Season 1, Episode 438 · Hacker Valley Studio
Let AI Do More Without Surrendering Your Judgment with Jen Easterly
14 Aug 2026 · 24 min
Season 1, Episode 438 · Hacker Valley Studio
14 Aug 2026 · 24 min
Fresh off the showroom floor at Black Hat 2026, Ron brings back some hot takes from the crowd. Nearly every booth he visited, including the Exaforce booth, was pushing in the same direction. Trust in AI isn’t a philosophy debate anymore, it’s an engineering problem people are actively solving. Ron then catches up with Jen Easterly, CEO of RSAC, for a wide-ranging conversation on what it actually takes to build that trust. From her move out of government to her hard line on AI regulation and liability, the conversation takes an unexpected turn when Jen opens up about "cognitive surrender" and…
by Hacker Valley Media · English · Tech & Science
Welcome back to the show! Hacker Valley Studio podcast features Host Ron Eddings, as he explores the world of cybersecurity through the eyes of professionals in the industry. We cover everything from inspirational real-life stories in tech, to highlighting influential cybersecurity companies,…
S6 · E441 · 1 Sep 2026 · 36 min
Security teams spent decades begging for more logs. Now the enterprise is generating petabytes a day, and the thing drowning in it isn't just the SOC anymore, it's your AI agents too. In this episode, Ron sits down with Myke Lyons, CISO at Cribl, who cut his teeth in telemetry and logging decades ago and has landed right back there in the age of AI. Ron and Myke dig into why most telemetry failures aren't data problems at all, they're decisions nobody made about why the logs are being collected in the first place. Myke breaks down what to track on every agent in your environment, why token…
S6 · E440 · 25 Aug 2026 · 36 min
A year ago, the average employee held about 30 OAuth grants. Today that number has risen to 88, and it isn't slowing down. Ron sits down with Russell Spitler, co-founder and CEO of Nudge Security, and Richard Penshorn, a senior security engineer at a top financial services company, to talk about the AI already living inside your business. Ron, Russell, and Richard dig into why shadow AI doesn't behave like shadow IT, how one forgotten grant became the door into a real world breach, and whether AI agents should ever get access to a corporate inbox. Underneath all of it is the one thing…
S6 · E439 · 19 Aug 2026 · 35 min
Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigation platform from scratch. John's system runs on more than 30 specialized agents that reason through cases instead of following a script. In one run, that meant over 140 detections investigated in under four hours at an 80 to 85% quality rating. Ron and John dig into the hard lesson that made John rip out his own tooling and rebuild it around function calling, why "humans first" drives every…
S6 · E437 · 12 Aug 2026 · 31 min
What if the encrypted traffic flowing across the internet right now (emails, files, logins) is already being quietly collected and stored by someone waiting for the day they can finally crack it open? That's the threat behind "harvest now, decrypt later," and it's closer than most people think. Ron Eddings sits down with Michael Fasulo, Senior Director of Portfolio Marketing at Commvault, to talk about where post-quantum cryptography (PQC) really stands in 2026. They discuss "harvest now, decrypt later," the specific industries quietly racing to prepare, and why a commercially viable quantum…
S6 · E436 · 7 Aug 2026 · 38 min
What if the biggest risk to your organization isn't the device that gets lost, but the data that lives on it? Ron Eddings sits down with Jared Shepard, Founder and CEO of Hypori, whose path ran from homeless high school dropout to Army infantry to building a company that rethinks mobile security from the ground up. Jared makes the case for something more radical than most vendors will admit: stop defending the edge device entirely, and make sure sensitive data never lands there in the first place. He and Ron cover MDM and MAM's blind spots, executive protection, and the shadow AI habits…
S6 · E435 · 28 Jul 2026 · 35 min
What does the world's most prolific cybercrime operation look like from the inside? And why does it operate suspiciously like a mid-sized tech company, complete with HR headaches, salary negotiations, and a distracted boss nobody respects? Ron Eddings sits down with investigative journalist and author, Geoff White, who has spent over 20 years covering cybercrime for the BBC, Channel 4 News, and Sky News. Geoff has read 47,000 of Conti’s 300,000 leaked internal chats, the gang that dominated the ransomware world in 2021 and 2022, pulling in hundreds of millions of dollars in ransoms. From the…
S6 · E446 · 7 Oct 2026 · 37 minNew
What happens when your marketing team, your sales team, and the person down the hall can all ship a full app from a single prompt? And what is that app quietly connected to? In this episode, Ron sits down with Roi Nisimi, Principal Security Researcher, and Yonatan Levi, AI Security Researcher, of Orca Security. They built apps on the most popular AppGen platforms and then tried to break into them.Ron, Roi, and Yonatan get into what's really running behind a prompt-built app, and what Orca's team found when they went looking for trouble. In one case, a single misconfigured app gave them a way…
S6 · E445 · 30 Sep 2026 · 32 min
Your newest hire has a Google Workspace account, a Slack login and a laptop. It never sleeps, and it never asks before it acts. So who owns its identity? Ron welcomes back Ashish Rajan, CISO at Techriot.io and researcher with AI Security Lab, who spent 17 years in identity, cloud security and security leadership. His take: vendors haven't solved AI identity, and the open questions are on your side, not the product's.Ashish got into identity after failing his OSCP three times: if he couldn't break in, he wouldn't let anyone else in. Now he reviews Ron's own setup, where Hacker Valley's AI…
S6 · E444 · 23 Sep 2026 · 32 min
What if someone got full admin access to your company's platform, including your CRM, your payments app, and your private messages, and the only tool they used was an AI chatbot? Can AI models really find zero-days on their own, or is that just the headline? And if AI can do the attacker's job, who's actually holding the scissors? In this solo episode, Ron Eddings shares his own methodology for offensive assessments with AI. He talks about the models he trusts, the tools he uses to get agents working together, and a real assessment where his agents turned SQL read access into admin control…
S6 · E443 · 16 Sep 2026 · 38 min
Every AI agent in your environment inherits someone's permissions, and most teams have no idea what those agents are actually doing with them. Amir Ofek, CEO and co-founder of Aizome, shares how to make every agent accountable before the damage shows up as a $150,000 bill.In this episode, Amir explains why human and machine identity tools both fail for AI, why agents act more like eager, naive interns than employees, and how a new category called ARISE (Agentic Runtime Identity Security Enforcement) is emerging to fix it. This one's for anyone building with AI agents right now (so, most of…