
Sign up to save your podcasts
Or


What does the world's most prolific cybercrime operation look like from the inside? And why does it operate suspiciously like a mid-sized tech company, complete with HR headaches, salary negotiations, and a distracted boss nobody respects?
Ron Eddings sits down with investigative journalist and author, Geoff White, who has spent over 20 years covering cybercrime for the BBC, Channel 4 News, and Sky News. Geoff has read 47,000 of Conti’s 300,000 leaked internal chats, the gang that dominated the ransomware world in 2021 and 2022, pulling in hundreds of millions of dollars in ransoms. From the Moscow movie studio the gang's leader used to launder money years previously, to the Ukraine war leak that brought the whole Conti empire down, this one plays like true crime… because it is.
Geoff makes the case that defenders should think the same way: you're not buying security tools to fend off a hoodie in a basement, you're investing to outcompete a rival business. For anyone trying to integrate a better incident response plan, this episode reframes the whole conversation.
Impactful Moments
Links
Connect with Geoff White on LinkedIn: https://www.linkedin.com/in/geoffwhitetech/
Get your own copy of Geoff's books (Crime Dot Com, The Lazarus Heist, Rinsed): https://geoffwhite.tech/book/
Want more information on Conti? Check out Geoff’s BBC podcast series, Cyber Hack: The Conti Files, available on BBC Sounds, Spotify, and Apple Podcasts
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
What happens when the adversary moves at machine speed, and your SOC is still responding at human speed? Why does nearly every security team say AI should handle L1 work, while 64% of organizations still have zero agents in production? And how long until the "coworker" resolving your ticket in Slack turns out not to be human at all?
Tim Leehealey, VP of Strategy and Operations at Strike 48, joins us this week to talk about what it actually takes to get AI agents out of the demo and into production. Tim agenticized his own company's IT, watched it blow up, and came out the other side with lessons from Fortune 100 SOCs running agents at serious scale.
He shares where AI actually belongs in the alert pipeline, the objections holding teams back, and a blunt warning for any leader still waiting on the sidelines in 2027. If AI in the SOC is on your roadmap before the end of this year, start here.
Impactful Moments
00:00 - Introduction
Connect with Tim Leehealey on LinkedIn: https://www.linkedin.com/in/tim-leehealey-b8b04321
Learn more about Strike48: https://strike48.com
Check out the 2026 State of Agentic Security report here: https://hubs.ly/Q04p49S20
Go deeper on Strike 48's technology: https://labs.strike48.com
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
Think about everything you could accomplish if you don’t have to be the one driving your browser. In this solo episode, Ron Eddings introduces Interceptor, Hacker Valley Media's first piece of software.
Interceptor is an open-source Chrome extension that lets an AI agent drive your real browser, logged-in sessions and all, with no vendor lock-in. Ron shares how it works and describes the use cases that matter most to security practitioners: OSINT and recon, bug bounty operations, prompt-injection testing, and threat-intelligence automation.
Ron also puts himself in the hot seat, answering the hardest questions he's gotten about the tool, including why anyone should trust an open-source tool from a podcast company over a polished product from a billion-dollar AI lab. The delegation is coming, and we would rather the security community be the ones who understand it.
Links
Download Interceptor on GitHub: https://github.com/hackervalleymedia/interceptor
Connect with Ron on LinkedIn: https://www.linkedin.com/in/ronaldeddings/
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
What if the same psychology that threat actors use to manipulate their targets is the same psychology that marketers use to earn your trust?
Check out our upcoming events: https://www.hackervalley.com/livestreams
In 2025, out of all 70+ guests we had on our show, not one of them said they’d trust AI to run their SOC. Now in 2026, that mindset is shifting. In this episode, Ron sits down with Aqsa Taylor, Chief Security Evangelist at Exaforce, to find out what changed, and what's still standing in the way of security teams being able to trust AI agents with response.
Connect with Aqsa Taylor on LinkedIn: https://www.linkedin.com/in/aqsa-taylor
Is AI really coming for your red teaming job? What does it actually take to build a team that thinks like the adversary, and what happens when that team stops caring? And what do you do when you've been in this field long enough that the job that once fired you up has started to feel hollow?
In this episode, Ron catches up with Johnny Xmas, Head of Offensive Security at a Fortune 150 Global Food Manufacturer, and one of the most candid voices in offensive security, for a conversation that covers a lot of ground fast.
They go deep on where AI actually fits into offensive security workflows, what Johnny really looks for when building elite teams, and why the career advice everyone gives early practitioners might be setting them up for burnout down the road. The conversation takes a turn that doesn't come up enough in this industry, and it's the part you won't want to miss. If you've ever felt your tank running low, this episode was made for you.
Impactful Moments
Johnny Christmas on LinkedIn: https://www.linkedin.com/in/johnnyxmas/
Johnny's SEC 8-K IoC parser tool: https://github.com/johnnyxmas/its-over-8k
—
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
What does a calf kick have to do with vulnerability management? What can a fighter's mindset teach a security practitioner about operating against an adversary they've never faced?
Impactful Moments
Links
What happens when AI writes all the code and nobody reads it? What if the security prompt you trusted still produced software designed to leak your secrets? And who exactly is on the hook when an AI-generated application takes down your company?
In this episode, Ron sits down with returning guest Tanya Janca, Secure Coding Trainer at SheHacksPurple Consulting, to dig into one of the most underestimated risks in software development today: vibe coding.
Tanya breaks down what vibe coding actually means, why AI trained on the internet's worst repositories is quietly baking the OWASP Top 10 into every app being built, and what her AI-powered secure coding prompt library can do to help. This is a candid, practical, and community-driven episode, the kind that'll make you want to audit your vibe code-a-thon project before it ever touches production.
Impactful Moments
Connect with our guest, Tanya Janca, on LinkedIn: https://www.linkedin.com/in/tanya-janca
Get Tanya's free secure coding guideline: https://securecodingguideline.com
Subscribe to Tanya’s AI Secure Coding Prompt Library: https://securemyvibe.ca
Access Tanya's Newsletter & Free Monthly Training: https://newsletter.shehackspurple.ca
Connect with Tanya across all social channels: @shehackspurple
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
What if the most sophisticated attack has nothing to do with your firewall? In a world where AI can clone voices, re-lip-sync politicians, and spread a fake newscast to 200,000 people in days, the real target has always been your brain.
Ron sits down with Perry Carpenter, Chief Deception Strategist at KnowBe4, to unpack why we're still getting fooled in 2026 and what we can actually do about it. Perry gets into the neuroscience behind why our brains are wired the way they are, how attackers exploit that, and what it really takes to build better instincts in a world full of AI-generated content. You'll also want to stick around for the live demos, where Perry breaks down why they worked and how to spot the tells.
Impactful Moments
Connect with our guest, Perry Carpenter, on LinkedIn: https://www.linkedin.com/in/perrycarpenter
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
Right now, someone in your organization is probably feeding sensitive data into an AI system that nobody approved. So when something goes wrong, who's responsible? And more critically, do you even have a policy in place to answer that question?
Ron Eddings sits down with his Hacker Valley co-founder, Chris Cochran, now serving as SANS Field CISO and VP of AI Security, to talk about his freshly released SANS AI Security Maturity Model, a practical framework built for security leaders who need to stop philosophizing and start making decisions.
They cover the three pillars of AI security maturity: utilizing AI for defense, protecting AI itself, and governing it across the organization. Chris then gets real about where most enterprises actually stand (hint: not as far along as they think). Listen for a conversation that meets you wherever you are: skeptic, early adopter, or somewhere in between.
00:00 - Introduction
03:00 - Chris Cochran: from Co-Founder to SANS Field CISO
04:20 - Your board is pushing AI before security is ready
06:00 - Tiers of AI uses: summarization to full automation
07:50 - When AI shouldn't make the final call
10:10 - Bite-sized AI: starting small in the enterprise
11:45 - Introducing the SANS AI Security Maturity Model
13:20 - You can no longer afford to be an AI skeptic
16:30 - Three buckets: utilize, protect, and govern AI
18:50 - Fact or Cap: what level of maturity is your enterprise?
21:00 - Retroactive vendor risk and the AI explosion
23:05 - Agentic Identity: workforce, non-human, and beyond
25:00 - What works in the agentic identity space?
27:05 - Blockchain for agent identity: promising or hype?
29:00 - A Message for the next generation of practitioners
31:30 - Ron's closing take: who owns your AI policy?
Connect with Chris Cochran on LinkedIn: https://www.linkedin.com/in/chrishvm/
Download the SANS AI Security Maturity Model: https://www.sans.org/mlp/2026-ai-security-maturity-model-ebook
Check out our upcoming events: https://www.hackervalley.com/livestreams
Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Continue the conversation by joining our Discord: https://hackervalley.com/discord
Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/
From the publisher's feed

192 Listeners

373 Listeners

375 Listeners

653 Listeners

1,029 Listeners

318 Listeners

421 Listeners

8,059 Listeners

179 Listeners

314 Listeners

191 Listeners

73 Listeners

2,650 Listeners

138 Listeners

168 Listeners