Omsätt insikter i handling: Bitwarden Access Intelligence är nu tillgängligt Läs mer >

Bitwarden-bloggen

Open Source Security Summit 2026 recap: Hacking history, AI risk, and physical industry security

BE
skriven av:Bitwarden Events
publicerad :

As AI accelerates both attack and defense, speakers at the 7th annual Open Source Security Summit kept returning to one question: where does human judgment matter most?

Authors, journalists, and practitioners explored the roots of hacking culture, the growing overlap between cyber and AI risk, and how physical industries protect critical assets. Along the way, they traded war stories, debated where AI helps or complicates security efforts, and shared lessons on legacy systems, third-party access, and incident response.

To explore past summits, session recordings for 2025, 2024, 2023, 2022, 2021, and 2020 are available at opensourcesecuritysummit.com or on the Bitwarden YouTube channel.

Fireside chat with Joseph Menn: The hacking community's untold history

Adrian Sanabria, founder of the Defenders Initiative and host of the Enterprise Security Weekly podcast, sat down with journalist Joseph Menn, author of “Cult of the Dead Cow,” to discuss why the origins of hacking culture still matter now more than ever.

The conversation ranged from bulletin boards and sky-high long-distance phone bills to the founding of billion-dollar security companies, the birth of hacktivism, and the rise of nation-state-backed groups adopting activist personas. Throughout, Menn made the case that the scrappy, rule-bending origins of the field still shape how strong security practitioners think.

"Hackers, by definition, are critical thinkers because they're looking at something that was built for one thing and wondering what else they can do with it and how to break it. That's a precious thing." - Joseph Menn

Sanabria and Menn also explored why black-box security products can lose their edge, how an antivirus engine became an attack vector, and what happens when AI finds vulnerabilities faster than engineers can triage them.

"It's this land rush to find vulnerabilities. So much more is now visible. Decades of technical debt are coming due at the same time, and it’s going to be a wild ride for a year or two. But at the end of it, a lot of stuff is going to get patched that has been there working for a long time, and that's a good thing." - Joseph Menn

The session closed with a look at what the Cult of the Dead Cow is building today.

Fireside chat with David Sanger: Cyber, AI, and the new cold wars

Rick Howard, CEO of the CyberCanon Project, welcomed David Sanger, national security correspondent for The New York Times and author of “The Perfect Weapon” and “New Cold Wars,” to revisit whether cyber is still the perfect weapon in the AI era.

"I'd probably call AI a more perfect weapon because what it manages to do is take all of those things that one could do with cyber, automate them, speed them up, and make them much better at hiding their tracks." - David Sanger

From there, the conversation moved across AI agents that broke out of a test sandbox and left notes for future agents on hiding their activity, why nuclear-era arms control doesn't map cleanly onto code, whether an AI kill switch is possible, and how the XZ Utils backdoor complicates attribution across the open source supply chain.

Sanger also revisited stories from “The Perfect Weapon,” including a lesser-known U.S. operation that sabotaged North Korean missile testing, sending them into the sea, and what those examples reveal about the limits of cyber operations.

"Cyber is an incredibly powerful weapon, but it may not be terribly permanent." - David Sanger

His closing advice offered a useful lens for following AI developments: ask which lessons from the cyber age still apply.

Panel: Protecting critical assets across physical industries

Mary Writz, chief product officer at Bitwarden, moderated a discussion with Anthony Green, chief technology officer at FoxTech Cyber, and Sean Habing, director of information security at Pollard Banknote, on defining and defending critical assets when operational technology (OT), legacy systems, and third-party access are all in play.

Drawing on experience across railways, airports, government systems, and the lottery industry, the panelists covered monitoring OT devices that cannot produce audit logs, managing vendor access on legacy systems, and deciding when AI should act autonomously.

"If you haven't got sight of what things you have on the ground, what infrastructure you've got, what equipment, what's talking to what... how are you going to know what you've got to update?" - Anthony Green, FoxTech Cyber

Some of the most memorable moments were also among the most practical:

  • How a firewall with a physical switch can give operators direct control over when machine builders have remote access. 

  • Why a sporting event scoring system might stay online even if it's riddled with malware

  • Why security leaders should have the direct contact information of critical team members before a major incident

"AI can help us make decisions faster, but it doesn't remove the need for human judgment or accountability at the end of the day." - Sean Habing, Pollard Banknote

Watch the full sessions

From hacking history to nation-state cyber operations to OT and legacy systems, all three sessions returned to the same fundamentals: observability, critical thinking, and human accountability, even as AI reshapes the pace of both attack and defense.

Each conversation goes deeper than a recap can. Watch all three sessions from the 7th annual summit at opensourcesecuritysummit.com or on the Bitwarden YouTube channel.

Back to Blog

Get started with Bitwarden today.