
Welcome back to the show! Hacker Valley Studio podcast features Host Ron Eddings, as he explores the world of cybersecurity through the eyes of professionals in the industry. We cover everything from inspirational real-life stories in tech, to highlighting influential cybersecurity companies, and we do so in a fun and enthusiastic way. We’re making cybersecurity accessible, creating a whole new form of entertainment: cybertainment.
Episodes
2 hours ago
2 hours ago
31 min
What if someone got full admin access to your company's platform, including your CRM, your payments app, and your private messages, and the only tool they used was an AI chatbot? Can AI models really find zero-days on their own, or is that just the headline? And if AI can do the attacker's job, who's actually holding the scissors?
In this solo episode, Ron Eddings shares his own methodology for offensive assessments with AI. He talks about the models he trusts, the tools he uses to get agents working together, and a real assessment where his agents turned SQL read access into admin control and unlocked the API keys stored inside. Ron also calls out what's hype and what's real with today's models, and why the agent still needs a skilled person behind it.
For defenders, Ron covers what attackers go after once they're in, and why the fundamentals like asset inventory are still where every strong security program starts. He closes with the bigger picture: anyone, good or bad, now has powerful intelligence on hand, and it's on all of us to look out for each other.
Impactful Moments
00:00 - Introduction
02:25 - Can AI Really Find Zero-Days Alone?
04:20 - The Real Danger Is Human Intent
05:00 - Why Grok 4.6 Tops Ron's List
07:55 - Ron's Three-Model Assessment Workflow
09:50 - Maestro, Interceptor, and Agent Ensembles
11:20 - Privilege Escalation and Persistence With LLMs
12:50 - Why AI Hacking Feels Like Cheating
14:20 - Ron Called Automated Security in 2015
16:05 - The Lazy Way to Hack
17:55 - From SQL Read Access to Admin
21:05 - What Attackers Want After Getting In
23:40 - Asset Inventory Is Security Flossing
27:05 - Why AI Is Like Scissors
29:05 - Waymos, Robotaxis, and Physical AI Risk
Links
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
Sep 16, 2026
Sep 16, 2026
38 min
Every AI agent in your environment inherits someone's permissions, and most teams have no idea what those agents are actually doing with them. Amir Ofek, CEO and co-founder of Aizome, shares how to make every agent accountable before the damage shows up as a $150,000 bill.
In this episode, Amir explains why human and machine identity tools both fail for AI, why agents act more like eager, naive interns than employees, and how a new category called ARISE (Agentic Runtime Identity Security Enforcement) is emerging to fix it.
This one's for anyone building with AI agents right now (so, most of us). Amir's take: the biggest danger isn't a breach. It's agents quietly doing the wrong thing at scale while nobody's watching.
Impactful Moments
00:00 - Introduction
02:30 - Busting the Myth: "I Know What My Agents Are Doing"
05:30 - The Samurai Story Behind Aizome's Name
08:25 - Why Not All AI Agents Are Born Equal
11:15 - Where Enterprises Are Actually Deploying AI Agents Today
14:25 - What Claude Cowork Inherits Without You Realizing It
17:15 - Machine Identity vs. Human Identity vs. AI Identity
19:35 - Treating AI Agents Like Eager, Naive Interns
23:00 - The Biggest AI Risk Isn't Security, It's Cost
25:45 - Meet Ito: Aizome's Supervisor Agent
26:40 - Inside the New ARISE Category
33:35 - What Aizome Actually Does
35:30 - The Callback: Was the Myth Wrong, or Dangerously Wrong?
Links
Connect with Amir Ofek on LinkedIn: https://www.linkedin.com/in/amirofek/
Learn more about Aizome: https://www.aizome.ai/
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
Sep 9, 2026
Sep 9, 2026
36 min
Cybersecurity has survived cloud, mobile, and a dozen other "biggest disruptions of our lifetime," and each one felt unprecedented in the moment. In this episode, Ron sits down with Alyssa "Dr. Jay" Abdullah, Deputy CISO at MasterCard, who started her career as a radio DJ and has since worked inside the White House, Lockheed Martin, Stryker, and Xerox before landing in payments security.
Ron and Dr. Jay trace her path from spinning records to securing global payment infrastructure, and dig into why she'd argue cloud, not AI, was the real turning point in her career. They cover what convergence actually looks like when AI, cloud, and synthetic identity start overlapping, why curiosity matters more than fast answers, and what it means when employees start bringing their own trained AI agents to work.
The conversation closes on something most teams haven't fully reckoned with yet: AI agents that carry their own identity, independent of the humans who built them, and what that shift demands from the people responsible for securing them.
Impactful Moments
00:00 - Introduction
02:25 - Busting the AI hype myth
04:40 - From radio DJ to Dr. Jay
06:10 - A day in the life as Deputy CISO at Mastercard
07:25 - Why AI hasn't disrupted her world
08:50 - White House tech through the decades
12:30 - Smartphones, wearables, and what's next
13:30 - Defining convergence for 2026
14:50 - When AI meets quantum computing
17:20 - Bring your own AI agent to work
19:00 - Negotiating salary in tokens
21:05 - Teaching curiosity over answers
23:50 - Overhype equals overtrust
27:10 - The future of tier one and autonomous SOC
29:50 - Hot take: AI in the SOC
31:35 - Predictions: AI identities and the human outside the loop
Links
Connect with Alissa "Dr. Jay" Abdullah on LinkedIn: https://www.linkedin.com/in/dralissajay/
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
Sep 1, 2026
Sep 1, 2026
35 min
Security teams spent decades begging for more logs. Now the enterprise is generating petabytes a day, and the thing drowning in it isn't just the SOC anymore, it's your AI agents too. In this episode, Ron sits down with Myke Lyons, CISO at Cribl, who cut his teeth in telemetry and logging decades ago and has landed right back there in the age of AI.
Ron and Myke dig into why most telemetry failures aren't data problems at all, they're decisions nobody made about why the logs are being collected in the first place. Myke breaks down what to track on every agent in your environment, why token spend belongs on the security team's plate, why dashboards are quietly dying, and why treating an AI agent like just another employee is a mistake that's going to bite security teams hard.
Underneath it all is one question Myke keeps circling back to: do you actually know what normal looks like for every agent in your environment?
Impactful Moments
00:00 - Introduction
01:50 - Myth Busting: AI Agents Aren't Just Another User Account
04:25 - Meet Myke Lyons, CISO at Cribl
05:05 - What it means to run security at a telemetry company
06:10 - From gigabytes of logs at GE to petabytes today
07:45 - MITRE ATT&CK, Cribl's new APEX framework, and orienting telemetry
10:20 - Why most telemetry problems are decision problems, not data problems
13:20 - OCSF and how security teams are rethinking their schemas
14:25 - Why the dashboard is dying
17:35 - What Myke wants to track about every AI agent
20:10 - How to spot an agent going rogue
23:15 - Making your data AI-ready and the case for schematizing everything
27:10 - Tokenomics: treating AI spend as a security responsibility
29:05 - The non-negotiable logs every org should be collecting
31:50 - Hot takes: build vs. buy, tier two to three, and Myke's daily AI briefing
33:35 - Closing thoughts and outro
Links
Connect with Myke Lyons on LinkedIn: https://www.linkedin.com/in/mykelyons/
Learn more about Cribl: https://cribl.io/
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
Aug 25, 2026
Aug 25, 2026
35 min
A year ago, the average employee held about 30 OAuth grants. Today that number has risen to 88, and it isn't slowing down. Ron sits down with Russell Spitler, co-founder and CEO of Nudge Security, and Richard Penshorn, a senior security engineer at a top financial services company, to talk about the AI already living inside your business.
Ron, Russell, and Richard dig into why shadow AI doesn't behave like shadow IT, how one forgotten grant became the door into a real world breach, and whether AI agents should ever get access to a corporate inbox.
Underneath all of it is the one thing Russell and Richard keep coming back to: ownership. Give an AI agent access with no owner attached and it becomes invisible. Give every employee an approved, low-friction path to use AI and they stop wandering off it. Find out how you can get ahead of the AI already running inside your walls.
Impactful Moments
00:00 - Introduction
02:00 - Busting the "shadow AI is just shadow IT" myth
03:45 - Meet Russell Spitler and Richard Penshorn
05:50 - The surprising long tail of AI tool usage
07:00 - Entertainment vs. finance: build vs. buy culture
08:50 - How 30 OAuth grants became 88 in 2026
10:25 - Why manual OAuth audits became untenable
11:30 - The Canva example: what "click to connect" really grants
15:20 - Benign vs. malicious: how a stolen OAuth grant gets exploited
17:00 - Shadow IT vs. Shadow AI: what's actually different now
21:00 - Hot take: should AI agents ever touch corporate email?
25:10 - The three buckets of AI agent discovery
27:55 - Russell's best practices for locking down agents
31:00 - Fundamentals for the next 18 months: visibility and easy paths
Links
Connect with Russell Spitler on LinkedIn: https://www.linkedin.com/in/russell-spitler/
Connect with Richard Penshorn on LinkedIn: https://www.linkedin.com/in/richardpenshorn/
Learn more about Nudge Security: https://www.nudgesecurity.com/
–
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/
