DiscoverDavid Bombal
David Bombal
Claim Ownership

David Bombal

Author: David Bombal

Subscribed: 173Played: 2,805
Share

Description

Want to learn about IT? Want to get ahead in your career? Well, this is the right place!

On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics.

This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content.

David’s details:
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
Website: http://www.davidbombal.com
YouTube: https://www.youtube.com/davidbombal

All the best!
David
605 Episodes
Reverse
Big thanks to Proton VPN for sponsoring this video. You can use my link: https://protonvpn.com/davidbombal to get 70% off your Proton VPN subscription How do you hack an AI system? And what happens when one malicious instruction spreads between AI agents? I’m joined by Harriet, author of Practical AI Security, to explore how AI models and agents can be manipulated, with practical Python demonstrations. You'll see an image classifier misidentify a rifle, a demonstration of prompt injection spreading across five agents, and how memory poisoning can plant instructions that affect an agent later. We discuss why securing AI takes more than blocking prompt injection, how machine learning creates different security challenges, and what you need to understand before deploying agents in your organisation. Want to learn this yourself? Harriet explains how to get started with her collection of 30+ free Python notebooks, including examples you can explore in Google Colab. We also discuss the skills involved in AI security and how people from different backgrounds can contribute. Topics include: • Adversarial machine learning and image manipulation • Prompt injection and attacks spreading between agents • Memory poisoning and model backdoors • AI supply chain security • Learning AI security with Python • AI security careers, training and fundamentals // Link to No Starch Website for Harriet Farlow’s Book // Order Practical AI Security on No Starch: https://nostarch.com/practical-ai-sec... Use Coupon code FARLOW25 for 25% off Practical AI Security // HarrietHacks Labs REFERENCE // https://labs.harriethacks.com/ // Harriet Farlow’s AI Security Fundamentals Course REFERENCE // https://aisecurityfundamentals.com/ // Harriet Farlow’s SOCIALS // Website: https://harriethacks.com/about/ LinkedIn: / harriet-farlow-654963b7 Instagram: / harriethacks // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Intro 01:05 - Harriet Farlow AI security background 05:55 - Proton VPN sponsor segment 08:02 - Practical AI Security book // AI Security 10:40 - Who's the book for 11:32 - Harriet's YouTube channel 12:32 - AI security course 14:27 - Practical demos 15:41 - Hacking an AI demo // Learning how AIs work 22:22 - Hacking an AI summary 24:40 - Hacking an AI visualizations 28:48 - AI deceiving another AI 33:09 - Hacking an AI visualizations continued 34:07 - Rushing to the AI market 36:26 - Adversarial patch explained 38:12 - Vibe coded visuals 40:27 - More visualization 44:04 - Growth of interest in AI security 45:09 - No advanced skills required 49:40 - Get in contact with Harriet Farlow // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #aisecurity #aiagents #defcon
Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Is Microsoft Defender enough to protect your PC? Malware researcher Leo joins me at Black Hat to discuss antivirus, Windows security and how hackers steal your accounts. We explore how infostealers target saved passwords and session tokens, why two-factor authentication cannot prevent every account takeover, and how a message from a compromised friend’s account can lead to an infection. Leo shares practical starting points for investigating your computer, including Autoruns for startup entries, TCPView for linking connections to applications, and Wireshark for examining network traffic. We also discuss password managers, account recovery planning, Windows telemetry and why switching operating systems does not eliminate security risks. In this interview: • Microsoft Defender’s strengths and limitations • Free tools for investigating suspicious Windows activity • How infostealers and initial access brokers operate • Stolen session tokens and the limits of 2FA • Fake download sites, malicious ads and targeted phishing • Preparing recovery options before your accounts are compromised • Security and privacy trade-offs across Windows, Linux and macOS // Leo’s SOCIAL // YouTube: / @pcsecuritychannel X: https://x.com/leotday Discord: / discord // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 0:35 - Intro 0:48 - Leo's Background & How Malware Has Evolved 03:27 - How to Detect Malware on Your Computer 05:21 - Best Sysinternals Tools for Malware Analysis 08:21 - Windows Device Tracking & Privacy Concerns 10:42 - Would you Recommend Windows in 2026? 11:59 - Privacy Laws & the Future of Tracking 12:50 - How Telemetry Helps Catch Cybercriminals 14:02 - ThreatLocker Sponsor 15:18 - How Hackers Actually Get Into Systems 16:42 - How to Protect Yourself From Getting Hacked 19:12 - Do You Really Need Antivirus? 21:35 - Security Advice for Home Users 25:59 - Why Smart People Still Get Hacked 26:59 - What Happens After Your Credentials Are Stolen 28:06 - Linux vs Mac vs Windows 29:40 - Is Windows Really Targeted More by Malware? 31:18 - Conclusion & Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #malware #bhusa2026 #microsoftdefender
Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker, please use the following link: https://www.threatlocker.com/davidbombal Is cybersecurity still worth learning in 2026? AI agents are changing vulnerability research, but where does that leave you? At Black Hat, I’m joined by Arizona State University professor Yan Shoshitaishvili to discuss what AI can actually do, where it falls short, and why he would still choose a career in cybersecurity today. Yan shares how his lab used AI agents and human-designed workflows to find what he describes as over 1,000 Linux kernel vulnerabilities triggerable by an unprivileged local user. Running 128 agents was only part of the story. Understanding which vulnerabilities to look for and improving the research process proved critical. We discuss: • How AI agents test potential vulnerabilities instead of simply reporting suspected bugs • How agentic AI compares with fuzzing and static analysis • Why finding new bugs does not automatically prove one tool is better • Why human expertise still matters in security research • How to use AI as a learning assistant without skipping the learning • Free, hands-on cybersecurity training through pwn.college • Yan’s advice for anyone considering cybersecurity in 2026 // Yan Shoshitaishvili SOCIAL // LinkedIn: / yan-shoshitaishvili-7024305 ASU website: https://www.asu.edu/ // ThreatLocker’s SOCIAL // LinkedIn: https://www.linkedin.com/company/thre... X: https://x.com/threatlocker Instagram: / threatlocker Website: https://www.threatlocker.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming up 0:34 - Intro 02:10 - Rethinking How Cybersecurity Is Taught 04:35 - AI Agents Are Changing Vulnerability Research 10:11 - Sponsored Section 11:18 - Are AI Agents Really Better at Finding Bugs? 16:00 - AI Agents vs the Linux Kernel 19:30 - Where Human Expertise Still Matters 23:09 - Learning Cybersecurity With AI 25:17 - Will AI Eventually Replace Everyone? 30:26 - Would You Still Choose Cybersecurity? 30:50 - Conclusion & Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #aiagents #vulnerabilityresearch #bhusa2026
Big thank you to DeleteMe for sponsoring this video. Use my link join https://joindeleteme.com/Bombal or use the QR code in the video to get 20% off. Your license plate could reveal more than you think. Flock cameras, vehicle tracking and OSINT can turn information about your car into clues about where you live and your daily routines. I’m joined by an OSINT expert to discuss how vehicle information can be connected with public records, why surveillance raises privacy concerns and what happens when people trust an incorrect license plate match. He shares his experiences of locating a missing car after a police search came up short and investigating a hit-and-run using a partial plate and publicly available information. We discuss: • Flock cameras and vehicle identification beyond license plates • How vehicle data can expose patterns in your movements • License plate recognition errors and the importance of verification • How public records can connect a vehicle to a person • The risks of surveillance access being abused • Privacy measures, their limitations and the need for accountability • DeFlock and community scrutiny of surveillance cameras How much can someone discover about you from the information you leave exposed? // Mishaal Kahn’s SOCIALS // LinkedIn: / mish-aal Website: https://www.mishaalkhan.com/ Tool created: https://www.operationprivacy.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 0:47 - The Growing Flock Camera Controversy 01:28 - What Are Flock Cameras Actually Collecting? 02:33 - Police Misuse and Abuse of Surveillance Data 03:45 - Mapping and Avoiding Flock Cameras 04:57 - How Personal Data Fuels Scams 06:54 - What Can Police Actually Do With Flock Data? 07:12 - Testing Flock: A Real Missing Vehicle Case 09:09 - How Mishaal Found the Vehicle Himself 10:20 - Drones: The Next Level of Surveillance 11:11 - How Can You Protect Your Privacy? 13:07 - Facial Recognition Is Expanding Everywhere 14:13 - AI Can Rebuild Your Entire Pattern of Life 15:51 - What Can Someone Find From Your License Plate? 17:16 - Solving a Hit-and-Run With a Partial Plate 19:08 - What Could a Rogue Police Officer Do? 20:28 - Is There Any Hope for Privacy? 21:53 - Where to Learn More About Privacy and OSINT Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #flockcameras #defcon #privacy
Big thanks to Proton Drive for sponsoring this video. You can use my link http://proton.me/drive/davidbombal to sign up for Proton Drive and get 40% discount. John DiMaggio created fake identities, profiled ransomware operators and spent approximately 18 months earning the trust of LockBit. In this interview, John explains how his investigation led to work with the FBI and the UK’s National Crime Agency, contributed to indictments and resulted in death threats against him. He also reveals how the work affected his mental health, relationships and everyday life. John shares the remarkable story of a young REvil hacker connected to the Kaseya ransomware attack and its $70 million ransom demand. He explains how ransomware operators are recruited, manipulated and sometimes controlled by intelligence agencies. You will also learn why stolen cryptocurrency is difficult to spend, how Bitcoin tracing and money-laundering mistakes expose cybercriminals and why technical hacking skills do not make someone good at hiding money. Finally, John warns aspiring researchers not to approach ransomware gangs without professional training and support. He discusses his new book, Owned, and how he plans to use his experience to help cybersecurity teams and business leaders prepare for ransomware attacks. // Link to No Starch Website for Jon DiMaggio’s Book // Order Owned on No Starch: https://nostarch.com/owned Use Coupon Code OWNED30 for 30% off Owned at NoStarch.com // Jon DiMaggio’s SOCIALS // Website: https://arkemcyber.com/ X: https://x.com/Jon__DiMaggio LinkedIn: / jondimaggio // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 0:36 - Introduction 01:28 - Infiltrating the LockBit Ransomware Gang 03:45 - Working With the FBI & NCA 04:55 - Sponsor – Proton Drive 06:54 - Stories From the Ransomware Gang 07:35 - Befriending a Hacker 10:21 - The Kaseya Ransomware Attack 12:10 - Arrest, Extradition & a 14-Year Sentence 13:12 - An Unexpected Message From Prison 14:57 - The LockBit Story & the Mental Health Toll 16:30 - Advice for Young People Drawn to Cybercrime 18:09 - Why Hackers Can’t Easily Spend Their Money 19:12 - How to Become a Jon DiMaggio 21:58 - What’s Next for Jon DiMaggio 23:08 - Preparing Companies for Ransomware Attacks 23:52 - Final Thoughts Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #lockbit #ransomware #revil
loading
Comments 
loading