DiscoverHacker Valley Studio
Hacker Valley Studio

Hacker Valley Studio

Author: Hacker Valley Media

Subscribed: 237Played: 12,856
Share

Description

Welcome back… to the show! Hacker Valley Studio podcast features Host Ron Eddings, as he explores the world of cybersecurity through the eyes of professionals in the industry. We cover everything from inspirational real-life stories in tech, to highlighting influential cybersecurity companies, and we do so in a fun and enthusiastic way. We’re making cybersecurity accessible, creating a whole new form of entertainment: cybertainment.
444 Episodes
Reverse
What happens when your marketing team, your sales team, and the person down the hall can all ship a full app from a single prompt? And what is that app quietly connected to? In this episode, Ron sits down with Roi Nisimi, Principal Security Researcher, and Yonatan Levi, AI Security Researcher, of Orca Security. They built apps on the most popular AppGen platforms and then tried to break into them. Ron, Roi, and Yonatan get into what's really running behind a prompt-built app, and what Orca's team found when they went looking for trouble. In one case, a single misconfigured app gave them a way into every integration connected to the workspace. They also explain why Supabase has become a favorite of builders and attackers alike, and share the security questions they ask before sending a prompt. The bigger tension is speed. With no code review between the prompt and production, Roi argues that velocity has broken the threat models that security relied on for years. And when the agent makes every decision, nobody fully understands what was built, not even the security researchers. Impactful Moments 00:00 - Introduction 02:15 - Busting the vibe coding myth 04:40 - Inside Orca's State of AI report 05:55 - The unpatched AI SDK problem 07:40 - What is AppGen? 10:20 - Who builds the backend? 12:25 - Inside Orca's AppGen hackathon 14:10 - Thinking like a citizen developer 15:15 - Who's really building these apps 19:25 - One misconfigured app, every integration exposed 20:45 - Why Supabase is the holy grail 23:00 - Checking your own exposure 24:30 - Why the SDLC is breaking down 26:55 - Prompting for a secure app 28:15 - Don't hand the agent every decision 31:20 - Staying sharp by never stopping learning 33:35 - From protecting environments to protecting apps Links Connect with Roi Nisimi on LinkedIn: https://www.linkedin.com/in/roinisimi/  Connect with Yonatan Levi on LinkedIn: https://www.linkedin.com/in/yonatan-levi-b22168258/  Register for Orca’s virtual Builder Exchange: https://orca.security/builder-exchange/?utm_source=HVN&utm_medium=3rd-part Read the security findings in Orca’s 2026 State of AI Security Report: https://orca.security/lp/2026-state-of-ai-security-report/?utm_source=HVN&utm_medium=3rd-party  – Check out our upcoming events: https://www.hackervalley.com/livestreams  Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com  Become a sponsor of the show: https://hackervalley.com/work-with-us/ 
Your newest hire has a Google Workspace account, a Slack login and a laptop. It never sleeps, and it never asks before it acts. So who owns its identity? Ron welcomes back Ashish Rajan, CISO at Techriot.io and researcher with AI Security Lab, who spent 17 years in identity, cloud security and security leadership. His take: vendors haven't solved AI identity, and the open questions are on your side, not the product's. Ashish got into identity after failing his OSCP three times: if he couldn't break in, he wouldn't let anyone else in. Now he reviews Ron's own setup, where Hacker Valley's AI agent, Jennifer Romani, has her own accounts just like an employee. Ashish explains how that call changes from a one-laptop small business to an enterprise where every developer's machine acts like five. They also cover the Gemini breach headlines, swarms of agents and AI Security Lab, which Ashish describes as what OWASP is for AppSec, but for AI security. The uncomfortable truth: defenders have the same models attackers do, but attackers don't wait for a pull request review. Ashish calls that a people problem, not a technology problem. He also shares the question he asks before handing anything to an AI agent: can this be reversed? Impactful Moments 00:00 - Introduction 02:30 - Busting a myth: AI identity isn't solved 05:30 - Three OSCP attempts and a pivot to IAM 07:00 - Why AI identity is more complex than ever 09:15 - Hot or not: giving an AI agent its own accounts 11:10 - One laptop, five machines in the enterprise 12:50 - AI gateways and developer observability 14:05 - Where Ashish would spend his AI security budget 18:20 - Why defenders don't hack themselves first 19:05 - The real problem is people 22:15 - Swarms of agents are coming 23:50 - What AI Security Lab is building 26:35 - Never share your credit card with AI 28:40 - Ron's callback: can it be reversed? Links Connect with Ashish Rajan on LinkedIn: https://www.linkedin.com/in/ashishrajan/ Listen to Ashish's first Hacker Valley Studio episode: https://www.podbean.com/pw/pbblog-bpaij-51b280 –  Check out our upcoming events: https://www.hackervalley.com/livestreams  Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com  Become a sponsor of the show: https://hackervalley.com/work-with-us/ 
What if someone got full admin access to your company's platform, including your CRM, your payments app, and your private messages, and the only tool they used was an AI chatbot? Can AI models really find zero-days on their own, or is that just the headline? And if AI can do the attacker's job, who's actually holding the scissors? In this solo episode, Ron Eddings shares his own methodology for offensive assessments with AI. He talks about the models he trusts, the tools he uses to get agents working together, and a real assessment where his agents turned SQL read access into admin control and unlocked the API keys stored inside. Ron also calls out what's hype and what's real with today's models, and why the agent still needs a skilled person behind it. For defenders, Ron covers what attackers go after once they're in, and why the fundamentals like asset inventory are still where every strong security program starts.  He closes with the bigger picture: anyone, good or bad, now has powerful intelligence on hand, and it's on all of us to look out for each other. Impactful Moments 00:00 - Introduction 02:25 - Can AI Really Find Zero-Days Alone? 04:20 - The Real Danger Is Human Intent 05:00 - Why Grok 4.6 Tops Ron's List 07:55 - Ron's Three-Model Assessment Workflow 09:50 - Maestro, Interceptor, and Agent Ensembles 11:20 - Privilege Escalation and Persistence With LLMs 12:50 - Why AI Hacking Feels Like Cheating 14:20 - Ron Called Automated Security in 2015 16:05 - The Lazy Way to Hack 17:55 - From SQL Read Access to Admin 21:05 - What Attackers Want After Getting In 23:40 - Asset Inventory Is Security Flossing 27:05 - Why AI Is Like Scissors 29:05 - Waymos, Robotaxis, and Physical AI Risk Links Check out our upcoming events: https://www.hackervalley.com/livestreams  Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com  Become a sponsor of the show: https://hackervalley.com/work-with-us/ 
Every AI agent in your environment inherits someone's permissions, and most teams have no idea what those agents are actually doing with them. Amir Ofek, CEO and co-founder of Aizome, shares how to make every agent accountable before the damage shows up as a $150,000 bill. In this episode, Amir explains why human and machine identity tools both fail for AI, why agents act more like eager, naive interns than employees, and how a new category called ARISE (Agentic Runtime Identity Security Enforcement) is emerging to fix it.  This one's for anyone building with AI agents right now (so, most of us). Amir's take: the biggest danger isn't a breach. It's agents quietly doing the wrong thing at scale while nobody's watching. Impactful Moments 00:00 - Introduction 02:30 - Busting the Myth: "I Know What My Agents Are Doing" 05:30 - The Samurai Story Behind Aizome's Name 08:25 - Why Not All AI Agents Are Born Equal 11:15 - Where Enterprises Are Actually Deploying AI Agents Today 14:25 - What Claude Cowork Inherits Without You Realizing It 17:15 - Machine Identity vs. Human Identity vs. AI Identity 19:35 - Treating AI Agents Like Eager, Naive Interns 23:00 - The Biggest AI Risk Isn't Security, It's Cost 25:45 - Meet Ito: Aizome's Supervisor Agent 26:40 - Inside the New ARISE Category 33:35 - What Aizome Actually Does 35:30 - The Callback: Was the Myth Wrong, or Dangerously Wrong? Links Connect with Amir Ofek on LinkedIn: https://www.linkedin.com/in/amirofek/ Learn more about Aizome: https://www.aizome.ai/  –  Check out our upcoming events: https://www.hackervalley.com/livestreams  Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com  Become a sponsor of the show: https://hackervalley.com/work-with-us/ 
Cybersecurity has survived cloud, mobile, and a dozen other "biggest disruptions of our lifetime," and each one felt unprecedented in the moment. In this episode, Ron sits down with Alyssa "Dr. Jay" Abdullah, Deputy CISO at MasterCard, who started her career as a radio DJ and has since worked inside the White House, Lockheed Martin, Stryker, and Xerox before landing in payments security. Ron and Dr. Jay trace her path from spinning records to securing global payment infrastructure, and dig into why she'd argue cloud, not AI, was the real turning point in her career. They cover what convergence actually looks like when AI, cloud, and synthetic identity start overlapping, why curiosity matters more than fast answers, and what it means when employees start bringing their own trained AI agents to work. The conversation closes on something most teams haven't fully reckoned with yet: AI agents that carry their own identity, independent of the humans who built them, and what that shift demands from the people responsible for securing them. Impactful Moments 00:00 - Introduction 02:25 - Busting the AI hype myth 04:40 - From radio DJ to Dr. Jay 06:10 - A day in the life as Deputy CISO at Mastercard 07:25 - Why AI hasn't disrupted her world 08:50 - White House tech through the decades 12:30 - Smartphones, wearables, and what's next 13:30 - Defining convergence for 2026 14:50 - When AI meets quantum computing 17:20 - Bring your own AI agent to work 19:00 - Negotiating salary in tokens 21:05 - Teaching curiosity over answers 23:50 - Overhype equals overtrust 27:10 - The future of tier one and autonomous SOC 29:50 - Hot take: AI in the SOC 31:35 - Predictions: AI identities and the human outside the loop Links Connect with Alissa "Dr. Jay" Abdullah on LinkedIn: https://www.linkedin.com/in/dralissajay/  –  Check out our upcoming events: https://www.hackervalley.com/livestreams    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com    Become a sponsor of the show: https://hackervalley.com/work-with-us/ 
loading
Comments