top of page

CYBER & INFOSEC

"blogger, InfoSec specialist, super hero ... and all round good guy" 

DISCUSSIONS, CONCEPTS & TECHNOLOGIES FOR THE WORLD OF

JOIN THE DISCUSSION

Black Hat & DEF CON 2025: Where AI Meets Adversaries

  • Writer: Aamir Lakhani
    Aamir Lakhani
  • Aug 26
  • 3 min read

My annual pilgrimage to Las Vegas for Black Hat USA and DEF CON—what many of my friends affectionately call “Hacker Summer Camp”—took place from August 2–7, 2025, at the Mandalay Bay Convention Center, with DEF CON extending the festivities through August 10 at the Las Vegas Convention Center.


ree

Last year’s highlight was me catching Cirque du Soleil: Michael Jackson ONE. This year, I was hoping to see the Backstreet Boys at The Sphere—but after a few disapproving looks from my friends, that plan didn’t quite happen.


AI Everywhere (and I mean everywhere)


If there was a single dominant theme at Black Hat this year, it was AI. I heard the term “AI” at least once an hour—sometimes more. It was the focus of countless talks, hallway conversations, and vendor pitches. Organizers framed the event around the “escalating arms race between malicious generative AI tools and the defensive AI systems built to stop them.”


Real-world demos included AI-generated phishing campaigns, deepfake voice attacks, and offensive AI techniques that stretched the imagination of even seasoned attendees.

At the opening keynote, Mikko Hyppönen, outgoing Chief Research Officer at WithSecure, captured the duality of the moment:


“I do believe that AI is the key [in security] because that’s one of the few fields where defenders are ahead of the attackers. All the cybersecurity companies here will tell you how extensively they use generative AI in their products.”

But Hyppönen also warned that the advantage won’t last forever—attackers are closing the gap, with AI systems already credited with discovering around two dozen zero-day vulnerabilities in 2025.


IR Shortcuts, AI Reversers, and Missed Opportunities


Microsoft’s incident response panel spotlighted “cheat codes” for accelerating threat containment. Yet they also revealed a sobering fact: only 26% of organizations rehearse incident response plans in practice.


Meanwhile, Booz Allen’s “Vellox Reverser” stole the expo floor—a cloud-native, AI-first malware reverse-engineering platform designed to turn binaries into actionable defensive guidance in minutes.


My Research: Targeting at Scale with AI


I also had the opportunity to showcase some of the research I have been conducting. I demonstrated how threat actors could potentially fine-tune AI to identify and target high-profile individuals at scale.


By combining facial recognition systems with social media data, attackers could filter targets by county, geolocation, or even inferred personality traits. AI could then automate both target selection and custom attack generation.


While our work was presented as a theoretical scenario, I don’t think we’re far from seeing adversaries experiment with these exact techniques in the wild.


DEF CON: Hands-On and Community-Driven


Over at DEF CON, AI wasn’t just a buzzword—it was hands-on. Specialized training sessions like “Solving Modern Cybersecurity Problems with AI” taught attendees how to build their own AI frameworks, from ingestion pipelines to defending against adversarial attacks.


Of course, DEF CON wouldn’t be complete without LineCon, the rite-of-passage badge pickup experience. With the move to the Las Vegas Convention Center, LineCon has evolved but kept its soul.


  • Badge pickup started Thursday at 8:00 AM, with the hardcore arriving at 4–5 AM.

  • Prices rose to $500 cash (up from $460 in 2024), with pre-purchase options reaching $580.

  • Despite online pre-sales, the two lines still merged, ensuring the wait lived on.


But LineCon was less a chore and more a celebration: DEF CON goons blasting music from backpack speakers, swag giveaways, and the legendary beach ball passing made it arguably “the most fun line you’ll ever stand in.” Wait times were 1.5–2.5 hours, but the atmosphere made it fly by.


Final Reflections


Black Hat and DEF CON once again delivered an action-packed week for the global cybersecurity community. Black Hat’s business- and research-driven briefings contrasted with DEF CON’s raw, hands-on hacking chaos—but together they reflect the innovation, urgency, and community spirit that define this industry.


Would I change my approach next year? Absolutely. After years of hitting both conferences back-to-back, I’ve realized it’s exhausting—especially when I inevitably fail at staying hydrated or eating properly. Next year, I’ll likely skip Black Hat and stick to DEF CON (and maybe BSides), where I find the technical depth and community interaction align more closely with my interests.

For now, I’ll be keeping an eye out for the detailed reports and follow-up research that always emerge in the weeks and months after Hacker Summer Camp.

6 Comments


John Adam
John Adam
Oct 30

Your post on Black Hat & DEF CON 2025 really captured the tension between innovation and threat reading how AI tools were both shields and spies had me thinking about how we all face pressures in different arenas. It reminded me of a time when my academic workload felt like a battlefield, and I quietly wondered if I should pay someone to complete my Sophia course, not to bypass learning, but simply to find a moment’s peace so I could regroup and come back stronger. Thanks for sharing such a raw perspective it reminded me that whether in code or coursework, sometimes the biggest move is giving ourselves space to reset.

Like

John. Snow.
John. Snow.
Oct 07

That post on Black Hat and DEF CON 2025 was really interesting, AI is truly redefining the boundaries between innovation and cybersecurity risks. It’s impressive how experts are addressing these evolving digital threats. On a different note, The Online Class Help also operates in the digital sphere, assisting students with their online coursework. Both platforms, in their own ways, highlight the growing importance of adapting to technology-driven challenges.

Like

Harriet Armstrong
Harriet Armstrong
Oct 07

When Jordan attended Black Hat & DEF CON 2025, he was fascinated by how rapidly AI was transforming cybersecurity. The conference buzzed with talks about ethical hacking, evolving digital threats, and how AI could both defend and deceive. During one intense workshop, he discussed strategies similar to those used by McGraw Hill test-taking experts, who analyse complex problems and think critically under pressure. It reminded him that whether in hacking or studying, precision and adaptability matter most.

Like

Jenny Eastwood
Jenny Eastwood
Sep 12

The finished result was precise and well-organised, and it was beyond all of my expectations. After utilising Global Assignment Help's outstanding Assignment Help UK service, I feel comfortable referring them to others. Their staff of exceptionally talented writers and researchers is extremely informed and proficient in the field. I decided to give their Assignment Help London a go after this encounter, and I was astounded by how reliable and excellent it was.

Like

doctorchaos.com and drchaos.com is a blog dedicated to Cyber Counter Intelligence and Cybersecurity technologies. The posts will be a discussion of concepts and technologies that make up emerging threats and techniques related to Cyber Defense. Sometimes we get a little off-topic. Articles are gathered or written by cyber security professionals, leading OEMs, and enthusiasts from all over the world to bring an in-depth, real-world, look at Cyber Security. About this blog doctorchaos.com and drchaos.com and any affiliate website does not represent or endorse the accuracy or reliability of any information’s, content or advertisements contained on, distributed through, or linked, downloaded or accessed from any of the services contained on this website, nor the quality of any products, information’s or any other material displayed, purchased, or obtained by you as a result of an advertisement or any other information’s or offer in or in connection with the services herein. Everything on this blog is based on personal opinion and should be interoperated as such. Contact Info If you would like to contact this blog, you may do so by emailing ALAKHANI(AT)YMAIL(DOT)COM  

SOCIALS 

SUBSCRIBE 

Keeping you informed | Latest News

© 2018 Dr. Chaos 

bottom of page