Ga naar de inhoud

David Bombal

David Bombal
David Bombal
Nieuwste aflevering

594 afleveringen

  • David Bombal

    #598: AI Can’t Understand Intent. That’s a Security Problem

    26-08-2026 | 26 Min.
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

    AI is changing cybersecurity, but simply using more AI to defend against AI attacks may not be the answer.

    David Bombal sits down with Danny Jenkins, CEO of ThreatLocker, to discuss the security risks created by AI, autonomous agents, zero-day vulnerabilities, ransomware, and the rapidly expanding attack surface businesses now have to deal with.

    Danny explains one of the fundamental problems with AI security: AI can understand what something does, but it may not understand the intent behind it. The same action could be performed legitimately by an administrator or maliciously by an attacker.

    They also discuss how AI is giving attackers capabilities that previously required significantly more expertise and resources, including vulnerability discovery and
    sophisticated phishing attacks.

    But AI creates another problem inside organizations. Autonomous agents can potentially access files, upload data, perform actions, and make mistakes extremely quickly. Every new piece of software adds attack surface, and powerful AI agents can dramatically increase that risk. Danny argues that the answer isn't simply AI versus AI.
    Instead, organizations need to rethink trust itself.

    The discussion covers deny by default, application control, restricting what software and AI agents are allowed to access, and why AI should be used as an additional
    security layer rather than becoming your primary defense.

    Topics include:
    • AI security risks
    • Autonomous and agentic AI
    • Why AI struggles with intent
    • How hackers are using AI
    • AI-powered vulnerability discovery
    • Zero-day vulnerabilities
    • Ransomware
    • AI attack surfaces
    • Application control
    • Deny by default security
    • Why AI alone can't solve AI security
    • Securing AI inside businesses

    // Danny Jenkins’ SOCIAL //
    LinkedIn: / dannyjenkinscyber

    // ThreatLocker’s SOCIAL //
    LinkedIn: https://www.linkedin.com/company/thre...
    X: https://x.com/threatlocker
    Instagram: / threatlocker
    Website: https://www.threatlocker.com/

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming Up
    0:34 - Introduction
    0:46 - Why Businesses Are Afraid of AI
    02:17 - AI Can Be Used for Good or Bad
    03:29 - The Race to Adopt AI
    05:02 - AI Gives Attackers Nation-State Capabilities
    06:09 - Why AI Can't Be Your Primary Defense
    07:59 - How AI Is Expanding the Attack Surface
    08:53 - Solving AI Security With Limited Access
    11:04 - The Deny-by-Default Security Model
    14:12 - AI-Powered Vulnerability Hunting
    17:29 - How ThreatLocker Actually Uses AI
    20:01 - Why Deny-by-Default Beats Chasing Zero-Days
    21:15 - What Cybersecurity Customers Are Most Worried About
    22:16 - AI Hype, Jobs & Closing Thoughts
    24:55 - ThreatLocker Advert

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #threatlocker #bhusa2026 #blackhat
  • David Bombal

    #597: The Hacking Gadgets You Need to Know

    24-08-2026 | 42 Min.
    Note: Hak5 did not pay me to make this video. But, I'm marking it as sponsored because Darren was kind enough to give me some cool Hak5 gadgets. Get your own using my link: https://davidbombal.wiki/gethak5

    // Darren Kitchen SOCIAL //
    YouTube: https://www.youtube.com/darrenkitchen
    Website: https://hak5.org/pages/hack-across-america
    X: https://x.com/hak5darren

    // Hak5 WEBSITE (affiliate) //
    https://davidbombal.wiki/gethak5

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU//
    0:00 - Coming up
    01:00 - 21 Years of Hak5 // Device overview
    05:30 - USB Rubber Ducky
    09:22 - Bash Bunny
    12:41 - Plunder Bug
    13:28 - Shark Jack & Shark Jack Display
    16:28 - Packet Squirrel
    18:51 - Key Croc
    21:51 - Screen Crab
    24:07 - Lan Turtle Hub
    28:14 - WiFi Pineapple
    33:16 - WiFi Pineapple Pager
    37:32 - Hak5 books
    39:15 - Darren's favourite tools
    41:27 - Future projects // Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.

    #hak5 #hackinggadgets #hacktool
  • David Bombal

    #596: This is the Real Cybersecurity Problem

    20-08-2026 | 28 Min.
    Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people.

    Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a software quality problem.

    For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place.

    They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it.

    Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders.

    Topics include:
    Why cybersecurity may be a software quality problem
    Why users are blamed for insecure software
    CISA’s Secure by Design initiative
    Why default passwords should disappear
    AI agents behaving in unexpected ways
    AI and the future of zero-day attacks
    Memory safety, C, C++ and Rust
    Government regulation and vendor accountability
    The EU Cyber Resilience Act
    Why Patch Tuesday may eventually become unacceptable
    How AI could help defenders find and fix vulnerabilities
    Jen Easterly’s advice for cybersecurity professionals

    If you work in cybersecurity, ethical hacking, software development, networking, AI security, or critical infrastructure, this is a conversation you don’t want to miss.

    // Jen Easterly’s SOCIAL //
    LinkedIn: / jen-easterly

    // Website REFERENCE //
    https://www.cisa.gov/

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming up
    0:55 - Jen Easterly introduction & background
    04:20 - Advice for the youth
    07:10 - Advice for ethical hackers and leadership
    11:35 - Software security // Who's to blame?
    17:39 - Power and responsibility
    21:17 - Secure by design
    26:38 - Is it important to attend RSAC? // Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #rsac #bhusa2026 #securebydesign
  • David Bombal

    #595: How to Detect Fake Cell Towers Near You

    18-08-2026 | 1 u. 2 Min.
    Big thanks to Proton VPN for sponsoring this video. To sign up for Proton VPN please use the following link https://protonvpn.com/davidbombal and get 70% off.

    Learn how fake cell towers and Stingray-style devices can be used to track phones, capture metadata, and monitor cellular activity.

    OTW joins David Bombal to demonstrate how SDR tools such as HackRF, RTL-SDR, DragonOS, and Falcon can be used to scan nearby cell towers and investigate suspicious signals. They look at how 4G and 5G networks work, why mobile networks still expose valuable metadata, how IMSI catchers operate, and what suspicious or rogue cell towers may look like.

    They also discuss SS7 vulnerabilities, mobile network attacks, Signal, GrapheneOS, and practical steps you can take to better protect your communications.

    Topics covered:
    How to scan for nearby cell towers
    How fake cell towers and Stingrays work
    Detecting suspicious cell towers with SDR
    HackRF and RTL-SDR
    DragonOS and Falcon
    IMSI catchers and phone tracking
    4G and 5G security
    SS7 vulnerabilities
    Mobile phone metadata
    Signal and GrapheneOS
    Mobile network security

    // Occupy The Web SOCIAL //
    X: / three_cube
    Website: https://hackers-arise.net/

    // Occupy The Web Books //
    Linux Basics for Hackers 2nd Ed
    US: https://amzn.to/3TscpxY
    UK: https://amzn.to/45XaF7j

    Linux Basics for Hackers:
    US: https://amzn.to/3wqukgC
    UK: https://amzn.to/43PHFev

    Getting Started Becoming a Master Hacker
    US: https://amzn.to/4bmGqX2
    UK: https://amzn.to/43JG2iA

    Network Basics for hackers:
    US: https://amzn.to/3yeYVyb
    UK: https://amzn.to/4aInbGK

    // OTW Discount //
    Use the code BOMBAL to get a 20% discount off anything from OTW's website: https://hackers-arise.net/

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming up
    0:37 - Mobile system vulnerability explained
    12:29 - Proton VPN sponsor segment
    15:07 - How to search cell towers in your area // CellSearch demo
    19:45 - Cell tower frequencies explained
    22:19 - CellSearch demo continued
    32:41 - Discovering the identifiers
    37:42 - Scanning for Stingrays/rogue cell towers // CellSearch demo continued
    44:00 - Ordinary people being victims of WiFi hacking
    47:28 - Authentication bypass on IoT devices
    49:01 - Scanning higher frequencies with CellSearch
    52:06 - Falcon demo // Discovering cellphones connecting to a cell tower
    57:46 - Recommended protection from traffic interception
    01:01:38 - Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #stingray #celltower #sdrhacking
  • David Bombal

    #594: How to Protect Your Network From Insecure IoT Devices

    30-07-2026 | 31 Min.
    Hackers are using overlooked IoT devices such as IP cameras, printers and smart speakers to gain access to networks and spread ransomware.

    Philip Wylie explains how an outdated IP camera became a ransomware gateway, why default passwords and poor segmentation remain serious risks, and how to protect your network using separate VLANs, firmware updates, monitoring and zero-trust controls. The interview also explores medical devices, OT security, AI-enabled devices and the growing demand for IoT penetration-testing skills.

    Big thanks to ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

    // Philip Wylie’s SOCIAL //
    X: https://x.com/phillipwylie
    LinkedIn: / phillipwylie
    YouTube: / @phillipwylie
    Instagram: / phillipwylie

    // Book REFERENCE //
    The Pentester Blueprint Phillip Wylie:
    US: https://amzn.to/4jkigAa
    UK: https://amzn.to/42vShPB

    // YouTube video REFERENCE //
    Pentester Blueprint: Your Road to Success: • Pentester Blueprint: Your road to success
    How to hack IP Cameras (Ethically) and learn IoT hacking: • How to hack IP Cameras (Ethically) and lea...

    // Website REFERENCE //
    https://training.brownfinesecurity.com/

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming Up
    0:56 - Intro
    03:08 - The Weakness in Pen-testing
    07:38 - How Do Hackers Get Access?
    11:30 - How To Protect IoT Devices
    14:36 - Dangers of Medical IoT Devices
    18:24 - Countries Banning IoT Devices
    20:46 - Phillip's Recommendations
    22:42 - What is Exploit DB
    27:30 - How Vulnerable Are You?
    28:28 - Advice To The Youth
    29:40 - How To Start Learning
    31:15 - Conclusion
    31:23 - Threatlocker Advert

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #iot #iothacking #security
Meer Technologie podcasts
Over David Bombal
Want to learn about IT? Want to get ahead in your career? Well, this is the right place! On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics. This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content. David’s details: Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co Website: http://www.davidbombal.com YouTube: https://www.youtube.com/davidbombal All the best! David
Podcast website

Luister naar David Bombal, Bright Podcast en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app

  • Zenders en podcasts om te bookmarken
  • Streamen via Wi-Fi of Bluetooth
  • Ondersteunt Carplay & Android Auto
  • Veel andere app-functies