Season 6, Episode 425 · Hacker Valley Studio
Turning 30,000 Findings Into 50 That Matter with Dan Pagel and Brad Hibbert
1 May 2026 · 35 min
Season 6, Episode 425 · Hacker Valley Studio
1 May 2026 · 35 min
Mythos just found 30,000 new vulnerabilities, and now every security team is asking the same question: what actually matters? In this episode, Ron Eddings sits down with Dan Pagel, CEO at Brinqa, and Brad Hibbert COO & CSO at Brinqa, to break down the Anthropic Mythos moment that rattled the security industry. From the panic of millions of new findings dropping overnight to the strategy of narrowing them down to the 50 that actually matter in YOUR environment, this episode is a masterclass in exposure management at machine speed. Dan and Brad share how Brinqa helps organizations make sense…
by Hacker Valley Media · English · Tech & Science
Welcome back to the show! Hacker Valley Studio podcast features Host Ron Eddings, as he explores the world of cybersecurity through the eyes of professionals in the industry. We cover everything from inspirational real-life stories in tech, to highlighting influential cybersecurity companies,…
S6 · E428 · 2 Jun 2026 · 36 min
What happens when AI writes all the code and nobody reads it? What if the security prompt you trusted still produced software designed to leak your secrets? And who exactly is on the hook when an AI-generated application takes down your company? In this episode, Ron sits down with returning guest Tanya Janca, Secure Coding Trainer at SheHacksPurple Consulting, to dig into one of the most underestimated risks in software development today: vibe coding. Tanya breaks down what vibe coding actually means, why AI trained on the internet's worst repositories is quietly baking the OWASP Top 10 into…
S6 · E427 · 26 May 2026 · 36 min
What if the most sophisticated attack has nothing to do with your firewall? In a world where AI can clone voices, re-lip-sync politicians, and spread a fake newscast to 200,000 people in days, the real target has always been your brain. Ron sits down with Perry Carpenter, Chief Deception Strategist at KnowBe4, to unpack why we're still getting fooled in 2026 and what we can actually do about it. Perry gets into the neuroscience behind why our brains are wired the way they are, how attackers exploit that, and what it really takes to build better instincts in a world full of AI-generated…
S6 · E426 · 18 May 2026 · 35 min
Right now, someone in your organization is probably feeding sensitive data into an AI system that nobody approved. So when something goes wrong, who's responsible? And more critically, do you even have a policy in place to answer that question? Ron Eddings sits down with his Hacker Valley co-founder, Chris Cochran, now serving as SANS Field CISO and VP of AI Security, to talk about his freshly released SANS AI Security Maturity Model, a practical framework built for security leaders who need to stop philosophizing and start making decisions. They cover the three pillars of AI security…
S1 · E424 · 24 Apr 2026 · 39 min
SOAR promised to close the loop in the SOC and fell flat. Agentic AI is finally delivering what a decade of playbooks couldn’t. In this episode, Ron sits down with Allan Alford, SVP at NTT Global Data Centers, and Tom Findling, co-founder and CEO of Conifers.ai. They cover why static playbooks broke under real-world conditions and how agentic systems are flipping the SOC operating model. They get into hallucination guardrails, human-on-the-loop versus human-in-the-loop, and the QR-code phishing investigation an agent solved on its own without being told how. The conversation closes on trust…
S6 · E423 · 17 Apr 2026 · 35 min
In 2025, Torq brought a monster truck to RSAC. And Don Jeter, Torq's CMO, will be the first to tell you: nobody's buying an AI SOC platform because of a grave digger in the booth. In this episode, Ron sits down with Don to discuss what Torq is actually doing in a category packed with 60 near-identical vendors, and why "the epidemic of sameness" is the real threat to every cybersecurity brand right now. Don explains why Torq builds everything in-house, why he starts every strategy by listening instead of pitching the product, and why the only differentiator left in cyber marketing is how much…
S6 · E422 · 7 Apr 2026 · 29 min
Most organizations are prepping for disaster recovery when they should be building for cyber recovery, and those are not the same thing. Recorded live at RSAC Conference 2026, Ron sat down with Chris Bevil, Principal Security AI Strategist at Commvault, to break down what actually happens after a breach hits and why most teams are caught flat-footed. Chris walks us through Commvault's Minutes to Meltdown tabletop exercise, why isolated recovery environments matter, and how clean data determines whether you get your company back in hours or in 200+ days. This episode will tell you what…
S6 · E446 · 7 Oct 2026 · 37 min
What happens when your marketing team, your sales team, and the person down the hall can all ship a full app from a single prompt? And what is that app quietly connected to? In this episode, Ron sits down with Roi Nisimi, Principal Security Researcher, and Yonatan Levi, AI Security Researcher, of Orca Security. They built apps on the most popular AppGen platforms and then tried to break into them.Ron, Roi, and Yonatan get into what's really running behind a prompt-built app, and what Orca's team found when they went looking for trouble. In one case, a single misconfigured app gave them a way…
S6 · E445 · 30 Sep 2026 · 32 min
Your newest hire has a Google Workspace account, a Slack login and a laptop. It never sleeps, and it never asks before it acts. So who owns its identity? Ron welcomes back Ashish Rajan, CISO at Techriot.io and researcher with AI Security Lab, who spent 17 years in identity, cloud security and security leadership. His take: vendors haven't solved AI identity, and the open questions are on your side, not the product's.Ashish got into identity after failing his OSCP three times: if he couldn't break in, he wouldn't let anyone else in. Now he reviews Ron's own setup, where Hacker Valley's AI…
S6 · E444 · 23 Sep 2026 · 32 min
What if someone got full admin access to your company's platform, including your CRM, your payments app, and your private messages, and the only tool they used was an AI chatbot? Can AI models really find zero-days on their own, or is that just the headline? And if AI can do the attacker's job, who's actually holding the scissors? In this solo episode, Ron Eddings shares his own methodology for offensive assessments with AI. He talks about the models he trusts, the tools he uses to get agents working together, and a real assessment where his agents turned SQL read access into admin control…
S6 · E443 · 16 Sep 2026 · 38 min
Every AI agent in your environment inherits someone's permissions, and most teams have no idea what those agents are actually doing with them. Amir Ofek, CEO and co-founder of Aizome, shares how to make every agent accountable before the damage shows up as a $150,000 bill.In this episode, Amir explains why human and machine identity tools both fail for AI, why agents act more like eager, naive interns than employees, and how a new category called ARISE (Agentic Runtime Identity Security Enforcement) is emerging to fix it. This one's for anyone building with AI agents right now (so, most of…