Your Last Pentest Is Already Out of Date.
AI ships code faster than humans can test it.
Sara (Synack Autonomous Red Agent) doesn't wait for your next scheduled engagement — she hunts continuously, while elite human researchers confirm what's actually exploitable.
August 6–9 | Las Vegas Convention Center
What happens in your 30 minutes with us
No slides. No pitch. A direct technical conversation about the gap between your last test and right now.
Your attack surface changed while you were waiting for the next test.
We'll walk through how AI-generated code, API sprawl, and continuous deployment create exposure windows that point-in-time testing was never designed to catch.
Agentic AI that hunts continuously — with humans confirming what's actually exploitable.
Sara (Synack Autonomous Red Agent) identifies, validates, and prioritizes exploitable risk around the clock, while the Synack Red Team cuts the false positives and confirms what's actually exploitable — signal over noise.
Be among the first to see our State of Continuous Security Validation findings.
Data from real programs on how teams are adapting — or failing to adapt — to the speed of modern deployment. Not a vendor whitepaper. Actual numbers from the field.
Based on Synack program data.
Spots are limited. Request a meeting and we'll confirm your slot.
Catch Synack at DEF CON 2026
Synack team members will present at DEF CON 34 across these sessions.
Navigating AI-Assisted Submissions
AI is reshaping offensive security and Bug Bounty, creating new questions around submission volumes, program scope, report quality, and platform processes. This panel explores the challenges platforms are facing, the solutions they're putting in place, and what researchers can do to succeed as AI-assisted security testing becomes increasingly common.
Eddie Rios
Synack — Panelist
Joined by Tony Lee (HackerOne), Michael Skelton (Bugcrowd), Alexander Wren (Intigriti), and Selim Jaafar (YesWeHack). Moderated by Shlomie Liberow.
Reflections on Disregarding Trust
Weaponizing CDP and MHTML for Header-Agnostic Session Hijacking
Adversary-in-the-Middle (AitM) phishing has become the de facto standard for bypassing legacy MFA, but modern frameworks break against strict client-side security headers like SRI and CSP. This talk introduces a "Browser-in-the-Middle" architecture that weaponizes the Chrome DevTools Protocol to neutralize SRI and CSP organically, then uses a JIT JavaScript shim to silently harvest post-MFA tokens from major IdPs including Okta, Microsoft, Google, and Shibboleth.
Gregory "1umberhack" Disney-Leugers
Senior Penetration Tester · Synack