594 episodes
- Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
AI is changing cybersecurity, but simply using more AI to defend against AI attacks may not be the answer.
David Bombal sits down with Danny Jenkins, CEO of ThreatLocker, to discuss the security risks created by AI, autonomous agents, zero-day vulnerabilities, ransomware, and the rapidly expanding attack surface businesses now have to deal with.
Danny explains one of the fundamental problems with AI security: AI can understand what something does, but it may not understand the intent behind it. The same action could be performed legitimately by an administrator or maliciously by an attacker.
They also discuss how AI is giving attackers capabilities that previously required significantly more expertise and resources, including vulnerability discovery and
sophisticated phishing attacks.
But AI creates another problem inside organizations. Autonomous agents can potentially access files, upload data, perform actions, and make mistakes extremely quickly. Every new piece of software adds attack surface, and powerful AI agents can dramatically increase that risk. Danny argues that the answer isn't simply AI versus AI.
Instead, organizations need to rethink trust itself.
The discussion covers deny by default, application control, restricting what software and AI agents are allowed to access, and why AI should be used as an additional
security layer rather than becoming your primary defense.
Topics include:
• AI security risks
• Autonomous and agentic AI
• Why AI struggles with intent
• How hackers are using AI
• AI-powered vulnerability discovery
• Zero-day vulnerabilities
• Ransomware
• AI attack surfaces
• Application control
• Deny by default security
• Why AI alone can't solve AI security
• Securing AI inside businesses
// Danny Jenkins’ SOCIAL //
LinkedIn: / dannyjenkinscyber
// ThreatLocker’s SOCIAL //
LinkedIn: https://www.linkedin.com/company/thre...
X: https://x.com/threatlocker
Instagram: / threatlocker
Website: https://www.threatlocker.com/
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming Up
0:34 - Introduction
0:46 - Why Businesses Are Afraid of AI
02:17 - AI Can Be Used for Good or Bad
03:29 - The Race to Adopt AI
05:02 - AI Gives Attackers Nation-State Capabilities
06:09 - Why AI Can't Be Your Primary Defense
07:59 - How AI Is Expanding the Attack Surface
08:53 - Solving AI Security With Limited Access
11:04 - The Deny-by-Default Security Model
14:12 - AI-Powered Vulnerability Hunting
17:29 - How ThreatLocker Actually Uses AI
20:01 - Why Deny-by-Default Beats Chasing Zero-Days
21:15 - What Cybersecurity Customers Are Most Worried About
22:16 - AI Hype, Jobs & Closing Thoughts
24:55 - ThreatLocker Advert
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#threatlocker #bhusa2026 #blackhat - Note: Hak5 did not pay me to make this video. But, I'm marking it as sponsored because Darren was kind enough to give me some cool Hak5 gadgets. Get your own using my link: https://davidbombal.wiki/gethak5
// Darren Kitchen SOCIAL //
YouTube: https://www.youtube.com/darrenkitchen
Website: https://hak5.org/pages/hack-across-america
X: https://x.com/hak5darren
// Hak5 WEBSITE (affiliate) //
https://davidbombal.wiki/gethak5
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU//
0:00 - Coming up
01:00 - 21 Years of Hak5 // Device overview
05:30 - USB Rubber Ducky
09:22 - Bash Bunny
12:41 - Plunder Bug
13:28 - Shark Jack & Shark Jack Display
16:28 - Packet Squirrel
18:51 - Key Croc
21:51 - Screen Crab
24:07 - Lan Turtle Hub
28:14 - WiFi Pineapple
33:16 - WiFi Pineapple Pager
37:32 - Hak5 books
39:15 - Darren's favourite tools
41:27 - Future projects // Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#hak5 #hackinggadgets #hacktool - Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people.
Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a software quality problem.
For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place.
They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it.
Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders.
Topics include:
Why cybersecurity may be a software quality problem
Why users are blamed for insecure software
CISA’s Secure by Design initiative
Why default passwords should disappear
AI agents behaving in unexpected ways
AI and the future of zero-day attacks
Memory safety, C, C++ and Rust
Government regulation and vendor accountability
The EU Cyber Resilience Act
Why Patch Tuesday may eventually become unacceptable
How AI could help defenders find and fix vulnerabilities
Jen Easterly’s advice for cybersecurity professionals
If you work in cybersecurity, ethical hacking, software development, networking, AI security, or critical infrastructure, this is a conversation you don’t want to miss.
// Jen Easterly’s SOCIAL //
LinkedIn: / jen-easterly
// Website REFERENCE //
https://www.cisa.gov/
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming up
0:55 - Jen Easterly introduction & background
04:20 - Advice for the youth
07:10 - Advice for ethical hackers and leadership
11:35 - Software security // Who's to blame?
17:39 - Power and responsibility
21:17 - Secure by design
26:38 - Is it important to attend RSAC? // Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#rsac #bhusa2026 #securebydesign - Big thanks to Proton VPN for sponsoring this video. To sign up for Proton VPN please use the following link https://protonvpn.com/davidbombal and get 70% off.
Learn how fake cell towers and Stingray-style devices can be used to track phones, capture metadata, and monitor cellular activity.
OTW joins David Bombal to demonstrate how SDR tools such as HackRF, RTL-SDR, DragonOS, and Falcon can be used to scan nearby cell towers and investigate suspicious signals. They look at how 4G and 5G networks work, why mobile networks still expose valuable metadata, how IMSI catchers operate, and what suspicious or rogue cell towers may look like.
They also discuss SS7 vulnerabilities, mobile network attacks, Signal, GrapheneOS, and practical steps you can take to better protect your communications.
Topics covered:
How to scan for nearby cell towers
How fake cell towers and Stingrays work
Detecting suspicious cell towers with SDR
HackRF and RTL-SDR
DragonOS and Falcon
IMSI catchers and phone tracking
4G and 5G security
SS7 vulnerabilities
Mobile phone metadata
Signal and GrapheneOS
Mobile network security
// Occupy The Web SOCIAL //
X: / three_cube
Website: https://hackers-arise.net/
// Occupy The Web Books //
Linux Basics for Hackers 2nd Ed
US: https://amzn.to/3TscpxY
UK: https://amzn.to/45XaF7j
Linux Basics for Hackers:
US: https://amzn.to/3wqukgC
UK: https://amzn.to/43PHFev
Getting Started Becoming a Master Hacker
US: https://amzn.to/4bmGqX2
UK: https://amzn.to/43JG2iA
Network Basics for hackers:
US: https://amzn.to/3yeYVyb
UK: https://amzn.to/4aInbGK
// OTW Discount //
Use the code BOMBAL to get a 20% discount off anything from OTW's website: https://hackers-arise.net/
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming up
0:37 - Mobile system vulnerability explained
12:29 - Proton VPN sponsor segment
15:07 - How to search cell towers in your area // CellSearch demo
19:45 - Cell tower frequencies explained
22:19 - CellSearch demo continued
32:41 - Discovering the identifiers
37:42 - Scanning for Stingrays/rogue cell towers // CellSearch demo continued
44:00 - Ordinary people being victims of WiFi hacking
47:28 - Authentication bypass on IoT devices
49:01 - Scanning higher frequencies with CellSearch
52:06 - Falcon demo // Discovering cellphones connecting to a cell tower
57:46 - Recommended protection from traffic interception
01:01:38 - Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#stingray #celltower #sdrhacking - Hackers are using overlooked IoT devices such as IP cameras, printers and smart speakers to gain access to networks and spread ransomware.
Philip Wylie explains how an outdated IP camera became a ransomware gateway, why default passwords and poor segmentation remain serious risks, and how to protect your network using separate VLANs, firmware updates, monitoring and zero-trust controls. The interview also explores medical devices, OT security, AI-enabled devices and the growing demand for IoT penetration-testing skills.
Big thanks to ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
// Philip Wylie’s SOCIAL //
X: https://x.com/phillipwylie
LinkedIn: / phillipwylie
YouTube: / @phillipwylie
Instagram: / phillipwylie
// Book REFERENCE //
The Pentester Blueprint Phillip Wylie:
US: https://amzn.to/4jkigAa
UK: https://amzn.to/42vShPB
// YouTube video REFERENCE //
Pentester Blueprint: Your Road to Success: • Pentester Blueprint: Your road to success
How to hack IP Cameras (Ethically) and learn IoT hacking: • How to hack IP Cameras (Ethically) and lea...
// Website REFERENCE //
https://training.brownfinesecurity.com/
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming Up
0:56 - Intro
03:08 - The Weakness in Pen-testing
07:38 - How Do Hackers Get Access?
11:30 - How To Protect IoT Devices
14:36 - Dangers of Medical IoT Devices
18:24 - Countries Banning IoT Devices
20:46 - Phillip's Recommendations
22:42 - What is Exploit DB
27:30 - How Vulnerable Are You?
28:28 - Advice To The Youth
29:40 - How To Start Learning
31:15 - Conclusion
31:23 - Threatlocker Advert
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#iot #iothacking #security
More Technology podcasts
Trending Technology podcasts
About David Bombal
Want to learn about IT? Want to get ahead in your career? Well, this is the right place!
On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics.
This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content.
David’s details:
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
Website: http://www.davidbombal.com
YouTube: https://www.youtube.com/davidbombal
All the best!
David
Podcast websiteListen to David Bombal, Acquired and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


David Bombal
Scan code,
download the app,
start listening.
download the app,
start listening.






























