Skip to Content

Discover Our Newest Resources Resource Center

Dark teal and black gradient

Blog

Hacker Mindset, Defender Strategy: 7 Takeaways from DEF CON 2026 

Every year, DEF CON brings together the people who think about security from every angle: researchers, hackers, defenders, builders, and curious problem-solvers who want to understand where technology is strongest, weakest, and headed next. Held August 6–9, 2026, in Las Vegas, Nevada, DEF CON 34 continued its reputation as one of the world’s largest and longest-running hacker conferences, drawing roughly 25,000 attendees for four days of technical talks, hands-on villages, contests, workshops, and real-world security research.  

For Tevora’s Threat Management and Response team, the event was an opportunity to network with other experts across the field and discuss the issues that are continuing to shape today’s cyber defenses, explore emerging attack techniques, and bring back practical insights that can help organizations strengthen detection, response, and resilience.  

If you missed DEF CON, here are some of the biggest takeaways from this year’s conference. 

1. AI Is an Active Part of the Attack Surface 

One of the clearest themes from this year’s DEF CON was the clear move from AI as a general productivity tool to AI as an operational component of both attack and defense. Talks and workshops focused heavily on agentic AI, local models, and security-specific AI workflows, highlighting how quickly AI systems are evolving from generating information to taking action across connected tools, applications, APIs, and data sources. 

That shift introduces a broader and less familiar attack surface. AI agents that can browse repositories, interact with websites, execute workflows, or connect to enterprise systems may create new opportunities for prompt injection, supply chain manipulation, data exposure, and misuse of delegated permissions. For security teams, the takeaway is clear: AI security cannot be treated as a narrow governance or policy concern. It must be tested, monitored, and validated as part of the broader application and infrastructure environment. 

2. AI Is Changing Both Offensive and Defensive Workflows 

DEF CON also reinforced that AI is a reality for security work on both sides of the equation. Offensive demonstrations showed how AI can support reconnaissance, exploitation, vulnerability discovery, and social engineering with less manual intervention. Defensive use cases focused on threat hunting, vulnerability analysis, detection engineering, workflow automation, and incident response support. 

The team’s takeaway is that security organizations should expect AI-enabled activity to become more common, faster, and more accessible. As attackers use AI to scale research and execution, defenders will need to apply the same speed and automation to detection, triage, and response. The organizations that benefit most will be those that pair AI-driven efficiency with disciplined validation, human oversight, and strong security controls around the tools themselves.  

3. Code Quality and Application Testing Matter More as AI Accelerates Development 

Unsurprisingly, today’s speed-focused AI-assisted development is expected to impact future application security. As AI coding tools and agents allow teams to produce more code more quickly, the volume of code requiring review also increases.  Not to mention that AI-assistance lowers the required level of expertise to create and ship code. 

If review processes, secure coding practices, and testing coverage do not keep pace with the increased volume, organizations may ship more defects, insecure patterns, and exploitable logic into production environments. 

This makes comprehensive application testing even more important, especially for custom applications that may not appear externally exposed but still create opportunities for internal movement. Web applications remain important, but DEF CON’s conversations pointed to a broader testing need across internal tools, APIs, AI-enabled workflows, and applications built or accelerated with AI assistance. 

4. Hardware, Wireless, and Embedded Systems Still Present Overlooked Risk 

Beyond AI, several hands-on villages and workshops highlighted persistent risk in hardware, wireless, and embedded systems. Sessions involving CAN bus communications, Wi-Fi, RFID, badge cloning, and device testing showed how common technologies can expose meaningful weaknesses when physical access, low-cost tools, or short-range wireless connectivity are available. Small technical gaps can have a significant impact. 

For example, CAN bus systems, which are used across vehicles, boats, heavy machinery, and industrial equipment, often carry operational commands and sensor data. When these systems lack strong protections, attackers with physical or nearby wireless access may be able to capture, replay, or manipulate signals. The broader lesson is that security teams should not overlook embedded systems, operational technology, wireless interfaces, and hardware-adjacent environments simply because they fall outside traditional IT and cloud security programs. 

5. Social Engineering Continues to Evolve with Technology 

The social engineering content at DEF CON underscored that attackers continue to adapt their techniques to match current expectations and behaviors. (One notable example involved a vishing scenario where the attacker impersonated an AI agent!)  

As organizations become more comfortable interacting with automated systems, attackers may exploit that familiarity by blending social engineering with the language and behaviors of AI-powered tools. 

This reinforces the need for security awareness programs to evolve alongside the threat landscape. Employees should be prepared not only for traditional impersonation attempts, but also for scenarios involving automation, AI-branded services, voice interactions, and other techniques that may appear legitimate because they mirror familiar digital experiences. 

6. Accessible Tools Are Lowering the Barrier to Advanced Testing 

Across workshops and villages, there was a strong emphasis on accessible, hands-on security tooling. Topics such as Scapy, local AI models, wireless testing, RFID, IoT, cryptography challenges, and hardware hacking demonstrated that sophisticated techniques can often be practiced with open-source software and relatively inexpensive equipment. 

That accessibility is useful for defenders because it makes experimentation, training, and validation more practical. At the same time, it means attackers have access to the same tools and learning pathways. Organizations should assume that techniques once considered specialized may become more widely used as tooling becomes easier to obtain, configure, and share. 

7. Security Is Still About Ownership, Interoperability, and Resilience 

A broader theme that emerged from the conference was the importance of ownership and control over systems, data, and devices. Discussions around interoperability and the right to repair connect directly to security because they determine whether organizations and individuals can inspect, maintain, move, and secure the technologies they rely on. 

When products are closed, difficult to repair, or designed in ways that limit visibility, defenders may have fewer options to assess risk or respond effectively. Resilience depends not only on controls and monitoring, but also on the ability to understand, maintain, and adapt the systems that support business operations. 

 

What This Means for Security Teams 

DEF CON 34 made one thing clear: the modern attack surface is expanding in both expected and unexpected directions. AI agents, internal applications, wireless systems, embedded devices, satellite infrastructure, and social engineering techniques are all evolving quickly. For defenders, the challenge is not just to understand each trend individually, but to recognize how they intersect. 

Tevora’s Threat Management and Response team left DEF CON with practical, field-informed insights that reinforce the value of proactive testing, continuous threat awareness, and adaptable defensive strategies. As attackers gain access to more capable tools and broader attack paths, organizations need security programs that are equally hands-on, curious, and prepared to test assumptions before attackers do. 

Authors

Kevin Dick
Senior Director, Threat Services
Kevin is an information security professional with expertise in penetration testing. Kevin’s threat research expertise includes network, web, and mobile application penetration testing, development of internal Tevora penetration testing and social engineering tool kits, malware analysis, and incident response. 
View Bio   More Posts By This Author