cd /news/artificial-intelligence/summer-of-semgrep-everywhere-you-ll-… · home topics artificial-intelligence article
[ARTICLE · art-69291] src=semgrep.dev ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Summer of Semgrep: Everywhere You'll Find Us at Hacker Summer Camp 2026

Semgrep will have a major presence at Hacker Summer Camp 2026, with talks and a booth at Black Hat, BSidesLV, and DEF CON from August 4-8. Sessions cover AI-assisted development, LLM-based vulnerability detection, cryptographic failures, and a new method called Slop Spotting to detect AI-generated bug bounty reports. The company's CTO Drew Dennison will discuss combining SAST and LLMs to find bugs at scale, while security advocate Katie Paxton-Fear will present on hacking eReaders and triaging AI slop.

read7 min views2 publishedJul 22, 2026
Summer of Semgrep: Everywhere You'll Find Us at Hacker Summer Camp 2026
Image: Semgrep (auto-discovered)

Hacker Summer Camp means Black Hat, BSidesLV, and DEF CON, back to back, in one wild week in Vegas. This year, Semgrep is showing up everywhere: people on stage at all three conferences, a booth in the Black Hat Business Hall, and a few sessions worth putting on your calendar if AI-assisted development, LLM-based vuln detection, or crypto failures are your thing. Here's the full rundown, and why you'll want to come find us.

On the Schedule at Hacker Summer Camp

Semgrep at a Glance

| | | | | Aug 4 | 10 AM | BSides Las Vegas Proving Ground | Diptendu Kar | Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures | Aug 4 | 5:30 PM | Black Hat Business Hall Booth 4943 | Drew Dennison Leif Dreizler Katie Paxton-Fear Cathy Polinsky | Fireside Screensaver Chat: Agentically Engineered the Future of AppSec | Aug 5 | 1:30 PM | Black Hat Business Hall Booth 4943 | Katie Paxton-Fear Milan Williams | Overcoming the Fear of Security Risk with AI-Assisted Development | Aug 6 | 9:30 AM | Black Hat Business Hall Booth 4943 | Cris Thomas (Space Rogue) Pablo Estrada | AI Writes Code. Who Reviews It? | Aug 6 | 3:15 PM | Black Hat Business Hall Pulse Stage 4 | Drew Dennison | Using SAST + Mythos To Shift Right | Aug 7 | 4:30 PM | DEF CON Crypto & Privacy Village Stage 2 | Diptendu Kar | Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures | Aug 8 | 2:30 PM | DEF CON Bug Bounty Village Stage 6 | Katie Paxton-Fear Max vonBlankenburg | Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty | Aug 8 | 3:15 PM | DEF CON IoT Village Stage 3 | Katie Paxton-Fear | Beyond Your Bookshelf: Hackable eReaders |

Using SAST + Mythos To Shift Right

Drew Dennison: Paranoid Optimist, Co-founder and CTO of Semgrep, building tools to secure code since 2014.

Black Hat Business Hall, Pulse Stage 4 | Thursday, August 6, 3:15 PM

LLMs are moving the security control point from CI/CD to deep hunts for novel vulnerabilities. Drew's talk covers how combining SAST, LLMs, tooling, and data can surface bugs at scale that have been sitting in codebases for years. If you're skeptical that "SAST + LLMs" is more than a buzzword pairing, this is the talk built to change your mind.

Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty

Katie Paxton-Fear: Security Advocate at Semgrep, API hacker, and host of the InsiderPhD YouTube channel, where she teaches bug bounty hunting to about 100,000 subscribers.

Max vonBlankenburg: Security Researcher at Semgrep, focused on security detection on all fronts and Capture the Flag Lead at Pacific Hackers Association.

DEF CON, Bug Bounty Village, Stage 6 | Saturday, August 8, 2:30 PM

After curl shut down its HackerOne program in January 2026 under a wave of AI-generated reports — some weeks saw seven reports in sixteen hours, none valid — Dr. Katie and Max are introducing Slop Spotting: a lightweight triage method that uses SAST rule generation as a validity signal. The core idea: if a vulnerability is real and well-specified, you should be able to write a SAST rule for it and get a result. If it's slop, even convincing slop, you get a fast no. Anyone who's watched a maintainer drown in obviously-fake reports will recognize the problem immediately.

Beyond Your Bookshelf: Hackable eReaders

Katie Paxton-Fear

DEF CON, IoT Village, Stage 3 | Sat, August 8, 3:15 PM

Kindles, Kobos, Boox, BigMe — eReaders look like the most boring IoT device you own, until you look underneath the eInk display. Dr. Katie digs into the quirks of hacking these devices, from jailbreaking a locked-down Kindle to the xTeink's open-source Crosspoint firmware. Bring your own eReader. She might jailbreak it for you on the spot.

Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures

Diptendu Kar: Security Researcher at Semgrep, previous part-time faculty at Northeastern. BSides Las Vegas, Proving Ground | Tuesday, August 4, 10 AM

DEF CON, Crypto & Privacy Village, Stage 2 | Friday, August 7, 4:30 PM

Cryptographic failures rarely come from bad math. They come from a skipped validation check, unvalidated input, or the wrong algorithm picked under deadline pressure. Diptendu is giving this talk twice: once at BSidesLV and again at DEF CON's Crypto & Privacy Village, using GitHub Security Advisories data (collected as of January 2026) to walk through the OWASP Cryptographic Failures category. Expect real vulnerable open-source libraries, signature verification bypasses, algorithm confusion bugs, and live demos with CTF-style challenges built in. No cryptography background required to enjoy this talk.

What You’ll Find at the Semgrep Booth (#4943)

Fireside Screensaver Chat: Agentically Engineered the Future of AppSec

Panelists:

: AppSec Engineer at Semgrep. Previously helped build and launch Semgrep Secrets; former Engineering Manager at Twilio Segment.Leif Dreizler: Co-CTO and VP of Engineering at Semgrep, with 20+ years of engineering leadership at Yahoo!, Salesforce, Stitch Fix, and Shopify.__Cathy Polinsky__Drew Dennison

Moderated by Katie Paxton-Fear

Business Hall, Welcome Reception | Tuesday, August 4, 5:30 PM

Kicking off the week with a fireside-style conversation on what it actually looks like when AppSec, CTOs, and software teams try to agentically engineer their way into the future. Grab a drink at the Welcome Reception first. This one's meant to feel like a conversation, not a keynote.

Overcoming the Fear of Security Risk with AI-Assisted Development

Milan Williams: Senior Product Manager at Semgrep, currently overseeing Semgrep Guardian. Katie Paxton-Fear

Business Hall | Wednesday, August 5, 1:30 PM

70% of engineering leaders list AI adoption as their #1 goal for increasing velocity. 59% of those same leaders say security threats and data control are what's stopping them. Katie and Milan get into how to bring tools like Cursor, Codex, Claude Code, and Replit onto your dev teams without losing the plot on security. Bring your AI IDE questions. Between the two of them, they've probably heard your exact one already.

AI Writes Code. Who Reviews It?

Cris Thomas (Space Rogue): Security Advocate at Semgrep, founding member of the legendary hacker collective L0pht, and author of

Space Rogue: How the Hackers Known as L0pht Changed the World.

Pablo Estrada: Head of Product Marketing at Semgrep and one of our most tenured employees. Electrical engineer turned security enthusiast.

Business Hall | Thursday, August 6, 9:30 AM

AI writes code fast but security review still moves at human speed. Space Rogue and Pablo get into what it takes to close that gap without turning review into a rubber stamp. If your team's already shipping AI-generated code faster than anyone can keep up with, come compare notes.

Also at our Black Hat Booth: Partner & Customer Sessions

We're sharing the mic. Visit our booth for quick hits from our partners and customers:

Wednesday, August 5

10:45 AM — Preethi Kumaresan, Sr. Architect, AWS:

Zero-Trust AppSec: A Hands-On Semgrep + AWS Platform Tour2:15 PM — Mark Lambert, Chief Product Officer, ArmorCode:

From Detection to Decision: How Semgrep and ArmorCode Close the Loop at Machine Speed4:45 PM — Gianluca Brindisi

, Sr. Security Engineer, Synthesia; Preethi Kumaresan, Sr. Architect, AWS; Milan Williams, Sr. Product Manager, Semgrep: Fireside Chat -How Synthesia Automates AI Code Security Reviews: Built on AWS, Secured by Semgrep

Thursday, August 6

10:45 AM — Eric Carter, Director of Product Marketing, Sysdig:

Sysdig + Semgrep: From 10,000 Findings to the 10 That Matter2:00 PM — Neil Johnson, VP of Security, International Copyright Enterprise Services: Customer Talk

Come Find Us #

That's Semgrep's Hacker Summer Camp, top to bottom. But honestly, the best part of Hacker Summer Camp has never been the schedule. It's the conversations that happen in between. Request a meeting in advance or just come find us in person, we'd love to meet you IRL:

See a live look at Semgrep in action and snag some limited edition swag at our booth.

Join Semgrep, ArmorCode, AWS, and Sysdig for a fun night of gaming (no pitches!) at It's All Fun and Games, Thursday, August 6, 7-10 PM. Spots are limited.

.__RSVP Required__Grab a booster pack of our “Semgrep Threat Dex” stickers at the booth, celebrating(?) the last 12 months in cyber security. From the Shai-Hulud supply chain attacks, to the briefly-banned Mythos, and the OWASP Top 10 2025, there are 22 to collect or (avoid?).

Visit the AWS booth (#1648) Thursday, August 6, 3:30 PM to see a demo presented by Milan Williams:Using Chat Agents Securely Without Losing Company IP.

Need help with the rest of the week? Space Rogue covered [ how to survive it](https://semgrep.dev/blog/2026/black-hat-usa-2026-survival-guide/), and Dr. Katie covered

[.](https://semgrep.dev/blog/2026/so-its-your-first-time-at-hacker-summer-camp-and-you-want-to-make-the-most-of-it/)

__what to do if it’s your first time__But for now: hydrate, pack smart, and start banking your sleep hours now. See you in Vegas!

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @semgrep 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/summer-of-semgrep-ev…] indexed:0 read:7min 2026-07-22 ·