Skip to content
PodcastsTechnologyDavid Bombal

David Bombal

David Bombal
David Bombal
Latest episode

607 episodes

  • David Bombal

    #611: Building AI Agents? Set Up These Guardrails First

    01/10/2026 | 22 mins.
    Big thanks to ‪@Cisco‬ & ‪@Splunkofficial‬ for sponsoring my trip to .Conf 2026 and also for sponsoring this video.

    AI agents can do things you never intended. So how do you monitor their behavior, spot security problems and decide what they should be allowed to do? I’m joined by Splunk’s Kamal Hathi at .conf26 to discuss AI agent security, observability and what an agentic SOC means for the people working in cybersecurity.

    Kamal explains why setting a goal isn’t enough. You need visibility into what your agents are actually doing, clear guardrails and human oversight for important decisions. We also discuss why monitoring only a sample of agent activity can leave gaps, and how focused small language models could help reduce evaluation costs.

    In this interview, we cover:
    • Known agents, unregistered agents and unexpected behavior
    • AI evaluations, guardrails and zero trust
    • Automating SOC alert triage while keeping humans in control
    • Using AI to create SOAR playbooks
    • Running models locally for privacy, cost and control
    • Choosing between local models and cloud models
    • Whether you should still study computer science in 2027
    If you’re building AI agents, working in cybersecurity or deciding what to learn next, this conversation will give you plenty to think about.

    // Kamal Hathi’s’ SOCIAL //
    LinkedIn: / kamal-hathi

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming Up
    0:43 - Intro
    02:25 - Security Against AI
    06:26 - Collecting Data on your AI
    08:33 - AI Hallucinations
    10:48 - Is Life Like Sci-Fi?
    14:09 - Will AI Replace You?
    17:16 - Not Giving Your Information to AI
    18:50 - Kamal's Prediction for the Future of AI
    20:20 - Final Thoughts
    21:29 - What Should you Study in 2027?
    22:00 - Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #SplunkConf26 #Splunk #Cisco
  • David Bombal

    #610: WiFi Pineapple Pager: What Can It Actually Do?

    01/10/2026 | 22 mins.
    Big thank you to proton VPN for sponsoring the video. To get 70% off your Proton VPN subscription use the following link: https://protonvpn.com/davidbombal

    Note: Hak5 did not pay me to make this video. But, for full transparency: Darren was kind enough to give me some cool Hak5 gadgets. Get your own using my link below.

    // Buy Hak5 coolness here (Affiliate Link): //
    Buy Hak5: https://davidbombal.wiki/gethak5

    WiFi hacking without opening your laptop? ‪@DarrenKitchen‬ from ‪@hak5‬ joins me to talk about the WiFi Pineapple Pager and what this little Linux device can actually do.

    Darren shares the story behind the Pager, explains its support for 2.4, 5, and 6 GHz WiFi, and walks us through features including wireless reconnaissance, eventtriggered alerts, and community-created payloads. We also discuss how Bash and DuckyScript helpers let users build their own functionality, and how Pager Portal makes it possible to download payloads directly onto the device.

    How does it compare with the WiFi Pineapple Mark VII and Enterprise? We look at the different use cases, from portable testing to remotely auditing a client’s wireless network.

    And yes, someone has already made it run Doom.

    This is an interview and feature overview with the creator, covering the ideas, technology, and community behind the WiFi Pineapple Pager.

    // Darren Kitchen SOCIAL //
    YouTube: / darrenkitchen
    Website: https://hak5.org/pages/hack-across-am...
    X: https://x.com/hak5darren

    // Hak5 WEBSITE //
    https://shop.hak5.org/

    // Previous YouTube video with Darren REFERENCE //
    Hacking Gadgets Every Cybersecurity Pro should know: • Hacking Gadgets Every Cybersecurity Pro Sh...

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU//
    0:00 - Intro
    0:35 - Coolest hacking tool // Hak5 WiFi Pineapple Pager
    03:10 - Proton VPN sponsor segment
    05:28 - History of the WiFi Pineapple
    08:53 - WiFi Pineapple Pager overview
    12:17 - The community
    15:55 - Easy to get started
    16:50 - WiFi Pineapple Mk7
    18:53 - WiFi Pineapple Enterprise
    21:23 - Supported WiFi frequencies
    22:43 - Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #wifipineapplepager #wifi #hackinggadgets
  • David Bombal

    #609: How Hackers Target Satellites Through Ground Control Systems

    01/10/2026 | 39 mins.
    Big thanks to DeleteMe for sponsoring this video. Protect your business with DeleteMe by using the following Link: https://joindeleteme.com/bombal-biz You’ll also get a free year of social media protection for every seat you purchase.

    How do you hack a satellite? The attack can start on the ground. Watch a mission control demo showing how web vulnerabilities can change a simulated spacecraft’s orbit.

    At DEF CON, I meet Milenko and Andrzej, the authors of The Spacecraft Hackers Handbook, to explore spacecraft cybersecurity. They explain the infrastructure behind satellite operations, what the Via sat attack actually targeted, and why protecting spacecraft requires both security and space engineering knowledge. Then Andrzej demonstrates previously patched vulnerabilities in an older version of mission control software. Using Burp Suite, he shows how path traversal exposes configuration files and how cross-site scripting can trigger a spacecraft command through an operator’s browser.

    We cover:
    • Why satellite security extends to systems on the ground
    • How path traversal and XSS affect mission control software
    • Telemetry, telecommands, CCSDS and the SDLS security layer
    • How GPS supports timing as well as navigation
    • Python examples, a prepared lab VM and learning resources
    • The authors’ nine satellite cybersecurity challenges on Hack The Box
    • Skills and career opportunities in spacecraft cybersecurity

    The demonstration uses a spacecraft simulator. The vulnerabilities shown were disclosed to the vendor and patched.

    // Link to No Starch Website for Milenko and Andrzej’s Book//
    The Spacecraft Hacker’s Handbook: https://nostarch.com/spacecraft-hacke...
    Use Coupon Code SPACE25 for 25% off The Spacecraft Hacker’s Handbook.

    // Milenko Starcik’s SOCIALS //
    Website: https://visionspace.com/team/milenko-...
    Website 2: https://starcik.space/

    // Andrzej Olchawa’s SOCIALS //
    Website: https://visionspace.com/author/a-olch...
    Website 2: https://andy.codes/
    X: https://x.com/0x4ndy

    // Online Resources //
    https://spacesecurity.club
    https://github.com/orgs/spacecrafthac...

    // Blog Post REFERENCE //
    https://www.hackthebox.com/blog/hack-...

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Intro
    0:52 - How Russia hacked satellites
    02:12 - The Spacecraft Hacker's Handbook
    03:23 - VisionSpace
    04:04 - DeleteMe sponsor segment
    05:29 - Growth in satellites launched
    06:28 - What would losing satellites mean
    07:12 - Protocols explained
    08:00 - Misconceptions of satellite hacking
    09:28 - Threat level of satellite hacking
    10:39 - Upcoming demo explained
    12:20 - Who is the book for?
    16:46 - A gap
    17:48 - Other recommendations
    19:49 - Hacking satellite demo overview
    20:34 - Hacking satellite demo walkthrough
    33:54 - Demo next steps
    34:29 - Demo walkthrough continued
    38:51 - Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #sattelitehacking #spacecraftcybersecurity #defcon
  • David Bombal

    #608: Before You Deploy AI Agents, Understand These Attacks

    19/09/2026 | 52 mins.
    Big thanks to Proton VPN for sponsoring this video. You can use my link: https://protonvpn.com/davidbombal to get 70% off your Proton VPN subscription

    How do you hack an AI system? And what happens when one malicious instruction spreads between AI agents?

    I’m joined by Harriet, author of Practical AI Security, to explore how AI models and agents can be manipulated, with practical Python demonstrations. You'll see an image classifier misidentify a rifle, a demonstration of prompt injection spreading across five agents, and how memory poisoning can plant instructions that affect an agent later. We discuss why securing AI takes more than blocking prompt injection, how machine learning creates different security challenges, and what you need to understand before deploying agents in your organisation.

    Want to learn this yourself? Harriet explains how to get started with her collection of 30+ free Python notebooks, including examples you can explore in Google Colab. We also discuss the skills involved in AI security and how people from different backgrounds can contribute.

    Topics include:
    • Adversarial machine learning and image manipulation
    • Prompt injection and attacks spreading between agents
    • Memory poisoning and model backdoors
    • AI supply chain security
    • Learning AI security with Python
    • AI security careers, training and fundamentals

    // Link to No Starch Website for Harriet Farlow’s Book //
    Order Practical AI Security on No Starch: https://nostarch.com/practical-ai-sec...

    Use Coupon code FARLOW25 for 25% off Practical AI Security

    // HarrietHacks Labs REFERENCE //
    https://labs.harriethacks.com/

    // Harriet Farlow’s AI Security Fundamentals Course REFERENCE //
    https://aisecurityfundamentals.com/

    // Harriet Farlow’s SOCIALS //
    Website: https://harriethacks.com/about/
    LinkedIn: / harriet-farlow-654963b7
    Instagram: / harriethacks

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Intro
    01:05 - Harriet Farlow AI security background
    05:55 - Proton VPN sponsor segment
    08:02 - Practical AI Security book // AI Security
    10:40 - Who's the book for
    11:32 - Harriet's YouTube channel
    12:32 - AI security course
    14:27 - Practical demos
    15:41 - Hacking an AI demo // Learning how AIs work
    22:22 - Hacking an AI summary
    24:40 - Hacking an AI visualizations
    28:48 - AI deceiving another AI
    33:09 - Hacking an AI visualizations continued
    34:07 - Rushing to the AI market
    36:26 - Adversarial patch explained
    38:12 - Vibe coded visuals
    40:27 - More visualization
    44:04 - Growth of interest in AI security
    45:09 - No advanced skills required
    49:40 - Get in contact with Harriet Farlow // Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #aisecurity #aiagents #defcon
  • David Bombal

    #607: How Hackers Steal Your Accounts Even With 2FA Enabled

    19/09/2026 | 31 mins.
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

    Is Microsoft Defender enough to protect your PC? Malware researcher Leo joins me at Black Hat to discuss antivirus, Windows security and how hackers steal your accounts.

    We explore how infostealers target saved passwords and session tokens, why two-factor authentication cannot prevent every account takeover, and how a message from a compromised friend’s account can lead to an infection.

    Leo shares practical starting points for investigating your computer, including Autoruns for startup entries, TCPView for linking connections to applications, and Wireshark for examining network traffic. We also discuss password managers, account recovery planning, Windows telemetry and why switching operating systems does not eliminate security risks.

    In this interview:
    • Microsoft Defender’s strengths and limitations
    • Free tools for investigating suspicious Windows activity
    • How infostealers and initial access brokers operate
    • Stolen session tokens and the limits of 2FA
    • Fake download sites, malicious ads and targeted phishing
    • Preparing recovery options before your accounts are compromised
    • Security and privacy trade-offs across Windows, Linux and macOS

    // Leo’s SOCIAL //
    YouTube: / @pcsecuritychannel
    X: https://x.com/leotday
    Discord: / discord

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming Up
    0:35 - Intro
    0:48 - Leo's Background & How Malware Has Evolved
    03:27 - How to Detect Malware on Your Computer
    05:21 - Best Sysinternals Tools for Malware Analysis
    08:21 - Windows Device Tracking & Privacy Concerns
    10:42 - Would you Recommend Windows in 2026?
    11:59 - Privacy Laws & the Future of Tracking
    12:50 - How Telemetry Helps Catch Cybercriminals
    14:02 - ThreatLocker Sponsor
    15:18 - How Hackers Actually Get Into Systems
    16:42 - How to Protect Yourself From Getting Hacked
    19:12 - Do You Really Need Antivirus?
    21:35 - Security Advice for Home Users
    25:59 - Why Smart People Still Get Hacked
    26:59 - What Happens After Your Credentials Are Stolen
    28:06 - Linux vs Mac vs Windows
    29:40 - Is Windows Really Targeted More by Malware?
    31:18 - Conclusion & Outro

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    #malware #bhusa2026 #microsoftdefender
More Technology podcasts
About David Bombal
Want to learn about IT? Want to get ahead in your career? Well, this is the right place! On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics. This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content. David’s details: Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co Website: http://www.davidbombal.com YouTube: https://www.youtube.com/davidbombal All the best! David
Podcast website

Listen to David Bombal, All-In with Chamath, Jason, Sacks & Friedberg and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features