Hydrate, Hack, Repeat: Security Summer Camp 2026

My schedule, a new role at Empirical Security, and the CVE and vulnerability talks worth your time.

It is almost the first week of August, which means it is time to point myself at the desert one more time. BSides Las Vegas, Black Hat, and DEF CON all land back to back, and for me it is the same ritual it has always been: an exhausting, sunburned, over-caffeinated, absolutely amazing week of reconnecting with the people who make this industry worth being in. If you have never done all three in a row, a word of warning: hydrate, wear real shoes, and clear your calendar for the following Monday.

This year the trip feels a little different, because I am showing up with some news.

Big News: I Joined Empirical Security

A few weeks back I announced that I have taken on the role of Head of Research at Empirical Security. I wrote about why in Country Roads, Take Me Home, but the short version is that this is a homecoming. Empirical is where the math actually gets done: predictive models, EPSS, and the kind of data-driven vulnerability management I have been talking about for years, built alongside people I have wanted to work with again for a long time.

The thesis I keep coming back to is simple: you cannot run a data-driven VM program on top of abstracted, artificially grouped vulnerability data. The numbers make the case. The first half of 2026 produced 34,601 CVEs, up nearly 49% over last year, and only 0.24% of them have landed in the CISA KEV catalog. KEV is a conservative floor, not a full exploitation census, so the real number runs higher, but even generously, exploitation stays a small fraction of the total. You cannot triage that flood, let alone predict it, unless the underlying data stays granular, transparent, and accurate. That is the work, and it is the thread that ties together everything on my schedule this week.

Where to Find Me in Vegas

I am on stage (and at a lunch table) a couple of times this week. Come say hi.

EventSessionWhen / Where
BSides Las VegasPanel: I am CVE, AMA!, with Tod Beardsley, Lindsey Cerkovnik, Madison Ficorilli, and Katie Noble (Common Ground track)Wed, Aug 5, 12:00-12:45pm PT, Tuscany Suites
Black HatPanel Luncheon: Universal Zero Trust in the Age of Autonomous Exploitation, with Dr. Chase Cunningham and Vikram Bedi (JP Morgan Chase)Thu, Aug 6, 12:00-1:30pm PT, Cipriani at the Wynn

The BSidesLV panel is the one I never miss. Last year we ran out of time before we ran out of questions, so bring the hard ones. The Black Hat luncheon is the one I am most curious about, because “what defenders do when AI collapses the gap between discovery and exploitation” is exactly the problem I moved to Empirical to work on. Seats are limited, so grab one if the topic is your thing (the free lunch from Cipriani does not hurt).

Fair warning: both of my sessions are in the noon slot, so a few of the talks I recommend below run at the same time. Choose wisely. I will be at DEF CON too, so if you want to meet up there, just reach out.

The Talks I’d Clear My Calendar For

Enough about me. I went through all three schedules and pulled the CVE, vulnerability, and exploitation talks that made my own must-see list, grouped by con and in rough time order. One theme jumps out of every program this year: AI is now doing vulnerability research at scale, and the gap between discovery and exploitation is collapsing. That is the exact thread running through my Black Hat panel, so I am biased, but the lineups back it up.

BSides Las Vegas

Black Hat

DEF CON 34

Let’s Connect

Summer Camp is, and always has been, about the people. If you want to talk CVE data, EPSS, and predictive VM, or just trade stories from the hallway track, find me. I will have a fresh run of stickers to hand out, so track me down before they are gone.

You can find me on LinkedInXBluesky, and infosec.exchange, or just yell my name in a hallway at any of the three cons. It usually works.

And tell me: what is the one talk you are not missing this year? I am always looking to fill the gaps in my own schedule.

See you in the desert. Stay hydrated.


One More Thing: Breakfast?

Still reading? Then you have earned an invite.

RogoLabs presents: Breakfast Forecast
Decoding Risks: From Omelets to Zero-Days

Quick context, since the top of this post is all Empirical: RogoLabs is my personal open-source research lab, the shingle I hang my side projects under when I am off the clock. Once a year, it also does breakfast.

  • When: Friday, Aug 7 (DEF CON), 8:00 AM
  • Where: The Peppermill, Las Vegas
  • Seats: Capped at 20, so this one is for the folks who made it to the bottom of the post
  • RSVP: [email protected] or Signal jgamblin.01

First come, first served. Bring your appetite and your hardest questions.

A digital illustration of the Las Vegas skyline at twilight from a desert viewpoint. Overlaid over the scene are intricate, glowing, and colorful holographic data visualizations, including 3D scatter plots, network graphs, and flowing waveforms.

Site Footer