Skip to content
Artwork for Hacker Valley Studio
TechnologyEducationSelf-Improvement

Hacker Valley Studio

Hacker Valley Media

Welcome back to the show! Hacker Valley Studio podcast features Host Ron Eddings, as he explores the world of cybersecurity through the eyes of professionals in the industry. We cover everything from inspirational real-life stories in tech, to highlighting influential cybersecurity companies, and we do so in a fun and enthusiastic way. We’re making cybersecurity accessible, creating a whole new form of entertainment: cybertainment.

Play
  • 20 episodes
  • weekly
  • Avg 33 min
  • English
  • S6 · E443
    Wednesday · 38 min

    Do You Know What Your Agent is Doing at 3AM? with Amir Ofek

    Every AI agent in your environment inherits someone's permissions, and most teams have no idea what those agents are actually doing with them. Amir Ofek, CEO and co-founder of Aizome, shares how to make every agent accountable before the damage shows up as a $150,000 bill. In this episode, Amir explains why human and machine identity tools both fail for AI, why agents act more like eager, naive interns than employees, and how a new category called ARISE (Agentic Runtime Identity Security Enforcement) is emerging to fix it. This one's for anyone building with AI agents right now (so, most of us). Amir's take: the biggest danger isn't a breach. It's agents quietly doing the wrong thing at scale while nobody's watching. Impactful Moments 00:00 - Introduction 02:30 - Busting the Myth: "I Know What My Agents Are Doing" 05:30 - The Samurai Story Behind Aizome's Name 08:25 - Why Not All AI Agents Are Born Equal 11:15 - Where Enterprises Are Actually Deploying AI Agents Today 14:25 - What Claude Cowork Inherits Without You Realizing It 17:15 - Machine Identity vs. Human Identity vs. AI Identity 19:35 - Treating AI Agents Like Eager, Naive Interns 23:00 - The Biggest AI Risk Isn't Security, It's Cost 25:45 - Meet Ito: Aizome's Supervisor Agent 26:40 - Inside the New ARISE Category 33:35 - What Aizome Actually Does 35:30 - The Callback: Was the Myth Wrong, or Dangerously Wrong? Links Connect with Amir Ofek on LinkedIn: https://www.linkedin.com/in/amirofek/ Learn more about Aizome: https://www.aizome.ai/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E442
    September 9 · 36 min

    Cloud Broke My World Before AI Did with Dr. Jay Abdullah

    Cybersecurity has survived cloud, mobile, and a dozen other "biggest disruptions of our lifetime," and each one felt unprecedented in the moment. In this episode, Ron sits down with Alyssa "Dr. Jay" Abdullah, Deputy CISO at MasterCard, who started her career as a radio DJ and has since worked inside the White House, Lockheed Martin, Stryker, and Xerox before landing in payments security. Ron and Dr. Jay trace her path from spinning records to securing global payment infrastructure, and dig into why she'd argue cloud, not AI, was the real turning point in her career. They cover what convergence actually looks like when AI, cloud, and synthetic identity start overlapping, why curiosity matters more than fast answers, and what it means when employees start bringing their own trained AI agents to work. The conversation closes on something most teams haven't fully reckoned with yet: AI agents that carry their own identity, independent of the humans who built them, and what that shift demands from the people responsible for securing them. Impactful Moments 00:00 - Introduction 02:25 - Busting the AI hype myth 04:40 - From radio DJ to Dr. Jay 06:10 - A day in the life as Deputy CISO at Mastercard 07:25 - Why AI hasn't disrupted her world 08:50 - White House tech through the decades 12:30 - Smartphones, wearables, and what's next 13:30 - Defining convergence for 2026 14:50 - When AI meets quantum computing 17:20 - Bring your own AI agent to work 19:00 - Negotiating salary in tokens 21:05 - Teaching curiosity over answers 23:50 - Overhype equals overtrust 27:10 - The future of tier one and autonomous SOC 29:50 - Hot take: AI in the SOC 31:35 - Predictions: AI identities and the human outside the loop Links Connect with Alissa "Dr. Jay" Abdullah on LinkedIn: https://www.linkedin.com/in/dralissajay/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E441
    September 1 · 35 min

    The Dashboard Is Dead, Long Live the Harness with Myke Lyons

    Security teams spent decades begging for more logs. Now the enterprise is generating petabytes a day, and the thing drowning in it isn't just the SOC anymore, it's your AI agents too. In this episode, Ron sits down with Myke Lyons, CISO at Cribl, who cut his teeth in telemetry and logging decades ago and has landed right back there in the age of AI. Ron and Myke dig into why most telemetry failures aren't data problems at all, they're decisions nobody made about why the logs are being collected in the first place. Myke breaks down what to track on every agent in your environment, why token spend belongs on the security team's plate, why dashboards are quietly dying, and why treating an AI agent like just another employee is a mistake that's going to bite security teams hard. Underneath it all is one question Myke keeps circling back to: do you actually know what normal looks like for every agent in your environment? Impactful Moments 00:00 - Introduction 01:50 - Myth Busting: AI Agents Aren't Just Another User Account 04:25 - Meet Myke Lyons, CISO at Cribl 05:05 - What it means to run security at a telemetry company 06:10 - From gigabytes of logs at GE to petabytes today 07:45 - MITRE ATT&CK, Cribl's new APEX framework, and orienting telemetry 10:20 - Why most telemetry problems are decision problems, not data problems 13:20 - OCSF and how security teams are rethinking their schemas 14:25 - Why the dashboard is dying 17:35 - What Myke wants to track about every AI agent 20:10 - How to spot an agent going rogue 23:15 - Making your data AI-ready and the case for schematizing everything 27:10 - Tokenomics: treating AI spend as a security responsibility 29:05 - The non-negotiable logs every org should be collecting 31:50 - Hot takes: build vs. buy, tier two to three, and Myke's daily AI briefing 33:35 - Closing thoughts and outro Links Connect with Myke Lyons on LinkedIn: https://www.linkedin.com/in/mykelyons/ Learn more about Cribl: https://cribl.io/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E440
    August 25 · 35 min

    The AI Already Inside Your Company with Russell Spitler & Richard Penshorn

    A year ago, the average employee held about 30 OAuth grants. Today that number has risen to 88, and it isn't slowing down. Ron sits down with Russell Spitler, co-founder and CEO of Nudge Security, and Richard Penshorn, a senior security engineer at a top financial services company, to talk about the AI already living inside your business. Ron, Russell, and Richard dig into why shadow AI doesn't behave like shadow IT, how one forgotten grant became the door into a real world breach, and whether AI agents should ever get access to a corporate inbox. Underneath all of it is the one thing Russell and Richard keep coming back to: ownership. Give an AI agent access with no owner attached and it becomes invisible. Give every employee an approved, low-friction path to use AI and they stop wandering off it. Find out how you can get ahead of the AI already running inside your walls. Impactful Moments 00:00 - Introduction 02:00 - Busting the "shadow AI is just shadow IT" myth 03:45 - Meet Russell Spitler and Richard Penshorn 05:50 - The surprising long tail of AI tool usage 07:00 - Entertainment vs. finance: build vs. buy culture 08:50 - How 30 OAuth grants became 88 in 2026 10:25 - Why manual OAuth audits became untenable 11:30 - The Canva example: what "click to connect" really grants 15:20 - Benign vs. malicious: how a stolen OAuth grant gets exploited 17:00 - Shadow IT vs. Shadow AI: what's actually different now 21:00 - Hot take: should AI agents ever touch corporate email? 25:10 - The three buckets of AI agent discovery 27:55 - Russell's best practices for locking down agents 31:00 - Fundamentals for the next 18 months: visibility and easy paths Links Connect with Russell Spitler on LinkedIn: https://www.linkedin.com/in/russell-spitler/ Connect with Richard Penshorn on LinkedIn: https://www.linkedin.com/in/richardpenshorn/ Learn more about Nudge Security: https://www.nudgesecurity.com/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E439
    August 19 · 34 min

    Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

    Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigation platform from scratch. John's system runs on more than 30 specialized agents that reason through cases instead of following a script. In one run, that meant over 140 detections investigated in under four hours at an 80 to 85% quality rating. Ron and John dig into the hard lesson that made John rip out his own tooling and rebuild it around function calling, why "humans first" drives every decision his team makes, and whether AI SOC is actually different from SOAR or just the same promise with way better marketing. Underneath all of it is the one thing John says decides whether any of this actually works: context. Give the AI too little and it's guessing, give it too much and it drowns just like a human would. Listen to find out what it actually takes to build an AI SOC that reasons instead of just automates. Impactful Moments 00:00 - Introduction 02:05 - The rewind: how SOAR promised to save the SOC in 2015 03:35 - Meet John Gillis, Adobe's Staff AI Security Engineer 05:30 - What cybersecurity looked like before AI at enterprise scale 07:00 - The "humans first" strategy behind Adobe's AI investigator 09:30 - Why careless context management is the biggest pitfall in agent design 14:45 - Solving the speed problem: is it tooling, process, or people? 17:10 - From monolith to microservices: rebuilding the platform for scale 24:05 - What actually makes an AI agent's "persona" work 26:00 - John's prediction for the SOC three years from now 28:50 - The three skills every security practitioner needs for 2026 32:10 - Final verdict: is AI SOC really different, or SOAR with new branding? Links Connect with John Gillis on LinkedIn: https://www.linkedin.com/in/john-gillis/ If you're a researcher ready to make an impact, check out the announcement about Adobe’s new home for the Adobe Bug Bounty Program here: https://blog.adobe.com/security/a-new-home-for-the-adobe-bug-bounty-program Check out Adobe’s Bug Bounty profile on Intigriti: https://app.intigriti.com/programs/adobe/adobepublic/detail Learn more about Adobe: https://www.adobe.com/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S1 · E438
    August 14 · 23 min

    Let AI Do More Without Surrendering Your Judgment with Jen Easterly

    Fresh off the showroom floor at Black Hat 2026, Ron brings back some hot takes from the crowd. Nearly every booth he visited, including the Exaforce booth, was pushing in the same direction. Trust in AI isn’t a philosophy debate anymore, it’s an engineering problem people are actively solving. Ron then catches up with Jen Easterly, CEO of RSAC, for a wide-ranging conversation on what it actually takes to build that trust. From her move out of government to her hard line on AI regulation and liability, the conversation takes an unexpected turn when Jen opens up about "cognitive surrender" and why she believes good judgment can't be automated away. Couldn't make it to Black Hat this year? This episode has you covered. Impactful Moments 00:00 - Introduction 02:45 - Reporting live from Black Hat 2026: hot takes from the showroom floor 05:05 - Welcoming Jen Easterly, CEO of RSAC 07:55 - A day in the life running RSAC and the Innovation Sandbox 10:00 - AI whack-a-mole and the sweet spot for regulation 11:00 - Governance vs. regulation, the EU AI Act, and state laws 13:30 - Why accountability and liability need to catch up to AI makers 14:45 - The case for autonomous patching and healing code like "The Matrix" 17:50 - The hot take Jen hasn't said before: not outsourcing our humanity 20:30 - Why in-person conferences matter more in the AI era 21:55 - Ron's takeaway: who decides when AI has earned our trust? Links Connect with Jen Easterly on LinkedIn: https://www.linkedin.com/in/jen-easterly Learn more about Exaforce: https://www.exaforce.com – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us

  • S6 · E437
    August 12 · 30 min

    Post-Quantum Cryptography: What Every Organization Needs to Know with Michael Fasulo

    What if the encrypted traffic flowing across the internet right now (emails, files, logins) is already being quietly collected and stored by someone waiting for the day they can finally crack it open? That's the threat behind "harvest now, decrypt later," and it's closer than most people think. Ron Eddings sits down with Michael Fasulo, Senior Director of Portfolio Marketing at Commvault, to talk about where post-quantum cryptography (PQC) really stands in 2026. They discuss "harvest now, decrypt later," the specific industries quietly racing to prepare, and why a commercially viable quantum machine might only be four years away. Ron and Michael trace the journey from a 1998 hack to today's quantum race, and the good news is there's still time to get ahead of it. Listen to hear where the real opportunity is, and how to start building your defense today. Impactful Moments 00:00 - Introduction 01:40 - Rewind: the 1998 Deep Crack story 04:10 - Michael Fasulo and the current state of post-quantum cryptography in 2026 05:05 - Harvest now, decrypt later: do people really have the storage to do this? 06:10 - Where is this actually happening? Nation-states vs. coffee shops 08:50 - Who the real targets are: government, financial services, oil and gas 10:05 - Are everyday SaaS tools like Zoom and Gmail implicated? 12:25 - How Commvault helps organizations inventory their crypto footprint 17:00 - Trust, vendor partnerships, and the Commvault / Microsoft Sentinel integration 18:30 - Signs that a commercial quantum machine may be closer than we think 24:45 - Are we already behind? What to do starting next week 28:20 - Deep Crack revisited Links Connect with Michael Fasulo on LinkedIn: https://www.linkedin.com/in/michael-fasulo Learn more about Commvault: https://www.commvault.com – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E436
    August 7 · 38 min

    Stop Defending the Edge: How to Rethink Your Mobile Security with Jared Shepard

    What if the biggest risk to your organization isn't the device that gets lost, but the data that lives on it? Ron Eddings sits down with Jared Shepard, Founder and CEO of Hypori, whose path ran from homeless high school dropout to Army infantry to building a company that rethinks mobile security from the ground up. Jared makes the case for something more radical than most vendors will admit: stop defending the edge device entirely, and make sure sensitive data never lands there in the first place. He and Ron cover MDM and MAM's blind spots, executive protection, and the shadow AI habits quietly becoming every security leader's next headache. The episode also lands at a tense moment for the defense industrial base with the Pentagon having just paused third party CMMC assessments, now putting the burden of proof back on self attestation. If you're still trusting the edge device to protect you, this episode is your wake up call. Impactful Moments 00:00 - Introduction 02:00 - Hack The Headlines: Top new from around the industry 07:30 - Meet Jared Shepard, founder and CEO of Hypori 10:00 - What Hypori does and how it started 15:40 - MDM vs. MAM: why both miss the real problem 18:45 - Shadow AI and the security habits practitioners can't ignore 20:30 - Collapsing the attack surface and bringing back BYOD (Bring Your Own Device) 22:40 - The 4-gigabit-speed "parlor trick" that proves the Cloud beats your device 25:20 - What the 60-day CMMC pause really changes (and what it doesn't) 29:20 - China, stolen tech, and the rise of AI models like Mythos 36:00 - Closing the loop on the CMMC pause Links Connect with Jared Shepard on LinkedIn: https://www.linkedin.com/in/shepardj Learn more about Hypori: https://hypori.com – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E435
    July 28 · 34 min

    Inside Conti: The Ransomware Gang That Ran Like a Company with Geoff White

    What does the world's most prolific cybercrime operation look like from the inside? And why does it operate suspiciously like a mid-sized tech company, complete with HR headaches, salary negotiations, and a distracted boss nobody respects? Ron Eddings sits down with investigative journalist and author, Geoff White, who has spent over 20 years covering cybercrime for the BBC, Channel 4 News, and Sky News. Geoff has read 47,000 of Conti’s 300,000 leaked internal chats, the gang that dominated the ransomware world in 2021 and 2022, pulling in hundreds of millions of dollars in ransoms. From the Moscow movie studio the gang's leader used to launder money years previously, to the Ukraine war leak that brought the whole Conti empire down, this one plays like true crime… because it is. Geoff makes the case that defenders should think the same way: you're not buying security tools to fend off a hoodie in a basement, you're investing to outcompete a rival business. For anyone trying to integrate a better incident response plan, this episode reframes the whole conversation. Impactful Moments 00:00 - Introduction 01:45 - The Rewind: Colonial Pipeline and the week the East Coast ran dry 03:50 - How Geoff went from tech news to cybercrime reporting 05:10 - The difference between threat groups, APTs, and crime gangs 07:25 - Inside the Conti leaks: 300,000 messages 08:55 - Meet the gang: Stern, Mango, and Target 13:20 - Stern's origin story: Zeus malware, money mules, and the 25th Floor front company 16:50 - Ransomware gangs vs. the mafia: where's the protection? 18:10 - The money: $2.5M single payouts and 400 years of wages 19:30 - The Conti member arrested on a layover in Miami 20:35 - The downfall: the Ukraine war and the leak that ended it all 23:05 - What businesses can learn from Conti: recruitment, retention, reputation 27:45 - Advice for defenders: response waves, segmentation, and negotiating down 31:05 - Ron's takeaway: belonging and the thin line between operator and criminal Links Connect with Geoff White on LinkedIn: https://www.linkedin.com/in/geoffwhitetech/ Get your own copy of Geoff's books (Crime Dot Com, The Lazarus Heist, Rinsed): https://geoffwhite.tech/book/ Want more information on Conti? Check out Geoff’s BBC podcast series, Cyber Hack: The Conti Files, available on BBC Sounds, Spotify, and Apple Podcasts – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E434
    July 21 · 35 min

    What AI Agents Should Own in Your SOC, And What Happens If You Wait with Tim Leehealey

    What happens when the adversary moves at machine speed, and your SOC is still responding at human speed? Why does nearly every security team say AI should handle L1 work, while 64% of organizations still have zero agents in production? And how long until the "coworker" resolving your ticket in Slack turns out not to be human at all? Tim Leehealey, VP of Strategy and Operations at Strike 48, joins us this week to talk about what it actually takes to get AI agents out of the demo and into production. Tim agenticized his own company's IT, watched it blow up, and came out the other side with lessons from Fortune 100 SOCs running agents at serious scale. He shares where AI actually belongs in the alert pipeline, the objections holding teams back, and a blunt warning for any leader still waiting on the sidelines in 2027. If AI in the SOC is on your roadmap before the end of this year, start here. Impactful Moments 00:00 - Introduction 01:55 - Busting a myth: AI will replace analysts 04:45 - Introducing Tim Leehealey 05:30 - The Strike48 survey: 84% say hand L1 to AI 08:00 - Fear the low-and-slow attacker, not the loud one 13:00 - Getting breached without agents in 2027 15:00 - When Tim's own rollout blew up 19:00 - Micro agents inside deterministic workflows 21:25 - Skills advice for L1 analysts 26:00 - The next 18 months of agentic adoption 28:00 - Jim Bob in your Slack is an agent 21:30 - Ron's take: transparency is the trust unlock Links Connect with Tim Leehealey on LinkedIn: https://www.linkedin.com/in/tim-leehealey-b8b04321 Learn more about Strike48: https://strike48.com Check out the 2026 State of Agentic Security report here: https://hubs.ly/Q04p49S20 Go deeper on Strike 48's technology: https://labs.strike48.com – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E433
    July 14 · 30 min

    We Shipped a Tool That Acts Like You. Meet Interceptor.

    Think about everything you could accomplish if you don’t have to be the one driving your browser. In this solo episode, Ron Eddings introduces Interceptor, Hacker Valley Media's first piece of software. Interceptor is an open-source Chrome extension that lets an AI agent drive your real browser, logged-in sessions and all, with no vendor lock-in. Ron shares how it works and describes the use cases that matter most to security practitioners: OSINT and recon, bug bounty operations, prompt-injection testing, and threat-intelligence automation. Ron also puts himself in the hot seat, answering the hardest questions he's gotten about the tool, including why anyone should trust an open-source tool from a podcast company over a polished product from a billion-dollar AI lab. The delegation is coming, and we would rather the security community be the ones who understand it. Impactful Moments: 00:00 - Introduction 02:35 - The Rewind: Same Origin Policy and the Web's Foundation 04:40 - Rapid-fire facts: AI agents got hands, and attacks followed 07:00 - What is Interceptor and why was it built? 10:20 - How Interceptor works: stealth, network visibility, teach and replay 13:10 - Live use-case: dynamic dashboard without writing code 17:05 - Cybersecurity use-cases: OSINT, bug bounty, prompt injection testing 21:50 - Ron answers the hard questions about Interceptor 24:10 - Why trust an open source tool from a podcast company? 25:20 - What a practitioner can do tomorrow 27:30 - Closing reflection: knocking down the vendor lock-in wall Links Download Interceptor on GitHub: https://github.com/hackervalleymedia/interceptor Connect with Ron on LinkedIn: https://www.linkedin.com/in/ronaldeddings/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E432
    July 7 · 30 min

    How to Turn Cybersecurity Customers into Lifelong Advocates with Antu Buck

    What if the same psychology that threat actors use to manipulate their targets is the same psychology that marketers use to earn your trust? In this episode, Ron sits down with Antu Buck, Senior Director of Customer Marketing & Community at Gigamon, who spent two decades building trust between vendors and the practitioners who use their tools. Antu walks us through the three pillars she's built her career around, and makes the case that advocacy shouldn't be an afterthought, but the very first marketing move a company invests in. The conversation lands on something the community doesn't talk about enough: customer marketing is hard to put a number on, so it consistently loses the budget fight to demand gen. Impactful Moments 00:00 - Introduction 02:15 - Myth Buster: "I don't fall for marketing tactics" 04:15 - Meet Antu Buck, Senior Director of Customer Marketing & Community at Gigamon 06:45 - From cold-calling BDR to customer marketing leader 09:40 - Antu’s three pillars: advocacy, community, lifecycle management 13:05 - Why customer advocacy is the most underrated pillar 14:40 - The problem with chasing the CISO 16:40 - From transactional selling to relationship building 17:20 - The cold call that became a lifelong champion 20:20 - Are threat actors borrowing tactics from sales and marketing? 23:00 - Why AI tools are off-limits with customer data 27:50 - Why customer marketing loses the budget fight Links Antu Buck on LinkedIn: https://www.linkedin.com/in/antu-buck/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E431
    June 23 · 31 min

    What's Really Stopping AI From Running Your SOC with Aqsa Taylor

    In 2025, out of all 70+ guests we had on our show, not one of them said they’d trust AI to run their SOC. Now in 2026, that mindset is shifting. In this episode, Ron sits down with Aqsa Taylor, Chief Security Evangelist at Exaforce, to find out what changed, and what's still standing in the way of security teams being able to trust AI agents with response. The conversation covers what's really behind the agentic SOC hype, why "vibe hunting" might be the most fun phrase in cybersecurity right now, and how teams can build enough confidence to hand over the keys to detection, investigation, and response. Aqsa also gets into the one thing she believes has to come before any of it works: the data. Without the right context feeding your AI you’re just getting confident guesses dressed up as answers. Listen to find out if your team is ready to take the leap into an agentic SOC. Impactful Moments 00:00 - Introduction 02:05 - Hack the headlines, June top trends in cybersecurity 05:30 - Welcoming Aqsa Taylor from Exaforce 06:15 - Inside Exaforce's $125M raise 08:50 - Redefining what AI SOC should mean 09:30 - The evolution from manual playbooks to AI-driven autonomy 13:40 - Where Exaforce fits in an existing stack 18:10 - What vibe hunting looks like in practice 19:40 - The challenges of securing sensitive data in a world dominated by SaaS platforms 22:00 - How to build your trust ladder for AI in the SOC 24:40 - Best use case to get started with AI SOC 28:50 - Ron's takeaway: the data has to be there first Links Connect with Aqsa Taylor on LinkedIn: https://www.linkedin.com/in/aqsa-taylor Learn more about Exaforce: https://www.exaforce.com Join Exaforce’s Force Multiplier Substack community: https://theforcemultiplier.substack.com – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E430
    June 16 · 28 min

    Feed Your Brain: What Cybersecurity Veterans Are Getting Wrong with Johnny Xmas

    Is AI really coming for your red teaming job? What does it actually take to build a team that thinks like the adversary, and what happens when that team stops caring? And what do you do when you've been in this field long enough that the job that once fired you up has started to feel hollow? In this episode, Ron catches up with Johnny Xmas, Head of Offensive Security at a Fortune 150 Global Food Manufacturer, and one of the most candid voices in offensive security, for a conversation that covers a lot of ground fast. They go deep on where AI actually fits into offensive security workflows, what Johnny really looks for when building elite teams, and why the career advice everyone gives early practitioners might be setting them up for burnout down the road. The conversation takes a turn that doesn't come up enough in this industry, and it's the part you won't want to miss. If you've ever felt your tank running low, this episode was made for you. Impactful Moments 00:00 - Introduction 02:10 - Busting the myth: AI is not replacing red teamers 04:30 - Guest introduction: Johnny Xmas 06:15 - How the offensive security job has changed with AI 09:35 - The SEC 8-K IoC parser tool Johnny just published 11:40 - Building elite teams: what skills Johnny actually hires for 12:45 - Soft skills over technical gaps, and why the fire has to come with you 15:40 - Why "where do you see yourself in five years?" is a garbage question 17:30 - Has Johnny ever crossed the line when it comes to hacking? 20:20 - What to do when you've stopped caring about the job 26:25 - Outro: The AI myth, revisited Links Johnny Christmas on LinkedIn: https://www.linkedin.com/in/johnnyxmas/ Johnny's SEC 8-K IoC parser tool: https://github.com/johnnyxmas/its-over-8k — Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E429
    June 9 · 25 min

    Fighting Smarter: What Combat Sports Teaches Us About Cyber Defense with Robin Black

    What does a calf kick have to do with vulnerability management? What can a fighter's mindset teach a security practitioner about operating against an adversary they've never faced? Ron Eddings brings back fan-favorite combat sports analyst and commentator Robin Black for a conversation that was never meant to be about cybersecurity, and ends up being one of the most insightful episodes on the human side of the field. They dig into how underdogs actually win (hint: we're usually wrong about who the underdog is), what it really means to maintain control in a fight, and why the highest level of mastery might actually look like letting go of control entirely. The conversation closes with a look at how the cybersecurity landscape is mutating alongside AI, and whether an arms race that trains itself is heading somewhere catastrophic, or whether it's simply the next evolution of the fight. The answer, like most things in this episode, is more nuanced than you'd expect. Impactful Moments 00:00 - Introduction 02:10 - The Rewind: The Calf Kick and the Peroneal Nerve 04:05 - Welcome back, Robin Black 05:30 - Can smaller still beat bigger? 07:00 - Why underdogs don't win (And why we were wrong) 08:25 - Fighting is about exploiting belief systems 09:30 - Maintaining control against an unknown adversary 10:25 - Adapting vs. anticipating: be water 13:00 - Failure is mandatory 17:25 - How Robin’s thoughts have changed about being attacked online 19:00 - AI and the mutating threat landscape 22:15 - Ron's closing thoughts Links Connect with Robin Black on LinkedIn: https://www.linkedin.com/in/robin-black-31b6bb39/ Check out Robin Black on YouTube: https://www.youtube.com/RobinBlack – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E428
    June 2 · 35 min

    Is Vibe Coding Breaking the Internet? with Tanya Janca

    What happens when AI writes all the code and nobody reads it? What if the security prompt you trusted still produced software designed to leak your secrets? And who exactly is on the hook when an AI-generated application takes down your company? In this episode, Ron sits down with returning guest Tanya Janca, Secure Coding Trainer at SheHacksPurple Consulting, to dig into one of the most underestimated risks in software development today: vibe coding. Tanya breaks down what vibe coding actually means, why AI trained on the internet's worst repositories is quietly baking the OWASP Top 10 into every app being built, and what her AI-powered secure coding prompt library can do to help. This is a candid, practical, and community-driven episode, the kind that'll make you want to audit your vibe code-a-thon project before it ever touches production. Impactful Moments 00:00 - Introduction 01:40 - The Rewind: Margaret Hamilton and Apollo 11 05:00 - Knight Capital and the $460M software failure 07:00 - Guest introduction: Tanya Janca 08:15 - What vibe coding actually means in 2026 10:00 - Real story: Claude leaked secrets in a live training 11:30 - Securemyvibe.ca and Tanya’s secure coding prompt library 15:00 - OWASP Top 10 vs OWASP Top 10 for LLMs 22:45 - Tanya's petition for the world's first secure coding law 24:55 - Device flow authentication and reducing security friction 28:00 - What the internet would look like in five years without change Links Connect with our guest, Tanya Janca, on LinkedIn: https://www.linkedin.com/in/tanya-janca Get Tanya's free secure coding guideline: https://securecodingguideline.com Subscribe to Tanya’s AI Secure Coding Prompt Library: https://securemyvibe.ca Access Tanya's Newsletter & Free Monthly Training: https://newsletter.shehackspurple.ca Connect with Tanya across all social channels: @shehackspurple – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E427
    May 26 · 35 min

    Why Smart People Fall for Deepfakes with Perry Carpenter

    What if the most sophisticated attack has nothing to do with your firewall? In a world where AI can clone voices, re-lip-sync politicians, and spread a fake newscast to 200,000 people in days, the real target has always been your brain. Ron sits down with Perry Carpenter, Chief Deception Strategist at KnowBe4, to unpack why we're still getting fooled in 2026 and what we can actually do about it. Perry gets into the neuroscience behind why our brains are wired the way they are, how attackers exploit that, and what it really takes to build better instincts in a world full of AI-generated content. You'll also want to stick around for the live demos, where Perry breaks down why they worked and how to spot the tells. Impactful Moments 00:00 - Introduction 02:15 - The myth: smart people don't get fooled 05:20 - Flashback segment: the Ireland deepfake and why it went viral 06:15 - Guest introduction: Perry Carpenter 09:50 - Exploiting cultural bias and tribal instincts 13:45 - Live deepfake demo: face and body replacement in real time 15:30 - Synthetic media vs. deepfake: what's the difference? 20:40 - Breaking down a deepfake: what made it convincing 23:00 - Overproof: why bad deepfakes try too hard 27:15 - System 1 vs. System 2 thinking in cybersecurity 29:45 - The FAIK framework: freeze, analyze, investigate, know 32:40 - Ron's closing reflection Links Connect with our guest, Perry Carpenter, on LinkedIn: https://www.linkedin.com/in/perrycarpenter Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/

  • S6 · E426
    May 18 · 35 min

    Who Owns Your AI Security Policy? with Chris Cochran

    Right now, someone in your organization is probably feeding sensitive data into an AI system that nobody approved. So when something goes wrong, who's responsible? And more critically, do you even have a policy in place to answer that question? Ron Eddings sits down with his Hacker Valley co-founder, Chris Cochran, now serving as SANS Field CISO and VP of AI Security, to talk about his freshly released SANS AI Security Maturity Model, a practical framework built for security leaders who need to stop philosophizing and start making decisions. They cover the three pillars of AI security maturity: utilizing AI for defense, protecting AI itself, and governing it across the organization. Chris then gets real about where most enterprises actually stand (hint: not as far along as they think). Listen for a conversation that meets you wherever you are: skeptic, early adopter, or somewhere in between. Impactful Moments 00:00 - Introduction 03:00 - Chris Cochran: from Co-Founder to SANS Field CISO 04:20 - Your board is pushing AI before security is ready 06:00 - Tiers of AI uses: summarization to full automation 07:50 - When AI shouldn't make the final call 10:10 - Bite-sized AI: starting small in the enterprise 11:45 - Introducing the SANS AI Security Maturity Model 13:20 - You can no longer afford to be an AI skeptic 16:30 - Three buckets: utilize, protect, and govern AI 18:50 - Fact or Cap: what level of maturity is your enterprise? 21:00 - Retroactive vendor risk and the AI explosion 23:05 - Agentic Identity: workforce, non-human, and beyond 25:00 - What works in the agentic identity space? 27:05 - Blockchain for agent identity: promising or hype? 29:00 - A Message for the next generation of practitioners 31:30 - Ron's closing take: who owns your AI policy? Links Connect with Chris Cochran on LinkedIn: ​​https://www.linkedin.com/in/chrishvm/ Download the SANS AI Security Maturity Model: https://www.sans.org/mlp/2026-ai-security-maturity-model-ebook Check out our upcoming events: https://www.hackervalley.com/livestreams Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Continue the conversation by joining our Discord: https://hackervalley.com/discord Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

  • S6 · E425
    May 1 · 34 min

    Turning 30,000 Findings Into 50 That Matter with Dan Pagel and Brad Hibbert

    Mythos just found 30,000 new vulnerabilities, and now every security team is asking the same question: what actually matters? In this episode, Ron Eddings sits down with Dan Pagel, CEO at Brinqa, and Brad Hibbert COO & CSO at Brinqa, to break down the Anthropic Mythos moment that rattled the security industry. From the panic of millions of new findings dropping overnight to the strategy of narrowing them down to the 50 that actually matter in YOUR environment, this episode is a masterclass in exposure management at machine speed. Dan and Brad share how Brinqa helps organizations make sense of massive volumes of findings, correlating data across 260+ connectors, enriching vulnerability context, and delivering clear, explainable actions to IT operations teams. They also tackle the bigger question: how do you build enough trust in AI to let it take autonomous action on your behalf? The answer starts with better data, better explainability, and knowing when to keep humans in (or on) the loop. Impactful Moments 00:00 - Introduction 02:00 - What just happened? Breaking down the Anthropic Mythos moment 04:10 - Why most new findings don’t apply to your environment 07:12 - What Mythos means to the broader market 09:09 - Why AI-driven discovery isn’t slowing down 11:00 - The gap between security and IT ops: how explainability closes it 13:38 - How fast you should go through findings 15:53 - Why MTTR is the wrong metric and what businesses actually care about 18:03 - Why real-time visibility is replacing scheduled scanning 19:50 - Human IN the loop vs. human ON the loop 22:14 - What happens when AI hallucinates? 27:20 - Why we’re over and under-estimating the impact of AI 29:54 - The immediate win Brinqa achieves for its customers 31:50 - What CISOs are really asking now: "What does good look like?" Links Connect with our guest, Dan Pagel, on LinkedIn: https://www.linkedin.com/in/dpagel/ Connect with our guest, Brad Hibbert, on LinkedIn: https://www.linkedin.com/in/bradhibbert/ Learn more about Brinqa: https://www.brinqa.com/ Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

  • S1 · E424
    April 24 · 39 min

    Killing the Playbook with Agentic AI with Allan Alford and Tom Findling

    SOAR promised to close the loop in the SOC and fell flat. Agentic AI is finally delivering what a decade of playbooks couldn’t. In this episode, Ron sits down with Allan Alford, SVP at NTT Global Data Centers, and Tom Findling, co-founder and CEO of Conifers.ai. They cover why static playbooks broke under real-world conditions and how agentic systems are flipping the SOC operating model. They get into hallucination guardrails, human-on-the-loop versus human-in-the-loop, and the QR-code phishing investigation an agent solved on its own without being told how. The conversation closes on trust thresholds, the speed of enterprise adoption, and Allan's blunt warning to any CISO trying to slow this train down… you're already on the tracks. Impactful Moments 00:00 - Intro 02:30 - Why the lazy sysadmin always wins 05:15 - Why SOAR fell flat 08:00 - Guardrails, hallucinations, and showing the work 13:00 - The SOC AI holy grail 15:30 - The moment you start saying we 17:30 - QR-code phishing the agent solved alone 19:00 - Why playbooks were never going to scale 28:00 - Earning trust at enterprise scale 33:30 - Stand in front of this revolution and lose 35:40 - Risk quantification on business steroids Links Connect with our guest, Tom Findling, on LinkedIn: https://www.linkedin.com/in/tomfindling/ Learn more about Conifers.ai at https://www.conifers.ai Connect with our guest, Allan Alford, on LinkedIn: https://www.linkedin.com/in/allanalford/ ___ Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Showing 1–20 of 20 episodes