Skip to content

What the Swarm brought home from DEF CON 34 and Black Hat USA 2026

Over half of the Swarm travelled to Las Vegas for DEF CON 34. They came home with a first-place trophy, a costume award, and a stronger case for why point-in-time testing is dying.

DEF CON 2026 Swarm

Over half of the Swarm travelled to Las Vegas this August. What did they bring back? A first-place trophy, a costume award, a stack of new research to unpack, and a stronger case for why point-in-time testing is dying.

That’s the short version, here’s the rest.

Two main events

Before DEF CON even started,  our very own Iain Jackson, James Sheppard and Jayson E Street ran a two-day training at Black Hat USA 2026: “Observe & Defend: using situational awareness and adversary mindset to counter social engineering”. Twenty external participants worked through the tradecraft we use to think and move like a real adversary, not just scan for one.

Then came DEF CON #34, where Dominika Pietrzak and Ibai Castells presented a talk on offensive AI agents. Clients, prospects, and colleagues filled the room. And if this wasn’t enough, after the madness of Hacker Summer Camp, another full training session by Iain, James and Jayson took place: “Simulated Adversary: Tactics & Tools Training.”

Competing where it counts

DEF CON culture rewards people who show up and do the thing, not just talk about it. Our team competed in three separate events.

We took first place in the Bug Bounty Village CTF ( congratulations to Ibai Castells and Pablo Sanchez). We also ran a live vishing challenge in the Social Engineering Village: voice phishing, in full costume, against the clock, where Iain Jackson and James Sheppard earned us a “Best Dressed” award. And another part of the Swarm built a hardware capture-the-flag project too, a custom electronic badge add-on, designed and built on-site over the course of the conference.

These weren’t party tricks. Bug bounty hunting, live social engineering, and hardware hacking all sharpen the same muscle: finding the weakness nobody thought to check.

Nobody wants another vendor promising miracles.

The conversations we held throughout the duration of both conferences mattered as much as the sessions. We kept hearing the same skepticism from security leaders: nobody wants another vendor promising “fully autonomous” AI pentesting as a silver bullet. Point-in-time, checkbox testing has become a commodity and most CISOs already know it.

One CISO we spoke with put it bluntly: “I don’t need to see another header vulnerability. I need to see how an attack would materially impact my business and cause irreparable harm.”  That’s the gap continuous, human-led testing closes. Business impact beats a long list of low-severity findings, every time.

Trends and threads

A few research threads from the week are worth flagging here. Not as deep technical breakdowns (those will be coming soon), but as signals for what to watch on your own attack surface.

Simple pretexts still beat complex ones. In live vishing challenges, urgency plus a human touch consistently outperformed elaborate scripts. Voice cloning has also gotten fast. One researcher cloned a voice in under thirty seconds using free, open-source tools, then used it to fool a helpdesk on a live call. Is identity verified by voice alone for your Helpdesk? If so, that’s definitely worth a second look.

AI agents are already exposed. One research project scanned the public web and found thousands of unauthenticated corporate AI agents and copilots sitting wide open. Separate research showed sandbox-breakout techniques working at scale against mainstream AI assistants. A newly disclosed vulnerability class allows zero-click account takeover against autonomous browser agents.

Patience is still a weapon. Ransomware groups like Cl0p reuse infrastructure across campaigns. They run low-and-slow reconnaissance for up to two years before deploying a zero-day. The software supply chain has a quieter problem, too: most of the most-downloaded AI models on Hugging Face still rely on the insecure “pickle” serialization format.

Even language matters. How you name and frame prompts and tools measurably changes whether an AI system resists or complies with an adversarial request. Flooding defensive teams with noise can mask the real objective of an attack. This reminded us of one of our podcast episodes from last year (Words as weapons – listen here).

Here’s the thread that runs through all of it: simple weaknesses still cause as much damage as the clever ones. A trusting helpdesk, an open copilot, an unpatched serialization format; none of them need a zero-day to matter. Red teaming that proves business impact beats red teaming that only proves a hack is possible. And the attack surface keeps growing faster than most security programs account for, from voice channels to AI agents to the software supply chain.

That’s the case we made in Las Vegas, on and off stage.


If you want to talk through what any of this means for your own environment, contact us.