AI is reshaping how security teams discover threats, investigate them, and defend against them. As AI systems grow more capable of analyzing a situation, deciding, and acting on that decision, automation and human expertise need to work together more closely.
That shift set the agenda for Security Bootcamp 2026, the 12th edition of Vietnam’s annual cybersecurity event, held September 10–12 in Buon Ma Thuot, Dak Lak. Based on the Agentic Security theme, the event gathered more than 300 cybersecurity professionals, researchers, government representatives, and technology organizations to explore how AI is transforming both offensive and defensive security alike.
For the second consecutive year, OPSWAT joined the event to share practical research, trade insights with Vietnam’s cybersecurity community, and put that expertise to the test in the Security Bootcamp Arena.
From Post-Patch Exploitation to AI-Driven Security Research
Coming back for a second year gave OPSWAT another chance to show Vietnam’s cybersecurity community how our research evolves alongside new technologies and emerging threats.
At the 2025 edition, Loc Nguyen of OPSWAT Unit 515 presented “Breaking the Fix: A Technical Approach to Post-Patch Exploitation,” sharing our research into how security patches can be analyzed to identify incomplete fixes and residual security risk.
This year, our focus shifted to another rapidly evolving area: the role of AI agents in cybersecurity research.
On the second day of Security Bootcamp 2026, Khoi Tran of OPSWAT Unit 515 demonstrated how an AI agent can support firmware reverse engineering and vulnerability discovery on a real-world IoT target.

One key lesson was that AI delivers the greatest value when it is given the right context, clear objectives, and guidance from experienced researchers. With that foundation, AI can help researchers explore complex systems more efficiently, uncover potential security risks, and accelerate traditionally time-intensive analysis.
The research demonstrated how AI can become a practical part of the vulnerability research workflow, helping security researchers work through complex targets more efficiently.
Rather than replacing security expertise, the value comes from combining AI’s ability to rapidly explore and analyze complex technical environments with the experience and direction of security researchers.
Agentic Security Is About More Than AI
One message ran through the entire event: as AI agents become more capable of analyzing, deciding, and acting, cybersecurity must evolve with them. Agentic Security is not simply about bringing AI into existing workflows but also about ensuring that greater autonomy comes with the right level of control, visibility, and human oversight.
Speakers showed AI agents applied to security operations, cloud detection and response, vulnerability research, code analysis, and malware investigation. These examples demonstrated AI’s potential to help security teams process complex information faster, connect signals across multiple sources, and automate parts of traditionally manual workflows.

But greater autonomy also introduces new security considerations.
Once an AI system can act, organizations need to think beyond model accuracy. Identity, permissions, tool access, context, validation, auditability, and human oversight all become part of the security boundary.
This was a recurring message throughout the event: the goal should not be maximum autonomy, but governed and verifiable autonomy.
AI agents can accelerate investigation and reduce repetitive work, but important decisions still require clear controls and appropriate human oversight. For cybersecurity teams, the opportunity lies in finding the right balance: allowing AI to operate at greater speed and scale while ensuring that its actions remain controlled, traceable, and aligned with security policies.
For us, the rise of Agentic AI reinforces a principle already at the core of our security approach: Zero Trust. As AI takes on a greater role in cybersecurity, ensuring that the data and workflows behind every action are verified, controlled, and protected becomes even more critical.

Putting Cybersecurity Expertise into Action
Alongside the presentations and discussions, Security Bootcamp offered an opportunity to put cybersecurity skills into practice.
The Security Bootcamp Arena 2026 brought teams into a competitive Attack vs. Defense environment designed to test technical expertise, teamwork, and the ability to respond under pressure.
The competition began with a series of CTF challenges focused on offensive security. Each solved challenge required teams to identify and successfully exploit a weakness in the target environment, earning points and demonstrating their ability to turn vulnerability analysis into practical results.

From there, the competition expanded into a more complex scenario. Teams were given infrastructure representing an organization affected by a ransomware attack and had to investigate the compromise, restore critical systems, remediate vulnerabilities, maintain service availability, and defend against competing teams.
At the same time, teams could analyze and attack other teams’ servers. A successful compromise earned points for the attacking team while reducing the score of the team being attacked, creating a continuous cycle of attack, defense, remediation, and adaptation throughout the competition.

The Arena brought together multiple cybersecurity disciplines in one environment, from offensive and defensive security to incident response, vulnerability analysis, system administration, and rapid decision-making.
For OPSWAT Unit 515, it was an opportunity to apply the same mindset we bring to vulnerability research and penetration testing: identify weaknesses, validate real impact, understand how attacks work, and use that knowledge to strengthen defense.
This was Unit 515’s second year competing in the Security Bootcamp Arena, and for the second year in a row, Unit 515 was the first team to complete all offensive security challenges.

This year, Unit 515 combined strong offensive security expertise with effective AI-agent adoption to work faster, adapt quickly, and compete at a higher level. We were proud to finish with Second Prize at Security Bootcamp Arena 2026, among nearly 30 cybersecurity teams from different organizations.

Beyond the ranking, the Arena reinforced an important lesson for our team: effective cybersecurity requires understanding both sides of the equation: how systems can be compromised, and how they can be restored, hardened, and defended against the same techniques.
What We Took Away from Security Bootcamp 2026
Across the talks, technical discussions, and competition, several themes stood out for our team.
AI is becoming part of both sides of cybersecurity.
The same technologies that help defenders analyze incidents and automate security operations can help offensive teams accelerate reconnaissance, vulnerability discovery, and attack-path analysis.
Scale is becoming a security capability.
AI enables researchers to analyze targets and technical data at a scale that traditional manual workflows cannot easily match. The challenge is ensuring that increased speed does not come at the expense of accuracy and validation.
Human expertise becomes even more important. As AI gains more autonomy, researchers need to understand when to trust its conclusions, when to challenge them, and when deeper manual investigation is required.
Security research must remain practical.
Whether analyzing an AI-generated attack path, investigating a vulnerability, or responding to a simulated ransomware incident, the real value comes from testing each finding against the real system: the attack path has to execute, the exploit has to land, the recovery has to hold.
And finally, community matters as much as technology.
Security Bootcamp continues to provide an environment where researchers, practitioners, organizations, and the wider Vietnamese cybersecurity community can openly exchange ideas, share technical research, and learn from one another.
Continuing the Journey
For Unit 515, Security Bootcamp 2026 was more than an event.
It was an opportunity to share what we have been researching, challenge ourselves against other talented security teams, learn from the wider community, and see firsthand how quickly AI is changing cybersecurity.
From post-patch exploitation research in 2025 to AI-driven security research and Agentic Security in 2026, our focus remains the same: exploring emerging attack techniques, understanding how new technologies change the threat landscape, and turning research into practical security knowledge.
Winning Second Prize at the Security Bootcamp Arena was a memorable way to close this year’s event, but the conversations, technical insights, and lessons we brought back with us are just as valuable.
These lessons also connect closely with how OPSWAT is bringing AI into the next generation of critical infrastructure protection. Through the MetaDefender AI-Powered Platform, OPSWAT combines AI with a Zero Trust, prevention-first approach to help organizations scan, sanitize, verify, and control data before it moves deeper into critical environments.
As AI continues to reshape cybersecurity, the connection between research and real-world protection becomes even more important. Unit 515 will continue exploring emerging threats and AI-driven security techniques, while helping turn those insights into stronger technologies and solutions that protect the world’s critical infrastructure.
