Ten days. Same statute, opposite direction.

  • Worth restating, because it is the asymmetry underneath all of it: offense scales with compute, defense scales with committees.

  • Speaking of which, aside from coming up in a number of presentations, the Black Hat attendee space was oddly quiet about August 2027.

  • I'm quietly optimistic about the future of PPP, especially amongst the four eyes. The US seems to be catching up quickly as well.

  • Calling it out: there's always a strong desire for community at Hacker Summer Camp, but this year it felt like it had gone up a notch. To me it felt like the herd closing ranks on some of the problems and threats that have surfaced over the past 12 months, along with the general desire just to "be in the same space". Some of my favorite moments through the week were the really, really quiet ones.

  • The preservation instinct was the tell. The Hacker Culture Manual, Bugtraq coming back, Kaminsky remembered 18 years on from the DNS disclosure. In the age of "Clank The Planet" it has never been more important to preserve and promote community, the people who comprise it, and the culture that defines it. A community that spends its week archiving itself is a community that thinks something is at risk.

  • There were TONNES of founders and people working on things. These are some of my favorite conversations, and they happened ALL WEEK, partly on account of the advisory stuff I'm doing at the moment, and partly because Bugcrowd is in effect a micro entrepreneurial ecosystem. You can just "build things". At the same time, there's a dearth of knowledge on how to approach branding, pricing, go-to-market, etc.

  • Black Hat: the vendor market is generally continuing to flatten out. Lots of companies are pitching nearly identical AI and agentic capabilities, emphasizing what their products contain rather than why customers need them or why it matters. It feels like a scramble with a lack of vision (there are a few bright spots, and early or strong movers still have an advantage).

  • BSides LV: the conversation focused more heavily on neglected security problems: critical infrastructure, hybrid conflict, resource-poor organizations, and adversaries using AI for economic advantage. Its defining question was: we've probably spent enough time admiring the problem at this point, what are we going to do?

  • DEF CON: the community remained allergic to hype, but blanket rejection of AI was giving way to reluctant acceptance that the shift is a real thing. There was definitely a lot of anxiety around job security and the future, along the lines of "if AI democratizes techniques that once made vulnerability hunters exceptional, where does their value go next?"

  • For what it's worth, my answer to that anxiety is the one I gave when people kept asking whether I'm "AGI-pilled". It's a flat no, and the reasoning is short: AI has the same phase-shift properties as the arrival of the Internet, but I'm already human-pilled.

  • In general, there was a lot more focussed conversation around critical infrastructure and societal resilience, which I was very happy to see. The conversation around AI has shone light on a large number of "inconvenient truths" about the PRE-EXISTING state of technology resilience, and in doing so has revealed the state of the industry that is meant to be protecting it in some fairly uncomfortable, but hopefully useful ways.

  • The physical cost, for the record: 97,573 steps and 88.2 kilometres over eight days, about 2.6 times my normal daily average at home. I averaged 5.2 hours of sleep a night which, ngl, I'm quietly proud of.

Casey Ellis
Casey Ellis
Hacker, founder, advisor, and pioneer of crowdsourced security. Founder of Bugcrowd, co-founder of disclose.io, principal of Tall Poppy Group. Board member at SRLDF.
bio →

Comments ·

members only