Season 6, Episode 431 · Hacker Valley Studio
What's Really Stopping AI From Running Your SOC with Aqsa Taylor
23 Jun 2026 · 32 min
Season 6, Episode 431 · Hacker Valley Studio
23 Jun 2026 · 32 min
In 2025, out of all 70+ guests we had on our show, not one of them said they’d trust AI to run their SOC. Now in 2026, that mindset is shifting. In this episode, Ron sits down with Aqsa Taylor, Chief Security Evangelist at Exaforce, to find out what changed, and what's still standing in the way of security teams being able to trust AI agents with response. The conversation covers what's really behind the agentic SOC hype, why "vibe hunting" might be the most fun phrase in cybersecurity right now, and how teams can build enough confidence to hand over the keys to detection, investigation, and…
by Hacker Valley Media · English · Tech & Science
Welcome back to the show! Hacker Valley Studio podcast features Host Ron Eddings, as he explores the world of cybersecurity through the eyes of professionals in the industry. We cover everything from inspirational real-life stories in tech, to highlighting influential cybersecurity companies,…
S6 · E434 · 21 Jul 2026 · 36 min
What happens when the adversary moves at machine speed, and your SOC is still responding at human speed? Why does nearly every security team say AI should handle L1 work, while 64% of organizations still have zero agents in production? And how long until the "coworker" resolving your ticket in Slack turns out not to be human at all? Tim Leehealey, VP of Strategy and Operations at Strike 48, joins us this week to talk about what it actually takes to get AI agents out of the demo and into production. Tim agenticized his own company's IT, watched it blow up, and came out the other side with…
S6 · E433 · 14 Jul 2026 · 31 min
Think about everything you could accomplish if you don’t have to be the one driving your browser. In this solo episode, Ron Eddings introduces Interceptor, Hacker Valley Media's first piece of software. Interceptor is an open-source Chrome extension that lets an AI agent drive your real browser, logged-in sessions and all, with no vendor lock-in. Ron shares how it works and describes the use cases that matter most to security practitioners: OSINT and recon, bug bounty operations, prompt-injection testing, and threat-intelligence automation. Ron also puts himself in the hot seat, answering…
S6 · E432 · 7 Jul 2026 · 31 min
What if the same psychology that threat actors use to manipulate their targets is the same psychology that marketers use to earn your trust? In this episode, Ron sits down with Antu Buck, Senior Director of Customer Marketing & Community at Gigamon, who spent two decades building trust between vendors and the practitioners who use their tools. Antu walks us through the three pillars she's built her career around, and makes the case that advocacy shouldn't be an afterthought, but the very first marketing move a company invests in. The conversation lands on something the community doesn't talk…
S6 · E430 · 16 Jun 2026 · 29 min
Is AI really coming for your red teaming job? What does it actually take to build a team that thinks like the adversary, and what happens when that team stops caring? And what do you do when you've been in this field long enough that the job that once fired you up has started to feel hollow? In this episode, Ron catches up with Johnny Xmas, Head of Offensive Security at a Fortune 150 Global Food Manufacturer, and one of the most candid voices in offensive security, for a conversation that covers a lot of ground fast. They go deep on where AI actually fits into offensive security workflows,…
S6 · E429 · 9 Jun 2026 · 25 min
What does a calf kick have to do with vulnerability management? What can a fighter's mindset teach a security practitioner about operating against an adversary they've never faced? Ron Eddings brings back fan-favorite combat sports analyst and commentator Robin Black for a conversation that was never meant to be about cybersecurity, and ends up being one of the most insightful episodes on the human side of the field. They dig into how underdogs actually win (hint: we're usually wrong about who the underdog is), what it really means to maintain control in a fight, and why the highest level of…
S6 · E428 · 2 Jun 2026 · 36 min
What happens when AI writes all the code and nobody reads it? What if the security prompt you trusted still produced software designed to leak your secrets? And who exactly is on the hook when an AI-generated application takes down your company? In this episode, Ron sits down with returning guest Tanya Janca, Secure Coding Trainer at SheHacksPurple Consulting, to dig into one of the most underestimated risks in software development today: vibe coding. Tanya breaks down what vibe coding actually means, why AI trained on the internet's worst repositories is quietly baking the OWASP Top 10 into…
S6 · E446 · 7 Oct 2026 · 37 min
What happens when your marketing team, your sales team, and the person down the hall can all ship a full app from a single prompt? And what is that app quietly connected to? In this episode, Ron sits down with Roi Nisimi, Principal Security Researcher, and Yonatan Levi, AI Security Researcher, of Orca Security. They built apps on the most popular AppGen platforms and then tried to break into them.Ron, Roi, and Yonatan get into what's really running behind a prompt-built app, and what Orca's team found when they went looking for trouble. In one case, a single misconfigured app gave them a way…
S6 · E445 · 30 Sep 2026 · 32 min
Your newest hire has a Google Workspace account, a Slack login and a laptop. It never sleeps, and it never asks before it acts. So who owns its identity? Ron welcomes back Ashish Rajan, CISO at Techriot.io and researcher with AI Security Lab, who spent 17 years in identity, cloud security and security leadership. His take: vendors haven't solved AI identity, and the open questions are on your side, not the product's.Ashish got into identity after failing his OSCP three times: if he couldn't break in, he wouldn't let anyone else in. Now he reviews Ron's own setup, where Hacker Valley's AI…
S6 · E444 · 23 Sep 2026 · 32 min
What if someone got full admin access to your company's platform, including your CRM, your payments app, and your private messages, and the only tool they used was an AI chatbot? Can AI models really find zero-days on their own, or is that just the headline? And if AI can do the attacker's job, who's actually holding the scissors? In this solo episode, Ron Eddings shares his own methodology for offensive assessments with AI. He talks about the models he trusts, the tools he uses to get agents working together, and a real assessment where his agents turned SQL read access into admin control…
S6 · E443 · 16 Sep 2026 · 38 min
Every AI agent in your environment inherits someone's permissions, and most teams have no idea what those agents are actually doing with them. Amir Ofek, CEO and co-founder of Aizome, shares how to make every agent accountable before the damage shows up as a $150,000 bill.In this episode, Amir explains why human and machine identity tools both fail for AI, why agents act more like eager, naive interns than employees, and how a new category called ARISE (Agentic Runtime Identity Security Enforcement) is emerging to fix it. This one's for anyone building with AI agents right now (so, most of…