
Sign up to save your podcasts
Or


Your newest hire has a Google Workspace account, a Slack login and a laptop. It never sleeps, and it never asks before it acts. So who owns its identity? Ron welcomes back Ashish Rajan, CISO at Techriot.io and researcher with AI Security Lab, who spent 17 years in identity, cloud security and security leadership. His take: vendors haven't solved AI identity, and the open questions are on your side, not the product's.
00:00 - Introduction
Links
Listen to Ashish's first Hacker Valley Studio episode: https://www.podbean.com/pw/pbblog-bpaij-51b280
What if someone got full admin access to your company's platform, including your CRM, your payments app, and your private messages, and the only tool they used was an AI chatbot? Can AI models really find zero-days on their own, or is that just the headline? And if AI can do the attacker's job, who's actually holding the scissors?
In this solo episode, Ron Eddings shares his own methodology for offensive assessments with AI. He talks about the models he trusts, the tools he uses to get agents working together, and a real assessment where his agents turned SQL read access into admin control and unlocked the API keys stored inside. Ron also calls out what's hype and what's real with today's models, and why the agent still needs a skilled person behind it.
For defenders, Ron covers what attackers go after once they're in, and why the fundamentals like asset inventory are still where every strong security program starts. He closes with the bigger picture: anyone, good or bad, now has powerful intelligence on hand, and it's on all of us to look out for each other.
Impactful Moments
00:00 - Introduction
Links
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
Every AI agent in your environment inherits someone's permissions, and most teams have no idea what those agents are actually doing with them. Amir Ofek, CEO and co-founder of Aizome, shares how to make every agent accountable before the damage shows up as a $150,000 bill.
Impactful Moments
00:00 - Introduction
Links
Connect with Amir Ofek on LinkedIn: https://www.linkedin.com/in/amirofek/
Cybersecurity has survived cloud, mobile, and a dozen other "biggest disruptions of our lifetime," and each one felt unprecedented in the moment. In this episode, Ron sits down with Alyssa "Dr. Jay" Abdullah, Deputy CISO at MasterCard, who started her career as a radio DJ and has since worked inside the White House, Lockheed Martin, Stryker, and Xerox before landing in payments security.
Ron and Dr. Jay trace her path from spinning records to securing global payment infrastructure, and dig into why she'd argue cloud, not AI, was the real turning point in her career. They cover what convergence actually looks like when AI, cloud, and synthetic identity start overlapping, why curiosity matters more than fast answers, and what it means when employees start bringing their own trained AI agents to work.
The conversation closes on something most teams haven't fully reckoned with yet: AI agents that carry their own identity, independent of the humans who built them, and what that shift demands from the people responsible for securing them.
Impactful Moments
00:00 - Introduction
Links
Connect with Alissa "Dr. Jay" Abdullah on LinkedIn: https://www.linkedin.com/in/dralissajay/
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
Security teams spent decades begging for more logs. Now the enterprise is generating petabytes a day, and the thing drowning in it isn't just the SOC anymore, it's your AI agents too. In this episode, Ron sits down with Myke Lyons, CISO at Cribl, who cut his teeth in telemetry and logging decades ago and has landed right back there in the age of AI.
Ron and Myke dig into why most telemetry failures aren't data problems at all, they're decisions nobody made about why the logs are being collected in the first place. Myke breaks down what to track on every agent in your environment, why token spend belongs on the security team's plate, why dashboards are quietly dying, and why treating an AI agent like just another employee is a mistake that's going to bite security teams hard.
Underneath it all is one question Myke keeps circling back to: do you actually know what normal looks like for every agent in your environment?
Impactful Moments
00:00 - Introduction
Links
Connect with Myke Lyons on LinkedIn: https://www.linkedin.com/in/mykelyons/
Learn more about Cribl: https://cribl.io/
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
A year ago, the average employee held about 30 OAuth grants. Today that number has risen to 88, and it isn't slowing down. Ron sits down with Russell Spitler, co-founder and CEO of Nudge Security, and Richard Penshorn, a senior security engineer at a top financial services company, to talk about the AI already living inside your business.
Ron, Russell, and Richard dig into why shadow AI doesn't behave like shadow IT, how one forgotten grant became the door into a real world breach, and whether AI agents should ever get access to a corporate inbox.
Underneath all of it is the one thing Russell and Richard keep coming back to: ownership. Give an AI agent access with no owner attached and it becomes invisible. Give every employee an approved, low-friction path to use AI and they stop wandering off it. Find out how you can get ahead of the AI already running inside your walls.
Impactful Moments
00:00 - Introduction
Links
Connect with Russell Spitler on LinkedIn: https://www.linkedin.com/in/russell-spitler/
Connect with Richard Penshorn on LinkedIn: https://www.linkedin.com/in/richardpenshorn/
Learn more about Nudge Security: https://www.nudgesecurity.com/
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigation platform from scratch.
John's system runs on more than 30 specialized agents that reason through cases instead of following a script. In one run, that meant over 140 detections investigated in under four hours at an 80 to 85% quality rating. Ron and John dig into the hard lesson that made John rip out his own tooling and rebuild it around function calling, why "humans first" drives every decision his team makes, and whether AI SOC is actually different from SOAR or just the same promise with way better marketing.
Underneath all of it is the one thing John says decides whether any of this actually works: context. Give the AI too little and it's guessing, give it too much and it drowns just like a human would. Listen to find out what it actually takes to build an AI SOC that reasons instead of just automates.
00:00 - Introduction
Connect with John Gillis on LinkedIn: https://www.linkedin.com/in/john-gillis/
If you're a researcher ready to make an impact, check out the announcement about Adobe’s new home for the Adobe Bug Bounty Program here: https://blog.adobe.com/security/a-new-home-for-the-adobe-bug-bounty-program
Check out Adobe’s Bug Bounty profile on Intigriti: https://app.intigriti.com/programs/adobe/adobepublic/detail
Learn more about Adobe: https://www.adobe.com/
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Become a sponsor of the show: https://hackervalley.com/work-with-us/
Fresh off the showroom floor at Black Hat 2026, Ron brings back some hot takes from the crowd. Nearly every booth he visited, including the Exaforce booth, was pushing in the same direction. Trust in AI isn’t a philosophy debate anymore, it’s an engineering problem people are actively solving.
Ron then catches up with Jen Easterly, CEO of RSAC, for a wide-ranging conversation on what it actually takes to build that trust. From her move out of government to her hard line on AI regulation and liability, the conversation takes an unexpected turn when Jen opens up about "cognitive surrender" and why she believes good judgment can't be automated away. Couldn't make it to Black Hat this year? This episode has you covered.
Impactful Moments
00:00 - Introduction
02:45 - Reporting live from Black Hat 2026: hot takes from the showroom floor
05:05 - Welcoming Jen Easterly, CEO of RSAC
07:55 - A day in the life running RSAC and the Innovation Sandbox
10:00 - AI whack-a-mole and the sweet spot for regulation
11:00 - Governance vs. regulation, the EU AI Act, and state laws
13:30 - Why accountability and liability need to catch up to AI makers
14:45 - The case for autonomous patching and healing code like "The Matrix"
17:50 - The hot take Jen hasn't said before: not outsourcing our humanity
20:30 - Why in-person conferences matter more in the AI era
21:55 - Ron's takeaway: who decides when AI has earned our trust?
Links
Connect with Jen Easterly on LinkedIn: https://www.linkedin.com/in/jen-easterly
Learn more about Exaforce: https://www.exaforce.com
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us
What if the encrypted traffic flowing across the internet right now (emails, files, logins) is already being quietly collected and stored by someone waiting for the day they can finally crack it open? That's the threat behind "harvest now, decrypt later," and it's closer than most people think.
Links
What if the biggest risk to your organization isn't the device that gets lost, but the data that lives on it? Ron Eddings sits down with Jared Shepard, Founder and CEO of Hypori, whose path ran from homeless high school dropout to Army infantry to building a company that rethinks mobile security from the ground up.
Impactful Moments
00:00 - Introduction
Links
Learn more about Hypori: https://hypori.com
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
From the publisher's feed

192 Listeners

373 Listeners

375 Listeners

653 Listeners

1,029 Listeners

318 Listeners

421 Listeners

8,059 Listeners

179 Listeners

314 Listeners

191 Listeners

73 Listeners

2,650 Listeners

138 Listeners

168 Listeners