• 34 minutes 52 seconds
    Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

    Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigation platform from scratch.

    John's system runs on more than 30 specialized agents that reason through cases instead of following a script. In one run, that meant over 140 detections investigated in under four hours at an 80 to 85% quality rating. Ron and John dig into the hard lesson that made John rip out his own tooling and rebuild it around function calling, why "humans first" drives every decision his team makes, and whether AI SOC is actually different from SOAR or just the same promise with way better marketing.

    Underneath all of it is the one thing John says decides whether any of this actually works: context. Give the AI too little and it's guessing, give it too much and it drowns just like a human would. Listen to find out what it actually takes to build an AI SOC that reasons instead of just automates.

    Impactful Moments

    00:00 - Introduction
    02:05 - The rewind: how SOAR promised to save the SOC in 2015
    03:35 - Meet John Gillis, Adobe's Staff AI Security Engineer
    05:30 - What cybersecurity looked like before AI at enterprise scale
    07:00 - The "humans first" strategy behind Adobe's AI investigator
    09:30 - Why careless context management is the biggest pitfall in agent design
    14:45 - Solving the speed problem: is it tooling, process, or people?
    17:10 - From monolith to microservices: rebuilding the platform for scale
    24:05 - What actually makes an AI agent's "persona" work
    26:00 - John's prediction for the SOC three years from now
    28:50 - The three skills every security practitioner needs for 2026
    32:10 - Final verdict: is AI SOC really different, or SOAR with new branding?

    Links

    Connect with John Gillis on LinkedIn: https://www.linkedin.com/in/john-gillis/

    If you're a researcher ready to make an impact, check out the announcement about Adobe’s new home for the Adobe Bug Bounty Program here: https://blog.adobe.com/security/a-new-home-for-the-adobe-bug-bounty-program

    Check out Adobe’s Bug Bounty profile on Intigriti: https://app.intigriti.com/programs/adobe/adobepublic/detail

    Learn more about Adobe: https://www.adobe.com/

    – 

    Check out our upcoming events: https://www.hackervalley.com/livestreams


    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com

    Become a sponsor of the show: https://hackervalley.com/work-with-us/

    19 August 2026, 3:39 pm
  • 23 minutes 57 seconds
    Let AI Do More Without Surrendering Your Judgment with Jen Easterly

    Fresh off the showroom floor at Black Hat 2026, Ron brings back some hot takes from the crowd. Nearly every booth he visited, including the Exaforce booth, was pushing in the same direction. Trust in AI isn’t a philosophy debate anymore, it’s an engineering problem people are actively solving. 

     

    Ron then catches up with Jen Easterly, CEO of RSAC, for a wide-ranging conversation on what it actually takes to build that trust. From her move out of government to her hard line on AI regulation and liability, the conversation takes an unexpected turn when Jen opens up about "cognitive surrender" and why she believes good judgment can't be automated away. Couldn't make it to Black Hat this year? This episode has you covered.

     

    Impactful Moments 

    00:00 - Introduction 

    02:45 - Reporting live from Black Hat 2026: hot takes from the showroom floor 

    05:05 - Welcoming Jen Easterly, CEO of RSAC

    07:55 - A day in the life running RSAC and the Innovation Sandbox

    10:00 - AI whack-a-mole and the sweet spot for regulation

    11:00 - Governance vs. regulation, the EU AI Act, and state laws

    13:30 - Why accountability and liability need to catch up to AI makers

    14:45 - The case for autonomous patching and healing code like "The Matrix"

    17:50 - The hot take Jen hasn't said before: not outsourcing our humanity

    20:30 - Why in-person conferences matter more in the AI era

    21:55 - Ron's takeaway: who decides when AI has earned our trust?

     

    Links

    Connect with Jen Easterly on LinkedIn: https://www.linkedin.com/in/jen-easterly 

    Learn more about Exaforce: https://www.exaforce.com

    – 

    Check out our upcoming events: https://www.hackervalley.com/livestreams 

    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com 

    Become a sponsor of the show: https://hackervalley.com/work-with-us

    14 August 2026, 6:26 pm
  • 30 minutes 55 seconds
    Post-Quantum Cryptography: What Every Organization Needs to Know with Michael Fasulo

    What if the encrypted traffic flowing across the internet right now (emails, files, logins) is already being quietly collected and stored by someone waiting for the day they can finally crack it open? That's the threat behind "harvest now, decrypt later," and it's closer than most people think.


    Ron Eddings sits down with Michael Fasulo, Senior Director of Portfolio Marketing at Commvault, to talk about where post-quantum cryptography (PQC) really stands in 2026. They discuss "harvest now, decrypt later," the specific industries quietly racing to prepare, and why a commercially viable quantum machine might only be four years away. 


    Ron and Michael trace the journey from a 1998 hack to today's quantum race, and the good news is there's still time to get ahead of it. Listen to hear where the real opportunity is, and how to start building your defense today.


    Impactful Moments
    00:00 - Introduction
    01:40 - Rewind: the 1998 Deep Crack story
    04:10 - Michael Fasulo and the current state of post-quantum cryptography in 2026
    05:05 - Harvest now, decrypt later: do people really have the storage to do this?
    06:10 - Where is this actually happening? Nation-states vs. coffee shops
    08:50 - Who the real targets are: government, financial services, oil and gas
    10:05 - Are everyday SaaS tools like Zoom and Gmail implicated?
    12:25 - How Commvault helps organizations inventory their crypto footprint
    17:00 - Trust, vendor partnerships, and the Commvault / Microsoft Sentinel integration
    18:30 - Signs that a commercial quantum machine may be closer than we think
    24:45 - Are we already behind? What to do starting next week
    28:20 - Deep Crack revisited 

    Links


    Connect with Michael Fasulo on LinkedIn: https://www.linkedin.com/in/michael-fasulo 


    Learn more about Commvault: https://www.commvault.com 


    – 
    Check out our upcoming events: https://www.hackervalley.com/livestreams 


    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com


    Become a sponsor of the show: https://hackervalley.com/work-with-us/ 

    12 August 2026, 2:57 pm
  • 38 minutes 27 seconds
    Stop Defending the Edge: How to Rethink Your Mobile Security with Jared Shepard

    What if the biggest risk to your organization isn't the device that gets lost, but the data that lives on it? Ron Eddings sits down with Jared Shepard, Founder and CEO of Hypori, whose path ran from homeless high school dropout to Army infantry to building a company that rethinks mobile security from the ground up.


    Jared makes the case for something more radical than most vendors will admit: stop defending the edge device entirely, and make sure sensitive data never lands there in the first place. He and Ron cover MDM and MAM's blind spots, executive protection, and the shadow AI habits quietly becoming every security leader's next headache.


    The episode also lands at a tense moment for the defense industrial base with the Pentagon having just paused third party CMMC assessments, now putting the burden of proof back on self attestation. If you're still trusting the edge device to protect you, this episode is your wake up call.

    Impactful Moments 

    00:00 - Introduction 
    02:00 - Hack The Headlines: Top new from around the industry
    07:30 - Meet Jared Shepard, founder and CEO of Hypori 
    10:00 - What Hypori does and how it started 
    15:40 - MDM vs. MAM: why both miss the real problem 
    18:45 - Shadow AI and the security habits practitioners can't ignore 
    20:30 - Collapsing the attack surface and bringing back BYOD (Bring Your Own Device) 
    22:40 - The 4-gigabit-speed "parlor trick" that proves the Cloud beats your device
    25:20 - What the 60-day CMMC pause really changes (and what it doesn't)
    29:20 - China, stolen tech, and the rise of AI models like Mythos 
    36:00 - Closing the loop on the CMMC pause 

     

    Links 
    Connect with Jared Shepard on LinkedIn: https://www.linkedin.com/in/shepardj 

    Learn more about Hypori: https://hypori.com 


    – 


    Check out our upcoming events: https://www.hackervalley.com/livestreams

    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com

    Become a sponsor of the show: https://hackervalley.com/work-with-us/  

    7 August 2026, 3:24 pm
  • 34 minutes 41 seconds
    Inside Conti: The Ransomware Gang That Ran Like a Company with Geoff White

    What does the world's most prolific cybercrime operation look like from the inside? And why does it operate suspiciously like a mid-sized tech company, complete with HR headaches, salary negotiations, and a distracted boss nobody respects?

    Ron Eddings sits down with investigative journalist and author, Geoff White, who has spent over 20 years covering cybercrime for the BBC, Channel 4 News, and Sky News. Geoff has read 47,000 of Conti’s 300,000 leaked internal chats, the gang that dominated the ransomware world in 2021 and 2022, pulling in hundreds of millions of dollars in ransoms. From the Moscow movie studio the gang's leader used to launder money years previously, to the Ukraine war leak that brought the whole Conti empire down, this one plays like true crime… because it is.

    Geoff makes the case that defenders should think the same way: you're not buying security tools to fend off a hoodie in a basement, you're investing to outcompete a rival business. For anyone trying to integrate a better incident response plan, this episode reframes the whole conversation.

    Impactful Moments
    00:00 - Introduction
    01:45 - The Rewind: Colonial Pipeline and the week the East Coast ran dry
    03:50 - How Geoff went from tech news to cybercrime reporting
    05:10 - The difference between threat groups, APTs, and crime gangs
    07:25 - Inside the Conti leaks: 300,000 messages
    08:55 - Meet the gang: Stern, Mango, and Target
    13:20 - Stern's origin story: Zeus malware, money mules, and the 25th Floor front company
    16:50 - Ransomware gangs vs. the mafia: where's the protection?
    18:10 - The money: $2.5M single payouts and 400 years of wages
    19:30 - The Conti member arrested on a layover in Miami
    20:35 - The downfall: the Ukraine war and the leak that ended it all
    23:05 - What businesses can learn from Conti: recruitment, retention, reputation
    27:45 - Advice for defenders: response waves, segmentation, and negotiating down
    31:05 - Ron's takeaway: belonging and the thin line between operator and criminal

     

    Links

    Connect with Geoff White on LinkedIn: https://www.linkedin.com/in/geoffwhitetech/

    Get your own copy of Geoff's books (Crime Dot Com, The Lazarus Heist, Rinsed): https://geoffwhite.tech/book/

    Want more information on Conti? Check out Geoff’s BBC podcast series, Cyber Hack: The Conti Files, available on BBC Sounds, Spotify, and Apple Podcasts

    Check out our upcoming events: https://www.hackervalley.com/livestreams 

    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com 

    Become a sponsor of the show: https://hackervalley.com/work-with-us/

    28 July 2026, 1:00 pm
  • 35 minutes 58 seconds
    What AI Agents Should Own in Your SOC, And What Happens If You Wait with Tim Leehealey

    What happens when the adversary moves at machine speed, and your SOC is still responding at human speed? Why does nearly every security team say AI should handle L1 work, while 64% of organizations still have zero agents in production? And how long until the "coworker" resolving your ticket in Slack turns out not to be human at all?

    Tim Leehealey, VP of Strategy and Operations at Strike 48, joins us this week to talk about what it actually takes to get AI agents out of the demo and into production. Tim agenticized his own company's IT, watched it blow up, and came out the other side with lessons from Fortune 100 SOCs running agents at serious scale. 

    He shares where AI actually belongs in the alert pipeline, the objections holding teams back, and a blunt warning for any leader still waiting on the sidelines in 2027. If AI in the SOC is on your roadmap before the end of this year, start here.

     

    Impactful Moments

    00:00 - Introduction
    01:55 - Busting a myth: AI will replace analysts
    04:45 - Introducing Tim Leehealey 
    05:30 - The Strike48 survey: 84% say hand L1 to AI
    08:00 - Fear the low-and-slow attacker, not the loud one
    13:00 - Getting breached without agents in 2027
    15:00 - When Tim's own rollout blew up
    19:00 - Micro agents inside deterministic workflows
    21:25 - Skills advice for L1 analysts
    26:00 - The next 18 months of agentic adoption
    28:00 - Jim Bob in your Slack is an agent
    21:30 - Ron's take: transparency is the trust unlock

    Links

    Connect with Tim Leehealey on LinkedIn: https://www.linkedin.com/in/tim-leehealey-b8b04321 

    Learn more about Strike48: https://strike48.com

    Check out the 2026 State of Agentic Security report here: https://hubs.ly/Q04p49S20

    Go deeper on Strike 48's technology: https://labs.strike48.com

    – 

    Check out our upcoming events: https://www.hackervalley.com/livestreams 

    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com 

    Become a sponsor of the show: https://hackervalley.com/work-with-us/

    21 July 2026, 2:00 pm
  • 30 minutes 36 seconds
    We Shipped a Tool That Acts Like You. Meet Interceptor.

    Think about everything you could accomplish if you don’t have to be the one driving your browser. In this solo episode, Ron Eddings introduces Interceptor, Hacker Valley Media's first piece of software. 

    Interceptor is an open-source Chrome extension that lets an AI agent drive your real browser, logged-in sessions and all, with no vendor lock-in. Ron shares how it works and describes the use cases that matter most to security practitioners: OSINT and recon, bug bounty operations, prompt-injection testing, and threat-intelligence automation.

    Ron also puts himself in the hot seat, answering the hardest questions he's gotten about the tool, including why anyone should trust an open-source tool from a podcast company over a polished product from a billion-dollar AI lab. The delegation is coming, and we would rather the security community be the ones who understand it.


    Impactful Moments: 
    00:00 - Introduction
    02:35 - The Rewind: Same Origin Policy and the Web's Foundation
    04:40 - Rapid-fire facts: AI agents got hands, and attacks followed
    07:00 - What is Interceptor and why was it built? 
    10:20 - How Interceptor works: stealth, network visibility, teach and replay
    13:10 - Live use-case: dynamic dashboard without writing code
    17:05 - Cybersecurity use-cases: OSINT, bug bounty, prompt injection testing
    21:50 - Ron answers the hard questions about Interceptor
    24:10 - Why trust an open source tool from a podcast company? 
    25:20 - What a practitioner can do tomorrow 
    27:30 - Closing reflection: knocking down the vendor lock-in wall

     

    Links 

    Download Interceptor on GitHub: https://github.com/hackervalleymedia/interceptor

    Connect with Ron on LinkedIn: https://www.linkedin.com/in/ronaldeddings/ 

    – 

    Check out our upcoming events: https://www.hackervalley.com/livestreams

    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com

    Become a sponsor of the show: https://hackervalley.com/work-with-us/

    14 July 2026, 3:32 pm
  • 30 minutes 51 seconds
    How to Turn Cybersecurity Customers into Lifelong Advocates with Antu Buck

    What if the same psychology that threat actors use to manipulate their targets is the same psychology that marketers use to earn your trust? 


    In this episode, Ron sits down with Antu Buck, Senior Director of Customer Marketing & Community at Gigamon, who spent two decades building trust between vendors and the practitioners who use their tools. 


    Antu walks us through the three pillars she's built her career around, and makes the case that advocacy shouldn't be an afterthought, but the very first marketing move a company invests in. The conversation lands on something the community doesn't talk about enough: customer marketing is hard to put a number on, so it consistently loses the budget fight to demand gen. 


    Impactful Moments
    00:00 - Introduction
    02:15 - Myth Buster: "I don't fall for marketing tactics"
    04:15 - Meet Antu Buck, Senior Director of Customer Marketing & Community at Gigamon
    06:45 - From cold-calling BDR to customer marketing leader
    09:40 - Antu’s three pillars: advocacy, community, lifecycle management
    13:05 - Why customer advocacy is the most underrated pillar
    14:40 - The problem with chasing the CISO
    16:40 - From transactional selling to relationship building
    17:20 - The cold call that became a lifelong champion
    20:20 - Are threat actors borrowing tactics from sales and marketing?
    23:00 - Why AI tools are off-limits with customer data
    27:50 - Why customer marketing loses the budget fight


    Links


    Antu Buck on LinkedIn: https://www.linkedin.com/in/antu-buck/


    – 

    Check out our upcoming events: https://www.hackervalley.com/livestreams


    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com


    Become a sponsor of the show: https://hackervalley.com/work-with-us/

    7 July 2026, 2:06 pm
  • 31 minutes 34 seconds
    What's Really Stopping AI From Running Your SOC with Aqsa Taylor

    In 2025, out of all 70+ guests we had on our show, not one of them said they’d trust AI to run their SOC. Now in 2026, that mindset is shifting. In this episode, Ron sits down with Aqsa Taylor, Chief Security Evangelist at Exaforce, to find out what changed, and what's still standing in the way of security teams being able to trust AI agents with response. 


    The conversation covers what's really behind the agentic SOC hype, why "vibe hunting" might be the most fun phrase in cybersecurity right now, and how teams can build enough confidence to hand over the keys to detection, investigation, and response. 


    Aqsa also gets into the one thing she believes has to come before any of it works: the data. Without the right context feeding your AI you’re just getting confident guesses dressed up as answers. Listen to find out if your team is ready to take the leap into an agentic SOC. 


    Impactful Moments
    00:00 - Introduction 
    02:05 - Hack the headlines, June top trends in cybersecurity 
    05:30 - Welcoming Aqsa Taylor from Exaforce
    06:15 - Inside Exaforce's $125M raise 
    08:50 - Redefining what AI SOC should mean 
    09:30 - The evolution from manual playbooks to AI-driven autonomy 
    13:40 - Where Exaforce fits in an existing stack 
    18:10 - What vibe hunting looks like in practice 
    19:40 - The challenges of securing sensitive data in a world dominated by SaaS platforms
    22:00 - How to build your trust ladder for AI in the SOC 
    24:40 - Best use case to get started with AI SOC 
    28:50 - Ron's takeaway: the data has to be there first


    Links

    Connect with Aqsa Taylor on LinkedIn: https://www.linkedin.com/in/aqsa-taylor 


    Learn more about Exaforce: https://www.exaforce.com


    Join Exaforce’s Force Multiplier Substack community: https://theforcemultiplier.substack.com 


    – 


    Check out our upcoming events: https://www.hackervalley.com/livestreams 


    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com 


    Become a sponsor of the show: https://hackervalley.com/work-with-us/ 

    23 June 2026, 4:28 pm
  • 28 minutes 59 seconds
    Feed Your Brain: What Cybersecurity Veterans Are Getting Wrong with Johnny Xmas

    Is AI really coming for your red teaming job? What does it actually take to build a team that thinks like the adversary, and what happens when that team stops caring? And what do you do when you've been in this field long enough that the job that once fired you up has started to feel hollow?

    In this episode, Ron catches up with Johnny Xmas, Head of Offensive Security at a Fortune 150 Global Food Manufacturer, and one of the most candid voices in offensive security, for a conversation that covers a lot of ground fast. 

    They go deep on where AI actually fits into offensive security workflows, what Johnny really looks for when building elite teams, and why the career advice everyone gives early practitioners might be setting them up for burnout down the road. The conversation takes a turn that doesn't come up enough in this industry, and it's the part you won't want to miss. If you've ever felt your tank running low, this episode was made for you.

    Impactful Moments
    00:00 - Introduction
    02:10 - Busting the myth: AI is not replacing red teamers
    04:30 - Guest introduction: Johnny Xmas
    06:15 - How the offensive security job has changed with AI 
    09:35 - The SEC 8-K IoC parser tool Johnny just published
    11:40 - Building elite teams: what skills Johnny actually hires for
    12:45 - Soft skills over technical gaps, and why the fire has to come with you
    15:40 - Why "where do you see yourself in five years?" is a garbage question
    17:30 - Has Johnny ever crossed the line when it comes to hacking? 
    20:20 - What to do when you've stopped caring about the job
    26:25 - Outro: The AI myth, revisited

    Links

    Johnny Christmas on LinkedIn: https://www.linkedin.com/in/johnnyxmas/

    Johnny's SEC 8-K IoC parser tool: https://github.com/johnnyxmas/its-over-8k 

    Check out our upcoming events: https://www.hackervalley.com/livestreams 

    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com 

    Become a sponsor of the show: https://hackervalley.com/work-with-us/

    16 June 2026, 3:00 pm
  • 25 minutes 1 second
    Fighting Smarter: What Combat Sports Teaches Us About Cyber Defense with Robin Black

    What does a calf kick have to do with vulnerability management? What can a fighter's mindset teach a security practitioner about operating against an adversary they've never faced? 


    Ron Eddings brings back fan-favorite combat sports analyst and commentator Robin Black for a conversation that was never meant to be about cybersecurity, and ends up being one of the most insightful episodes on the human side of the field. They dig into how underdogs actually win (hint: we're usually wrong about who the underdog is), what it really means to maintain control in a fight, and why the highest level of mastery might actually look like letting go of control entirely. 


    The conversation closes with a look at how the cybersecurity landscape is mutating alongside AI, and whether an arms race that trains itself is heading somewhere catastrophic, or whether it's simply the next evolution of the fight. The answer, like most things in this episode, is more nuanced than you'd expect.

     

    Impactful Moments
    00:00 - Introduction
    02:10 - The Rewind: The Calf Kick and the Peroneal Nerve
    04:05 - Welcome back, Robin Black
    05:30 - Can smaller still beat bigger?
    07:00 - Why underdogs don't win (And why we were wrong)
    08:25 - Fighting is about exploiting belief systems
    09:30 - Maintaining control against an unknown adversary
    10:25 - Adapting vs. anticipating: be water
    13:00 - Failure is mandatory
    17:25 - How Robin’s thoughts have changed about being attacked online
    19:00 - AI and the mutating threat landscape
    22:15 - Ron's closing thoughts

     

    Links
    Connect with Robin Black on LinkedIn: https://www.linkedin.com/in/robin-black-31b6bb39/  


    Check out Robin Black on YouTube: https://www.youtube.com/RobinBlack  


    – 


    Check out our upcoming events: https://www.hackervalley.com/livestreams  


    Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com  


    Become a sponsor of the show: https://hackervalley.com/work-with-us/ 

    9 June 2026, 2:00 pm
  • More Episodes? Get the App