OpenSSF at Hacker Summer Camp 2026: Black Hat & DEF CON Highlights and Recap

By September 4, 2026Blog

By Laura Guazzelli

Las Vegas was once again the center of the cybersecurity universe from August 1–9 for Black Hat and DEF CON 2026. The Open Source Security Foundation (OpenSSF) had a major presence throughout the week, engaging with security leaders, project maintainers, and the broader community to advance open source security.

Whether you joined us to dive deep into software supply chain security, learned about the latest in open source secrets management, or grabbed a drink with fellow security advocates, here is a look back at OpenSSF’s highlights from Hacker Summer Camp.

Community Connections at the OpenSSF Happy Hour

Bringing everyone together to take a break from the busy conference floors provided a welcome respite. We hosted a Happy Hour Reception at The Cosmopolitan’s Vesper Lounge on August 4 and thank everyone who joined us.

It was an incredible evening of networking, idea sharing, and catching up with open source security leaders and advocates. Thank you to everyone who registered and joined us for this exclusive event!

OpenSSF Community on the Big Stage at Black Hat USA

We were incredibly proud to see our members and project contributors taking the stage to tackle some of the most pressing issues in cybersecurity today. Christopher Robinson (CRob) took the stage at The Convergence for a highly interactive AMA panel, answering the community’s toughest questions about what we are still getting wrong in software supply chain security.

Beyond the Expo Floor: Why the Best Black Hat Value Happens in the ‘Hallway Track’

In the hallway conversations, we met with members, the community, and prospective members to discuss the OpenSSF and Akrites initiatives.

This year the topic for BlackHat was heavily focused on the explosive use of AI and security implications. As autonomous security tools such as Mythos and GPT-5.4-Cyber continue their relentless hunt for flaws, FIRST projects are actively documenting these automated vulnerability discoveries. As automated AI models scrutinize expansive dependency trees with increased precision, they are surfacing latent security flaws at a velocity that far exceeds the bandwidth of human-led security teams. We learned about industry initiatives and community presentations on AI security and the security of AI. What people are really struggling with is the volume of AI generated security findings and how to parse through the volume and quality of findings, from false negatives to vibe code introduction of new vulnerabilities and regressions.

We had several chats about what the OpenSSF and Akrites initiatives are trying to bring the community together to address the security of open source. OpenSSF working groups are working on long-term solutions to secure the ecosystem with the projects and to provide developer support with secure tooling and best practices.

CRob discussed the role that Akrites was formed to tackle a specific, urgent crisis: acting as a neutral broker to triage and remediate the hundreds of thousands of existing vulnerabilities currently being unearthed by AI scanning tools.

Speaking of CRob, he was part of a panel of experts on AI and cybersecurity with the press. 

 Community Spotlights & Member Shoutouts

A huge shoutout to our incredible community members and partner organizations who were on the ground this week, including teams from ActiveState, Aikido Security, G-Research, Sonatype, Snyk, Microsoft, AWS, Google, Cisco, Minimus, Red Hat, ReversingLabs, Trail of Bits, Kusari, Socket, and Sysdig.

It’s always a highlight to catch up with familiar faces driving the mission forward.

As we wrap up another successful Hacker Summer Camp, we are energized by the community’s dedication to securing the future of open source. We look forward to continuing these conversations and collaborations in the months ahead!

Stay connected. Subscribe to the OpenSSF newsletter for updates on upcoming events and initiatives.

About the Author

Laura Guazzelli is a Security Architect – AI/ML/LLM/Agentic Systems at The Linux Foundation/OpenSSF. Laura brings extensive expertise in partnering with engineering and product organizations to seamlessly integrate security into the development lifecycle. With a professional background encompassing DevSecOps, CI/CD, and the complexities of AI/ML governance, she is dedicated to fostering the human-centric processes and collaborative cultures that power robust security architectures alongside technical innovation.