David Bombal

David Bombal

By David BombalTechnology
Download on the App Store

David Bombal episodes

  • #611: Building AI Agents? Set Up These Guardrails First
    Big thanks to ‪@Cisco‬ & ‪@Splunkofficial‬ for sponsoring my trip to .Conf 2026 and also for sponsoring this video.
    AI agents can do things you never intended. So how do you monitor their behavior, spot security problems and decide what they should be allowed to do? I’m joined by Splunk’s Kamal Hathi at .conf26 to discuss AI agent security, observability and what an agentic SOC means for the people working in cybersecurity.
    Kamal explains why setting a goal isn’t enough. You need visibility into what your agents are actually doing, clear guardrails and human oversight for important decisions. We also discuss why monitoring only a sample of agent activity can leave gaps, and how focused small language models could help reduce evaluation costs.
    In this interview, we cover:
    • Known agents, unregistered agents and unexpected behavior
    • AI evaluations, guardrails and zero trust
    • Automating SOC alert triage while keeping humans in control
    • Using AI to create SOAR playbooks
    • Running models locally for privacy, cost and control
    • Choosing between local models and cloud models
    • Whether you should still study computer science in 2027
    If you’re building AI agents, working in cybersecurity or deciding what to learn next, this conversation will give you plenty to think about.
    // Kamal Hathi’s’ SOCIAL //
    LinkedIn: / kamal-hathi
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    // MENU //
    0:00 - Coming Up
    0:43 - Intro
    02:25 - Security Against AI
    06:26 - Collecting Data on your AI
    08:33 - AI Hallucinations
    10:48 - Is Life Like Sci-Fi?
    14:09 - Will AI Replace You?
    17:16 - Not Giving Your Information to AI
    18:50 - Kamal's Prediction for the Future of AI
    20:20 - Final Thoughts
    21:29 - What Should you Study in 2027?
    22:00 - Conclusion
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.
    #SplunkConf26 #Splunk #Cisco
    23 min
  • #610: WiFi Pineapple Pager: What Can It Actually Do?
    Big thank you to proton VPN for sponsoring the video. To get 70% off your Proton VPN subscription use the following link: https://protonvpn.com/davidbombal
    Note: Hak5 did not pay me to make this video. But, for full transparency: Darren was kind enough to give me some cool Hak5 gadgets. Get your own using my link below.
    // Buy Hak5 coolness here (Affiliate Link): //
    Buy Hak5: https://davidbombal.wiki/gethak5
    WiFi hacking without opening your laptop? ‪@DarrenKitchen‬ from ‪@hak5‬ joins me to talk about the WiFi Pineapple Pager and what this little Linux device can actually do.
    Darren shares the story behind the Pager, explains its support for 2.4, 5, and 6 GHz WiFi, and walks us through features including wireless reconnaissance, eventtriggered alerts, and community-created payloads. We also discuss how Bash and DuckyScript helpers let users build their own functionality, and how Pager Portal makes it possible to download payloads directly onto the device.
    How does it compare with the WiFi Pineapple Mark VII and Enterprise? We look at the different use cases, from portable testing to remotely auditing a client’s wireless network.
    And yes, someone has already made it run Doom.
    This is an interview and feature overview with the creator, covering the ideas, technology, and community behind the WiFi Pineapple Pager.
    // Darren Kitchen SOCIAL //
    YouTube: / darrenkitchen
    Website: https://hak5.org/pages/hack-across-am...
    X: https://x.com/hak5darren
    // Hak5 WEBSITE //
    https://shop.hak5.org/
    // Previous YouTube video with Darren REFERENCE //
    Hacking Gadgets Every Cybersecurity Pro should know: • Hacking Gadgets Every Cybersecurity Pro Sh...
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    // MENU//
    0:00 - Intro
    0:35 - Coolest hacking tool // Hak5 WiFi Pineapple Pager
    03:10 - Proton VPN sponsor segment
    05:28 - History of the WiFi Pineapple
    08:53 - WiFi Pineapple Pager overview
    12:17 - The community
    15:55 - Easy to get started
    16:50 - WiFi Pineapple Mk7
    18:53 - WiFi Pineapple Enterprise
    21:23 - Supported WiFi frequencies
    22:43 - Conclusion
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.
    #wifipineapplepager #wifi #hackinggadgets
    23 min
  • #609: How Hackers Target Satellites Through Ground Control Systems
    Big thanks to DeleteMe for sponsoring this video. Protect your business with DeleteMe by using the following Link: https://joindeleteme.com/bombal-biz You’ll also get a free year of social media protection for every seat you purchase.
    How do you hack a satellite? The attack can start on the ground. Watch a mission control demo showing how web vulnerabilities can change a simulated spacecraft’s orbit.
    At DEF CON, I meet Milenko and Andrzej, the authors of The Spacecraft Hackers Handbook, to explore spacecraft cybersecurity. They explain the infrastructure behind satellite operations, what the Via sat attack actually targeted, and why protecting spacecraft requires both security and space engineering knowledge. Then Andrzej demonstrates previously patched vulnerabilities in an older version of mission control software. Using Burp Suite, he shows how path traversal exposes configuration files and how cross-site scripting can trigger a spacecraft command through an operator’s browser.
    We cover:
    • Why satellite security extends to systems on the ground
    • How path traversal and XSS affect mission control software
    • Telemetry, telecommands, CCSDS and the SDLS security layer
    • How GPS supports timing as well as navigation
    • Python examples, a prepared lab VM and learning resources
    • The authors’ nine satellite cybersecurity challenges on Hack The Box
    • Skills and career opportunities in spacecraft cybersecurity
    The demonstration uses a spacecraft simulator. The vulnerabilities shown were disclosed to the vendor and patched.
    // Link to No Starch Website for Milenko and Andrzej’s Book//
    The Spacecraft Hacker’s Handbook: https://nostarch.com/spacecraft-hacke...
    Use Coupon Code SPACE25 for 25% off The Spacecraft Hacker’s Handbook.
    // Milenko Starcik’s SOCIALS //
    Website: https://visionspace.com/team/milenko-...
    Website 2: https://starcik.space/
    // Andrzej Olchawa’s SOCIALS //
    Website: https://visionspace.com/author/a-olch...
    Website 2: https://andy.codes/
    X: https://x.com/0x4ndy
    // Online Resources //
    https://spacesecurity.club
    https://github.com/orgs/spacecrafthac...
    // Blog Post REFERENCE //
    https://www.hackthebox.com/blog/hack-...
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    // MENU //
    0:00 - Intro
    0:52 - How Russia hacked satellites
    02:12 - The Spacecraft Hacker's Handbook
    03:23 - VisionSpace
    04:04 - DeleteMe sponsor segment
    05:29 - Growth in satellites launched
    06:28 - What would losing satellites mean
    07:12 - Protocols explained
    08:00 - Misconceptions of satellite hacking
    09:28 - Threat level of satellite hacking
    10:39 - Upcoming demo explained
    12:20 - Who is the book for?
    16:46 - A gap
    17:48 - Other recommendations
    19:49 - Hacking satellite demo overview
    20:34 - Hacking satellite demo walkthrough
    33:54 - Demo next steps
    34:29 - Demo walkthrough continued
    38:51 - Conclusion
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.
    #sattelitehacking #spacecraftcybersecurity #defcon
    39 min
  • #608: Before You Deploy AI Agents, Understand These Attacks
    Big thanks to Proton VPN for sponsoring this video. You can use my link: https://protonvpn.com/davidbombal to get 70% off your Proton VPN subscription
    How do you hack an AI system? And what happens when one malicious instruction spreads between AI agents?
    I’m joined by Harriet, author of Practical AI Security, to explore how AI models and agents can be manipulated, with practical Python demonstrations. You'll see an image classifier misidentify a rifle, a demonstration of prompt injection spreading across five agents, and how memory poisoning can plant instructions that affect an agent later. We discuss why securing AI takes more than blocking prompt injection, how machine learning creates different security challenges, and what you need to understand before deploying agents in your organisation.
    Want to learn this yourself? Harriet explains how to get started with her collection of 30+ free Python notebooks, including examples you can explore in Google Colab. We also discuss the skills involved in AI security and how people from different backgrounds can contribute.
    Topics include:
    • Adversarial machine learning and image manipulation
    • Prompt injection and attacks spreading between agents
    • Memory poisoning and model backdoors
    • AI supply chain security
    • Learning AI security with Python
    • AI security careers, training and fundamentals
    // Link to No Starch Website for Harriet Farlow’s Book //
    Order Practical AI Security on No Starch: https://nostarch.com/practical-ai-sec...
    Use Coupon code FARLOW25 for 25% off Practical AI Security
    // HarrietHacks Labs REFERENCE //
    https://labs.harriethacks.com/
    // Harriet Farlow’s AI Security Fundamentals Course REFERENCE //
    https://aisecurityfundamentals.com/
    // Harriet Farlow’s SOCIALS //
    Website: https://harriethacks.com/about/
    LinkedIn: / harriet-farlow-654963b7
    Instagram: / harriethacks
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    // MENU //
    0:00 - Intro
    01:05 - Harriet Farlow AI security background
    05:55 - Proton VPN sponsor segment
    08:02 - Practical AI Security book // AI Security
    10:40 - Who's the book for
    11:32 - Harriet's YouTube channel
    12:32 - AI security course
    14:27 - Practical demos
    15:41 - Hacking an AI demo // Learning how AIs work
    22:22 - Hacking an AI summary
    24:40 - Hacking an AI visualizations
    28:48 - AI deceiving another AI
    33:09 - Hacking an AI visualizations continued
    34:07 - Rushing to the AI market
    36:26 - Adversarial patch explained
    38:12 - Vibe coded visuals
    40:27 - More visualization
    44:04 - Growth of interest in AI security
    45:09 - No advanced skills required
    49:40 - Get in contact with Harriet Farlow // Conclusion
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.
    #aisecurity #aiagents #defcon
    53 min
  • #607: How Hackers Steal Your Accounts Even With 2FA Enabled
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
    Is Microsoft Defender enough to protect your PC? Malware researcher Leo joins me at Black Hat to discuss antivirus, Windows security and how hackers steal your accounts.
    We explore how infostealers target saved passwords and session tokens, why two-factor authentication cannot prevent every account takeover, and how a message from a compromised friend’s account can lead to an infection.
    Leo shares practical starting points for investigating your computer, including Autoruns for startup entries, TCPView for linking connections to applications, and Wireshark for examining network traffic. We also discuss password managers, account recovery planning, Windows telemetry and why switching operating systems does not eliminate security risks.
    In this interview:
    • Microsoft Defender’s strengths and limitations
    • Free tools for investigating suspicious Windows activity
    • How infostealers and initial access brokers operate
    • Stolen session tokens and the limits of 2FA
    • Fake download sites, malicious ads and targeted phishing
    • Preparing recovery options before your accounts are compromised
    • Security and privacy trade-offs across Windows, Linux and macOS
    // Leo’s SOCIAL //
    YouTube: / @pcsecuritychannel
    X: https://x.com/leotday
    Discord: / discord
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    // MENU //
    0:00 - Coming Up
    0:35 - Intro
    0:48 - Leo's Background & How Malware Has Evolved
    03:27 - How to Detect Malware on Your Computer
    05:21 - Best Sysinternals Tools for Malware Analysis
    08:21 - Windows Device Tracking & Privacy Concerns
    10:42 - Would you Recommend Windows in 2026?
    11:59 - Privacy Laws & the Future of Tracking
    12:50 - How Telemetry Helps Catch Cybercriminals
    14:02 - ThreatLocker Sponsor
    15:18 - How Hackers Actually Get Into Systems
    16:42 - How to Protect Yourself From Getting Hacked
    19:12 - Do You Really Need Antivirus?
    21:35 - Security Advice for Home Users
    25:59 - Why Smart People Still Get Hacked
    26:59 - What Happens After Your Credentials Are Stolen
    28:06 - Linux vs Mac vs Windows
    29:40 - Is Windows Really Targeted More by Malware?
    31:18 - Conclusion & Outro
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    #malware #bhusa2026 #microsoftdefender
    32 min
  • #606: Is Cybersecurity Still Worth Learning in 2026?
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker, please use the following link: https://www.threatlocker.com/davidbombal
    Is cybersecurity still worth learning in 2026? AI agents are changing vulnerability research, but where does that leave you?
    At Black Hat, I’m joined by Arizona State University professor Yan Shoshitaishvili to discuss what AI can actually do, where it falls short, and why he would still choose a career in cybersecurity today.
    Yan shares how his lab used AI agents and human-designed workflows to find what he describes as over 1,000 Linux kernel vulnerabilities triggerable by an unprivileged local user. Running 128 agents was only part of the story. Understanding which vulnerabilities to look for and improving the research process proved critical.
    We discuss:
    • How AI agents test potential vulnerabilities instead of simply reporting suspected bugs
    • How agentic AI compares with fuzzing and static analysis
    • Why finding new bugs does not automatically prove one tool is better
    • Why human expertise still matters in security research
    • How to use AI as a learning assistant without skipping the learning
    • Free, hands-on cybersecurity training through pwn.college
    • Yan’s advice for anyone considering cybersecurity in 2026
    // Yan Shoshitaishvili SOCIAL //
    LinkedIn: / yan-shoshitaishvili-7024305
    ASU website: https://www.asu.edu/
    // ThreatLocker’s SOCIAL //
    LinkedIn: https://www.linkedin.com/company/thre...
    X: https://x.com/threatlocker
    Instagram: / threatlocker
    Website: https://www.threatlocker.com/
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    // MENU //
    0:00 - Coming up
    0:34 - Intro
    02:10 - Rethinking How Cybersecurity Is Taught
    04:35 - AI Agents Are Changing Vulnerability Research
    10:11 - Sponsored Section
    11:18 - Are AI Agents Really Better at Finding Bugs?
    16:00 - AI Agents vs the Linux Kernel
    19:30 - Where Human Expertise Still Matters
    23:09 - Learning Cybersecurity With AI
    25:17 - Will AI Eventually Replace Everyone?
    30:26 - Would You Still Choose Cybersecurity?
    30:50 - Conclusion & Outro
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.
    #aiagents #vulnerabilityresearch #bhusa2026
    32 min
  • #605: Flock Cameras: What They Can Reveal About Your Life
    Big thank you to DeleteMe for sponsoring this video. Use my link join https://joindeleteme.com/Bombal or use the QR code in the video to get 20% off.
    Your license plate could reveal more than you think. Flock cameras, vehicle tracking and OSINT can turn information about your car into clues about where you live and your daily routines.
    I’m joined by an OSINT expert to discuss how vehicle information can be connected with public records, why surveillance raises privacy concerns and what happens when people trust an incorrect license plate match.
    He shares his experiences of locating a missing car after a police search came up short and investigating a hit-and-run using a partial plate and publicly available
    information.
    We discuss:
    • Flock cameras and vehicle identification beyond license plates
    • How vehicle data can expose patterns in your movements
    • License plate recognition errors and the importance of verification
    • How public records can connect a vehicle to a person
    • The risks of surveillance access being abused
    • Privacy measures, their limitations and the need for accountability
    • DeFlock and community scrutiny of surveillance cameras
    How much can someone discover about you from the information you leave exposed?
    // Mishaal Kahn’s SOCIALS //
    LinkedIn: / mish-aal
    Website: https://www.mishaalkhan.com/
    Tool created: https://www.operationprivacy.com/
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    // MENU //
    0:00 - Coming Up
    0:47 - The Growing Flock Camera Controversy
    01:28 - What Are Flock Cameras Actually Collecting?
    02:33 - Police Misuse and Abuse of Surveillance Data
    03:45 - Mapping and Avoiding Flock Cameras
    04:57 - How Personal Data Fuels Scams
    06:54 - What Can Police Actually Do With Flock Data?
    07:12 - Testing Flock: A Real Missing Vehicle Case
    09:09 - How Mishaal Found the Vehicle Himself
    10:20 - Drones: The Next Level of Surveillance
    11:11 - How Can You Protect Your Privacy?
    13:07 - Facial Recognition Is Expanding Everywhere
    14:13 - AI Can Rebuild Your Entire Pattern of Life
    15:51 - What Can Someone Find From Your License Plate?
    17:16 - Solving a Hit-and-Run With a Partial Plate
    19:08 - What Could a Rogue Police Officer Do?
    20:28 - Is There Any Hope for Privacy?
    21:53 - Where to Learn More About Privacy and OSINT
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.
    #flockcameras #defcon #privacy
    23 min
  • #604: How He Infiltrated LockBit and Helped Get Them Indicted
    Big thanks to Proton Drive for sponsoring this video. You can use my link http://proton.me/drive/davidbombal to sign up for Proton Drive and get 40% discount.
    John DiMaggio created fake identities, profiled ransomware operators and spent approximately 18 months earning the trust of LockBit.
    In this interview, John explains how his investigation led to work with the FBI and the UK’s National Crime Agency, contributed to indictments and resulted in death threats against him. He also reveals how the work affected his mental health, relationships and everyday life.
    John shares the remarkable story of a young REvil hacker connected to the Kaseya ransomware attack and its $70 million ransom demand. He explains how ransomware operators are recruited, manipulated and sometimes controlled by intelligence agencies.
    You will also learn why stolen cryptocurrency is difficult to spend, how Bitcoin tracing and money-laundering mistakes expose cybercriminals and why technical hacking skills do not make someone good at hiding money. Finally, John warns aspiring researchers not to approach ransomware gangs without professional training and support. He discusses his new book, Owned, and how he plans to use his experience to help cybersecurity teams and business leaders prepare for ransomware attacks.
    // Link to No Starch Website for Jon DiMaggio’s Book //
    Order Owned on No Starch: https://nostarch.com/owned
    Use Coupon Code OWNED30 for 30% off Owned at NoStarch.com
    // Jon DiMaggio’s SOCIALS //
    Website: https://arkemcyber.com/
    X: https://x.com/Jon__DiMaggio
    LinkedIn: / jondimaggio
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    // MENU //
    0:00 - Coming Up
    0:36 - Introduction
    01:28 - Infiltrating the LockBit Ransomware Gang
    03:45 - Working With the FBI & NCA
    04:55 - Sponsor – Proton Drive
    06:54 - Stories From the Ransomware Gang
    07:35 - Befriending a Hacker
    10:21 - The Kaseya Ransomware Attack
    12:10 - Arrest, Extradition & a 14-Year Sentence
    13:12 - An Unexpected Message From Prison
    14:57 - The LockBit Story & the Mental Health Toll
    16:30 - Advice for Young People Drawn to Cybercrime
    18:09 - Why Hackers Can’t Easily Spend Their Money
    19:12 - How to Become a Jon DiMaggio
    21:58 - What’s Next for Jon DiMaggio
    23:08 - Preparing Companies for Ransomware Attacks
    23:52 - Final Thoughts
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.
    #lockbit #ransomware #revil
    25 min
  • #603: How Age Verification Threatens Your Online Privacy
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
    Age verification is spreading across the internet. It promises to protect children, but what happens when accessing a website or using your own device requires facial recognition, identity documents or third-party verification?
    David speaks with Alexis Hancock from the Electronic Frontier Foundation about the growing privacy risks surrounding age verification and digital ID systems. They examine how these technologies could threaten online anonymity, create new surveillance infrastructure and expose sensitive personal information.
    Alexis explains why age verification alone does not teach children how to stay safe online, how data brokers and behavioral advertising contribute to the problem, and why banning VPNs or weakening encryption would make everyone less secure.
    They also discuss zero-knowledge proofs, facial recognition, encryption backdoors, government surveillance and the danger of building a digital identity system that could be abused by future governments.
    Finally, Alexis shares practical ways to protect your privacy, including using encrypted communication, learning from EFF’s Surveillance Self-Defense guides and contacting elected representatives when harmful legislation is proposed.
    // Alexis Hancock’ SOCIAL //
    LinkedIn: / alexishancock
    // EFF Website REFERENCE //
    https://www.eff.org/
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    // MENU //
    0:00 - Intro
    0:41 - Alexis Hancock background // Who are the EFF
    01:48 - Eroding privacy & age verification
    08:48 - Online safety for children
    12:25 - Online monitoring
    14:20 - ThreatLocker sponsor segment
    15:27 - Big tech vs government
    17:49 - How to fight for privacy
    20:19 - Online censorship & privacy
    26:17 - The push for age verification
    29:29 - Age verification "whack-a-mole"
    33:03 - Parental control vs age verification
    36:24 - What about non-tech savvy people?
    41:02 - Zero-knowledge proof
    44:48 - Is it too late? // Conclusion
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.
    #ageverification #privacy #bhusa2026
    48 min
  • #602: How Compilers Turn Secure C Code Into Vulnerable Binaries
    Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
    You can write secure C code, follow accepted best practices and still end up with a vulnerable binary. The reason is simple: the CPU does not run your source code. It runs whatever the compiler produces.
    David sits down with security researcher Chris Domas at Black Hat to examine how legal compiler optimizations can remove security protections, delete memory-clearing operations and introduce time-of-check to time-of-use vulnerabilities into code that appeared secure.
    Chris explains the C abstract machine, why compilers are allowed to transform code so dramatically and how register pressure, structure layout and even data size can affect whether a binary is vulnerable. In one striking example, 17 or 33 bytes can be safe while nearby sizes produce vulnerable code. They also discuss whether Rust solves the problem, why switching between GCC and Clang is not the answer and how AI helped analyse 500 million lines of open-source code to identify 300 potentially dangerous patterns.
    Most importantly, Chris explains what developers can do now, including enabling compiler warnings, using sanitizers, analysing optimized builds and testing the exact binary that will be shipped.
    // Christopher Domas’ SOCIAL //
    LinkedIn: / christopher-domas
    GitHub: https://github.com/xoreaxeaxeax
    X: https://x.com/xoreaxeaxeax
    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...
    // MY STUFF //
    https://www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: [email protected]
    // MENU //
    0:00 - Coming Up
    0:48 - Intro
    02:05 - Different Ways of Exploiting CPU’s
    04:10 - The C Specifications
    06:17 - The Compiler Deleting Nemsec
    08:40 - Do we need to use a new Compiler ?
    10:09 - Compiler Inventing Vulnerabilities
    12:13 - Don't Give up Writing Secure Code
    12:44 - Sponsored Section
    14:25 - Any Easy Options To Create A New Compiler ?
    15:09 - Chris’s Presentation at Black Hat
    20:00 - Weird Situations with Size of Data
    21:22 - What Can Developers Do ?
    23:32 - Who Can Leverage this Vulnerability ?
    25:02 - Could AI Make it Easy For Attackers To Leverage This?
    28:27 - Recommendations For Developers
    29:48 - Advice To Be Like Chris
    30:36 - Conclusion & Outro
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.
    #bhusa2026 #securecoding #compiler
    31 min

About David Bombal

From the publisher's feed

Want to learn about IT? Want to get ahead in your career? Well, this is the right place!

More shows like David Bombal

Hacked by Hacked

Hacked

191 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

168 Listeners