A multimedia information hub for cyber enthusiasts who enjoy threat intelligence, threat hunting, vulnerability management, development, secure coding, technical leadership, risk analysis, and artificial intelligence.
The Hacker Valley Studio podcast is an incredibly informative and engaging show focused on cybersecurity and technology. However, don't let the technical nature of the subject matter deter you from giving it a listen. This podcast is accessible to everyone, even if you're not a technologist. Hosted by Ron and Chris, the episodes cover a wide range of topics including personal growth, mental health, leadership, and leveling up in general. The guests they bring on are diverse, ranging from bestselling authors to military veterans, cyber experts, and everyday people. One unique aspect of this podcast is their Discord community, which comes highly recommended by listeners.
One of the best aspects of The Hacker Valley Studio is its versatility. While it primarily focuses on cybersecurity and technology, it also delves into personal growth and development topics that can resonate with anyone. Ron and Chris have a knack for selecting quality guests who share their stories in a relatable manner that appeals to a broad audience. The information shared in each episode is of high quality, allowing listeners to learn something new regardless of their expertise level.
Another commendable aspect of this podcast is the professionalism and tight ship run by Ron and Chris. They conduct themselves with utmost professionalism when hosting guests or being guests themselves. Their interviewing skills shine through as they guide conversations seamlessly while extracting valuable insights from each guest. Listeners really appreciate how well-structured the episodes are because they leave feeling educated and inspired.
While it's challenging to point out any negative aspects of this podcast due to its overall excellence, one minor drawback could be that some episodes may feel too technical for those unfamiliar with cybersecurity. However, this shouldn't discourage anyone from listening because there are plenty of other episodes that touch upon personal growth and development without overwhelming technical jargon.
In conclusion, The Hacker Valley Studio podcast stands out as one of the best in the cybersecurity space. Whether you're an industry expert or just starting out in the field, this show offers a wealth of knowledge and inspiration. Ron and Chris have created a platform where listeners can learn from their guests' experiences, gain insights into cybersecurity, and explore personal growth. The high level of professionalism exhibited by the hosts ensures that each episode is enjoyable and informative. If you're looking to broaden your understanding of cybersecurity while also nurturing personal development, this podcast is a must-listen.

A year ago, the average employee held about 30 OAuth grants. Today that number has risen to 88, and it isn't slowing down. Ron sits down with Russell Spitler, co-founder and CEO of Nudge Security, and Richard Penshorn, a senior security engineer at a top financial services company, to talk about the AI already living inside your business. Ron, Russell, and Richard dig into why shadow AI doesn't behave like shadow IT, how one forgotten grant became the door into a real world breach, and whether AI agents should ever get access to a corporate inbox. Underneath all of it is the one thing Russell and Richard keep coming back to: ownership. Give an AI agent access with no owner attached and it becomes invisible. Give every employee an approved, low-friction path to use AI and they stop wandering off it. Find out how you can get ahead of the AI already running inside your walls. Impactful Moments 00:00 - Introduction 02:00 - Busting the "shadow AI is just shadow IT" myth 03:45 - Meet Russell Spitler and Richard Penshorn 05:50 - The surprising long tail of AI tool usage 07:00 - Entertainment vs. finance: build vs. buy culture 08:50 - How 30 OAuth grants became 88 in 2026 10:25 - Why manual OAuth audits became untenable 11:30 - The Canva example: what "click to connect" really grants 15:20 - Benign vs. malicious: how a stolen OAuth grant gets exploited 17:00 - Shadow IT vs. Shadow AI: what's actually different now 21:00 - Hot take: should AI agents ever touch corporate email? 25:10 - The three buckets of AI agent discovery 27:55 - Russell's best practices for locking down agents 31:00 - Fundamentals for the next 18 months: visibility and easy paths Links Connect with Russell Spitler on LinkedIn: https://www.linkedin.com/in/russell-spitler/ Connect with Richard Penshorn on LinkedIn: https://www.linkedin.com/in/richardpenshorn/ Learn more about Nudge Security: https://www.nudgesecurity.com/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigation platform from scratch. John's system runs on more than 30 specialized agents that reason through cases instead of following a script. In one run, that meant over 140 detections investigated in under four hours at an 80 to 85% quality rating. Ron and John dig into the hard lesson that made John rip out his own tooling and rebuild it around function calling, why "humans first" drives every decision his team makes, and whether AI SOC is actually different from SOAR or just the same promise with way better marketing. Underneath all of it is the one thing John says decides whether any of this actually works: context. Give the AI too little and it's guessing, give it too much and it drowns just like a human would. Listen to find out what it actually takes to build an AI SOC that reasons instead of just automates. Impactful Moments 00:00 - Introduction 02:05 - The rewind: how SOAR promised to save the SOC in 2015 03:35 - Meet John Gillis, Adobe's Staff AI Security Engineer 05:30 - What cybersecurity looked like before AI at enterprise scale 07:00 - The "humans first" strategy behind Adobe's AI investigator 09:30 - Why careless context management is the biggest pitfall in agent design 14:45 - Solving the speed problem: is it tooling, process, or people? 17:10 - From monolith to microservices: rebuilding the platform for scale 24:05 - What actually makes an AI agent's "persona" work 26:00 - John's prediction for the SOC three years from now 28:50 - The three skills every security practitioner needs for 2026 32:10 - Final verdict: is AI SOC really different, or SOAR with new branding? Links Connect with John Gillis on LinkedIn: https://www.linkedin.com/in/john-gillis/ If you're a researcher ready to make an impact, check out the announcement about Adobe's new home for the Adobe Bug Bounty Program here: https://blog.adobe.com/security/a-new-home-for-the-adobe-bug-bounty-program Check out Adobe's Bug Bounty profile on Intigriti: https://app.intigriti.com/programs/adobe/adobepublic/detail Learn more about Adobe: https://www.adobe.com/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

Fresh off the showroom floor at Black Hat 2026, Ron brings back some hot takes from the crowd. Nearly every booth he visited, including the Exaforce booth, was pushing in the same direction. Trust in AI isn't a philosophy debate anymore, it's an engineering problem people are actively solving. Ron then catches up with Jen Easterly, CEO of RSAC, for a wide-ranging conversation on what it actually takes to build that trust. From her move out of government to her hard line on AI regulation and liability, the conversation takes an unexpected turn when Jen opens up about "cognitive surrender" and why she believes good judgment can't be automated away. Couldn't make it to Black Hat this year? This episode has you covered. Impactful Moments 00:00 - Introduction 02:45 - Reporting live from Black Hat 2026: hot takes from the showroom floor 05:05 - Welcoming Jen Easterly, CEO of RSAC 07:55 - A day in the life running RSAC and the Innovation Sandbox 10:00 - AI whack-a-mole and the sweet spot for regulation 11:00 - Governance vs. regulation, the EU AI Act, and state laws 13:30 - Why accountability and liability need to catch up to AI makers 14:45 - The case for autonomous patching and healing code like "The Matrix" 17:50 - The hot take Jen hasn't said before: not outsourcing our humanity 20:30 - Why in-person conferences matter more in the AI era 21:55 - Ron's takeaway: who decides when AI has earned our trust? Links Connect with Jen Easterly on LinkedIn: https://www.linkedin.com/in/jen-easterly Learn more about Exaforce: https://www.exaforce.com – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us

What if the encrypted traffic flowing across the internet right now (emails, files, logins) is already being quietly collected and stored by someone waiting for the day they can finally crack it open? That's the threat behind "harvest now, decrypt later," and it's closer than most people think. Ron Eddings sits down with Michael Fasulo, Senior Director of Portfolio Marketing at Commvault, to talk about where post-quantum cryptography (PQC) really stands in 2026. They discuss "harvest now, decrypt later," the specific industries quietly racing to prepare, and why a commercially viable quantum machine might only be four years away. Ron and Michael trace the journey from a 1998 hack to today's quantum race, and the good news is there's still time to get ahead of it. Listen to hear where the real opportunity is, and how to start building your defense today. Impactful Moments 00:00 - Introduction 01:40 - Rewind: the 1998 Deep Crack story 04:10 - Michael Fasulo and the current state of post-quantum cryptography in 2026 05:05 - Harvest now, decrypt later: do people really have the storage to do this? 06:10 - Where is this actually happening? Nation-states vs. coffee shops 08:50 - Who the real targets are: government, financial services, oil and gas 10:05 - Are everyday SaaS tools like Zoom and Gmail implicated? 12:25 - How Commvault helps organizations inventory their crypto footprint 17:00 - Trust, vendor partnerships, and the Commvault / Microsoft Sentinel integration 18:30 - Signs that a commercial quantum machine may be closer than we think 24:45 - Are we already behind? What to do starting next week 28:20 - Deep Crack revisited Links Connect with Michael Fasulo on LinkedIn: https://www.linkedin.com/in/michael-fasulo Learn more about Commvault: https://www.commvault.com – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

What if the biggest risk to your organization isn't the device that gets lost, but the data that lives on it? Ron Eddings sits down with Jared Shepard, Founder and CEO of Hypori, whose path ran from homeless high school dropout to Army infantry to building a company that rethinks mobile security from the ground up. Jared makes the case for something more radical than most vendors will admit: stop defending the edge device entirely, and make sure sensitive data never lands there in the first place. He and Ron cover MDM and MAM's blind spots, executive protection, and the shadow AI habits quietly becoming every security leader's next headache. The episode also lands at a tense moment for the defense industrial base with the Pentagon having just paused third party CMMC assessments, now putting the burden of proof back on self attestation. If you're still trusting the edge device to protect you, this episode is your wake up call. Impactful Moments 00:00 - Introduction 02:00 - Hack The Headlines: Top new from around the industry 07:30 - Meet Jared Shepard, founder and CEO of Hypori 10:00 - What Hypori does and how it started 15:40 - MDM vs. MAM: why both miss the real problem 18:45 - Shadow AI and the security habits practitioners can't ignore 20:30 - Collapsing the attack surface and bringing back BYOD (Bring Your Own Device) 22:40 - The 4-gigabit-speed "parlor trick" that proves the Cloud beats your device 25:20 - What the 60-day CMMC pause really changes (and what it doesn't) 29:20 - China, stolen tech, and the rise of AI models like Mythos 36:00 - Closing the loop on the CMMC pause Links Connect with Jared Shepard on LinkedIn: https://www.linkedin.com/in/shepardj Learn more about Hypori: https://hypori.com – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

What does the world's most prolific cybercrime operation look like from the inside? And why does it operate suspiciously like a mid-sized tech company, complete with HR headaches, salary negotiations, and a distracted boss nobody respects? Ron Eddings sits down with investigative journalist and author, Geoff White, who has spent over 20 years covering cybercrime for the BBC, Channel 4 News, and Sky News. Geoff has read 47,000 of Conti's 300,000 leaked internal chats, the gang that dominated the ransomware world in 2021 and 2022, pulling in hundreds of millions of dollars in ransoms. From the Moscow movie studio the gang's leader used to launder money years previously, to the Ukraine war leak that brought the whole Conti empire down, this one plays like true crime… because it is. Geoff makes the case that defenders should think the same way: you're not buying security tools to fend off a hoodie in a basement, you're investing to outcompete a rival business. For anyone trying to integrate a better incident response plan, this episode reframes the whole conversation. Impactful Moments 00:00 - Introduction 01:45 - The Rewind: Colonial Pipeline and the week the East Coast ran dry 03:50 - How Geoff went from tech news to cybercrime reporting 05:10 - The difference between threat groups, APTs, and crime gangs 07:25 - Inside the Conti leaks: 300,000 messages 08:55 - Meet the gang: Stern, Mango, and Target 13:20 - Stern's origin story: Zeus malware, money mules, and the 25th Floor front company 16:50 - Ransomware gangs vs. the mafia: where's the protection? 18:10 - The money: $2.5M single payouts and 400 years of wages 19:30 - The Conti member arrested on a layover in Miami 20:35 - The downfall: the Ukraine war and the leak that ended it all 23:05 - What businesses can learn from Conti: recruitment, retention, reputation 27:45 - Advice for defenders: response waves, segmentation, and negotiating down 31:05 - Ron's takeaway: belonging and the thin line between operator and criminal Links Connect with Geoff White on LinkedIn: https://www.linkedin.com/in/geoffwhitetech/ Get your own copy of Geoff's books (Crime Dot Com, The Lazarus Heist, Rinsed): https://geoffwhite.tech/book/ Want more information on Conti? Check out Geoff's BBC podcast series, Cyber Hack: The Conti Files, available on BBC Sounds, Spotify, and Apple Podcasts – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

What happens when the adversary moves at machine speed, and your SOC is still responding at human speed? Why does nearly every security team say AI should handle L1 work, while 64% of organizations still have zero agents in production? And how long until the "coworker" resolving your ticket in Slack turns out not to be human at all? Tim Leehealey, VP of Strategy and Operations at Strike 48, joins us this week to talk about what it actually takes to get AI agents out of the demo and into production. Tim agenticized his own company's IT, watched it blow up, and came out the other side with lessons from Fortune 100 SOCs running agents at serious scale. He shares where AI actually belongs in the alert pipeline, the objections holding teams back, and a blunt warning for any leader still waiting on the sidelines in 2027. If AI in the SOC is on your roadmap before the end of this year, start here. Impactful Moments 00:00 - Introduction 01:55 - Busting a myth: AI will replace analysts 04:45 - Introducing Tim Leehealey 05:30 - The Strike48 survey: 84% say hand L1 to AI 08:00 - Fear the low-and-slow attacker, not the loud one 13:00 - Getting breached without agents in 2027 15:00 - When Tim's own rollout blew up 19:00 - Micro agents inside deterministic workflows 21:25 - Skills advice for L1 analysts 26:00 - The next 18 months of agentic adoption 28:00 - Jim Bob in your Slack is an agent 21:30 - Ron's take: transparency is the trust unlock Links Connect with Tim Leehealey on LinkedIn: https://www.linkedin.com/in/tim-leehealey-b8b04321 Learn more about Strike48: https://strike48.com Check out the 2026 State of Agentic Security report here: https://hubs.ly/Q04p49S20 Go deeper on Strike 48's technology: https://labs.strike48.com – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

Think about everything you could accomplish if you don't have to be the one driving your browser. In this solo episode, Ron Eddings introduces Interceptor, Hacker Valley Media's first piece of software. Interceptor is an open-source Chrome extension that lets an AI agent drive your real browser, logged-in sessions and all, with no vendor lock-in. Ron shares how it works and describes the use cases that matter most to security practitioners: OSINT and recon, bug bounty operations, prompt-injection testing, and threat-intelligence automation. Ron also puts himself in the hot seat, answering the hardest questions he's gotten about the tool, including why anyone should trust an open-source tool from a podcast company over a polished product from a billion-dollar AI lab. The delegation is coming, and we would rather the security community be the ones who understand it. Impactful Moments: 00:00 - Introduction 02:35 - The Rewind: Same Origin Policy and the Web's Foundation 04:40 - Rapid-fire facts: AI agents got hands, and attacks followed 07:00 - What is Interceptor and why was it built? 10:20 - How Interceptor works: stealth, network visibility, teach and replay 13:10 - Live use-case: dynamic dashboard without writing code 17:05 - Cybersecurity use-cases: OSINT, bug bounty, prompt injection testing 21:50 - Ron answers the hard questions about Interceptor 24:10 - Why trust an open source tool from a podcast company? 25:20 - What a practitioner can do tomorrow 27:30 - Closing reflection: knocking down the vendor lock-in wall Links Download Interceptor on GitHub: https://github.com/hackervalleymedia/interceptor Connect with Ron on LinkedIn: https://www.linkedin.com/in/ronaldeddings/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

What if the same psychology that threat actors use to manipulate their targets is the same psychology that marketers use to earn your trust? In this episode, Ron sits down with Antu Buck, Senior Director of Customer Marketing & Community at Gigamon, who spent two decades building trust between vendors and the practitioners who use their tools. Antu walks us through the three pillars she's built her career around, and makes the case that advocacy shouldn't be an afterthought, but the very first marketing move a company invests in. The conversation lands on something the community doesn't talk about enough: customer marketing is hard to put a number on, so it consistently loses the budget fight to demand gen. Impactful Moments 00:00 - Introduction 02:15 - Myth Buster: "I don't fall for marketing tactics" 04:15 - Meet Antu Buck, Senior Director of Customer Marketing & Community at Gigamon 06:45 - From cold-calling BDR to customer marketing leader 09:40 - Antu's three pillars: advocacy, community, lifecycle management 13:05 - Why customer advocacy is the most underrated pillar 14:40 - The problem with chasing the CISO 16:40 - From transactional selling to relationship building 17:20 - The cold call that became a lifelong champion 20:20 - Are threat actors borrowing tactics from sales and marketing? 23:00 - Why AI tools are off-limits with customer data 27:50 - Why customer marketing loses the budget fight Links Antu Buck on LinkedIn: https://www.linkedin.com/in/antu-buck/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

In 2025, out of all 70+ guests we had on our show, not one of them said they'd trust AI to run their SOC. Now in 2026, that mindset is shifting. In this episode, Ron sits down with Aqsa Taylor, Chief Security Evangelist at Exaforce, to find out what changed, and what's still standing in the way of security teams being able to trust AI agents with response. The conversation covers what's really behind the agentic SOC hype, why "vibe hunting" might be the most fun phrase in cybersecurity right now, and how teams can build enough confidence to hand over the keys to detection, investigation, and response. Aqsa also gets into the one thing she believes has to come before any of it works: the data. Without the right context feeding your AI you're just getting confident guesses dressed up as answers. Listen to find out if your team is ready to take the leap into an agentic SOC. Impactful Moments 00:00 - Introduction 02:05 - Hack the headlines, June top trends in cybersecurity 05:30 - Welcoming Aqsa Taylor from Exaforce 06:15 - Inside Exaforce's $125M raise 08:50 - Redefining what AI SOC should mean 09:30 - The evolution from manual playbooks to AI-driven autonomy 13:40 - Where Exaforce fits in an existing stack 18:10 - What vibe hunting looks like in practice 19:40 - The challenges of securing sensitive data in a world dominated by SaaS platforms 22:00 - How to build your trust ladder for AI in the SOC 24:40 - Best use case to get started with AI SOC 28:50 - Ron's takeaway: the data has to be there first Links Connect with Aqsa Taylor on LinkedIn: https://www.linkedin.com/in/aqsa-taylor Learn more about Exaforce: https://www.exaforce.com Join Exaforce's Force Multiplier Substack community: https://theforcemultiplier.substack.com – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

Is AI really coming for your red teaming job? What does it actually take to build a team that thinks like the adversary, and what happens when that team stops caring? And what do you do when you've been in this field long enough that the job that once fired you up has started to feel hollow? In this episode, Ron catches up with Johnny Xmas, Head of Offensive Security at a Fortune 150 Global Food Manufacturer, and one of the most candid voices in offensive security, for a conversation that covers a lot of ground fast. They go deep on where AI actually fits into offensive security workflows, what Johnny really looks for when building elite teams, and why the career advice everyone gives early practitioners might be setting them up for burnout down the road. The conversation takes a turn that doesn't come up enough in this industry, and it's the part you won't want to miss. If you've ever felt your tank running low, this episode was made for you. Impactful Moments 00:00 - Introduction 02:10 - Busting the myth: AI is not replacing red teamers 04:30 - Guest introduction: Johnny Xmas 06:15 - How the offensive security job has changed with AI 09:35 - The SEC 8-K IoC parser tool Johnny just published 11:40 - Building elite teams: what skills Johnny actually hires for 12:45 - Soft skills over technical gaps, and why the fire has to come with you 15:40 - Why "where do you see yourself in five years?" is a garbage question 17:30 - Has Johnny ever crossed the line when it comes to hacking? 20:20 - What to do when you've stopped caring about the job 26:25 - Outro: The AI myth, revisited Links Johnny Christmas on LinkedIn: https://www.linkedin.com/in/johnnyxmas/ Johnny's SEC 8-K IoC parser tool: https://github.com/johnnyxmas/its-over-8k — Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

What does a calf kick have to do with vulnerability management? What can a fighter's mindset teach a security practitioner about operating against an adversary they've never faced? Ron Eddings brings back fan-favorite combat sports analyst and commentator Robin Black for a conversation that was never meant to be about cybersecurity, and ends up being one of the most insightful episodes on the human side of the field. They dig into how underdogs actually win (hint: we're usually wrong about who the underdog is), what it really means to maintain control in a fight, and why the highest level of mastery might actually look like letting go of control entirely. The conversation closes with a look at how the cybersecurity landscape is mutating alongside AI, and whether an arms race that trains itself is heading somewhere catastrophic, or whether it's simply the next evolution of the fight. The answer, like most things in this episode, is more nuanced than you'd expect. Impactful Moments 00:00 - Introduction 02:10 - The Rewind: The Calf Kick and the Peroneal Nerve 04:05 - Welcome back, Robin Black 05:30 - Can smaller still beat bigger? 07:00 - Why underdogs don't win (And why we were wrong) 08:25 - Fighting is about exploiting belief systems 09:30 - Maintaining control against an unknown adversary 10:25 - Adapting vs. anticipating: be water 13:00 - Failure is mandatory 17:25 - How Robin's thoughts have changed about being attacked online 19:00 - AI and the mutating threat landscape 22:15 - Ron's closing thoughts Links Connect with Robin Black on LinkedIn: https://www.linkedin.com/in/robin-black-31b6bb39/ Check out Robin Black on YouTube: https://www.youtube.com/RobinBlack – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

What happens when AI writes all the code and nobody reads it? What if the security prompt you trusted still produced software designed to leak your secrets? And who exactly is on the hook when an AI-generated application takes down your company? In this episode, Ron sits down with returning guest Tanya Janca, Secure Coding Trainer at SheHacksPurple Consulting, to dig into one of the most underestimated risks in software development today: vibe coding. Tanya breaks down what vibe coding actually means, why AI trained on the internet's worst repositories is quietly baking the OWASP Top 10 into every app being built, and what her AI-powered secure coding prompt library can do to help. This is a candid, practical, and community-driven episode, the kind that'll make you want to audit your vibe code-a-thon project before it ever touches production. Impactful Moments 00:00 - Introduction 01:40 - The Rewind: Margaret Hamilton and Apollo 11 05:00 - Knight Capital and the $460M software failure 07:00 - Guest introduction: Tanya Janca 08:15 - What vibe coding actually means in 2026 10:00 - Real story: Claude leaked secrets in a live training 11:30 - Securemyvibe.ca and Tanya's secure coding prompt library 15:00 - OWASP Top 10 vs OWASP Top 10 for LLMs 22:45 - Tanya's petition for the world's first secure coding law 24:55 - Device flow authentication and reducing security friction 28:00 - What the internet would look like in five years without change Links Connect with our guest, Tanya Janca, on LinkedIn: https://www.linkedin.com/in/tanya-janca Get Tanya's free secure coding guideline: https://securecodingguideline.com Subscribe to Tanya's AI Secure Coding Prompt Library: https://securemyvibe.ca Access Tanya's Newsletter & Free Monthly Training: https://newsletter.shehackspurple.ca Connect with Tanya across all social channels: @shehackspurple – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

What if the most sophisticated attack has nothing to do with your firewall? In a world where AI can clone voices, re-lip-sync politicians, and spread a fake newscast to 200,000 people in days, the real target has always been your brain. Ron sits down with Perry Carpenter, Chief Deception Strategist at KnowBe4, to unpack why we're still getting fooled in 2026 and what we can actually do about it. Perry gets into the neuroscience behind why our brains are wired the way they are, how attackers exploit that, and what it really takes to build better instincts in a world full of AI-generated content. You'll also want to stick around for the live demos, where Perry breaks down why they worked and how to spot the tells. Impactful Moments 00:00 - Introduction 02:15 - The myth: smart people don't get fooled 05:20 - Flashback segment: the Ireland deepfake and why it went viral 06:15 - Guest introduction: Perry Carpenter 09:50 - Exploiting cultural bias and tribal instincts 13:45 - Live deepfake demo: face and body replacement in real time 15:30 - Synthetic media vs. deepfake: what's the difference? 20:40 - Breaking down a deepfake: what made it convincing 23:00 - Overproof: why bad deepfakes try too hard 27:15 - System 1 vs. System 2 thinking in cybersecurity 29:45 - The FAIK framework: freeze, analyze, investigate, know 32:40 - Ron's closing reflection Links Connect with our guest, Perry Carpenter, on LinkedIn: https://www.linkedin.com/in/perrycarpenter Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

Right now, someone in your organization is probably feeding sensitive data into an AI system that nobody approved. So when something goes wrong, who's responsible? And more critically, do you even have a policy in place to answer that question? Ron Eddings sits down with his Hacker Valley co-founder, Chris Cochran, now serving as SANS Field CISO and VP of AI Security, to talk about his freshly released SANS AI Security Maturity Model, a practical framework built for security leaders who need to stop philosophizing and start making decisions. They cover the three pillars of AI security maturity: utilizing AI for defense, protecting AI itself, and governing it across the organization. Chris then gets real about where most enterprises actually stand (hint: not as far along as they think). Listen for a conversation that meets you wherever you are: skeptic, early adopter, or somewhere in between. Impactful Moments 00:00 - Introduction 03:00 - Chris Cochran: from Co-Founder to SANS Field CISO 04:20 - Your board is pushing AI before security is ready 06:00 - Tiers of AI uses: summarization to full automation 07:50 - When AI shouldn't make the final call 10:10 - Bite-sized AI: starting small in the enterprise 11:45 - Introducing the SANS AI Security Maturity Model 13:20 - You can no longer afford to be an AI skeptic 16:30 - Three buckets: utilize, protect, and govern AI 18:50 - Fact or Cap: what level of maturity is your enterprise? 21:00 - Retroactive vendor risk and the AI explosion 23:05 - Agentic Identity: workforce, non-human, and beyond 25:00 - What works in the agentic identity space? 27:05 - Blockchain for agent identity: promising or hype? 29:00 - A Message for the next generation of practitioners 31:30 - Ron's closing take: who owns your AI policy? Links Connect with Chris Cochran on LinkedIn: https://www.linkedin.com/in/chrishvm/ Download the SANS AI Security Maturity Model: https://www.sans.org/mlp/2026-ai-security-maturity-model-ebook Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Mythos just found 30,000 new vulnerabilities, and now every security team is asking the same question: what actually matters? In this episode, Ron Eddings sits down with Dan Pagel, CEO at Brinqa, and Brad Hibbert COO & CSO at Brinqa, to break down the Anthropic Mythos moment that rattled the security industry. From the panic of millions of new findings dropping overnight to the strategy of narrowing them down to the 50 that actually matter in YOUR environment, this episode is a masterclass in exposure management at machine speed. Dan and Brad share how Brinqa helps organizations make sense of massive volumes of findings, correlating data across 260+ connectors, enriching vulnerability context, and delivering clear, explainable actions to IT operations teams. They also tackle the bigger question: how do you build enough trust in AI to let it take autonomous action on your behalf? The answer starts with better data, better explainability, and knowing when to keep humans in (or on) the loop. Impactful Moments 00:00 - Introduction 02:00 - What just happened? Breaking down the Anthropic Mythos moment 04:10 - Why most new findings don't apply to your environment 07:12 - What Mythos means to the broader market 09:09 - Why AI-driven discovery isn't slowing down 11:00 - The gap between security and IT ops: how explainability closes it 13:38 - How fast you should go through findings 15:53 - Why MTTR is the wrong metric and what businesses actually care about 18:03 - Why real-time visibility is replacing scheduled scanning 19:50 - Human IN the loop vs. human ON the loop 22:14 - What happens when AI hallucinates? 27:20 - Why we're over and under-estimating the impact of AI 29:54 - The immediate win Brinqa achieves for its customers 31:50 - What CISOs are really asking now: "What does good look like?" Links Connect with our guest, Dan Pagel, on LinkedIn: https://www.linkedin.com/in/dpagel/ Connect with our guest, Brad Hibbert, on LinkedIn: https://www.linkedin.com/in/bradhibbert/ Learn more about Brinqa: https://www.brinqa.com/ Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

SOAR promised to close the loop in the SOC and fell flat. Agentic AI is finally delivering what a decade of playbooks couldn't. In this episode, Ron sits down with Allan Alford, SVP at NTT Global Data Centers, and Tom Findling, co-founder and CEO of Conifers.ai. They cover why static playbooks broke under real-world conditions and how agentic systems are flipping the SOC operating model. They get into hallucination guardrails, human-on-the-loop versus human-in-the-loop, and the QR-code phishing investigation an agent solved on its own without being told how. The conversation closes on trust thresholds, the speed of enterprise adoption, and Allan's blunt warning to any CISO trying to slow this train down… you're already on the tracks. Impactful Moments 00:00 - Intro 02:30 - Why the lazy sysadmin always wins 05:15 - Why SOAR fell flat 08:00 - Guardrails, hallucinations, and showing the work 13:00 - The SOC AI holy grail 15:30 - The moment you start saying we 17:30 - QR-code phishing the agent solved alone 19:00 - Why playbooks were never going to scale 28:00 - Earning trust at enterprise scale 33:30 - Stand in front of this revolution and lose 35:40 - Risk quantification on business steroids Links Connect with our guest, Tom Findling, on LinkedIn: https://www.linkedin.com/in/tomfindling/ Learn more about Conifers.ai at https://www.conifers.ai Connect with our guest, Allan Alford, on LinkedIn: https://www.linkedin.com/in/allanalford/ ___ Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

In 2025, Torq brought a monster truck to RSAC. And Don Jeter, Torq's CMO, will be the first to tell you: nobody's buying an AI SOC platform because of a grave digger in the booth. In this episode, Ron sits down with Don to discuss what Torq is actually doing in a category packed with 60 near-identical vendors, and why "the epidemic of sameness" is the real threat to every cybersecurity brand right now. Don explains why Torq builds everything in-house, why he starts every strategy by listening instead of pitching the product, and why the only differentiator left in cyber marketing is how much you genuinely care. It's a conversation about brand, but it's really a conversation about trust, community, and what it takes to make a CISO text you back. Impactful Moments 00:00 - Introduction 03:50 - How Don landed at Torq 06:09 - What the Torq brand stands for 07:41 - Giving cybersecurity pros their flowers 09:09 - Cookie-cutter booths, cookie-cutter brands 12:00 - Why Torq built everything in-house 15:34 - Start with listening, not the product 18:13 - "We have to out-care the other teams" 21:45 - Nobody buys because of a monster truck 24:06 - Welcome to the experience age 28:30 - Entertain them or lose them Links Connect with our guest, Don Jeter, on LinkedIn: https://www.linkedin.com/in/donjeter/ Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Most organizations are prepping for disaster recovery when they should be building for cyber recovery, and those are not the same thing. Recorded live at RSAC Conference 2026, Ron sat down with Chris Bevil, Principal Security AI Strategist at Commvault, to break down what actually happens after a breach hits and why most teams are caught flat-footed. Chris walks us through Commvault's Minutes to Meltdown tabletop exercise, why isolated recovery environments matter, and how clean data determines whether you get your company back in hours or in 200+ days. This episode will tell you what separates a team that recovers from a team that unravels. Impactful Moments 01:16 - Live at RSAC 2026 with Chris Bevil, Principal, Security AI Strategist at Commvault 01:40 - Minutes to Meltdown origin story 03:00 - What goes into a Meltdown? 04:48 - What happens in the first 30 minutes of chaos 07:00 - What Commvault actually does 08:21 - What is IRE? Isolated recovery environment breakdown 10:40 - What is Disaster Recovery in 2026? 13:00 - How cyber recovery differs from disaster recovery 14:20 - Where attackers go in the first 30 minutes 15:40 - The 3-2-1 rule and where teams fail 21:45 - What successful recovery looks like 25:14 - AI strategy at Commvault Links Connect with our guest, Chris Bevil, on LinkedIn: https://www.linkedin.com/in/chris-b-211998a/ Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

AI adoption is outpacing governance at every level, and the cost of waiting is getting higher by the day. Guru Sethupathy, General Manager of AI Governance at Optro and former Founder of FairNow, breaks down what it really takes to build trust in AI systems before things go sideways. Guru lays out a simple but powerful 3 P's Framework: policies, process, and people, connecting it to what teams are actually dealing with right now, from shadow AI to security threats that don't look like anything we've seen before. If 2026 is the year AI moves from experiments to real operations, this conversation is your blueprint for keeping it under control. Impactful Moments 00:00 - Introduction 02:25 - What does Optro do? Helping companies with the AI governance journey. 03:10 - Why AI governance is really about trust, not control 05:15 - The moment AI went mainstream, and why that changed everything 05:50 - The three real business risks: performance, security, and transparency 07:30 - Human accountability in an AI-driven world 08:48 - What's actually happening with AI regulation, EU, US, and standards 10:28 - Where Optro fits, orchestration vs monitoring in AI governance 13:05 - The 3 Ps framework: policies, process, and people 14:47 - Governance 101, why AI inventory is the first move every team misses 16:12 - The reality check, AI adoption is outpacing governance everywhere 17:45 - Shadow AI explained, what your team is doing that you can't see 19:45 - Optro's top use cases: visibility, compliance, and operationalizing governance 20:43 - Who owns AI governance, and why it's becoming a team sport 22:20 - Final advice, start now or play catch-up later Links Connect with our guest, Guru Sethupathy, on LinkedIn: https://www.linkedin.com/in/guru-sethupathy/ Learn more about Optro: https://optro.ai/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

What happens when attackers collaborate better than defenders? Recorded live from RSAC 2026, this solo episode with Ron breaks down the biggest themes shaping cybersecurity right now, from organized threat groups and massive data breaches to the growing tension between productivity and control inside modern organizations. This conversation highlights a hard truth. The threat landscape is evolving through collaboration. From phishing-as-a-service platforms like Tycoon 2FA to supply chain breaches impacting entire ecosystems, attackers are sharing tools and moving faster than ever. But there's another side to the story. As AI becomes embedded in how work gets done, security teams are being pushed to rethink their role. Blocking tools is no longer enough. The real challenge is enabling the business while managing risk, and that requires trust, alignment, and a stronger sense of community across the industry. This episode is a call to rethink how we approach security. Not as isolated teams enforcing policy, but as a connected community working together to adapt, respond, and move forward. Impactful Moments 00:00 - Introduction, live from RSAC 2026 02:50 - Tycoon2FA and the rise of phishing-as-a-service 04:45 - The TELUS breach and what a petabyte-scale attack looks like 06:21 - Why you need strict controls … everywhere 07:30 - Are AI agents the new Shadow IT? 09:00 - The balance between productivity and security controls 09:27 - Boards' demands for their teams to use AI 11:53 - Why leading security teams is more like parenting than policing 12:42 - Community is the foundation for the future of cybersecurity Links Connect with Ron Eddings on LinkedIn: https://www.linkedin.com/in/ronaldeddings/ Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

What does it mean when your smart doorbell becomes an entry point for surveillance? What happens when a single hacker can jailbreak every major AI model within hours of its release? And why are the same tools being used by both nation-state attackers and the defenders trying to stop them? In this solo episode, Ron Eddings breaks down the urgent case for practitioner unity in cybersecurity, from AI-powered jailbreaking and IoT surveillance creep to geopolitical cyber operations. With RSAC 2026 just around the corner, this episode is a rallying cry for the community to come together, share intelligence, and build the defenses that no single team can build alone. The episode also tackles one of the biggest misconceptions in the industry right now. AI already came for your job, but now it is changing how we define responsibility, decision-making, and trust. Add in rising pressure across the workforce, new legislation pushing for human oversight, and real-world examples of AI being used in global conflict, and the stakes become hard to ignore. Impactful Moments 00:00 - Introduction 02:00 - Pliny the Elder, God Mode and AI Jailbreaks 03:30 - Cyber in US-Israeli Operations in Iran and Anthropic Tensions 06:00 - Cyber threats that are hitting normal people 07:30 - Is my Ring Doorbell a surveillance risk? 10:05 - Attackers are collaborating and sharing more than defenders today 11:30 - RSAC: the cyber Super Bowl 14:30 - AI has already replaced your job 14:30 - Why mental health is cybersecurity's hidden crisis 17:00 - Governance in AI and what Texas is doing about it 19:00 - Was Claude used in state-level ops? Links Connect with Ron Eddings on LinkedIn: https://www.linkedin.com/in/ronaldeddings/ Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

What does it look like when a cybersecurity founder who built a $2.5 billion company decides to level up, again? Dean Sysman, co-founder of Axonius, sits down with Ron Eddings to pull back the curtain on what it really took to go from zero to $100M ARR in four and a half years, and what came next. Dean breaks down the founder mindset, the emotional weight of tying your identity to your company, and why he stepped into the Executive Chairman role while simultaneously pursuing a PhD in AI systems at Columbia University. He gets into how boxing taught him what solo performance reveals about leadership, why vulnerability is a non-negotiable skill at scale, and what it means to care about something bigger than yourself. This one hits differently if you're building, leading, or figuring out what your next chapter looks like. Impactful Moments 00:00 – Introduction 05:00 – Boxing for charity: raising $55K 08:00 – Competitive by nature, born to build 10:00 – Solo performance sharpens team leadership 13:00 – Axonius: zero to $100M ARR in 4.5 years 15:00 – Founder identity tied to company success 21:00 – Purpose bigger than yourself fuels resilience 25:00 – Self-awareness as the #1 growth tool 28:00 – Executive Chairman + Columbia PhD pursuit 33:00 – Ron's personal reflection on founder identity Links Connect with our guest, Dean Sysman, on LinkedIn: https://www.linkedin.com/in/deansysman/ Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Last episode, Ron and Marcus made predictions. This episode, they brought the receipts. A journalist built an app with vibe coding and got hacked on live television. A social network built entirely by AI (not a single line of human code!) exposed 1.5 million authentication tokens and private messages between agents. And 88% of organizations have already had an AI security incident, while barely 14% of deployed agents ever saw a security review. The warnings from last episode aged fast. Marcus J. Carey is back to talk about what that actually means for the people building right now, not the people theorizing about it. Ron and Marcus are in the code themselves, and this conversation is what that experience actually looks like: OpenClaw running loose on your machine, agents racking up API bills, and why guidance, not prompts, not tools, is the real skill that separates builders who thrive from builders who ship disasters. Impactful Moments 00:00 - Introduction 02:00 - Vibe coding hack on live TV 03:30 - Mo Book leaks 1.5M auth tokens 06:00 - Marcus' origin story: War Games, 1983 08:00 - OpenClaw escapes the lab 13:30 - AT&T cuts help desk spend 90% 17:00 - Context is king, guidance is everything 19:00 - Can AI do your job rec right now? 24:00 - The first cybersecurity jobs agents will replace 27:00 - Expertise + AI = 1000x yourself 30:00 - Focus on outcomes, not new tools Links Connect with our guest, Marcus J. Carey, on LinkedIn: https://www.linkedin.com/in/marcuscarey/ Read the articles we referenced in this episode: The vibe coding hack that aired on live TV, ICAEW breaks down exactly how it happened and what it means for anyone building with AI: https://www.icaew.com/insights/viewpoints-on-the-news/2026/feb-2026/cyber-dangers-of-agents-and-vibe-coding 88% of organizations have already had an AI security incident. See the full data from the Cisco State of AI Security 2026 report: https://www.helpnetsecurity.com/2026/02/23/ai-agent-security-risks-enterprise/ Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

The CISO role isn't the finish line, it's a launchpad. 69% of security executives are eyeing the exit, and Anthony Johnson is proof that what comes next can be even bigger. Anthony Johnson, former Global CISO at JP Morgan and Fannie Mae, now founder and managing partner at Delve Risk, breaks down what really happens when a security leader stops buying tools and starts building companies. From the trap of unpaid advisory boards to why AI is eliminating the entry-level pipeline, Anthony delivers a no-nonsense look at career strategy, the future of fractional work, and why understanding how your company makes money is the most underrated skill in cybersecurity. If you're a security practitioner at any level, this episode will change how you think about your next move. Impactful Moments 00:00 - Introduction 01:00 - Meet Anthony Johnson 02:00 - 69% of CISOs want out 06:00 - Why Anthony left the CISO seat 09:00 - Revenue changes your security priorities 11:00 - Career paths after the CISO role 13:00 - The advisory board compensation trap 17:00 - AI's threat to the talent pipeline 22:00 - Hiring for aptitude over competency 24:00 - Soft skills win in the AI era 29:00 - Corporate loyalty is dead—now what 31:00 - Networking that actually lands roles 34:00 - Know how your company makes money 36:00 - Ron's personal reflection on freedom Links Connect with our guest, Anthony Johnson, on LinkedIn: https://www.linkedin.com/in/anthony-johnson-delverisk/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Your email gateway isn't enough anymore, attackers are already inside the workspace through OAuth apps, browser extensions, and account takeover. In this episode, Ron sits down with Rajan Kapoor, VP of Security at Material Security, to break down the real risks hiding inside Google Workspace and Microsoft 365. They cover how phishing has evolved into full-blown business email compromise, why malicious OAuth apps are the new favorite attack vector, and what security teams, especially lean ones, can do right now to lock down their cloud workspace. Rajan also drops practical advice on passkeys, document sharing hygiene, and why data lifecycle management is a problem no one is solving well enough. Impactful Moments 00:00 – Introduction 03:30 – The current state of phishing 05:30 – Outbound email compromise risk 09:30 – OAuth apps as attack vectors 15:00 – AI agents accessing your workspace 16:00 – Prompt injection is the new SQL injection 18:00 – Allow listing apps immediately 24:30 – Google Workspace vs Microsoft 365 security 27:30 – Custom detections require API expertise 28:00 – Why passkeys matter right now 32:00 – Data lifecycle management for shared docs Links Connect with our guest, Rajan Kapoor, on LinkedIn: https://www.linkedin.com/in/rajankkapoor/ Learn more about Material Security: https://material.security ___ Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/ Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com

Security doesn't fail because you missed a tool, it fails because “secure today” tricks you into relaxing tomorrow. This episode exposes why the real fight isn't compliance… it's whether your defenses hold up once attackers hit you with machine-speed pressure. Ron sits down with Sonali Shah, CEO of Cobalt, to talk about how human-led, AI-powered penetration testing is evolving into full-spectrum offensive security. Sonali shares how Cobalt can start a test in 24 hours, push findings directly into Slack/Teams and Jira, and use learnings from 5,000+ pentests a year to continuously sharpen what gets caught. The big takeaway: automation finds the easy stuff as humans find the business-logic traps and attack chains that actually break companies. Impactful Moments 00:00 - Introduction 02:21- Sonali's unexpected CEO path 06:10 - Compliance isn't real security 10:19 - PTaaS: start in 24 hours 12:33- 5,000 pentests yearly scale 17:01 - Humans beat automation limits 20:16 - AI behavior vulnerabilities emerge 27:54 - Indirect prompt injection explained 30:51 - Why juniors + AI is risky 38:27 - 2026 becomes AI battleground Links Connect with Sonali on LinkedIn: https://www.linkedin.com/in/sonalinshah/ Check out Cobalt: https://www.cobalt.io ____ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Text threads made AI feel personal, then agents made it productive, and suddenly “success” turns into chaos you can't even track. In this episode, Ron sits down with Pedram Amini, creator of Maestro, to show what agent work looks like when you stop babysitting and start orchestrating. Pedram lays out why context windows are the limiter, why harnessing beats model-chasing right now, and how Auto Run executes task-docs with fresh context every iteration so agents can run for hours (or days) without melting down. Impactful Moments 00:00 - Intro 02:05 - Codex desktop sparks agent shift 06:40 - Harness beats model iteration 08:10 - Context window: the hidden limiter 12:10 - Terminal sprawl creates agent chaos 14:05 - Maestro panels: agents, tabs, history 17:25 - Auto Run: fresh context per task 26:15 - “Donate tokens” via Symphony PRs 28:20 - AI tax debate gets spicy 33:05 - Start simple: download and run Links Connect with Pedram on LinkedIn: https://www.linkedin.com/in/pedramamini/ Check out Maestro for yourself: https://runmaestro.ai/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Phishing didn't get smarter, it got better at looking normal. What used to be obvious scams now blend directly into the platforms, workflows, and security controls people trust every day. In this episode, Ron sits down with Yaamini Barathi Mohan, 2024 DMA Rising Star and Co-Founder & CPO of Secto, to break down how modern phishing attacks bypass MFA, abuse trusted services like Microsoft 365, and ultimately succeed inside the browser. Together, they examine why over-reliance on automation creates blind spots, how zero trust becomes practical at the browser layer, and why human judgment is still the deciding factor as attackers scale with AI. Impactful Moments 00:00 - Introduction 02:44 - Cloud infrastructure powering crime at scale 07:45 - What phishing 2.0 really means 12:10 - How MFA gets bypassed in real attacks 15:30 - Why the browser is the final control point 18:40 - AI reducing SOC alert fatigue 23:07 - Mentorship shaping cybersecurity careers 27:00 - Thinking like attackers to defend better 31:15 - When trust becomes the attack surface Links Connect with our guest, Yaamini Barathi Mohan, on LinkedIn: https://www.linkedin.com/in/yaamini-mohan/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Cybersecurity didn't start as a billion-dollar crime machine. It started as pranks, ego, and curiosity. That origin story explains almost everything that's breaking today. Ron sits down with Graham Cluley, one of the earliest antivirus developers turned trusted cyber voice, to trace how malware evolved from digital graffiti into organized financial warfare. From floppy disks and casino-style viruses to ransomware, extortion, and agentic AI, the conversation shows how early decisions still shape today's most dangerous assumptions. Graham also explains why AI feels inevitable, but still deeply unfinished inside modern organizations. Impactful Moments 00:00 - Introduction 04:16 - Malware before money existed 07:30 - Cheesy biscuits changed cybersecurity 13:10 - When documents became dangerous 14:33 - Crime replaced curiosity 15:23 - Sony proved no one was safe 20:15 - Reporting hacks without causing harm 24:01 - AI replacing penetration testers 29:18 - Agentic AI shifts the threat model 36:30 - Why rushing AI breaks trust Links Connect with our guest on LinkedIn: https://www.linkedin.com/in/grahamcluley/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

The most dangerous attack surface isn't your infrastructure, it's desire under pressure. When people are emotional, impulsive, and hoping for connection, security controls don't fail… judgment does. Ron sits down with George Al-Koura, CISO at Ruby Life, to talk about securing some of the most psychologically sensitive data on the internet, and why dating data can carry more real-world risk than financial data. From the fallout of the Tea dating-safety app breaches to impulse-driven human behavior, sexual science, and intel-driven security, this conversation cuts straight to the uncomfortable truth: protecting users means understanding how people actually behave when emotion overrides logic. Impactful Moments 00:00 - Introduction 01:45 - Tea app breach reality-check 04:26 - Why George chose Ruby Life 09:10 - Dating data hits harder 11:52 - Competitors refuse threat sharing 16:15- AI boosts social engineering 18:47 - Horny brains create risk 19:49 - Sexual science meets security 21:20 - AI avatars dating first 33:13 - Trust is earned in layers Links Connect with our guest on LinkedIn: https://www.linkedin.com/in/george-y-al-koura/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

AI doesn't break security, it exposes where it was already fragile. When automation starts making decisions faster than humans can audit, AppSec becomes the only thing standing between scale and catastrophe. In this episode, Ron sits down with Joshua Bregler, Senior Security Manager at McKinsey's QuantumBlack, to dissect how AI agents, pipelines, and dynamic permissions are reshaping application security. From prompt chaining attacks and MCP server sprawl to why static IAM is officially obsolete, this conversation gets brutally honest about what works, what doesn't, and where security teams are fooling themselves. Impactful Moments 00:00 – Introduction 02:15 – AI agents create identity chaos 04:00 – Static permissions officially dead 07:05 – AI security is still AppSec 09:30 – Prompt chaining becomes invisible attack 12:23 – Solving problems vs solving AI 15:03 – Ethics becomes an AI blind spot 17:47 – Identity is the next security failure 20:07 – Frameworks no longer enough alone 26:38– AI fixing insecure code in real time 32:15 – Secure pipelines before production Connect with our Guest Joshua Bregler on LinkedIn: https://www.linkedin.com/in/breglercissp/ Our Links Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

AI didn't quietly evolve, it crossed the line from recommendation to execution. Once agents stopped advising humans and started acting inside real systems, trust replaced experimentation and consequences became unavoidable. In this episode, Ron sits down with Marcus J. Carey, Principal Research Scientist at ReliaQuest, to examine what happens after AI is given authority: agents running in production, prompt debt replacing technical debt, vibe coding accelerating risk, and maintenance emerging as the true bottleneck. Together, they discuss how cybersecurity, software engineering, and the job market are shifting now that AI operates with autonomy, often faster than organizations can explain what their systems are actually doing. Impactful Moments 00:00 - Introduction 02:26 - AI agents cross into production 03:35 - Trust boundaries become attack surfaces 6:46 - Vibe coding and hidden technical debt 09:22 - Prompt debt changes everything 17:40 - Why junior knowledge disappears 19:00 - AI replaces repetitive cyber workflows 23:43 - Coding becomes human leverage 29:30 - Fall in love with the problem Connect with our guest, Marcus J. Carey: LinkedIn https://www.linkedin.com/in/marcuscarey/ X https://x.com/marcusjcarey Articles and Books Mentioned: Article used for discussion: https://www.techradar.com/pro/security/this-webui-vulnerability-allows-remote-code-execution-heres-how-to-stay-safe Atomic Habits: https://jamesclear.com/atomic-habits-summary Fall in Love with the Problem, Not the Solution: https://sobrief.com/books/fall-in-love-with-the-problem-not-the-solution Our Links: Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

AI isn't quietly changing software development… it's rewriting the rules while most security programs are still playing defense. When agents write code at machine speed, the real risk isn't velocity, it's invisible security debt compounding faster than teams can see it. In this episode, Ron Eddings sits down with Varun Badhwar, Co-Founder & CEO of Endor Labs, and Henrik Plate, Principal Security Researcher of Endor Labs, to break down how AI-assisted development is reshaping the software supply chain in real time. From MCP servers exploding across GitHub to agents trained on insecure code patterns, they analyze why traditional AppSec controls fail in an agent-driven world and what must replace them. This conversation pulls directly from Endor Labs' 2025 State of Dependency Management Report, revealing why most AI-generated code is functionally correct yet fundamentally unsafe, how malicious packages are already exploiting agent workflows, and why security has to exist inside the IDE, not after the pull request. Impactful Moments 00:00 – Introduction 02:00 – Star Wars meets cybersecurity culture 03:00 – Why this report matters now 04:00 – MCP adoption explodes overnight 10:00 – Can you trust MCP servers 12:00 – Malicious packages weaponize agents 14:00 – Code works, security fails 22:00 – Hooks expose agent behavior 28:30 – 2026 means longer lunches 33:00 – How Endor Labs fixes this Links Connect with our Varun on LinkedIn: https://www.linkedin.com/in/vbadhwar/ Connect with our Henrik on LinkedIn: https://www.linkedin.com/in/henrikplate/ Check out Endor Labs State of Dependency Management 2025: https://www.endorlabs.com/lp/state-of-dependency-management-2025 Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

What if the most dangerous hackers are the ones who never touch a keyboard? The real threat isn't just about stolen credentials or ransomware; it's about understanding how attackers think before they even strike. In cybersecurity, defense starts with offense, and the best defenders are those who've walked in the hacker's shoes. In this episode, Ron sits down with John Hammond, principal security researcher at Huntress and one of cybersecurity's most recognizable educators. John shares his journey from Coast Guard enlistee to YouTube creator, building an entire media company around ethical hacking. They dig into the balance between public research and responsible disclosure, the rise of AI-augmented attacks, and why identity is now the biggest attack surface in modern enterprises. Impactful Moments: 00:00 - Introduction 01:00 - AI weaponized in cyber espionage 05:00 - Learning by teaching publicly 09:00 - Balancing curiosity with responsible disclosure 13:00 - Building a creator company 16:00 - Identity as the new frontier 20:00 - AI agents running breach simulations 22:00 - Predictions for cybersecurity in 2026 25:00 - Ron's hacking habit confession Links: John Hammond LinkedIn: https://www.linkedin.com/in/johnhammond010/ John Hammond Youtube: https://www.youtube.com/@_JohnHammond Article for Discussion: https://www.reuters.com/world/europe/russian-defense-firms-targeted-by-hackers-using-ai-other-tactics-2025-12-19/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Three banks in four days isn't just a bragging right for penetration testers. It's a wake-up call showing that expensive security tools and alarm systems often fail when tested by skilled operators who understand both human behavior and technical vulnerabilities. Greg Hatcher and John Stigerwalt, co-founders of White Knight Labs, talk about their latest physical penetration tests on financial institutions, manufacturing facilities protecting COVID-19 vaccine production, and why their new Server 2025 course had to rewrite most common Active Directory tools. They share stories of armed guards, police gun draws, poison ivy reconnaissance, and a bag of chips that saved them from serious trouble. The conversation reveals why EDR alone won't stop ransomware, how offline backups remain the exception rather than the rule, and what security controls actually work when attackers bring custom tooling. Impactful Moments: 00:00 - Intro 01:00 - New training courses launched 03:00 - Server 2025 breaks standard tools 05:00 - COVID facility physical penetration 07:00 - Armed guards change the game 10:00 - Police draw guns on operators 13:00 - Bag of chips saves the day 15:00 - Nighttime versus daytime physical tests 18:00 - VIP home security assessments 20:00 - 2026 threat predictions 22:00 - Why EDR doesn't stop ransomware 27:00 - Low cost ransomware simulation ROI 29:00 - Three banks in four days 32:00 - Deepfake as the new EDR Links: Connect with our guests – Greg Hatcher: https://www.linkedin.com/in/gregoryhatcher2/ John Stigerwalt: https://www.linkedin.com/in/john-stigerwalt-90a9b4110/ Learn more about White Knight Labs: https://www.whiteknightlabs.com Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

When your firewall forgets to buckle up, the crash doesn't happen in the network first, it happens in your blindspots. In this episode, Ron is joined by returning guest Chris Hughes, Co-Founder of Aquia and host of the Resilient Cyber podcast. Chris helps reframe vulnerability work as exposure management, connect technical risk to human resilience, and break down the scoring and runtime tools security teams actually need today. Expect clear takeaways on EPSS, reachability analysis, ADR, AI's double-edged role, and the one habit Chris swears by as a CEO. This episode fuses attack-surface reality with mental-attack-surface strategy so you walk away with both tactical moves and daily practices that protect systems and people. Impactful Moments: 00:00 - Intro 02:00 - Breaking: Fortinet WAF zero-day & visibility lesson 05:00 - Meet Chris Hughes: CEO, author, Resilient Cyber host 08:00 - Mental attack surface explained and why it matters 18:00 - From CVSS to EPSS, reachability, and ADR realities 21:00 - AI as force-multiplier for attackers and defenders 24:30 - Exposure vs vulnerability naming, market trends 26:00 - Chris's book & how to follow his work 30:00 - Ron's solo: 3 pillars to patch your mindset 34:00 - Closing takeaways and subscribe reminder Links: Connect with our guest, Chris Hughes, on LinkedIn: https://www.linkedin.com/in/resilientcyber/ Check out the article on the Fortinet exploit here: https://www.helpnetsecurity.com/2025/11/14/fortinet-fortiweb-zero-day-exploited/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

The real disruption isn't AI replacing humans, it's the shocking possibility that human labor was the economic bubble all along. In this episode, Ron Eddings sits down with Daniel Miessler, founder of Unsupervised Learning and longtime security leader, to break open why companies are hitting record profits with shrinking workforces, and what that means for your future. Daniel shares how AI agents, context management, and his Telos problem-first framework are reshaping what it means to create value in the modern economy. From Apple to Human 3.0, Daniel explains why building in public, learning fast, and solving real problems are the ultimate career edge in an AI-powered world. Impactful Moments: 00:00 - Introduction 02:00 - Jobless profit boom accelerates 05:00 - Daniel's AI journey at Apple 08:00 - Building careers around problems 12:00 - AI bubble or timing problem 15:00 - Nine-year-old codes app in two hours 18:00 - Human labor is the bubble 22:00 - Context management changes everything 26:00 - Adaptation equals survival Links: Daniel's Website: danielmiessler.com/ Daniel's Github: https://github.com/danielmiessler/ Daniel's LinkedIn: https://www.linkedin.com/in/danielmiessler/ Upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/ Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio

AI agents aren't just reacting anymore, they're thinking, learning, and sometimes deleting your entire production database without asking. The real question isn't if your AI agent will be hacked, it's when, and whether you'll have the right hooks in place to stop it before it happens. In this episode, Ron breaks down the ChatGPT Atlas vulnerability that shocked researchers, revealing how malicious prompts can turn AI assistants against their own users by bypassing safeguards and accessing file systems. He presents his new talk "Hooking Before Hacking," introducing a framework for applying EDR principles, prevention, detection, and response, to AI agents before they execute unauthorized commands. From pre-tool use hooks that catch malicious intent to one-time passwords that put humans back in the loop, this episode shares practical security controls you can implement today to prevent your AI agents from going rogue. Impactful Moments: 00:00 - Introduction 02:00 - ChatGPT Atlas vulnerability exposed 04:00 - AI technology outpacing security guardrails 05:00 - Guardrail jailbreaks and prompt injection 06:00 - AI agents deleting production databases 07:00 - EDR principles for AI agents 09:00 - Pre-tool use hooks catch intention 11:00 - User prompt sanitization prevents leaks 14:00 - One-time passwords for agent workflows 16:00 - Automation mistakes across 10 years Links: Connect with Ron on LinkedIn: https://www.linkedin.com/in/ronaldeddings/ Check out the entire article here: https://www.yahoo.com/news/articles/cybersecurity-experts-warn-openai-chatgpt-101658986.html GitHub Repository: https://hackervalley.com/hooking-before-hacking See Ron's "Hooking Before Hacking" presentation slides here: http://hackervalley.com/hooking-before-hacking-presentation Check out our website: https://hackervalley.com/ Upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/ Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio

What if your security team never missed a single alert and actually had time to think strategically? In this episode, Ahmed Achchak, CEO and Co-Founder of Qevlar AI, reveals how autonomous SOCs are reshaping security operations worldwide. From tackling alert fatigue to empowering analysts with intelligent AI-driven investigations, Ahmed shares the inside story of building a system that can act on threats faster than any human alone. Learn how Qevlar's innovative approach is giving organizations clarity, control, and measurable ROI while freeing security teams to focus on what truly matters. Impactful Moments 00:00 - Introduction 01:30 - Founding Qevlar AI by chance 03:30 - Inefficiency of current SOCs 05:00 - Augmenting analysts, not replacing them 08:00 - AI investigating alerts at scale 11:30 - How autonomous agents handle phishing 14:30 - Why tackling all alerts maximizes ROI 17:30 - Graph technology as investigation backbone 25:00 - Limitations and randomness of LLMs 30:30 - Advice for testing AI in SOCs Links Connect with our guest Ahmed on LinkedIn: https://www.linkedin.com/in/ahmed-achchak-872554109/ Check out Qevlar's website: https://www.qevlar.com/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Who said cybersecurity had to be serious? The future of cyber is creative, human, and even a little sexy. In this special 400th episode, Ron Eddings celebrates six incredible years of Hacker Valley Studio with one of cyber's most creative voices, Maria Velasquez, Co-Founder of the Cybersecurity Marketing Society and Co-Host of Breaking Through in Cybersecurity Marketing. Together, they discuss how bold storytelling, authentic community, and a touch of fun are reshaping the way we connect in cybersecurity. Maria opens up about turning burnout into purpose, building a 4,000-strong global movement, and why the next frontier in cyber might just be entertainment. Impactful Moments: 00:00 - Introduction 02:00 - CISA layoffs and collaboration fragility 04:00 - Welcoming Maria Velasquez 06:00 - How loneliness sparked a global community 08:00 - Why collaboration fuels cybersecurity growth 10:00 - When cybersecurity marketing was “boring” 12:00 - The rise of creativity and brand power 14:00 - Story behind Torque's “Kill the S.O.A.R” campaign 15:00 - Making cybersecurity emotional and human 17:00 - Maria's advice for bold marketing leaders 18:00 - The next big thing: experiential marketing 20:00 - Inside Cyber Marketing Con 2025 24:00 - Final reflections on community and creativity 27:00 - Ron's takeaways: connection drives innovation Links: Connect with Maria on LinkedIn: https://www.linkedin.com/in/maria-vepa/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

To defend like a human, you first have to think like a hacker. In this episode, Ron Eddings sits down with Chris Dale, Co-Founder and Chief Hacking Officer at River Security, to explore the human side of hacking, where curiosity, persistence, and vigilance meet defense. Chris shares how the traditional idea of penetration testing has evolved into a continuous journey of discovery, and why reconnaissance and storytelling are critical tools for modern defenders. From real-world breach stories to lessons on trust and responsibility, this episode reveals how thinking like a hacker, and acting like a human can transform the way we approach cybersecurity. Impactful Moments 00:00 - Introduction 01:00 - The shocking discovery of 266,000 exposed systems 03:30 - Why even trusted systems can become attack points 05:00 - Meet Chris Dale: hacker, educator, and human defender 07:30 - The truth about pen testing and real-world attacks 10:00 - Mapping your digital footprint, what most companies miss 13:00 - How continuous vigilance changes everything 16:00 - The hacker mindset vs. compliance checklists 18:00 - When hacking helps: becoming a company's “criminal best friend” 21:00 - Storytime: hacking Sketchers and getting free shoes 24:00 - The journalist hack that exposed a bigger issue 28:00 - Building trust through transparency in cybersecurity 31:00 - Lessons from hacking, teaching, and staying human Links: Connect with our Chris on LinkedIn: https://www.linkedin.com/in/chrisad/ Read the Tech Radar article here: https://www.techradar.com/pro/security/f5-breach-fallout-over-266-000-instances-exposed-to-remote-attacks Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

When code meets intuition, innovation gets personal. But what happens when we let AI vibe with our ideas? In this episode, Ron Eddings covers the rise of AI-driven development from Vibe Coding, where natural language shapes real code, to the emerging Model Context Protocols (MCPs) that redefine how apps talk to AI. He breaks down the recent Figma MCP vulnerability to discuss how creativity and security now collide in surprising ways. With hands-on insights using Raycast and practical steps for building responsibly, Ron takes you inside a new era where human intuition and machine intelligence truly build together. Impactful Moments 00:00 - Introduction 01:00 - The Figma vulnerability explained 03:00 - Why MCP security matters 05:00 - What vibe coding really means 07:00 - Writing with intention and context 08:00 - The power of structured prompting 10:00 - How MCP connects everything 12:00 - Why adoption is skyrocketing 15:00 - Setting up an MCP server 17:00 - Agents, actions, and security trust 19:00 - The real takeaway: curiosity with caution 30:00 - Predictions on OpenAI's upcoming browser 33:00 - The profit battle between OpenAI and Microsoft 35:00 - Windsurf's rollercoaster of acquisitions Links: Connect with our Ron on LinkedIn: https://www.linkedin.com/in/ronaldeddings/ Check out the Hacker News article here: https://thehackernews.com/2025/10/severe-figma-mcp-vulnerability-lets.html?m=1 Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

The real edge in cybersecurity isn't found in new tools, it's built through timeless fundamentals and a mindset that never stops learning. In this episode, Ron sits down with Rich Greene, Senior Solutions Engineer and Instructor at SANS Institute, to uncover how true cyber value starts with skills, curiosity, and mindset. Rich shares his remarkable story of surviving a battlefield injury, retraining his brain, and how that journey shaped his approach to mastering cybersecurity. Together, they connect real-world lessons like the recent Discord breach to the core truth that even advanced systems depend on people who master the basics. Impactful Moments 00:00 - Introduction 02:00 - Discord breach and third-party risk 05:00 - Meet Rich Greene from SANS 06:00 - The power of mastering fundamentals 07:00 - Learning how to learn 08:30 - Rich's story of rebuilding his memory 11:00 - Forcing the brain to grow stronger 12:00 - Top skills that get you paid 14:00 - Skills that lead to fulfillment 16:00 - Fundamentals that fuel long-term success 17:00 - The OSI model decoded 20:00 - Why operating systems matter 21:00 - Security operations fundamentals 23:00 - Why cloud is the #1 must-learn skill 25:00 - Final advice: sharpen your fundamentals Links Connect with our Rich on LinkedIn: https://www.linkedin.com/in/secgreene/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

What if protecting your digital twin becomes the new cyber hygiene? In this week's episode, Ron welcomes back cybersecurity leader Jason Rebholz, CEO of Evoke, to discuss how AI is reshaping the fundamentals of cyber hygiene. From data breaches and deepfakes to everyday habits that protect our digital lives, Jason shares how small actions and smarter use of AI can make all the difference. Together, they uncover how our growing digital footprints are giving rise to digital twins, AI replicas that can mirror our behaviors, voices, and even decisions, and what that means for the future of trust, identity, and security. Impactful Moments: 00:00 - Introduction 01:00 - The Neon app data leak story 03:00 - Why our voices are the new passwords 05:00 - How AI can strengthen cyber hygiene 07:00 - Jason's mission to secure AI systems 09:00 - AI as a force multiplier for defenders 11:00 - Deepfakes and the new social engineering playbook 13:00 - Attackers' use of AI and what it means for us 15:00 - The rise of digital twins and identity threats 19:00 - How to defend against “yourself” online 20:00 - Final reflection: Trust in the AI age Links: Connect with Jason on LinkedIn: https://www.linkedin.com/in/jrebholz/ Check out the TechCrunch article on the Neon app data leak story: https://techcrunch.com/2025/09/25/viral-call-recording-app-neon-goes-dark-after-exposing-users-phone-numbers-call-recordings-and-transcripts/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

The biggest security threat isn't in the cloud, it's hidden in the code you trust the most. In this episode, Ron sits down with Varun Badhwar, Co-Founder & CEO of Endor Labs, who shares why research shows that nearly 80–90% of application code comes from open source and third-party libraries, not your own developers. Varun discusses the unseen risks of AI-generated software, how attackers can now weaponize vulnerabilities in hours, and why precision in security matters more than ever. He also reveals how AI can be both the ultimate accelerator and the ultimate weakness in modern development. Impactful Moments: 00:00 - Introduction 02:00 - Varun's journey from RedLock to Endor Labs 04:00 - Why the software supply chain is broken 07:00 - AI coding assistants and insecure code risks 10:00 - The NPM self-replicating worm discovery 13:00 - Simple controls to enforce Zero Trust in code 16:00 - Pairing AI with security to prevent slop 19:00 - AI-powered security code reviews explained 22:00 - Why 88% of code goes unused 26:00 - Developer efficiency as the new security metric 29:00 - The next wave of AI-driven software threats Links: Connect with our Endor on LinkedIn: https://www.linkedin.com/in/vbadhwar/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Search engines aren't dying quietly, they're being replaced in real time by AI browsers and voice agents. AI isn't just answering questions anymore; it's acting for us. In this episode, Ron Eddings explores how tools like NanoBrowser and Comet are reshaping browsing, why Google may be in trouble, and how AI voices are becoming the new interface for productivity. From breakthroughs to risks, this is a front-row look at how AI agents are changing how we work, connect, and live online. Impactful Moments: 00:00 - Introduction 01:00 - AI agents as everyday tools 02:00 - Testing AI-powered browsers 03:00 - Comet: AI browser from Perplexity 04:30 - Why Google should be worried 05:30 - Real-world tasks for AI browsers 07:00 - Automating cybersecurity inventory 09:00 - Comet in action on LinkedIn 10:00 - Testing for malicious exploits 11:00 - Risks of persuasive AI prompts 12:00 - The rise of voice agents 13:30 - First real-world AI voice experience 15:00 - Security concerns with customer data 16:30 - Double-edged sword of AI adoption 17:30 - System prompt leakage vulnerabilities 18:00 - Why voice could shrink attack surfaces Links: Connect with Ron on LinkedIn: https://www.linkedin.com/in/ronaldeddings/ Check out NanoBrowser: https://nanobrowser.ai/ Check out Comet by Perplexity: https://www.perplexity.ai/comet Read the article ‘No more links, no more scrolling - the browser is becoming an AI Agent.' here: https://venturebeat.com/ai/no-more-links-no-more-scrolling-the-browser-is-becoming-an-ai-agent Read the article ‘How Voice AI Prompt Injection Threatens Enterprise Security' here: https://www.teneo.ai/blog/how-voice-ai-prompt-injection-threatens-enterprise-security Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Some tools replace tasks. Others reshape the way we think about security. In this episode, Ron welcomes back Phillip Wylie, one of the most respected voices in offensive security, author, educator, and longtime friend of the Hacker Valley community. With over 27 years of experience across cybersecurity disciplines, Phillip has guided thousands of professionals through his books, talks, and mentorship. He shares how AI is reshaping pen testing and red teaming, the value of automating away repetitive tasks, and why the fundamentals of security will always matter. From defining red teaming in 2025 to guiding newcomers on how to break in, Phillip delivers insights that balance cutting-edge innovation with timeless wisdom. Impactful Moments: 00:00 - Introduction 01:00 - Why Phillip keeps podcasting 03:00 - AI opportunities in pen testing 04:30 - What automation should replace 06:00 - Red teaming vs pen testing in 2025 08:00 - Defining adversary emulation 10:40 - Building the ideal AI assistant 15:00 - The best AI use cases today 18:30 - AI-driven threat modeling 21:00 - Breaking into pen testing now 25:00 - Building a portfolio and personal brand 27:30 - Why in-person networking still matters Links: Connect with Phillip on LinkedIn: https://www.linkedin.com/in/phillipwylie/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

What if showing up with consistency could spark opportunities, create careers, and build a global movement? In this episode, Ron sits down with Gerald Auger, Ph.D., cybersecurity educator, content creator, and founder of Simply Cyber. Gerald shares how his daily livestream grew into a thriving community, why consistency is the key to influence, and how AI is reshaping the way cyber professionals work. From building SimplyCyberCon to launching a new pentesting venture, Gerry's journey is a masterclass in community, creativity, and courage. This episode is filled with inspiration and practical takeaways for anyone ready to grow their career, brand, or business in cybersecurity.

What if defenders had their own AI-powered task force, always on, always adapting, and finally one step ahead of attackers? In this episode, Ron welcomes Vineet Edupuganti, Founder and CEO of Cogent Security, to discuss how AI agents are rewriting the rules of cybersecurity. Vineet shares why traditional vulnerability management is fundamentally broken, why exposure management matters more than ever, and how Cogent is building an “AI Task Force” to give defenders the edge. From his early days in machine learning to reshaping the future of cyber defense, Vineet breaks down the urgent need for automation, context-driven insights, and explainable AI in security. Impactful Moments: 00:00 - Introduction 02:00 - Vineet's journey into AI and cyber 04:30 - Why vulnerability management is broken 06:10 - Generative AI as a defender's edge 08:20 - Why AI agents outperform brittle automation 09:45 - The first use cases for Cogent's agents 12:00 - Rethinking tier-one SOC analyst roles 13:30 - The rise of exposure management (CTEM) 17:10 - Cogent's vision for an AI task force 18:30 - Early wins and insights with Cogent 20:00 - Biggest misconceptions about AI in security 23:00 - What enterprises should demand from vendors 25:00 - Why explainability is essential in AI systems 27:00 - Startups vs incumbents in cybersecurity innovation 29:30 - Why enterprises must invest in AI now Links: Connect with our guest, Vineet Edupuganti, on LinkedIn: https://www.linkedin.com/in/vineetedupuganti Learn more about Cogent Security: https://www.cogent.security Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

AI is neither friend nor foe, it's both. The way we choose to use it determines whether it helps or harms. In this solo episode, Ron Eddings shares lessons from his first job at a grocery store, his early days in cybersecurity, and today's AI-driven landscape. From productivity hacks like meeting transcription, to creative tools like content-aware editing, to the dark side of phishing and deepfakes, Ron shows why human judgment remains the ultimate defense. This is a passionate reminder that the real power isn't in the tools, it's in us. Impactful Moments 00:00 - Introduction 01:15 - AI is the tool, not the toolbox 03:00 - A grocery store scam that taught a life lesson 06:00 - The irreplaceable role of human judgment 07:30 - First cybersecurity job at Booz Allen Hamilton 09:00 - How AI boosts productivity with meeting transcription 12:00 - Creative shortcuts with AI in image and video editing 15:00 - Vibe coding and generative red teaming 17:30 - AI-powered phishing and scam emails 18:50 - Testing a deepfake voice on Ron's mom 21:30 - Why curiosity and skepticism beat AI deception 22:30 - Final challenge: don't serve AI—make AI serve you Links: Connect with our Ron on LinkedIn: https://www.linkedin.com/in/ronaldeddings/ Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/