David Bombal

Follow David Bombal
Share on
Copy link to clipboard

Want to learn about IT? Want to get ahead in your career? Well, this is the right place! On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics. This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content. David’s details: Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co Website: http://www.davidbombal.com YouTube: https://www.youtube.com/davidbombal All the best! David

David Bombal


    • Sep 12, 2026 LATEST EPISODE
    • weekdays NEW EPISODES
    • 28m AVG DURATION
    • 602 EPISODES


    Search for episodes from David Bombal with a specific topic:

    Latest episodes from David Bombal

    #605: Flock Cameras: What They Can Reveal About Your Life

    Play Episode Listen Later Sep 12, 2026 22:10


    Big thank you to DeleteMe for sponsoring this video. Use my link join https://joindeleteme.com/Bombal or use the QR code in the video to get 20% off. Your license plate could reveal more than you think. Flock cameras, vehicle tracking and OSINT can turn information about your car into clues about where you live and your daily routines. I'm joined by an OSINT expert to discuss how vehicle information can be connected with public records, why surveillance raises privacy concerns and what happens when people trust an incorrect license plate match. He shares his experiences of locating a missing car after a police search came up short and investigating a hit-and-run using a partial plate and publicly available information. We discuss: • Flock cameras and vehicle identification beyond license plates • How vehicle data can expose patterns in your movements • License plate recognition errors and the importance of verification • How public records can connect a vehicle to a person • The risks of surveillance access being abused • Privacy measures, their limitations and the need for accountability • DeFlock and community scrutiny of surveillance cameras How much can someone discover about you from the information you leave exposed? // Mishaal Kahn's SOCIALS // LinkedIn: / mish-aal Website: https://www.mishaalkhan.com/ Tool created: https://www.operationprivacy.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:47 - The Growing Flock Camera Controversy 01:28 - What Are Flock Cameras Actually Collecting? 02:33 - Police Misuse and Abuse of Surveillance Data 03:45 - Mapping and Avoiding Flock Cameras 04:57 - How Personal Data Fuels Scams 06:54 - What Can Police Actually Do With Flock Data? 07:12 - Testing Flock: A Real Missing Vehicle Case 09:09 - How Mishaal Found the Vehicle Himself 10:20 - Drones: The Next Level of Surveillance 11:11 - How Can You Protect Your Privacy? 13:07 - Facial Recognition Is Expanding Everywhere 14:13 - AI Can Rebuild Your Entire Pattern of Life 15:51 - What Can Someone Find From Your License Plate? 17:16 - Solving a Hit-and-Run With a Partial Plate 19:08 - What Could a Rogue Police Officer Do? 20:28 - Is There Any Hope for Privacy? 21:53 - Where to Learn More About Privacy and OSINT Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #flockcameras #defcon #privacy

    #604: How He Infiltrated LockBit and Helped Get Them Indicted

    Play Episode Listen Later Sep 12, 2026 24:29


    Big thanks to Proton Drive for sponsoring this video. You can use my link http://proton.me/drive/davidbombal to sign up for Proton Drive and get 40% discount. John DiMaggio created fake identities, profiled ransomware operators and spent approximately 18 months earning the trust of LockBit. In this interview, John explains how his investigation led to work with the FBI and the UK's National Crime Agency, contributed to indictments and resulted in death threats against him. He also reveals how the work affected his mental health, relationships and everyday life. John shares the remarkable story of a young REvil hacker connected to the Kaseya ransomware attack and its $70 million ransom demand. He explains how ransomware operators are recruited, manipulated and sometimes controlled by intelligence agencies. You will also learn why stolen cryptocurrency is difficult to spend, how Bitcoin tracing and money-laundering mistakes expose cybercriminals and why technical hacking skills do not make someone good at hiding money. Finally, John warns aspiring researchers not to approach ransomware gangs without professional training and support. He discusses his new book, Owned, and how he plans to use his experience to help cybersecurity teams and business leaders prepare for ransomware attacks. // Link to No Starch Website for Jon DiMaggio's Book // Order Owned on No Starch: https://nostarch.com/owned Use Coupon Code OWNED30 for 30% off Owned at NoStarch.com // Jon DiMaggio's SOCIALS // Website: https://arkemcyber.com/ X: https://x.com/Jon__DiMaggio LinkedIn: / jondimaggio // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:36 - Introduction 01:28 - Infiltrating the LockBit Ransomware Gang 03:45 - Working With the FBI & NCA 04:55 - Sponsor – Proton Drive 06:54 - Stories From the Ransomware Gang 07:35 - Befriending a Hacker 10:21 - The Kaseya Ransomware Attack 12:10 - Arrest, Extradition & a 14-Year Sentence 13:12 - An Unexpected Message From Prison 14:57 - The LockBit Story & the Mental Health Toll 16:30 - Advice for Young People Drawn to Cybercrime 18:09 - Why Hackers Can't Easily Spend Their Money 19:12 - How to Become a Jon DiMaggio 21:58 - What's Next for Jon DiMaggio 23:08 - Preparing Companies for Ransomware Attacks 23:52 - Final Thoughts Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #lockbit #ransomware #revil

    #603: How Age Verification Threatens Your Online Privacy

    Play Episode Listen Later Sep 8, 2026 47:37


    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Age verification is spreading across the internet. It promises to protect children, but what happens when accessing a website or using your own device requires facial recognition, identity documents or third-party verification? David speaks with Alexis Hancock from the Electronic Frontier Foundation about the growing privacy risks surrounding age verification and digital ID systems. They examine how these technologies could threaten online anonymity, create new surveillance infrastructure and expose sensitive personal information. Alexis explains why age verification alone does not teach children how to stay safe online, how data brokers and behavioral advertising contribute to the problem, and why banning VPNs or weakening encryption would make everyone less secure. They also discuss zero-knowledge proofs, facial recognition, encryption backdoors, government surveillance and the danger of building a digital identity system that could be abused by future governments. Finally, Alexis shares practical ways to protect your privacy, including using encrypted communication, learning from EFF's Surveillance Self-Defense guides and contacting elected representatives when harmful legislation is proposed. // Alexis Hancock' SOCIAL // LinkedIn: / alexishancock // EFF Website REFERENCE // https://www.eff.org/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Intro 0:41 - Alexis Hancock background // Who are the EFF 01:48 - Eroding privacy & age verification 08:48 - Online safety for children 12:25 - Online monitoring 14:20 - ThreatLocker sponsor segment 15:27 - Big tech vs government 17:49 - How to fight for privacy 20:19 - Online censorship & privacy 26:17 - The push for age verification 29:29 - Age verification "whack-a-mole" 33:03 - Parental control vs age verification 36:24 - What about non-tech savvy people? 41:02 - Zero-knowledge proof 44:48 - Is it too late? // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ageverification #privacy #bhusa2026

    #602: How Compilers Turn Secure C Code Into Vulnerable Binaries

    Play Episode Listen Later Sep 8, 2026 30:39


    Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal You can write secure C code, follow accepted best practices and still end up with a vulnerable binary. The reason is simple: the CPU does not run your source code. It runs whatever the compiler produces. David sits down with security researcher Chris Domas at Black Hat to examine how legal compiler optimizations can remove security protections, delete memory-clearing operations and introduce time-of-check to time-of-use vulnerabilities into code that appeared secure. Chris explains the C abstract machine, why compilers are allowed to transform code so dramatically and how register pressure, structure layout and even data size can affect whether a binary is vulnerable. In one striking example, 17 or 33 bytes can be safe while nearby sizes produce vulnerable code. They also discuss whether Rust solves the problem, why switching between GCC and Clang is not the answer and how AI helped analyse 500 million lines of open-source code to identify 300 potentially dangerous patterns. Most importantly, Chris explains what developers can do now, including enabling compiler warnings, using sanitizers, analysing optimized builds and testing the exact binary that will be shipped. // Christopher Domas' SOCIAL // LinkedIn: / christopher-domas GitHub: https://github.com/xoreaxeaxeax X: https://x.com/xoreaxeaxeax // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:48 - Intro 02:05 - Different Ways of Exploiting CPU's 04:10 - The C Specifications 06:17 - The Compiler Deleting Nemsec 08:40 - Do we need to use a new Compiler ? 10:09 - Compiler Inventing Vulnerabilities 12:13 - Don't Give up Writing Secure Code 12:44 - Sponsored Section 14:25 - Any Easy Options To Create A New Compiler ? 15:09 - Chris's Presentation at Black Hat 20:00 - Weird Situations with Size of Data 21:22 - What Can Developers Do ? 23:32 - Who Can Leverage this Vulnerability ? 25:02 - Could AI Make it Easy For Attackers To Leverage This? 28:27 - Recommendations For Developers 29:48 - Advice To Be Like Chris 30:36 - Conclusion & Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #bhusa2026 #securecoding #compiler

    #601: Google Researchers Hacked the Pixel Phone using Audio Messages

    Play Episode Listen Later Sep 8, 2026 39:19


    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal A zero-click attack can compromise your phone without you opening a link, installing an application or even touching the device. David sits down with Natalie Silvanovich and Seth Jenkins from Google Project Zero to examine how specially crafted audio messages were used to remotely compromise the Pixel 9 and Pixel 10. The attack begins inside the Dolby Unified Decoder, where Android automatically processes incoming audio for transcription. The researchers explain how they exploited the decoder, escaped the media codec sandbox and targeted vulnerable Pixel hardware drivers to achieve kernel code execution and root access. They also discuss ASLR, SELinux, memory corruption, the eight-week exploit development process, how AI helped automate repetitive tasks and why Apple's compiler protections prevented the same Dolby bug from affecting iPhones. Most importantly, they explain what manufacturers can do to reduce their attack surface and make commercial zero-click exploits significantly more expensive. These vulnerabilities were responsibly disclosed and patched. Pixel users running the latest security updates are protected. // Seth Jenkins SOCIAL // LinkedIn: https://www.linkedin.com/in/seth-jenkins-a20b914b/ X: https://x.com/__sethJenkins // Natalie Silvanovich SOCIAL // X: https://x.com/natashenka?lang=en Website: https://natashenka.ca/ // Website REFERENCE // Google Project Zero website: https://projectzero.google/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU// 0:00 - Intro 01:00 - ThreatLocker sponsor segment 02:10 - Natalie Silvanovich background 04:00 - Seth Jenkins background 04:49 - Zero click audio codec vulnerability 05:41 - Disclaimer 06:07 - Hacking using audio files // How it works 10:23 - What happens in the sandbox 13:27 - The next step 15:15 - Running into issues 22:55 - Would someone notice the hack? 26:20 - Not secure by default 27:44 - Using AI assistance 29:44 - How to reduce attack surface 34:57 - How to get into cybersecurity 39:05 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #google #bhusa2026 #pixel10

    #600: This Free Tool Decodes Game Boy ROM From a Photograph

    Play Episode Listen Later Sep 2, 2026 41:33


    Can you recover working software from a photograph of a microchip? Embedded systems reverse engineer Travis Goodspeed demonstrates how to extract the original Game Boy's 256-byte boot ROM from a microscopic photograph of the mask ROM inside its CPU. The source image was created by combining 22 microscope photographs captured at 50x magnification. Using his free, open-source Mask ROM Tool, Travis marks 2,048 ROM bit locations, separates the ones from the zeros and checks for possible recognition errors. He then determines the logical order of the bits, disassembles the program and shows how it can be exported as a ROM file for use in an emulator. Travis also explains the Game Boy's unusual copy-protection system. During startup, its boot ROM displays logo data supplied by the cartridge and compares it with Nintendo's internal copy. If the logos do not match, the game does not boot. Requiring cartridges to contain Nintendo's trademark gave the company legal leverage against unlicensed publishers. The video also explores techniques from Travis's book, Microcontroller Exploits. These include extracting protected firmware from an access-control reader, chemically decapsulating chips while preserving their operation and using ultraviolet light with a nail-polish mask to remove memory protection without erasing the program. The Mask ROM Tool, Game Boy chip photograph and step-by-step tutorial are publicly available, allowing you to reproduce the ROM-decoding demonstration without owning a microscope or chemistry lab. // Sponsored SEGMENT // Big thank you to Proton Pass for sponsoring this video. Take your security to the next level by getting Proton Pass using the following be www.proton.me/davidbombal // Link to No Starch Website for Travis' Book // Order Microcontroller Exploits and get the eBook free. https://nostarch.com/microcontroller-... Use Coupon Code GOODSPEED25 for 25% off Microcontroller Exploits at NoStarch.com // Travis Goodspeed SOCIAL // GitHub: https://github.com/travisgoodspeed // GitHub link to GameBoy ROM Tutorial // https://github.com/travisgoodspeed/gb... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU// 0:00 - Coming Up 0:40 - Intro 03:28 - Book Overview 05:27 - Proton Pass Ad 07:29 - Demonstration Context 09:56 - Demo Begins 12:48 - Marking the Chip Rows 18:27 - How Travis Wrote his Book 19:55 - Design Rule Check 23:11 - How to Decode the Binary 28:36 - Can the Binary Numbers Change? 30:30 - Why is this Method Useful? 34:24 - More book Overviews 40:48 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #gameboy #reverseengineering #rom

    #599: This Pocket Tool Diagnoses Wi-Fi in 45 Seconds

    Play Episode Listen Later Sep 2, 2026 42:32


    Your internet speed can look fine while your Wi-Fi is still failing. Packet loss, latency, congested channels, interference and poor configuration can all damage performance, but a normal speed test will not show you the full picture. In this video, I test the Ookla Speedtest Pulse, a pocket-sized Wi-Fi 7 diagnostic tool that measures more than 25 network metrics in around 45 seconds. We test Wi-Fi at the Natural History Museum in London and examine results from an Airbnb to identify whether the problem comes from the Wi-Fi network, wired connection or internet service provider. Matt explains how the device tests 2.4, 5 and 6 GHz Wi-Fi, detects channel problems, measures signal quality and gives you practical recommendations in plain English. We also compare Speedtest Pulse with the normal Speedtest application, laptopbased tools and the Ekahau Sidekick 2. You will see its current limitations, upcoming continuous monitoring features and how it could help technicians finally capture intermittent Wi-Fi problems. Big thanks to OOKLA for sponsoring this video. To get your own Speedtest Pulse please use the following link: https://wifi.ekahau.com/david-bombal-... // Matt Starling's SOCIAL // LinkedIn: / matt-starling-03913633 X: https://x.com/mattstarling?s=21 // Ookla's SOCIAL // LinkedIn: / ookla // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:58 - Testing Public Wi-Fi in London 01:40 - What Is the Speedtest Pulse? 03:40 - Pulse vs Speedtest vs Sidekick 2 06:19 - Making Wi-Fi Troubleshooting Easy 07:44 - Running a Wi-Fi Test 09:22 - Understanding Wi-Fi Performance Scores 11:16 - Reports and Cloud Results 13:00 - Active vs Continuous Pulse 15:14 - Wired and Wireless Network Testing 18:05 - Why Not Just Use a Laptop? 21:02 - Mobile Support and Wi-Fi 7 Hardware 23:17 - Understanding Your Wi-Fi Score 26:54 - Wi-Fi Security and PMF 29:03 - Signal Strength and Transmit Power 30:19 - Wi-Fi Channels and Interference 31:58 - How to Improve Your Wi-Fi 33:12 - WPA3 Best Practices 34:16 - Price and Coverage Mapping 35:59 - Pulse vs Sidekick 2 for Interference 38:36 - Solving Intermittent Wi-Fi Problems 40:32 - Cloud Monitoring and Multi-Site Management 42:12 - Final Thoughts Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ookla #speedtest #wifi

    #598: AI Can't Understand Intent. That's a Security Problem

    Play Episode Listen Later Aug 26, 2026 26:02


    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal AI is changing cybersecurity, but simply using more AI to defend against AI attacks may not be the answer. David Bombal sits down with Danny Jenkins, CEO of ThreatLocker, to discuss the security risks created by AI, autonomous agents, zero-day vulnerabilities, ransomware, and the rapidly expanding attack surface businesses now have to deal with. Danny explains one of the fundamental problems with AI security: AI can understand what something does, but it may not understand the intent behind it. The same action could be performed legitimately by an administrator or maliciously by an attacker. They also discuss how AI is giving attackers capabilities that previously required significantly more expertise and resources, including vulnerability discovery and sophisticated phishing attacks. But AI creates another problem inside organizations. Autonomous agents can potentially access files, upload data, perform actions, and make mistakes extremely quickly. Every new piece of software adds attack surface, and powerful AI agents can dramatically increase that risk. Danny argues that the answer isn't simply AI versus AI. Instead, organizations need to rethink trust itself. The discussion covers deny by default, application control, restricting what software and AI agents are allowed to access, and why AI should be used as an additional security layer rather than becoming your primary defense. Topics include: • AI security risks • Autonomous and agentic AI • Why AI struggles with intent • How hackers are using AI • AI-powered vulnerability discovery • Zero-day vulnerabilities • Ransomware • AI attack surfaces • Application control • Deny by default security • Why AI alone can't solve AI security • Securing AI inside businesses // Danny Jenkins' SOCIAL // LinkedIn: / dannyjenkinscyber // ThreatLocker's SOCIAL // LinkedIn: https://www.linkedin.com/company/thre... X: https://x.com/threatlocker Instagram: / threatlocker Website: https://www.threatlocker.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:34 - Introduction 0:46 - Why Businesses Are Afraid of AI 02:17 - AI Can Be Used for Good or Bad 03:29 - The Race to Adopt AI 05:02 - AI Gives Attackers Nation-State Capabilities 06:09 - Why AI Can't Be Your Primary Defense 07:59 - How AI Is Expanding the Attack Surface 08:53 - Solving AI Security With Limited Access 11:04 - The Deny-by-Default Security Model 14:12 - AI-Powered Vulnerability Hunting 17:29 - How ThreatLocker Actually Uses AI 20:01 - Why Deny-by-Default Beats Chasing Zero-Days 21:15 - What Cybersecurity Customers Are Most Worried About 22:16 - AI Hype, Jobs & Closing Thoughts 24:55 - ThreatLocker Advert Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #threatlocker #bhusa2026 #blackhat

    #597: The Hacking Gadgets You Need to Know

    Play Episode Listen Later Aug 24, 2026 42:33


    Note: Hak5 did not pay me to make this video. But, I'm marking it as sponsored because Darren was kind enough to give me some cool Hak5 gadgets. Get your own using my link: https://davidbombal.wiki/gethak5 // Darren Kitchen SOCIAL // YouTube: https://www.youtube.com/darrenkitchen Website: https://hak5.org/pages/hack-across-america X: https://x.com/hak5darren // Hak5 WEBSITE (affiliate) // https://davidbombal.wiki/gethak5 // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU// 0:00 - Coming up 01:00 - 21 Years of Hak5 // Device overview 05:30 - USB Rubber Ducky 09:22 - Bash Bunny 12:41 - Plunder Bug 13:28 - Shark Jack & Shark Jack Display 16:28 - Packet Squirrel 18:51 - Key Croc 21:51 - Screen Crab 24:07 - Lan Turtle Hub 28:14 - WiFi Pineapple 33:16 - WiFi Pineapple Pager 37:32 - Hak5 books 39:15 - Darren's favourite tools 41:27 - Future projects // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #hak5 #hackinggadgets #hacktool

    #596: This is the Real Cybersecurity Problem

    Play Episode Listen Later Aug 20, 2026 28:03


    Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people. Jen Easterly joins David Bombal to discuss why today's cybersecurity problem may actually be a software quality problem. For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place. They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it. Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders. Topics include: Why cybersecurity may be a software quality problem Why users are blamed for insecure software CISA's Secure by Design initiative Why default passwords should disappear AI agents behaving in unexpected ways AI and the future of zero-day attacks Memory safety, C, C++ and Rust Government regulation and vendor accountability The EU Cyber Resilience Act Why Patch Tuesday may eventually become unacceptable How AI could help defenders find and fix vulnerabilities Jen Easterly's advice for cybersecurity professionals If you work in cybersecurity, ethical hacking, software development, networking, AI security, or critical infrastructure, this is a conversation you don't want to miss. // Jen Easterly's SOCIAL // LinkedIn: / jen-easterly // Website REFERENCE // https://www.cisa.gov/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 0:55 - Jen Easterly introduction & background 04:20 - Advice for the youth 07:10 - Advice for ethical hackers and leadership 11:35 - Software security // Who's to blame? 17:39 - Power and responsibility 21:17 - Secure by design 26:38 - Is it important to attend RSAC? // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #rsac #bhusa2026 #securebydesign

    #595: How to Detect Fake Cell Towers Near You

    Play Episode Listen Later Aug 18, 2026 62:12


    Big thanks to Proton VPN for sponsoring this video. To sign up for Proton VPN please use the following link https://protonvpn.com/davidbombal and get 70% off. Learn how fake cell towers and Stingray-style devices can be used to track phones, capture metadata, and monitor cellular activity. OTW joins David Bombal to demonstrate how SDR tools such as HackRF, RTL-SDR, DragonOS, and Falcon can be used to scan nearby cell towers and investigate suspicious signals. They look at how 4G and 5G networks work, why mobile networks still expose valuable metadata, how IMSI catchers operate, and what suspicious or rogue cell towers may look like. They also discuss SS7 vulnerabilities, mobile network attacks, Signal, GrapheneOS, and practical steps you can take to better protect your communications. Topics covered: How to scan for nearby cell towers How fake cell towers and Stingrays work Detecting suspicious cell towers with SDR HackRF and RTL-SDR DragonOS and Falcon IMSI catchers and phone tracking 4G and 5G security SS7 vulnerabilities Mobile phone metadata Signal and GrapheneOS Mobile network security // Occupy The Web SOCIAL // X: / three_cube Website: https://hackers-arise.net/ // Occupy The Web Books // Linux Basics for Hackers 2nd Ed US: https://amzn.to/3TscpxY UK: https://amzn.to/45XaF7j Linux Basics for Hackers: US: https://amzn.to/3wqukgC UK: https://amzn.to/43PHFev Getting Started Becoming a Master Hacker US: https://amzn.to/4bmGqX2 UK: https://amzn.to/43JG2iA Network Basics for hackers: US: https://amzn.to/3yeYVyb UK: https://amzn.to/4aInbGK // OTW Discount // Use the code BOMBAL to get a 20% discount off anything from OTW's website: https://hackers-arise.net/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 0:37 - Mobile system vulnerability explained 12:29 - Proton VPN sponsor segment 15:07 - How to search cell towers in your area // CellSearch demo 19:45 - Cell tower frequencies explained 22:19 - CellSearch demo continued 32:41 - Discovering the identifiers 37:42 - Scanning for Stingrays/rogue cell towers // CellSearch demo continued 44:00 - Ordinary people being victims of WiFi hacking 47:28 - Authentication bypass on IoT devices 49:01 - Scanning higher frequencies with CellSearch 52:06 - Falcon demo // Discovering cellphones connecting to a cell tower 57:46 - Recommended protection from traffic interception 01:01:38 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #stingray #celltower #sdrhacking

    #594: How to Protect Your Network From Insecure IoT Devices

    Play Episode Listen Later Jul 30, 2026 31:37


    Hackers are using overlooked IoT devices such as IP cameras, printers and smart speakers to gain access to networks and spread ransomware. Philip Wylie explains how an outdated IP camera became a ransomware gateway, why default passwords and poor segmentation remain serious risks, and how to protect your network using separate VLANs, firmware updates, monitoring and zero-trust controls. The interview also explores medical devices, OT security, AI-enabled devices and the growing demand for IoT penetration-testing skills. Big thanks to ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal // Philip Wylie's SOCIAL // X: https://x.com/phillipwylie LinkedIn: / phillipwylie YouTube: / @phillipwylie Instagram: / phillipwylie // Book REFERENCE // The Pentester Blueprint Phillip Wylie: US: https://amzn.to/4jkigAa UK: https://amzn.to/42vShPB // YouTube video REFERENCE // Pentester Blueprint: Your Road to Success: • Pentester Blueprint: Your road to success How to hack IP Cameras (Ethically) and learn IoT hacking: • How to hack IP Cameras (Ethically) and lea... // Website REFERENCE // https://training.brownfinesecurity.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:56 - Intro 03:08 - The Weakness in Pen-testing 07:38 - How Do Hackers Get Access? 11:30 - How To Protect IoT Devices 14:36 - Dangers of Medical IoT Devices 18:24 - Countries Banning IoT Devices 20:46 - Phillip's Recommendations 22:42 - What is Exploit DB 27:30 - How Vulnerable Are You? 28:28 - Advice To The Youth 29:40 - How To Start Learning 31:15 - Conclusion 31:23 - Threatlocker Advert Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #iot #iothacking #security

    #593: How to pass the CCNA exam (advice from two Cisco instructors)

    Play Episode Listen Later Jul 25, 2026 36:06


    Two Cisco training veterans break down how to know you are ready for the CCNA exam, what changes in CCNA 2.0, and whether the CCNA is still worth it in 2026. Brian Bays has been teaching official Cisco classes since 2000. Michael Aldridge has been writing practice exam content since 2001. In this interview they answer the questions I get asked constantly: how long should I study, do I need physical equipment, should I do Network Plus first, and is AI going to take these jobs away? Short answer on that last one: they have heard this before. Automation was going to end tech jobs. Then virtualization. Then cloud. Every time, it just made good engineers more productive. Junior engineers become senior engineers, and we cannot function without senior engineers. We also cover what is coming in CCNA 2.0, including more troubleshooting woven through every section, a dark mode option, a full screen CLI, and the ability to send a command to every device in a lab at once. This video is not sponsored. I have known Brian and Michael for years and I recommend them because I rate them, not because anyone paid for this. Get CCNA Certified with Boson's comprehensive training solutions: https://boson.com/certifications/ccna/ // Bryan Baize SOCIAL // LinkedIn: / bbaize // Michael Aldridge SOCIAL // LinkedIn: / michael-aldridge-48125338a Reddit: / bosonmichael // Boson LinkedIn // LinkedIn: / boson // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 01:01 - Introductions 03:55 - When will you be ready for the CCNA exam? 08:34 - Overwhelming exam resources 11:14 - Do you need physical equipment for the CCNA exam? 13:52 - Mistakes preparing for the exam 16:56 - The learning never stops 17:57 - CCNA vs Network+ 19:52 - What is Boson NetSim? 20:53 - What is Boson ExSim? 21:37 - NetSim vs Packet Tracer 22:37 - Why trust Boson? 24:46 - Tips for passing the CCNA exam 25:37 - How long should you study for the CCNA exam? 27:34 - New CCNA exam expectations 29:27 - Mistakes when taking the exam 31:52 - Topics students struggle with 33:26 - Important resources 35:23 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #boson #ccna #networkengineer

    #592: Why most enterprise AI fails (and how to succeed)

    Play Episode Listen Later Jul 15, 2026 37:53


    Agentic AI is putting a 400x load on enterprise networks. Cisco and NTT Data experts reveal why only 13% of leaders successfully scale AI, the nightmare of quantum threats, and how to secure your infrastructure. Big thank you to NTT DATA for sponsoring this video. Book an AI Infrastructure Readiness Assessment using one of the following links: https://services.global.ntt/en-us/cam... or https://services.global.ntt/en-us/cam... // Vikesh Gumpalli's SOCIAL // LinkedIn: / vgumpalli // Vance Baran's SOCIAL // LinkedIn: / vancebaran // Website REFERENCE // https://www.nttdata.com/global/en/ https://www.nttdata.com/en-us/2026-gl... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 01:09 - Introduction 03:04 - Enterprise AI Adoption: The Board-Level Challenge 05:02 - How AI Agents Are Reshaping Network Infrastructure 07:22 - AI Agent Access, Sensitive Data and Security Risks 10:24 - Cybersecurity at Machine Speed and Modernising Security 14:08 - AI Budgets, ROI and Business Readiness 15:00 - AI's Impact on Jobs and an Insurance Case Study 19:08 - Data Sovereignty and Custom AI Models 22:18 - AI Factories, Edge Deployment and Public-Sector Use Cases 26:31 - Preparing for Quantum-Safe Security 28:43 - Managing Multi-Vendor Environments and Security Readiness 32:09 - Live Protect and Hybrid Mesh Firewalls 34:04 - Splunk, Galileo, AI Observability 36:33 - Where to Learn More Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only.

    #591: Inside the Cisco Live 2026 NOC (exclusive tour)

    Play Episode Listen Later Jul 15, 2026 26:02


    Big thanks to Cisco for sponsoring my trip to Cisco Live EMEA and for changing my life and the lives of many other people. // Joe Clarke SOCIAL // LinkedIn: / joeclarke2 // YouTube video REFERENCE // MCP Demo using Python, AI and a self healing network (Model Context Protocol): • MCP Demo using Python, AI and a self heali... Do you know what this weird IP address is about? (192.0.0.2): • Do you know what this weird IP address is ... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 01:11 - Introduction 02:34 - The Backup Network Operation Center (NOC) 04:30 - The Security in the NOC 07:38 - Joe Clark Shares a Story 10:23 - Improvements with MCP 12:50 - Equipment Demonstration 16:16 - Physical Security & Physical Separation 17:53 - IPv6 & Other Updates 19:56 - Why IPv6? 22:42 - The Interface Dashboard Monitors 24:53 - Tips & Tricks 25:49 - Conclusion & Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #noc #network #cisco

    #590: CCNA 2.0: What did Cisco just remove from the exam?

    Play Episode Listen Later Jul 2, 2026 44:21


    Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Vegas. Cisco has officially announced a major update to the CCNA, moving from version 1.1 to the new CCNA 2.0 blueprint. Recorded live at Cisco Live, David Bombal sits down with Cisco certification insiders Hank and Quinn to dissect exactly what these changes mean for your career, what entry-level networking topics have been completely removed, and how the test is shifting heavily toward hands-on performance-based testing lablets. Learn why traditional, shallow network automation topics were pulled to make room for 2026 enterprise priorities like Agentic AI, digital network assistants, and secure device management (including mandatory AAA, secure copy protocols, and client-side security). The team breaks down the structural consolidation from six domains down to five, including the revamped 25% weight on Switching and Network Access and the newly introduced AI Network Operations and Management domain. Whether you are currently studying for your exam or just beginning your networking journey, this comprehensive breakdown explains how to align your lab practice using free tools like Cisco Packet Tracer and Cisco Modeling Labs (CML) to become truly job-ready. // Hank Preston SOCIAL // LinkedIn: / hpreston // Quinn Snyder SOCIAL // LinkedIn: / qsnyder // Website REFERENCE // https://u.cisco.com/tutorials https://www.netacad.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:58 - Intro 03:51 - What Are 'Verbs'? 05:08 - New Blueprint Tasks 09:03 - Is Automation Important? 12:46 - AI in the CCNA Blueprint 15:15 - New Blueprint Additions and Changes 18:49 - Old and New Domains 25:21 - Hands-On Practice 29:18 - What is the 'Diagnose' verb? 30:50 - What is the 'Validate' verb? 32:11 - What is the 'Interoperate' verb? 33:13 - When Should You Take The CCNA? 35:42 - Do You Need Hardware to Study? 36:40 - Available Study Materials 40:03 - How To Cope with Studying for CCNA 42:22 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ccna #cisco #cml

    #589: How to run an AI agent INSIDE your network CLI for 2026

    Play Episode Listen Later Jun 30, 2026 31:34


    Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Vegas 2026. Network engineers, are you ready for 2026? Learn how to deploy an AI agent directly into your CLI using Cisco MCP and Claude to automate network configurations safely. In this tutorial with Karim from Cisco, we explore how to build a custom AI skill (Iris) using Anthropic's Claude Code and Cisco's Model Context Protocol (MCP). Watch how an agent can live in your terminal to automatically read ServiceNow tickets, discover network topologies, propose BGP/firewall changes, and execute commands while keeping a "human in the loop" to prevent hallucinations. Perfect for CCNA/CCIE candidates and anyone looking to learn agentic AI without adopting complex Python programmability. // Kareem Iskander's SOCIAL // LinkedIn: / kiskander X:Chttps://x.com/kareem_isk // Repo Link REFERENCE // https://github.com/kiskander/iris // Website REFERENCE // https://u.cisco.com/tutorials // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:39 - Intro 01:57 - Why Network Engineers Are Returning to the CLI 03:24 - The Real Cost of AI Token Usage 04:10 - What Is an Agent Skill? 05:17 - Network Automation Use Case: AWS to On-Prem Connectivity 07:40 - Building Iris, an AI Network Agent 09:17 - Setting AI Safety Rules and Defining the Workflow 12:17 - Security, Local Models and Private AI Environments 15:16 - Using Existing Automation Playbooks with AI 16:34 - Live Demo: Running Iris in the CLI 18:34 - Using AI to Analyse CLI Commands and Logs 20:11 - Using Iris to Read ServiceNow Tickets and Plan Network Changes 22:06 - AI, CCIE Skills and Firewall Recommendations 25:18 - Getting Iris from GitHub, Safety Concerns and Learning Resources Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ai #claudeskills #aiautomation

    #588: Which is Ethernet? What's the difference?

    Play Episode Listen Later Jun 30, 2026 22:57


    Big thank you to DeleteMe for sponsoring this video. Use my link https://joindeleteme.com/Bombal to receive a 20% discount or use the QR Code in the video. Also, a Big thanks to Cisco for sponsoring my trip to Cisco Live Vegas 2026. Do you really need Cat 8 Ethernet for your home network in 2026? And what actually happens when you touch the end of a fiber optic cable? We break it all down with hands-on demos. At Cisco Live, I caught up with Jim from Fluke Networks to dive deep into the physical layer of networking. We strip away the marketing hype and look at the real-world performance of both copper and glass. In this video, we cover everything from the crucial safety reasons why you should never look into a fiber cable, to a microscope demonstration showing how a single speck of dirt or finger oil can cause frame errors and take down your SFP modules. We also run a live cable certification test on Cat 6 vs Cat 8 to show you exactly why Cat 6A is all you actually need for your home network, and how pros use an OTDR to find exact breaks in long fiber runs. If you want to build or troubleshoot networks effectively, you need to understand the physical layer. // Jim Davis from Fluke Networks SOCIAL // LinkedIn: / jimdavisflukenetworks Website: https://www.flukenetworks.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 0:31 - Introduction 1:31 - Don't touch fiber optic cables! 04:53 - Single vs Multi-mode fiber 08:04 - Don't look directly into a fiber optic cable! 09:13 - DeleteMe sponsor segment 11:03 - How to find a break in a cable 16:01 - Can ethernet copper cables get dirty? 18:12 - How to test ethernet cables 20:00 - The future of ethernet 21:45 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #fluke #fiberoptics #ethernetcable

    #587: Agentic AI is attacking your network (how to defend it)

    Play Episode Listen Later Jun 24, 2026 16:42


    Are your legacy network devices a ticking time bomb? In this deep dive, Cisco's Head of Customer Experience reveals alarming statistics from the latest Talos report: 40% of top vulnerabilities directly target end-of-life devices, and 32% are over a decade old. We explore how older infrastructure has transitioned from a mere operational drag to ground zero for a new generation of agentic AI attacks, and why the looming threat of quantum computing breaking RSA encryption means you must assess your network now. Discover how the newly launched Cisco IQ provides real-time, dynamic visibility into hardware, software, and cryptographic assets. Learn how this powerful GPS for your network connects hidden operational trails, automates TAC troubleshooting, and ensures your enterprise is quantum-ready before post-Mythos era threats cause catastrophic downtime. A big thank you to Cisco for sponsoring this video and for sponsoring my trip to Cisco Live Vegas 2026. // Liz Centoni SOCIAL// LinkedIn: / lizcentoni Blogs: https://blogs.cisco.com/customerexper... https://blog.talosintelligence.com/20... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 01:03 - Intro 01:45 - Quantum Ready Assessments 04:35 - Other Cyber Threats 05:11 - Cisco IQ 08:41 - Cisco Assisting Customers 12:39 - Deploying Technolgy 13:24 - Customers Using Cisco IQ 16:18 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #cisco #ciscoiq #quantum

    #586: Stop zero days without a patch: You need to learn eBPF

    Play Episode Listen Later Jun 24, 2026 21:45


    How has AI changed cybersecurity and enterprise networks? In this interview, Michael (General Manager for Cisco's Campus Networking) joins David Bombal to discuss the real-world impact of agentic AI, physical AI, and modern security threats. Discover why the U.S. cybersecurity agency (CISA) reports that the mean time to exploit vulnerabilities has plummeted from 10 months to just 10 hours due to AI systems chaining CVEs together. Learn how autonomous agents are shifting campus and branch environments from traditional north-south traffic to massive east-west flows, creating up to 9x the bandwidth demand. Michael breaks down how network segmentation and "least agency" protect data, how Cisco Live Protect utilizes eBPF inside the Linux kernel to create a compensating shield before a patch is ready, and how line-rate encryption with post-quantum cryptography protects against "harvest now, decrypt later" threats. Finally, find out why network engineering remains an incredibly critical, high-demand career path in 2026. Big thanks to ‪@Cisco‬ for sponsoring my trip to Cisco Live Vegas 2026 // Michael Dickman SOCIAL // LinkedIn: / midickman // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:28 - Intro 0:53 - Concerns about Agentic AI 03:55 - Agent's Impact on the Network 05:25 - Agents and Cybersecurity 07:05 - Prevalence of Agentic AI 08:04 - Solving Cybersecurity in Your Enterprise 11:29 - Agentic AI and Firewalls 13:43 - Cisco's Live Protect 17:00 - Cisco and Quantum 19:13 - Cisco Cloud Control 20:45 - Still Networking as a Career? 21:35 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #cisco #agenticai #networking

    #585: Run Full WiFi Networks in your laptop

    Play Episode Listen Later Jun 24, 2026 19:55


    In this episode, David Bombal sits down with Joe and Dalton from Cisco to break down the biggest Cisco Modeling Labs (CML) 2.10 release yet. Joe demos the new open source MCP server (model context protocol) that lets an AI model like Claude build a full CML lab from plain English. Just by asking for three IOL routers with a simple BGP config, the AI looks up the node definitions, invents the IP addresses, builds the topology, chooses eBGP on its own, and even starts the lab and waits for convergence. From there you will see the MCP server spin up a CCNA troubleshooting scenario from the official blueprint, quiz you, review your console history and final config, and hand back an honest evaluation with coaching tips. It can even turn a BGP packet capture into a ladder diagram to explain how the protocol works. Dalton then shows off CML 2.10's new wireless fabric, which runs end to end WiFi simulations with no real radios or physical access points. Watch signal strength change as you drag a client across the canvas, simulate roaming between two APs, add link conditioning to mimic a concrete wall, and run wireless packet capture on the .11 frames. Finally, Joe walks through the upgraded breakout tool that streams live packet captures straight into Wireshark so you can troubleshoot BGP and other protocols in real time. Everything shown works in the free version of CML, making this a must watch for anyone studying for the CCNA or leveling up as a network engineer. Big thanks to Cisco for sponsoring my trip to Cisco Live Vegas. // Joe Clarke SOCIAL // LinkedIn: / joeclarke2 // Dalton Ortega SOCIAL // LinkedIn: / dalton-ortega // Website REFERENCE // https://www.cisco.com/site/us/en/lear... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 01:00 - Intro 02:08 - CML 2.X Updates 02:48 - AI and CML 03:40 - Using AI to Create Practice Labs 06:20 - Starting the Lab, Showing a Console 07:58 - AI Evaluation and Tips for Troubleshooting 11:06 - BGP Ladder Diagram 12:08 - Wireless Fabric in CML 15:20 - Wireless Support Demo 17:45 - Packet Capture 19:21 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #cml #cisco #ai

    #584: Will this replace PoE (Power over Ethernet)?

    Play Episode Listen Later Jun 24, 2026 23:48


    Big thanks to NTT DATA for sponsoring this video and to Cisco for sponsoring my trip to Cisco Live Vegas. For more information about NTT DATA and Cisco's partnership, click here https://services.global.ntt/en-us/abo... 1000W touch safe power sounds impossible, but Class 4 Fault Managed Power is changing how we think about power delivery for AI data centers, buildings, networking, and IT infrastructure. In this interview, we look at how Cisco, NTT, and Panduit are approaching the next generation of energy networking systems. Traditional Power over Ethernet is useful for endpoints like access points, cameras, sensors, and phones, but PoE tops out around 100 watts. Fault Managed Power introduces a new class of power delivery that can deliver much higher wattage while intelligently shutting down when it detects a fault, short circuit, or unsafe condition. The conversation explains why this matters now. AI is driving massive demand for data center compute, but that compute requires more power, more cooling, and more efficient infrastructure. The guests explain how AC-to-DC conversion losses add up across multiple power conversion stages, how transmission and distribution losses waste energy before it even reaches the building, and why many legacy data centers spend a large amount of energy on cooling and non-useful power. A key example from the discussion: an average 5 megawatt, air-cooled data center moving to direct liquid cooling and fault managed power could save 75% of its energy cost. That same energy profile could also translate into 2.3x the compute for the same amount of energy. We also discuss touch-safe DC power up to 400V, why DC-to-DC power matters for data centers, how this technology could reduce material and labor complexity, and why network engineers, electricians, data center operators, and IT professionals should understand Class 4 Fault Managed Power. This is not just about sustainability. It is about energy cost, AI infrastructure, safer power delivery, faster deployment, data center efficiency, retrofits, new builds, and the future of networking. // Stephen Kelly SOCIAL // LinkedIn: / stephen-kelly-70737a9 // Denise Lee SOCIAL // LinkedIn: / deniseleeyeh // Website REFERENCE // https://www.nttdata.com/global/en/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 0:53 - New cables 02:22 - Fault-Managed Power System explained 03:18 - Cisco & NTT DATA partnership 04:39 - Advantages of the new cables 08:57 - Sustainability 11:26 - AC vs DC 13:14 - Easy to install // Free training 14:50 - How new cables fit into old buildings 17:44 - Embrace the new 19:35 - Will electricians be replaced? 20:49 - Summary 21:50 - Free training and learning 23:09 - Stay connected // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #poe #class4 #ntt

    #583: Shadow AI: What every network engineer must know

    Play Episode Listen Later Jun 16, 2026 31:05


    Big thank you to Radware for sponsoring this video In this interview, David Bombal sits down with Randy Wood, Head of North American Business at Radware, to break down the massive shift occurring in enterprise cybersecurity. They discuss why the rise of Agentic AI is a "1994 internet moment times a thousand," creating an environment where autonomous AI agents are rapidly outgrowing traditional security guardrails. Randy explains the critical connection between AI and API security, revealing how undiscovered "Shadow AI" tools and thousands of hidden enterprise API vulnerabilities leave organizations completely exposed to highly sophisticated, AI-driven DDoS attacks and flawless localized phishing campaigns. Learn how network engineers and security professionals can protect confidential data by pivoting from rigid rules to analyzing behavioral intent before execution, ensuring your network is ready for an autonomous tech stack. Visit radware.com for more deep-dive technical resources. // Randy Wood's SOCIAL // LinkedIn: / rwoodiii // Website REFERENCE // https://www.radware.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:31 - Intro 01:21 - The Reality of AI Today 03:50 - Customer's Concerns About AI 07:12 - Deployment of AI Agents in Enterprise 08:08 - AI Used to Attack Enterprise 09:01 - AI as a Problem and a Solution 13:43 - Agentic Security with Radware 16:51 - Lack of Architecture and Policy 18:06 - The Impact of Claude Mythos 20:03 - How Do Attackers use AI? 22:25 - API Vulnerability and Security 24:38 - Most Common Attacks 26:13 - The Future of AI 28:00 - Advice for the Youth 30:33 - Where to Learn More Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ai #api #mythos

    #582: What is an Agentic SOC? (how to defend at machine speed)

    Play Episode Listen Later Jun 16, 2026 33:16


    Big thank you to Cisco for sponsoring my trip to Cisco Live Vegas In this video, we sit down to discuss the rapidly evolving world of cybersecurity, AI, and how an Agentic SOC is becoming the standard for modern defense. We cover the massive opportunity in the industry with over 4 million open cyber jobs, why mastering Splunk is a critical career move in 2026, and how you can get started for free. We also unpack emerging threats like Mythos class attackers, vulnerabilities in LLMs and MCP servers, and how the integration of Cisco Data Fabric and Splunk is helping organizations defend critical infrastructure against automated exploits at machine speed. // John Morgan's SOCIAL // LinkedIn: / johnmorganinc Guest Bio: https://newsroom.cisco.com/c/r/newsro... // Website REFERENCE // https://www.splunk.com/en_us/training... https://www.splunk.com/en_us/download... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 01:00 - A new era 01:54 - Top threat vectors 03:14 - AI in cyber 04:10 - Rise of zero days 04:57 - What is Splunk? 06:32 - Agentic SOC 08:16 - Cyber roles in the future 16:01 - How agentic SOC will help 17:24 - Risks of AI agents // More attack surfaces 21:49 - Services to protect customers 25:36 - Data between Cisco and Splunk 27:39 - "AI fatigue" // What Cisco is doing differently 31:16 - Studying Splunk in 2026 32:54 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ai #splunk #agenticsoc

    #581: AES Explained: How Encryption Protects Your Data

    Play Episode Listen Later Jun 13, 2026 28:02


    Big thanks to TryHackMe for sponsoring this video. Learn Cyber Security with Practical Labs on TryHackMe:https://tryhackme.com/DavidBombalTech Use my code DAVIDTECH25 to get 25% OFF on Annual Subscription! Dr. Mike Pound joins David Bombal to explain symmetric encryption, AES, secret keys, VPN encryption, TLS, block ciphers, stream ciphers and why encryption is one of the most important building blocks in modern cybersecurity. In this video, Mike explains what encryption actually does: it takes readable plaintext and turns it into unreadable ciphertext so that only someone with the correct secret key can decrypt it. He breaks down how symmetric encryption works, why the same key is used to encrypt and decrypt, and why algorithms like AES are used everywhere from secure websites and VPNs to BitLocker and full disk encryption. You'll learn why AES is so fast on modern CPUs, how keys interact with encryption algorithms, and why AES uses rounds of substitution and permutation to scramble data. Mike also explains the difference between block ciphers and stream ciphers, including AES, DES, Triple DES, ChaCha20 and older algorithms like RC4 and A5/1. The discussion also covers why symmetric encryption is used for bulk encryption in protocols like TLS and IPsec, why asymmetric encryption is used differently, and why you should never write your own encryption algorithm or implement your own AES code for real-world security. If you want to understand how encryption protects your data, how VPNs and secure web traffic work, and why AES is still one of the most important algorithms in cybersecurity, this is a great place to start. // Mike SOCIAL // X: / _mikepound YouTube Channel: / computerphile // YouTube Video REFERENCE //Password Cracking: Can a Rainbow table reverse a hashed password?: • Password Cracking: Can a Rainbow table rev... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:27 - TryHackMe Sponsor 0:49 - Intro 01:18 - Symmetric vs Asymmetric Encryption 04:38 - Key Exchange and VPN Analogy 06:10 - Examples of Symmetric Algorithms 08:56 - Advantages of Stream vs Block Cyber 10:31 - Deeper AES Explanation 14:34 - Substitution, Permutation, Mixing in AES 19:24 - Don't Implement your Own Encryption 20:16 - TryHackMe Sponsor - DEMO 24:21 - DES Algorithm and the NSA 26:01 - Where to Learn More about Encryption 27:42 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #symmetricencryption #aes #des

    #580: Cisco's first Quantum Switch: What it means for you

    Play Episode Listen Later Jun 13, 2026 47:23


    Big thanks to ‪@Cisco‬ for sponsoring this video and sponsoring my trip to Cisco Live Vegas 2026. In this deep dive into the future of networking, we explore the reality of quantum networking and Cisco's groundbreaking announcement of the world's first Universal Quantum Switch. Quantum computing is no longer just a buzzword; it's moving into the mainstream, bringing massive implications for network engineers and cybersecurity professionals in 2026 and beyond. We discuss why a quantum switch is essential for scaling distributed quantum computers and how it translates different quantum modalities, acting as a universal fabric. We also break down the quantum stack, from entanglement sources generating 200 million photon pairs per second to nanosecond switching speeds. Beyond the hardware, we tackle the elephant in the room: Shor's algorithm and the imminent threat to classical encryption (RSA/Diffie-Hellman). With "harvest now, decrypt later" attacks already happening and the January 2027 CNSA 2.0 compliance deadline approaching, we cover exactly how you can prepare using post-quantum cryptography (PQC). Finally, we explore fascinating real-world applications, including high-frequency trading advantages, unbreakable eavesdropper detection using the no-cloning theorem, and secure position verification. // Ramana Kompella's SOCIAL // LinkedIn: / rkompella // Website REFERENCE // https://outshift.cisco.com/ // Videos REFERENCE // • Cisco Quantum Summit 2026 - Quantum Data C... https://event.on24.com/wcc/r/5305787/... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:28 - Intro 02:13 - Universal Quantum Switch 04:11 - Why do we need a Quantum Switch? 06:42 - Scale Out Quantum Fabric 09:02 - Multi-Modality Ability 10:17 - Sharing an Entanglement Source 14:08 - Testing the Universal Quantum Switch 17:20 - The Stack: Application Layer 21:30 - Using Quantum to Detect a Tap 24:24 - Quantum Use-Cases 28:37 - The Stack: A Summary 30:26 - Advice for the Future 33:28 - Response to “Quantum is Fake” 36:12 - Holistic Quantum Security 40:06 - Shor's Algorithm 41:47 - Cisco's Quantum-Safe Devices 46:00 - Resources to Learn More 47:00 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #quantum #quantumnetworking #cisco

    #579: New CCNA Exam: Stop Memorizing and Start Labbing

    Play Episode Listen Later Jun 8, 2026 39:58


    Big thank you to Cisco for sponsoring my trip to Cisco Live Vegas // Ryan Rose's SOCIAL // LinkedIn: / ryanrose3 Cisco Blogs: https://blogs.cisco.com/author/ryanrose X: https://x.com/RyanRose // Cisco Blogs // Cisco Announcement: https://blogs.cisco.com/learning/ai-u... CCNA 2.0 Blueprint: https://learningnetwork.cisco.com/s/c... // Websites and YouTube Channel links // Cisco U: https://u.cisco.com/ Cisco Learning Network: https://learningnetwork.cisco.com/s/ Netacad: https://www.netacad.com // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:18 - Intro 0:25 - CCNA Update Announcement 03:03 - Practical Skills/Troubleshooting as the Focus 08:23 - Simlets/Lablets in the CCNA 11:40 - AI in the CCNA 15:24 - Biggest Changes in the New CCNA 18:35 - Goals of the New CCNA 20:58 - Transitioning to the New CCNA 24:37 - CML, Packet Tracer and Other Free Tools 26:25 - CCIE Update Announcement 32:57 - Communication and Critical Thinking Tutorials 35:29 - Free and Paid Training Resources 38:24 - Final Thoughts Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #ccna #cisco #ai

    #578: How Cisco Is Using AI to Fix Networks

    Play Episode Listen Later Jun 5, 2026 22:31


    Cisco is bringing AI agents into network operations with Cisco Cloud Control, AI Canvas, and Agentic Ops. In this demo, David Bombal is joined by DJ Sampath (SVP and General Manager, AI Software and Platform) to look at how Cisco is using AI to simplify complex network troubleshooting, infrastructure management, agent security, and observability. Instead of jumping between multiple dashboards, tools, teams, and tickets, Cisco Cloud Control brings network, security, observability, and infrastructure context into one interface. The demo starts with a simple real-world problem: why can't a phone connect to the network? From there, Cisco AI Canvas investigates the topology, calls the right agents, checks the wireless environment, moves into the firewall/security domain, and identifies the root cause: a site-to-site VPN tunnel issue caused by missing OSPF route exchange. You will see how Cisco is using MCP servers, topology agents, troubleshooting agents, firewall agents, and purpose-built models to help network engineers understand what is happening across Meraki, Catalyst, Firepower, Intersight, Splunk, Security, and other Cisco platforms. The video also covers the Unified Cisco Fabric app, which connects campus and data center environments with a firewall in between, plus Cisco's agentic security app for monitoring and controlling AI agents in the enterprise. DJ also shows how Cisco is thinking about token usage, runaway agents, agent observability, Splunk, Galileo, policy enforcement, and secure AI adoption. The interview also covers Cisco's work with OpenAI and Codex, including how frontier models, purpose-built Cisco models, MCP servers, APIs, Cisco data fabric, and real network data are being used to reduce hallucinations and make AI more useful for infrastructure teams. If you are a network engineer, cybersecurity professional, infrastructure engineer, or someone trying to understand how AI will affect networking, this demo shows where things are going. Thank you to ‪@Cisco‬ for sponsoring this video and my trip to Cisco Live! // DJ Sampath's SOCIAL // LinkedIn:  / djsampath X:  https://x.com/djsampath / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 01:05 - Is AI working? 02:55 - Cisco Cloud Control quick demo 09:38 - Cisco Cloud Control Summary 10:50 - Unified Cisco Fabric demo 12:38 - Agentic Security demo // Securing agents 15:25 - Agent Observability demo // Monitoring tokens 17:38 - Cisco Cloud Control in the real world 18:49 - Summary 19:22 - Cisco Cloud Control AI model explained 20:22 - Addressing hallucinations & false information 22:19 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #cisco #ai #cybersecurity

    #577: My Dream "home lab"

    Play Episode Listen Later May 22, 2026 28:27


    Join me for an exclusive, behind-the-scenes tour of Cisco's purpose-built $20 million AI data center lab in San Jose. AI is revolutionizing the tech industry, but running massive 10,000 GPU clusters can cost up to $175 million a year—and a mere 5% network bottleneck can flush $8 million down the drain. In this video, we break down the hardware, software, and networking topologies required to build, secure, and scale massive AI data centers. I sit down with Cisco engineers to explore scale-up domains with NVIDIA H200 and AMD MI350X servers, scale-out rail-optimized topologies, and the massive Cisco Silicon One G300 ASIC delivering 102.4 Terabits per second with innovative liquid cooling. We also dive into the Ethernet vs. InfiniBand debate for scaling to 100,000 GPUs, the power of Linear Pluggable Optics (LPO) to reduce power draw, and how Cisco used AI to safely refactor 500,000 lines of legacy code. Whether you are building an AI network today or upgrading your engineering skills for the future, this is video can help you learn. Big thanks to Cisco for sponsoring my trip to Cisco Data Center and Operational Control Center in San Jose. // Will Eatherton SOCIAL // LinkedIn: / willeatherton Newsroom: https://newsroom.cisco.com/c/r/newsro... // Rakesh Kumar SOCIAL // LinkedIn: / rakesh-kumar-78559b // Richard Licon SOCIAL // LinkedIn: / rlicon75 // Ram Gandikota // LinkedIn: / ramgandikota // Faraz Taifehesmatian SOCIAL // LinkedIn: / faraztaifeh // YouTube video REFERENCE // • The 100Tbps AI Switch: Inside the Beast / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - The power of AI data centers 0:51 - Cost and challenges of AI data centers 02:35 - How to connect GPUs in an AI cluster 05:23 - The future of data centers 08:45 - NeoCloud infrastructure in Australia 10:28 - The right components matter 16:32 - Testing to avoid failures 21:43 - Ethernet vs InfiniBand 23:27 - Cisco security services 26:14 - Future of speeds in the data center 27:23 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ai #network #datacenter

    #576: How to track dark ships using OSINT (with demos)

    Play Episode Listen Later Apr 23, 2026 49:57


    Big thank you to DeleteMe for sponsoring this video. Use my link https://joindeleteme.com/Bombal to receive a 20% discount or use the QR Code in the video. In this OSINT deep dive, professional OSINT analyst Ray Baker joins David Bombal to explore the shadowy world of maritime cybersecurity and vessel tracking. Discover the critical differences between the dark fleet and shadow fleet, and learn the exact open-source intelligence methods used to track ships attempting to hide their identities on the open ocean. From manipulating AIS tracking data and repainting ship decks to the terrifying reality of hacking Chinese-made port cranes, this video uncovers the hidden cyber threats facing global supply chains. We also explore the tools used by professionals, such as MarineTraffic and Equasis, to investigate illicit maritime activities and track adversarial movements. // Rae Baker's SOCIAL // Website: https://www.raebaker.net/ LinkedIn: / raebakerosint X: https://x.com/wondersmith_rae // Amazon Books REFERENCE // Deep Dive: Exploring the Real-world Value of Open Source Intelligence US: https://amzn.to/4mw8Swo UK: https://amzn.to/4t6uhhQ // Website REFERENCE // https://www.marinetraffic.com/en/ais/... https://home.treasury.gov/ https://tankertrackers.com/ // Video REFERENCE // Deep Dive into OSINT: • Deep Dive OSINT (Hacking, Shodan and more!) // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:52 - Intro 01:25 - About Deep Dive 03:15 - Sponsor 04:14 - Opinions on AI 06:20 - About Rae 07:41 - What are Dark Fleets? 10:04 - Automatic Identification Systems 14:42 - TankerTrackers.com 16:03 - MarineTraffic.com 21:50 - Info to be Gained from Ports 23:05 - Dark vs Shadow 26:43 - Extrapolating Ship Information 30:07 - Relevancy Of Ships to Cybersecurity 32:23 - Implications of Cyber Threats 34:41 - SHODAN.io 37:31 - Why is Maritime OSINT important? 40:02 - Commercial Reasons for OSINT 43:15 - How to Track Ships When They Go Dark 45:19 - Where to Learn More 49:30 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #osint #iran #cybersecurity

    #575: AI attackers are winning. Here is the SECRET to survive.

    Play Episode Listen Later Apr 14, 2026 60:55


    Are AI attackers winning the cybersecurity war? In this video, I sit down with Daniel Miessler, a 25-year security veteran, to discuss the terrifying reality of AI-driven cyber attacks and the massive advantage hackers have today. But it is not all doom and gloom. Daniel introduces his open-source project, PAI (Personal AI Infrastructure), demonstrating how you can build a customized, local AI assistant to automate your workflow, defend your data, and level up your tech skills. We cover everything from AI agents conducting prompt injection CTFs (like Gandalf) in real-time, to the future of work and why the ultimate goal of many corporations is zero human employees. Whether you are worried about AI replacing your job or you want to learn how to leverage local LLMs, Linux, and agentic AI to become an unstoppable force, this conversation is your blueprint for surviving and thriving in the 2026 tech landscape. Go here to get PAI for free: https://github.com/danielmiessler/Per... // Daniel's SOCIAL // Twitter/X: / danielmiessler Website: https://danielmiessler.com/ GitHub: https://github.com/danielmiessler LinkedIn: / danielmiessler YouTube: / @unsupervised-learning / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 01:05 - Introduction 02:06 - Daniel's Background & His Predictions of The Future of AI 05:52 - How Attackers use AI 08:40 - Open Source SSL Vulnerability 10:20 - Helping Businesses Scale using AI 12:48 - Personal AI Infrastructure (PAI) 15:54 - Empowering People To Believe in Themselves 17:34 - Demo (PAI) 31:12 - Examples of Using (PAI) for Automating Your Life 34:13 - The Real Internet Of Things Concept 37:39 - What Happens To Security & Privacy with Personalised AI 42:43 - Running AI Locally For Privacy & Security Reasons 44:44 - What Does AI Mean for Humans & Their Future 50:00 - The AI Hype, Real or Fake ? 56:01 - Will Universal basic Income be a Reality In the Future ? 59:10 - The Advantages of AI 01:00:23 - Outro & Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ai #anthropic #mythos

    #574: Hacking Windows Active Directory in 10 minutes

    Play Episode Listen Later Apr 14, 2026 25:28


    Thank you ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal // Spencer Alessi's SOCIAL // YouTube: / @techspence Website: https://spenceralessi.com/adsecuritykit/ X: https://x.com/techspence LinkedIn: / spenceralessi Swag: https://www.etsy.com/shop/ethicalthre... // ThreatLocker's SOCIAL // LinkedIn: https://www.linkedin.com/company/thre... X: https://x.com/threatlocker Instagram: / threatlocker Website: https://www.threatlocker.com/ / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 0:54 - Spencer Alessi introduction & background 02:20 - Pentesting demo // Active Directory 03:34 - Control paths // Finding bad permissions with ADeleg 06:04 - Finding bad permissions with NetTools 06:52 - The most common issue 08:15 - Certificate abuse 12:20 - Quick recap 12:30 - Certificate abuse continued 15:10 - Pentesting summary 15:09 - How to become a pentester 18:48 - Recommended certifications 20:54 - Advice for blue teamers 22:15 - Overcoming being an introvert // Soft skills vs tech skills 23:43 - Windows hacking in the real world 24:54 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #microsoft #windows11 #hacker

    #573: WhatsApp Hackers for Hire on the Dark Web (Surprisingly cheap)

    Play Episode Listen Later Apr 7, 2026 27:30


    Thank you to ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal // Colin Ellis' SOCIAL // LinkedIn: / collinellis95 // ThreatLocker's SOCIAL // LinkedIn: https://www.linkedin.com/company/thre... X: https://x.com/threatlocker Instagram: / threatlocker Website: https://www.threatlocker.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 01:00 - Intro 02:24 - Demo Start - Clear Net 03:37 - Tails and Tor 04:55 - Navigating the Dark Web 07:28 - Hire a Hacker 14:30 - Script Kitties and We The North 20:42 - Zero Trust World 21:46 - Ransomware Group Clop 23:35 - Digital Hygiene 27:17 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #darkweb #hacking #tor

    #572: How Cisco Protects AI Agents in Modern Data Centers

    Play Episode Listen Later Mar 31, 2026 14:30


    Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Amsterdam 2026. Join David as he sits down with Cisco's Dave West (SVP, Global Specialists), to unpack the technical reality behind the OneCisco platform. Dive deep into how Cisco is transitioning from traditional networking into a platform-centric powerhouse that seamlessly integrates secure networking, AI, and cybersecurity. This discussion explores the convergence of networking and security through the Splunk acquisition, the infrastructure of AI-ready data centers powered by NVIDIA's Spectrum X and NVLink, and the rollout of agentic operations. Discover how micro-segmentation, Zero Trust access, and hybrid cloud solutions are solving the complexities of modern, distributed workforces. Whether you are managing on-premise infrastructure, hybrid environments, or preparing your network for the AI revolution, this deep dive covers the essential reference architectures and visibility tools you need to secure your enterprise. // Dave West's SOCIAL // LinkedIn: / dave-west1 // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:14 - Introduction 01:07 - Cisco as a Platform Company 02:26 - Interest in AI 03:14 - Cybersecurity Today 04:18 - What is One Cisco? 08:27 - The Workplaces of Tomorrow 09:58 - Secure Networking as the Foundation 12:38 - The Complexity of Secure Networking 13:46 - A Journey of One Cisco 14:23 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #cisco #onecisco #ai

    #571: Google Big Sleep: The End of Human Hackers?

    Play Episode Listen Later Mar 31, 2026 68:21


    Big thank you to DeleteMe for sponsoring this video. Use my link http://jointdeleteme.com/Bombal to receive a 20% discount or use the QR code in the video. Welcome back to the channel! In this deep dive, Stephen returns to break down the rapidly evolving landscape of AI in cybersecurity. We explore the critical differences between offensive AI (using AI to enhance attacks) and adversarial AI (attacking the AI models themselves). Learn the mechanics behind prompt injection, LLM jailbreaking, and how vector databases are structured. We also analyze real-world case studies, including Google Project Zero's Big Sleep autonomous zero-day agent, and demonstrate how new AI-driven tools are being used for patch diffing and root cause analysis. Finally, we tackle the massive industry question: will AI replace human penetration testers, and what steps should you take right now to futureproof your tech career? Plus, a quick look at how automated agents are tackling API vulnerabilities like BOLA. // Stephen's Social // Twitter: / steph3nsims YouTube: / @offbyonesecurity Discord: / discord // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 01:10 - DeleteMe Ad 02:29 - Intro 03:25 - About Stephen 06:10 - AI Explained 09:45 - Why You Should Study AI 13:04 - The Different AI Defined 22:10 - Vector Databases 24:05 - How Are Red Teamers Using AI 28:47 - Where Red Teamers Can Practice 34:10 - How Chatbots Work 36:14 - AI's Affect on Companies / Jobs 42:51 - What AI Can't Do 44:33 - Exploit Mitigation 48:47 - AI Hallucinations 56:01 - Web Apps and API's 59:46 - AI-Powered Products 59:18 - Demo Begins 01:03:01 - Final Thoughts 01:06:23 - Where To Learn 01:08:01 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ai #aihacking #artificalintelligence

    #570: 100 Terabit Smart Switches: What You Need to Know

    Play Episode Listen Later Mar 31, 2026 36:12


    Thank you to Cisco for sponsoring my trip to the Cisco AI Lab in San Jose. In this deep dive into the future of data center networking, we sit down to explore the massive shifts happening in AI infrastructure. We discuss the rollout of new 100 terabit smart switches and firewalls powered by the Cisco Silicon One G300 chip, alongside the highly anticipated NVIDIA Spectrum 6. Discover the critical debate between Ethernet and InfiniBand for scaling AI clusters, the complexities of co-packaged optics (CPO) versus linear packaged optics (LPO), and how agentic AI and tools like Claude are revolutionizing legacy C code refactoring. From managing data center power constraints to enforcing security policies directly on DPUs, this conversation covers the hardware and software transformations you need to know to stay ahead in network engineering. // Will Eatherton SOCIAL // LinkedIn: / willeatherton Newsroom: https://newsroom.cisco.com/c/r/newsro... // YouTube video REFERENCE // • The 100Tbps AI Switch: Inside the Beast • Did Ethernet Just Win? Cisco's 100Tbps AI ... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:42 - Introduction 01:05 - Recap of Announcements from Cisco Live 03:19 - 1.6 Terabyts Client Optics 04:27 - Hyperscalers and Neo-Clouds 05:13 - Cisco and Nvidia working together 05:39 - Scale Across 06:43 - Announcements from Nvidia GTC 2026 09:15 - Firewalls and AI Clusters 10:36 - The Future, Growth and Innovation 11:53 - Why have a Cisco Switch and a Nvidia Switch? 14:33 - Operating Systems on the Switches 16:42 - Infiniband vs Ethernet in the Data Centre 17:52 - Other Announcements from GTC 19:35 - Concerns around Data Centres 21:22 - Agentic AI in Data Centres 22:44 - Evolution of Soltware in Data Centres 25:07 - The Future of Vibe Coding 29:13 - Updates In the Routing Circles 30:43 - Open Source AI 32:11 - A view into the Future 35:14 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #cisco #nvidia #agenticai

    #568: 5-Minute Cyber Hacks Everyone Should Know (2026)

    Play Episode Listen Later Mar 31, 2026 36:49


    Big thank you to ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Forget hot glue and paper clips. Here are 7 REAL 5-minute cybersecurity hacks everyone should know in 2026. Recorded live at Zero Trust World (ZTW26), David Bombal and a team of hackers demonstrate actual cyber attacks and how quickly your systems can be compromised. From forcing AI prompt injections to steal credentials, to hiding C2 servers in plain sight on a Steam profile, these are the real-world exploits threat actors are using right now. We're diving into the technical weeds to show you Windows LNK shortcut hijacking, Linux privilege escalation via sudo misconfigurations, and how to protect yourself from these exact attacks. // Guests' SOCIAL // Alex Benton: Rename StickyKeys / alex-benton-b805065 Kenneth Walker: Everthing is a C2 / kenneth-walker-527595109 Jacob Meyer: Shortcut Hijack / jacob-meyer-165b8359 David Smith: Alternate Data Streams / david-smith-sudo-wrestler Karla Abarca: The validity of an application before execution / karlaabarcacyber Ramsey Shaban: Prompt Injection / ramsey-shaban-390335205 Tillman Hall Powershell Fake Logon / tillmanhall Rayton Li: Rooting Around Linux: Privilege Escalations / rayton-li Kieran Human: Network Hash Stealing / kieran-human-5495ab170 // ThreatLocker's SOCIAL // LinkedIn: https://www.linkedin.com/company/thre... X: https://x.com/threatlocker Instagram: / threatlocker Website: https://www.threatlocker.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:59 - Intro 01:20 - ThreatLocker Sponsor 01:36 - Demo 1: Sticky Keys 04:20 - Demo 2: Steam-Based C2 Attack 09:25 - Demo 3: Shortcut Hijacking 13:32 - Demo 4: Hidden Malware in Alternate Data Streams 20:18 - Demo 5: Safe App Validation (3-Step Check) 24:39 - AI Prompt Injection Attack 28:45 - Demo 6: Linux Privilege Escalation (Sudo Abuse) 34:10 - Demo 7: Credential Theft & Hash Cracking 36:38 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #5minutehacks #hacking #redteaming

    #569: Why Vibe Hacking Is a Big Cybersecurity Threat in 2026

    Play Episode Listen Later Mar 30, 2026 75:31


    Big thank you to Radware for sponsoring this video. Download the Radware Global Threat Analysis Report 2026 here: https://www.radware.com/threat-analys... In this interview, David Bombal sits down with Radware's Pascal Geenens to unpack the realities of the latest global threat report. The cybersecurity landscape has experienced a major paradigm shift: the era of "Vibe Hacking" is here. Pascal explains how Agentic AI, the Model Context Protocol (MCP), and uncensored offline models (like DeepSeek-R1) have created a "digital garden of Eden" for adversaries. Discover how novice script kiddies are now use the power of AI hacking which once strictly reserved for nation-state actors. We dive deep into the automation of cyber attacks, the rise of AI-driven tools like Xantarox AI, the critical dangers of AI-generated code vulnerabilities, and why traditional defense mechanisms are struggling to keep up with non-deterministic AI threats. // Pascal Geenens' SOCIAL // LinkedIn: / Website: https://www.radware.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 01:20 - 2026 Global Threat Analysis Report // The future of cyber attacks 04:19 - AI threats & threat actors 09:21 - Threat Report cover page explained 15:31 - Vibe hacking 23:09 - Hackers using AI 30:28 - The rise of DDoS attacks 40:40 - AI & vulnerable APIs 53:58 - Getting easier with the help of AI 55:57 - Zero-click indirect prompt injection 01:13:33 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #radware #vibehacking #ddos

    #567: Why Power Is Becoming a Major Problem for AI in 2026

    Play Episode Listen Later Mar 28, 2026 19:43


    Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Amsterdam 2026. In this deep dive, Cisco's Head of Corporate Strategy, Nathan Jokel, joins David Bombal to unpack the future of AI data centers and the groundbreaking Cisco and NVIDIA partnership. Discover how 1.6T networking speeds and the new 100T G300 silicon are solving massive infrastructure bottlenecks to keep GPUs running at full capacity. We explore the critical role of network security in the AI era, detailing the Splunk acquisition, HyperShield, and eBPF technology. Plus, get an insider's look at the looming power constraints facing data centers in 2025, and how Cisco is preparing for the future with post-quantum cryptography and distributed quantum networking. // Nathan Jokel's SOCIAL // LinkedIn: / nathanjokel // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 01:29 - Intro 02:20 - Demo Overview 03:57 - Demo Begins 09:35 - Adding Guardrails 11:45 - Secure Workloads 14:30 - Segmentation Workflow 18:33 - Overviewing Finance App 21:02 - Encrypted Visibility Engine 24:34 - Firewall Observability and Control 25:44 - Ant's Advice For The Youth 26:40 - How to Learn Hybrid Mesh Firewall 28:16 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only.

    #566: Stop buying AI security tools until you watch this

    Play Episode Listen Later Mar 25, 2026 26:15


    Thank you to ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal AI isn't the magic cybersecurity cure the industry wants you to believe it is Danny Jenkins tells us in this interview. He cuts through the marketing hype and explains why relying solely on AI to block attacks is not a solution to all our cyber problems. We also discuss modern threats—including the rise of Agentic AI—and why determining the "intent" of software is practically impossible for artificial intelligence. Instead of chasing the latest buzzwords, learn the foundational, proven strategies to actually secure your network. We dive deep into Zero Trust Network Access (ZTNA), the power of default deny, and the specific, tangible controls you need to block ransomware, prevent Office 365 phishing, and stop bad actors. Whether you're an IT admin, SOC analyst, or CISO, this video outlines exactly what you should be doing instead of just buying another AI tool // Danny Jenkins' SOCIAL // LinkedIn: / dannyjenkinscyber // ThreatLocker's SOCIAL // LinkedIn: https://www.linkedin.com/company/thre... X: https://x.com/threatlocker Instagram: / threatlocker Website: https://www.threatlocker.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:36 - Introduction 01:01 - Solving Problems with AI and Security 03:14 - Concerns with Agentic AI 08:01 - ThreatLocker AI Products 09:20 - AI vs AI and Security 11:34 - Vibe Coding in Industry 14:42 - Ways for Companies to Stop Hacks 19:29 - Deny by Default vs AI 20:29 - Industry reaction to Deny by Default 22:10 - About ThreatLocker 23:19 - Announcements from ZTW26 25:22 - The Growth of Threatlocker 26:12 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #cybersecurity #ai #hack

    #565: Stop the AI Hype: What Enterprise Teams Are Really Building

    Play Episode Listen Later Mar 25, 2026 30:05


    Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Amsterdam 2026. In this deep dive, David Bombal sits down with Carlos Pereira (Cisco Fellow & Chief Architect, Customer Experience) to discuss the hard truth about AI deployment in 2025 and 2026. While the world is focused on B2C chatbots, Carlos explains why the real value lies in Agentic AI systems that don't just talk, but actually execute B2B workflows. We explore the "Year of Evals," where the industry is finally grappling with the struggle of probabilistic vs. deterministic logic, and how to secure these systems from the ground up rather than as an afterthought. Carlos also reveals his exact framework for identifying AI ROI, sharing a case study of a customer who narrowed 412 potential use cases down to just 5 proven implementations. // Carlos Pereira's SOCIAL // LinkedIn: / capereir /// David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 0:55 - Carlos Pereira introduction & background 01:41 - AI in enterprises // What's happening? 04:18 - "Don't follow the hype" 08:37 - AI & Agentic AI evaluations 15:40 - Input guard explained 17:44 - AI adoption // AI native workflows 22:13 - Security in AI 25:52 - The year of AI/Agentic AI workflows 28:37 - Securing AI/Agentic AI // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #cisco #agenticai #ai

    #564: Hackers can bypass Your MFA In 2026 (And How To Stop It)

    Play Episode Listen Later Mar 23, 2026 38:10


    Thank you to ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Are your passwords and 2FA enough to stop a modern cyber attack? In this interview, Rob from ThreatLocker breaks down the dangerous reality of password reuse, SIM swapping, and why traditional SMS MFA is no longer bulletproof. We dive deep into how threat actors use reverse proxies like Evilginx to steal session cookies, allowing them to bypass multi-factor authentication and hijack your accounts without ever needing your password. Discover why relying on legacy VPNs and leaving firewall ports open to the internet massively increases your attack surface, leaving your organization just one brute-force attack away from ransomware. Finally, we explore the mechanics of ThreatLocker's Zero Trust Network Access and Cloud Access, detailing how denying by default and routing through secure proxies can lock down Microsoft 365 and make your internal network effectively invisible to hackers. // Rob Allen's SOCIAL // LinkedIn: / threatlockerrob X: https://x.com/threatlockerrob // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 0:57 - What is 2FA/MFA and why is it important? 02:54 - Reusing passwords 04:38 - Malicious Chrome extensions 05:39 - Average person vs cybersecurity 12:18 - SMS 2FA 13:37 - Authenticator apps 16:26 - Yubikeys 17:58 - No one is "unhackable" 21:52 - "Cookie stealing" explained 22:53 - ThrearLocker's new tool/solution 28:22 - How ThreatLocker protects Office365 29:06 - ThreatLocker protecting organizations 33:11 - Should I trust ThreatLocker? 35:54 - How safe is ThreatLocker? 38:00 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #cybersecurity #hacker #hack

    #563: Securing LLMs and fighting Prompt Injection with Algorithmic Red Teaming

    Play Episode Listen Later Mar 23, 2026 33:19


    Thank you to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Amsterdam 2026. In this interview, Cisco VP Rick Miles breaks down the evolution of the firewall, the massive hardware leap of the 6100 series, and how AI agents and eBPF are completely reshaping the industry. Whether you're trying to secure AI models against prompt injection or wondering if AI will replace your networking job by 2030, this is the technical reality check every engineer needs to hear right now. Has the role of the traditional firewall changed? Rick Miles, VP of Product at Cisco, joins David Bombal at Cisco Live EMEA to reveal the massive architectural shift from static "firewalls" to dynamic "firewalling." This deep-dive interview covers the incredible specs of the new Cisco Secure Firewall 6100 series—boasting 80% less space, 60% less power, and up to 8 Terabits of clustered throughput in a 2RU form factor. We also explore how eBPF is revolutionizing deep visibility and virtual patching directly at the application layer, moving security beyond the edge. But hardware is only half the story. We also break down the new "Wild West" of AI cybersecurity. Learn how to secure the network against prompt injection, poisoned AI models, and unsecured Model Context Protocols (MCP). Finally, Rick shares his vision for 2030: "Agentic" security. Will AI agents replace network engineers, or will they become the ultimate force multiplier for your career? // Rick Miles' SOCIAL // LinkedIn: / rcmiles09 // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:19 - Introduction 01:17 - Are Firewalls Dead? 04:18 - Cisco and Firewalls 08:30 - Hyperscalers vs Neo-Clouds vs Enterprises 10:46 - EBPF and Switches as Firewalls 14:32 - Managing your Hybrid Mesh Firewall 16:20 - Cisco's Compatibility with other Firewalls 17:40 - Identity within Systems 19:05 - More on Hybrid Mesh Firewall 19:53 - Model Context Protocol and Security 23:57 - The Future of “Firewalling” 25:15 - The Effect of Agentic AI 26:57 - Will AI take all our Jobs? 27:56 - Should you get into Cyber Security? 28:48 - Cool Story about Firewall 30:30 - Talk to your Younger Self 32:32 - Does AI give Advantage to Attackers? 33:09 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #firewall #cisco #cybersecurity

    #562: Warning and demo: It's possible to Prompt Engineer Malware

    Play Episode Listen Later Mar 23, 2026 9:38


    Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Discover how easily hackers prompt engineer malware in 2026. Kieran Human from ThreatLocker demonstrates bypassing Microsoft Copilot guardrails to write PowerShell ransomware. // Kieran Human's SOCIAL // LinkedIn: / kieran-human-5495ab170 // GitHub page REFERENCE // https://github.com/ztwAdmin/ZTW-2026 // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:17 - Intro 01:00 - Demo 01:37 - Sponsored by Threatlocker 01:55 - Demo continued 07:38 - Where to Find these Tools 08:38 - Disclaimer 09:33 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #threatlocker #copilot #locallm

    #561: Why 1 small network FAIL breaks your massive 2026 AI job

    Play Episode Listen Later Mar 18, 2026 30:26


    Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Amsterdam 2026. The AI revolution is putting unprecedented strain on global network architectures. In this exclusive deep dive with networking leaders from Cisco and NTT, we break down the critical infrastructure challenges and hardware innovations shaping 2026. Discover how emerging NeoClouds are competing with traditional hyperscalers to deliver dedicated GPU clusters, and why a single non-blocking network failure can bring an entire AI deployment to a grinding halt. We explore the reality of deploying agentic AI across enterprise networks, the vital role of international data sovereignty, and the extreme power demands driving the shift toward liquid-cooled data centers and innovations like the Cisco Silicon One G300 Chip. We also dive into the future of physical AI at the edge, where robotics and autonomous systems demand ultra-low latency inferencing. For IT professionals and network engineers, the stakes have never been higher. Learn the proven skills you need to stay relevant in 2026, from mastering zero-trust AI network security and observability with Splunk to managing predictive networking autonomously. Finally, get a sneak peek into the spooky future of post-quantum cryptography and what it means for the next generation of cybersecurity. // Gary Middleton's SOCIAL // LinkedIn: / middletongary // Hendrik Blokhuis' SOCIAL // LinkedIn: / hendrik-blokhuis-886a8910 // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:30 - Introduction 01:48 - NeoClouds and the Importance of Networking 02:52 - Data Sovereignty 04:47 - Challenges faced for Data Centres 07:31 - Electricity and Data Centres 09:18 - Technical Problems and Cisco's Solutions 12:41 - Lack of Skills in the Industry 13:21 - Is it still Worth Getting into Cyber today? 15:44 - Security of AI and Trusting your AI 18:06 - NTT Data and Cisco Partnership 20:01 - Who is Buying and Deploying this New Tech 21:52 - Could Agentic AI help solve Problems 23:46 - Customer Feedback on Agentic AI 24:57 - Physical AI is the Next Step in AI 25:58 - The Future of AI and Networking 28:05 - Post Quantum Cryptography 28:57 - Advice for Young People today 30:17 - Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ntt #agenticai #postquantum

    #560: The one BIG mistake you are making with DNS security today

    Play Episode Listen Later Mar 18, 2026 58:05


    Big thank you to Infoblox for sponsoring this video. To learn more about Infoblox please visit: https://www.infoblox.com/ Do you know the difference between encrypted DNS and secure DNS? DNS veteran Cricket Liu, author of DNS and Bind, joins David Bombal to break down common misconceptions, explain the crucial distinction between security and privacy; and outline a massive update to the NIST Secure DNS Deployment Guide (SP 800-81). If you run a network, you cannot afford to ignore this control point. Detailed Breakdown: DNS is the Achilles' heel of internet infrastructure. While newer protocols like DNS over HTTPS (DoH) and DNS over TLS (DoT) solve the cleartext privacy problem, they do not stop malware, phishing, or data exfiltration. In fact, attackers are now using encrypted DNS against us. In this deep-dive interview, Cricket Liu explains how DNS security must evolve beyond simple encryption to include Protective DNS (PDNS) using Response Policy Zones (RPZ). Learn how to turn your existing DNS infrastructure into a low-cost, high-efficiency control point that blocks malicious C2 rendezvous, phishing links, and DNS tunneling automatically. We also tackle the DNSSEC confusion head-on. Cricket clarifies exactly why DNSSEC is about validation and integrity, not encryption, and discusses the looming threat of quantum computing on modern cryptographic standards. Finally, we discuss real-world attack vectors, including a wild story about a dangling CNAME record on CDC.gov that was hijacked to game search engine rankings, and how the updated NIST guide shifts focus from just network administrators to security practitioners. // Links to documents // NIST SP 800-81: https://nvlpubs.nist.gov/nistpubs/Spe... Inflox Q&A on NIST SP 800-81: https://www.infoblox.com/blog/securit... // Cricket Liu's SOCIAL // LinkedIn: / cricketliu // Renee Burton's SOCIAL // LinkedIn: / ren%c3%a9e-burton-b7161110b Blog Posts: https://www.infoblox.com/blog/author/... // Infoblox SOCIAL // LinkedIn: / infoblox Website: https://www.infoblox.com/ // Books by Cricket // DNS on Windows Server 2003: Mastering the Domain Name US: https://amzn.to/4byNAtQ UK: https://amzn.to/4rjqgoz DNS & BIND Cookbook: Solutions & Examples for System Administrators 1st Edition US: https://amzn.to/40iZPob UK: https://amzn.to/3Nk2MBM DNS and BIND on IPv6: DNS for the Next-Generation Internet 1st Edition US: https://amzn.to/3MXly1Y UK: https://amzn.to/4s2SFRe Learning CoreDNS: Configuring DNS for Cloud Native Environments 1st Edition US: https://amzn.to/4sC4GwS UK: https://amzn.to/4ro0T59 DNS & Bind 4th Edition: US: https://amzn.to/4s8WaWm UK: https://amzn.to/4sztLbB // Website REFERENCE // Nist: https://www.nist.gov/ Secure Domain Name System Deployment Guide: https://www.nist.gov/news-events/news... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #dns #dnssec #cybersecurity

    #559: How Splunk unlocks the Agentic AI transition in 2026

    Play Episode Listen Later Mar 16, 2026 18:04


    In this exclusive interview, Kamal Hathi reveals how the new Cisco Data Fabric and Splunk Machine GPT are unlocking agentic AI for cybersecurity. Discover the future of SOC analysts and network telemetry in 2026! Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Amsterdam 2026. // Kamal Hathi's' SOCIAL // LinkedIn: / kamal-hathi // Website REFERENCE // https://www.splunk.com/ / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 0:36 - Kamal Hathi introduction and machine gpt update 03:36 - Splunk and machine data 05:47 - Resources to learn Splunk 06:48 - Cisco Time Series Model on Hugging Face 07:50 - Cisco Data Fabric explained 09:37 - Updates in 2026 15:51 - Cisco & Splunk 17:50 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #cisco #splunk #ciscolive

    #558: Top 4 Web hacking demos for aspiring hackers (with labs and CTF)

    Play Episode Listen Later Mar 16, 2026 25:12


    Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Are you looking to get into bug bounty hunting but feel overwhelmed or worried the field is oversaturated? In this video, full-time bug bounty hunter Justin Gardner shares a realistic, actionable guide to web hacking for beginners. We dive straight into the practical side with five live demonstrations of common web vulnerabilities—all done using just your browser and DevTools. Justin explains how Insecure Direct Object Reference (IDOR), Broken Access Controls, Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF) work in the real world, including stories of finding these exact bugs on major platforms like Google. After the demos, we tackle the biggest questions new hackers have: Is there still money to be made in 2026? How has AI changed the landscape? And what is the exact roadmap to landing your first bounty? Justin breaks down his "200-hour rule" for learning, why you need to get comfortable with failing, and the best resources (like HackerOne and PortSwigger) to help you launch your cybersecurity career today. // Labs and more here: // Labs: https://ztw.ctbb.show/ More labs: https://labs.cai.do/ And more labs: https://portswigger.net/web-security // Justin Gardner's SOCIAL // YouTube: / @criticalthinkingpodcast LinkedIn: / rhynorater X: https://x.com/Rhynorater GitHub: https://rhynorater.github.io/aboutme/ / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:40 - Introduction 01:50 - Getting Started in Bug Bounty 03:11 - Can I Make Money in Bug Bounty? 04:11 - Demo 1 06:55 - Demo 2 08:47 - Lessons for Upcoming Hackers 10:09 - Demo 3 13:49 - Are There Demos on Justin's Podcast? 14:20 - Demo 4 18:11 - Real-Life Date of Birth Vulnerability 19:13 - Advice on Becoming a Hacker Like Justin 20:20 - What & Where to Study to Become a Bug Bounty Hacker 21:49 - How Long Does It Take? 25:07 - Outro & Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #webhacking #bugbounty #hack

    #557: Every Reason Why I Hate AI and You Should Too

    Play Episode Listen Later Mar 14, 2026 51:09


    Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Cybersecurity expert Marcus Hutchins (MalwareTech) sits down to cut through the 2026 AI hype, explaining why threat actors aren't using generative AI and why it won't replace tech jobs. In this deep dive, Marcus reveals the reality behind the AI tech bubble and how executive hype is distracting from actual network vulnerabilities. We discuss the dangers of "vibe coding" critical infrastructure, why reactive SOC teams are giving attackers too much time, and why mastering foundational cybersecurity skills is more important now than ever. If you're navigating the current tech job market or working in threat intelligence, this is the reality check you need. // Blog Entry // Every Reason Why I Hate AI and you should too: https://malwaretech.com/2025/08/every... // Marcus Hutchins' SOCIAL // YouTube: / malwaretechblog Website: https://marcushutchins.com/ Discord: / discord LinkedIn: / malwaretech BlueSky: https://bsky.app/profile/malwaretech.com TikTok: / itsmarcushutchins Mastadon: https://infosec.exchange/@malwaretech Instagram: / malwaretech X: https://x.com/malwaretechblog / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:58 - Intro 03:03 - Why Marcus Is Tired Of AI 04:49 - Threat Actors Hurting Themselves 06:35 - Data Centres In Space 09:07 - Will AI Damage Cybersecurity? 13:25 - AI Makes Developers Lazy (Vibe Coding) 19:58 - Every Reason Why Marcus Hates AI 24:07 - Is AI A Bubble? 25:54 - Will AI Take People's Jobs? 30:56 - When Will The AI Bubble Pop? 33:55 - Marcus' Advice To The Youth 34:40 - Is AI Malware Affective? 36:27 - Proactive Defence 40:26 - Marcus Is An AI Hater 45:58 - Will There Ever Be Enough Guardrails? 48:07 - Final Thoughts 49:57 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ai #cybersecurity #aimalware

    #556: Stop HARVEST Now DECRYPT Later Attacks: Survive Post Quantum Attacks

    Play Episode Listen Later Mar 14, 2026 25:51


    Quantum computing isn't just 10 years away, it's happening now. In this deep dive, I sit down with Ramana Kompella, Head of Research at Cisco Outshift, to separate the sci-fi vaporware from the engineering reality. We discuss the immediate threat of "Harvest Now, Decrypt Later" attacks, where bad actors steal your encrypted data today to unlock it with quantum computers tomorrow. Ramana breaks down exactly how Cisco is building the "Quantum Network" to counter this, leveraging the "No Cloning Theorem" to create unhackable communication channels. If you are in cybersecurity, networking, or studying computer science, this is your roadmap to the future. We cover the math you need to learn (Linear Algebra), the timeline for real-world adoption (it's closer than you think), and how Quantum Teleportation actually works at a packet level. Topics Covered: • The 5-Year Timeline: Why the "decade away" myth is wrong. • Quantum Networking vs. Computing: Why we need to interconnect quantum processors. • The Physics of Security: How Entanglement and Teleportation prevent eavesdropping. • Career Advice: Why Linear Algebra is the most critical skill for AI and Quantum jobs. • Cisco x IBM: The partnership building the future internet. Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Amsterdam 2026. // Ramana Kompella's SOCIAL // LinkedIn: / rkompella / David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming Up 0:43 - Introduction 02:36 - The Exciting Part about OutShift 04:12 - The Promise of Quantum Computing 07:09 - The Importance of Partnership between IBM & Cisco 07:55 - The Difference between Classical Computing & Quantum Computing 11:25 - Why It is Important to study Maths 12:31 - Technical Details About Quantum Computing 19:19 - When Will Quantum Computing Become a Reality? 20:00 - Will Quantum Computing Break Encryption? 25:36 - Outro & Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #quantumnetworking #ciscooutshift #cybersecurity

    #555: VirtualBox VM Escape: Integer Overflow Explained Clearly

    Play Episode Listen Later Mar 10, 2026 47:35


    In this episode, David Bombal sits down with vulnerability researcher Vladimir Tokarev (with Dawid on the interview) to show what AI-assisted vulnerability research looks like when it actually works. Vladimir walks through two real vulnerability case studies and uses them to explain a practical workflow for finding bugs faster with LLMs, without pretending the AI is “fully autonomous.” Demo 1: Gemini CLI command injection Vladimir demonstrates a command injection issue in Gemini CLI tied to the IDE / VS Code extension install flow. He shows how a malicious VSIX file name or path can be crafted so that when the install command is executed, the system ends up running an attacker-controlled command (the demo uses a harmless calculator launch to prove execution). The conversation then breaks down what a VSIX is, what the realistic attack paths are (user tricked into installing a malicious extension or placing it in the right directory), and why this class of bug matters for endpoints running local AI agents. Demo 2: VirtualBox integer overflow and VM escape class impact Next, Vladimir switches to a VirtualBox vulnerability involving an integer overflow that can lead to out-of-bounds read/write in the host process. Because of architecture constraints, he shows the exploit behavior via a recorded clip, then explains the bug using source code. The key teaching moment is the mismatch between 32-bit arithmetic used in bounds checking and 64-bit pointer arithmetic used during the actual memory move, creating a pathway to bypass checks and copy memory outside the intended buffer. Vladimir also explains why having both read and write primitives is powerful for exploitation, and how modern mitigations make “blind” exploitation unrealistic without memory disclosure. How the bugs were found with AI Vladimir then explains the workflow he uses in real engagements: • Run static analysis to generate leads at scale • Use an LLM to triage and filter out noise • Validate the remaining findings by tracing code paths and checking exploitability • Use AI again to accelerate setup, debugging, reverse engineering, and iteration He shares a key insight: the win is not “AI finds everything for you,” it is that AI helps you spend your time on the hardest parts—validation, exploit logic, and decision-making—instead of drowning in thousands (or millions) of findings. Why there is no fully autonomous vuln-research agent yet Finally, Vladimir lays out four practical blockers: 1. Depth reasoning (long multi-step exploit chains) 2. Context limits (missing system-level constraints and assumptions) 3. Learning from failure (repeating bad leads) 4. Exploration (poor goal-driven search without strong reinforcement learning) // Vladimir Tokarev's SOCIAL // X: https://x.com/G1ND1L4 LinkedIn: / vladimir-eliezer-tokarev // Dawid van Straaten's SOCIAL // LinkedIn: / dawid-van-straaten-31a3742b X: https://x.com/nullaxiom?s=21 // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... Disclaimer: This video is for educational purposes only.

    Claim David Bombal

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel