David Bombal

David Bombal

David Bombal
Ország Egyesült Államok
Műfajok Technológia
Nyelv EN
Epizódok 500
Legutóbbi 01.10.2026

David Bombal is a podcast about IT topics including Python, ethical hacking, networking, network automation, CCNA, and virtualization. The host shares technical, detailed content with new episodes every week. The show aims to help listeners advance their careers in IT.

Epizódok

  • #611: Building AI Agents? Set Up These Guardrails First 01.10.2026 22p
    Big thanks to ‪@Cisco‬ & ‪@Splunkofficial‬ for sponsoring my trip to .Conf 2026 and also for sponsoring this video. AI agents can do things you never intended. So how do you monitor their behavior, spot security problems and decide what they should be allowed to do? I’m joined by Splunk’s Kamal Hathi at .conf26 to discuss AI agent security, observability and what an agentic SOC means for the people working in cybersecurity. Kamal explains why setting a goal isn’t enough. You need visibility into what your agents are actually doing, clear guardrails and human oversight for important decisions. We also discuss why monitoring only a sample of agent activity can leave gaps, and how focused small language models could help reduce evaluation costs. In this interview, we cover: • Known agents, unregistered agents and unexpected behavior • AI evaluations, guardrails and zero trust • Automating SOC alert triage while keeping humans in control • Using AI to create SOAR playbooks • Running models locally for privacy, cost and control • Choosing between local models and cloud models • Whether you should still study computer science in 2027 If you’re building AI agents, working in cybersecurity or deciding what to learn next, this conversation will give you plenty to think about. // Kamal Hathi’s’ SOCIAL // LinkedIn: / kamal-hathi // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 0:43 - Intro 02:25 - Security Against AI 06:26 - Collecting Data on your AI 08:33 - AI Hallucinations 10:48 - Is Life Like Sci-Fi? 14:09 - Will AI Replace You? 17:16 - Not Giving Your Information to AI 18:50 - Kamal's Prediction for the Future of AI 20:20 - Final Thoughts 21:29 - What Should you Study in 2027? 22:00 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #SplunkConf26 #Splunk #Cisco
  • #610: WiFi Pineapple Pager: What Can It Actually Do? 01.10.2026 22p
    Big thank you to proton VPN for sponsoring the video. To get 70% off your Proton VPN subscription use the following link: https://protonvpn.com/davidbombal Note: Hak5 did not pay me to make this video. But, for full transparency: Darren was kind enough to give me some cool Hak5 gadgets. Get your own using my link below. // Buy Hak5 coolness here (Affiliate Link): // Buy Hak5: https://davidbombal.wiki/gethak5 WiFi hacking without opening your laptop? ‪@DarrenKitchen‬ from ‪@hak5‬ joins me to talk about the WiFi Pineapple Pager and what this little Linux device can actually do. Darren shares the story behind the Pager, explains its support for 2.4, 5, and 6 GHz WiFi, and walks us through features including wireless reconnaissance, eventtriggered alerts, and community-created payloads. We also discuss how Bash and DuckyScript helpers let users build their own functionality, and how Pager Portal makes it possible to download payloads directly onto the device. How does it compare with the WiFi Pineapple Mark VII and Enterprise? We look at the different use cases, from portable testing to remotely auditing a client’s wireless network. And yes, someone has already made it run Doom. This is an interview and feature overview with the creator, covering the ideas, technology, and community behind the WiFi Pineapple Pager. // Darren Kitchen SOCIAL // YouTube: / darrenkitchen Website: https://hak5.org/pages/hack-across-am... X: https://x.com/hak5darren // Hak5 WEBSITE // https://shop.hak5.org/ // Previous YouTube video with Darren REFERENCE // Hacking Gadgets Every Cybersecurity Pro should know: • Hacking Gadgets Every Cybersecurity Pro Sh... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU// 0:00 - Intro 0:35 - Coolest hacking tool // Hak5 WiFi Pineapple Pager 03:10 - Proton VPN sponsor segment 05:28 - History of the WiFi Pineapple 08:53 - WiFi Pineapple Pager overview 12:17 - The community 15:55 - Easy to get started 16:50 - WiFi Pineapple Mk7 18:53 - WiFi Pineapple Enterprise 21:23 - Supported WiFi frequencies 22:43 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #wifipineapplepager #wifi #hackinggadgets
  • #609: How Hackers Target Satellites Through Ground Control Systems 01.10.2026 39p
    Big thanks to DeleteMe for sponsoring this video. Protect your business with DeleteMe by using the following Link: https://joindeleteme.com/bombal-biz You’ll also get a free year of social media protection for every seat you purchase. How do you hack a satellite? The attack can start on the ground. Watch a mission control demo showing how web vulnerabilities can change a simulated spacecraft’s orbit. At DEF CON, I meet Milenko and Andrzej, the authors of The Spacecraft Hackers Handbook, to explore spacecraft cybersecurity. They explain the infrastructure behind satellite operations, what the Via sat attack actually targeted, and why protecting spacecraft requires both security and space engineering knowledge. Then Andrzej demonstrates previously patched vulnerabilities in an older version of mission control software. Using Burp Suite, he shows how path traversal exposes configuration files and how cross-site scripting can trigger a spacecraft command through an operator’s browser. We cover: • Why satellite security extends to systems on the ground • How path traversal and XSS affect mission control software • Telemetry, telecommands, CCSDS and the SDLS security layer • How GPS supports timing as well as navigation • Python examples, a prepared lab VM and learning resources • The authors’ nine satellite cybersecurity challenges on Hack The Box • Skills and career opportunities in spacecraft cybersecurity The demonstration uses a spacecraft simulator. The vulnerabilities shown were disclosed to the vendor and patched. // Link to No Starch Website for Milenko and Andrzej’s Book// The Spacecraft Hacker’s Handbook: https://nostarch.com/spacecraft-hacke... Use Coupon Code SPACE25 for 25% off The Spacecraft Hacker’s Handbook. // Milenko Starcik’s SOCIALS // Website: https://visionspace.com/team/milenko-... Website 2: https://starcik.space/ // Andrzej Olchawa’s SOCIALS // Website: https://visionspace.com/author/a-olch... Website 2: https://andy.codes/ X: https://x.com/0x4ndy // Online Resources // https://spacesecurity.club https://github.com/orgs/spacecrafthac... // Blog Post REFERENCE // https://www.hackthebox.com/blog/hack-... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Intro 0:52 - How Russia hacked satellites 02:12 - The Spacecraft Hacker's Handbook 03:23 - VisionSpace 04:04 - DeleteMe sponsor segment 05:29 - Growth in satellites launched 06:28 - What would losing satellites mean 07:12 - Protocols explained 08:00 - Misconceptions of satellite hacking 09:28 - Threat level of satellite hacking 10:39 - Upcoming demo explained 12:20 - Who is the book for? 16:46 - A gap 17:48 - Other recommendations 19:49 - Hacking satellite demo overview 20:34 - Hacking satellite demo walkthrough 33:54 - Demo next steps 34:29 - Demo walkthrough continued 38:51 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #sattelitehacking #spacecraftcybersecurity #defcon
  • #608: Before You Deploy AI Agents, Understand These Attacks 19.09.2026 52p
    Big thanks to Proton VPN for sponsoring this video. You can use my link: https://protonvpn.com/davidbombal to get 70% off your Proton VPN subscription How do you hack an AI system? And what happens when one malicious instruction spreads between AI agents? I’m joined by Harriet, author of Practical AI Security, to explore how AI models and agents can be manipulated, with practical Python demonstrations. You'll see an image classifier misidentify a rifle, a demonstration of prompt injection spreading across five agents, and how memory poisoning can plant instructions that affect an agent later. We discuss why securing AI takes more than blocking prompt injection, how machine learning creates different security challenges, and what you need to understand before deploying agents in your organisation. Want to learn this yourself? Harriet explains how to get started with her collection of 30+ free Python notebooks, including examples you can explore in Google Colab. We also discuss the skills involved in AI security and how people from different backgrounds can contribute. Topics include: • Adversarial machine learning and image manipulation • Prompt injection and attacks spreading between agents • Memory poisoning and model backdoors • AI supply chain security • Learning AI security with Python • AI security careers, training and fundamentals // Link to No Starch Website for Harriet Farlow’s Book // Order Practical AI Security on No Starch: https://nostarch.com/practical-ai-sec... Use Coupon code FARLOW25 for 25% off Practical AI Security // HarrietHacks Labs REFERENCE // https://labs.harriethacks.com/ // Harriet Farlow’s AI Security Fundamentals Course REFERENCE // https://aisecurityfundamentals.com/ // Harriet Farlow’s SOCIALS // Website: https://harriethacks.com/about/ LinkedIn: / harriet-farlow-654963b7 Instagram: / harriethacks // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Intro 01:05 - Harriet Farlow AI security background 05:55 - Proton VPN sponsor segment 08:02 - Practical AI Security book // AI Security 10:40 - Who's the book for 11:32 - Harriet's YouTube channel 12:32 - AI security course 14:27 - Practical demos 15:41 - Hacking an AI demo // Learning how AIs work 22:22 - Hacking an AI summary 24:40 - Hacking an AI visualizations 28:48 - AI deceiving another AI 33:09 - Hacking an AI visualizations continued 34:07 - Rushing to the AI market 36:26 - Adversarial patch explained 38:12 - Vibe coded visuals 40:27 - More visualization 44:04 - Growth of interest in AI security 45:09 - No advanced skills required 49:40 - Get in contact with Harriet Farlow // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #aisecurity #aiagents #defcon
  • #607: How Hackers Steal Your Accounts Even With 2FA Enabled 19.09.2026 31p
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Is Microsoft Defender enough to protect your PC? Malware researcher Leo joins me at Black Hat to discuss antivirus, Windows security and how hackers steal your accounts. We explore how infostealers target saved passwords and session tokens, why two-factor authentication cannot prevent every account takeover, and how a message from a compromised friend’s account can lead to an infection. Leo shares practical starting points for investigating your computer, including Autoruns for startup entries, TCPView for linking connections to applications, and Wireshark for examining network traffic. We also discuss password managers, account recovery planning, Windows telemetry and why switching operating systems does not eliminate security risks. In this interview: • Microsoft Defender’s strengths and limitations • Free tools for investigating suspicious Windows activity • How infostealers and initial access brokers operate • Stolen session tokens and the limits of 2FA • Fake download sites, malicious ads and targeted phishing • Preparing recovery options before your accounts are compromised • Security and privacy trade-offs across Windows, Linux and macOS // Leo’s SOCIAL // YouTube: / @pcsecuritychannel X: https://x.com/leotday Discord: / discord // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 0:35 - Intro 0:48 - Leo's Background & How Malware Has Evolved 03:27 - How to Detect Malware on Your Computer 05:21 - Best Sysinternals Tools for Malware Analysis 08:21 - Windows Device Tracking & Privacy Concerns 10:42 - Would you Recommend Windows in 2026? 11:59 - Privacy Laws & the Future of Tracking 12:50 - How Telemetry Helps Catch Cybercriminals 14:02 - ThreatLocker Sponsor 15:18 - How Hackers Actually Get Into Systems 16:42 - How to Protect Yourself From Getting Hacked 19:12 - Do You Really Need Antivirus? 21:35 - Security Advice for Home Users 25:59 - Why Smart People Still Get Hacked 26:59 - What Happens After Your Credentials Are Stolen 28:06 - Linux vs Mac vs Windows 29:40 - Is Windows Really Targeted More by Malware? 31:18 - Conclusion & Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! #malware #bhusa2026 #microsoftdefender
  • #606: Is Cybersecurity Still Worth Learning in 2026? 19.09.2026 31p
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker, please use the following link: https://www.threatlocker.com/davidbombal Is cybersecurity still worth learning in 2026? AI agents are changing vulnerability research, but where does that leave you? At Black Hat, I’m joined by Arizona State University professor Yan Shoshitaishvili to discuss what AI can actually do, where it falls short, and why he would still choose a career in cybersecurity today. Yan shares how his lab used AI agents and human-designed workflows to find what he describes as over 1,000 Linux kernel vulnerabilities triggerable by an unprivileged local user. Running 128 agents was only part of the story. Understanding which vulnerabilities to look for and improving the research process proved critical. We discuss: • How AI agents test potential vulnerabilities instead of simply reporting suspected bugs • How agentic AI compares with fuzzing and static analysis • Why finding new bugs does not automatically prove one tool is better • Why human expertise still matters in security research • How to use AI as a learning assistant without skipping the learning • Free, hands-on cybersecurity training through pwn.college • Yan’s advice for anyone considering cybersecurity in 2026 // Yan Shoshitaishvili SOCIAL // LinkedIn: / yan-shoshitaishvili-7024305 ASU website: https://www.asu.edu/ // ThreatLocker’s SOCIAL // LinkedIn: https://www.linkedin.com/company/thre... X: https://x.com/threatlocker Instagram: / threatlocker Website: https://www.threatlocker.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming up 0:34 - Intro 02:10 - Rethinking How Cybersecurity Is Taught 04:35 - AI Agents Are Changing Vulnerability Research 10:11 - Sponsored Section 11:18 - Are AI Agents Really Better at Finding Bugs? 16:00 - AI Agents vs the Linux Kernel 19:30 - Where Human Expertise Still Matters 23:09 - Learning Cybersecurity With AI 25:17 - Will AI Eventually Replace Everyone? 30:26 - Would You Still Choose Cybersecurity? 30:50 - Conclusion & Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #aiagents #vulnerabilityresearch #bhusa2026
  • #605: Flock Cameras: What They Can Reveal About Your Life 12.09.2026 22p
    Big thank you to DeleteMe for sponsoring this video. Use my link join https://joindeleteme.com/Bombal or use the QR code in the video to get 20% off. Your license plate could reveal more than you think. Flock cameras, vehicle tracking and OSINT can turn information about your car into clues about where you live and your daily routines. I’m joined by an OSINT expert to discuss how vehicle information can be connected with public records, why surveillance raises privacy concerns and what happens when people trust an incorrect license plate match. He shares his experiences of locating a missing car after a police search came up short and investigating a hit-and-run using a partial plate and publicly available information. We discuss: • Flock cameras and vehicle identification beyond license plates • How vehicle data can expose patterns in your movements • License plate recognition errors and the importance of verification • How public records can connect a vehicle to a person • The risks of surveillance access being abused • Privacy measures, their limitations and the need for accountability • DeFlock and community scrutiny of surveillance cameras How much can someone discover about you from the information you leave exposed? // Mishaal Kahn’s SOCIALS // LinkedIn: / mish-aal Website: https://www.mishaalkhan.com/ Tool created: https://www.operationprivacy.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 0:47 - The Growing Flock Camera Controversy 01:28 - What Are Flock Cameras Actually Collecting? 02:33 - Police Misuse and Abuse of Surveillance Data 03:45 - Mapping and Avoiding Flock Cameras 04:57 - How Personal Data Fuels Scams 06:54 - What Can Police Actually Do With Flock Data? 07:12 - Testing Flock: A Real Missing Vehicle Case 09:09 - How Mishaal Found the Vehicle Himself 10:20 - Drones: The Next Level of Surveillance 11:11 - How Can You Protect Your Privacy? 13:07 - Facial Recognition Is Expanding Everywhere 14:13 - AI Can Rebuild Your Entire Pattern of Life 15:51 - What Can Someone Find From Your License Plate? 17:16 - Solving a Hit-and-Run With a Partial Plate 19:08 - What Could a Rogue Police Officer Do? 20:28 - Is There Any Hope for Privacy? 21:53 - Where to Learn More About Privacy and OSINT Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #flockcameras #defcon #privacy
  • #604: How He Infiltrated LockBit and Helped Get Them Indicted 12.09.2026 24p
    Big thanks to Proton Drive for sponsoring this video. You can use my link http://proton.me/drive/davidbombal to sign up for Proton Drive and get 40% discount. John DiMaggio created fake identities, profiled ransomware operators and spent approximately 18 months earning the trust of LockBit. In this interview, John explains how his investigation led to work with the FBI and the UK’s National Crime Agency, contributed to indictments and resulted in death threats against him. He also reveals how the work affected his mental health, relationships and everyday life. John shares the remarkable story of a young REvil hacker connected to the Kaseya ransomware attack and its $70 million ransom demand. He explains how ransomware operators are recruited, manipulated and sometimes controlled by intelligence agencies. You will also learn why stolen cryptocurrency is difficult to spend, how Bitcoin tracing and money-laundering mistakes expose cybercriminals and why technical hacking skills do not make someone good at hiding money. Finally, John warns aspiring researchers not to approach ransomware gangs without professional training and support. He discusses his new book, Owned, and how he plans to use his experience to help cybersecurity teams and business leaders prepare for ransomware attacks. // Link to No Starch Website for Jon DiMaggio’s Book // Order Owned on No Starch: https://nostarch.com/owned Use Coupon Code OWNED30 for 30% off Owned at NoStarch.com // Jon DiMaggio’s SOCIALS // Website: https://arkemcyber.com/ X: https://x.com/Jon__DiMaggio LinkedIn: / jondimaggio // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 0:36 - Introduction 01:28 - Infiltrating the LockBit Ransomware Gang 03:45 - Working With the FBI & NCA 04:55 - Sponsor – Proton Drive 06:54 - Stories From the Ransomware Gang 07:35 - Befriending a Hacker 10:21 - The Kaseya Ransomware Attack 12:10 - Arrest, Extradition & a 14-Year Sentence 13:12 - An Unexpected Message From Prison 14:57 - The LockBit Story & the Mental Health Toll 16:30 - Advice for Young People Drawn to Cybercrime 18:09 - Why Hackers Can’t Easily Spend Their Money 19:12 - How to Become a Jon DiMaggio 21:58 - What’s Next for Jon DiMaggio 23:08 - Preparing Companies for Ransomware Attacks 23:52 - Final Thoughts Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #lockbit #ransomware #revil
  • #603: How Age Verification Threatens Your Online Privacy 08.09.2026 47p
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal Age verification is spreading across the internet. It promises to protect children, but what happens when accessing a website or using your own device requires facial recognition, identity documents or third-party verification? David speaks with Alexis Hancock from the Electronic Frontier Foundation about the growing privacy risks surrounding age verification and digital ID systems. They examine how these technologies could threaten online anonymity, create new surveillance infrastructure and expose sensitive personal information. Alexis explains why age verification alone does not teach children how to stay safe online, how data brokers and behavioral advertising contribute to the problem, and why banning VPNs or weakening encryption would make everyone less secure. They also discuss zero-knowledge proofs, facial recognition, encryption backdoors, government surveillance and the danger of building a digital identity system that could be abused by future governments. Finally, Alexis shares practical ways to protect your privacy, including using encrypted communication, learning from EFF’s Surveillance Self-Defense guides and contacting elected representatives when harmful legislation is proposed. // Alexis Hancock’ SOCIAL // LinkedIn: / alexishancock // EFF Website REFERENCE // https://www.eff.org/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Intro 0:41 - Alexis Hancock background // Who are the EFF 01:48 - Eroding privacy & age verification 08:48 - Online safety for children 12:25 - Online monitoring 14:20 - ThreatLocker sponsor segment 15:27 - Big tech vs government 17:49 - How to fight for privacy 20:19 - Online censorship & privacy 26:17 - The push for age verification 29:29 - Age verification "whack-a-mole" 33:03 - Parental control vs age verification 36:24 - What about non-tech savvy people? 41:02 - Zero-knowledge proof 44:48 - Is it too late? // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ageverification #privacy #bhusa2026
  • #602: How Compilers Turn Secure C Code Into Vulnerable Binaries 08.09.2026 30p
    Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal You can write secure C code, follow accepted best practices and still end up with a vulnerable binary. The reason is simple: the CPU does not run your source code. It runs whatever the compiler produces. David sits down with security researcher Chris Domas at Black Hat to examine how legal compiler optimizations can remove security protections, delete memory-clearing operations and introduce time-of-check to time-of-use vulnerabilities into code that appeared secure. Chris explains the C abstract machine, why compilers are allowed to transform code so dramatically and how register pressure, structure layout and even data size can affect whether a binary is vulnerable. In one striking example, 17 or 33 bytes can be safe while nearby sizes produce vulnerable code. They also discuss whether Rust solves the problem, why switching between GCC and Clang is not the answer and how AI helped analyse 500 million lines of open-source code to identify 300 potentially dangerous patterns. Most importantly, Chris explains what developers can do now, including enabling compiler warnings, using sanitizers, analysing optimized builds and testing the exact binary that will be shipped. // Christopher Domas’ SOCIAL // LinkedIn: / christopher-domas GitHub: https://github.com/xoreaxeaxeax X: https://x.com/xoreaxeaxeax // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 0:48 - Intro 02:05 - Different Ways of Exploiting CPU’s 04:10 - The C Specifications 06:17 - The Compiler Deleting Nemsec 08:40 - Do we need to use a new Compiler ? 10:09 - Compiler Inventing Vulnerabilities 12:13 - Don't Give up Writing Secure Code 12:44 - Sponsored Section 14:25 - Any Easy Options To Create A New Compiler ? 15:09 - Chris’s Presentation at Black Hat 20:00 - Weird Situations with Size of Data 21:22 - What Can Developers Do ? 23:32 - Who Can Leverage this Vulnerability ? 25:02 - Could AI Make it Easy For Attackers To Leverage This? 28:27 - Recommendations For Developers 29:48 - Advice To Be Like Chris 30:36 - Conclusion & Outro Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #bhusa2026 #securecoding #compiler
  • #601: Google Researchers Hacked the Pixel Phone using Audio Messages 08.09.2026 39p
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal A zero-click attack can compromise your phone without you opening a link, installing an application or even touching the device. David sits down with Natalie Silvanovich and Seth Jenkins from Google Project Zero to examine how specially crafted audio messages were used to remotely compromise the Pixel 9 and Pixel 10. The attack begins inside the Dolby Unified Decoder, where Android automatically processes incoming audio for transcription. The researchers explain how they exploited the decoder, escaped the media codec sandbox and targeted vulnerable Pixel hardware drivers to achieve kernel code execution and root access. They also discuss ASLR, SELinux, memory corruption, the eight-week exploit development process, how AI helped automate repetitive tasks and why Apple’s compiler protections prevented the same Dolby bug from affecting iPhones. Most importantly, they explain what manufacturers can do to reduce their attack surface and make commercial zero-click exploits significantly more expensive. These vulnerabilities were responsibly disclosed and patched. Pixel users running the latest security updates are protected. // Seth Jenkins SOCIAL // LinkedIn: https://www.linkedin.com/in/seth-jenkins-a20b914b/ X: https://x.com/__sethJenkins // Natalie Silvanovich SOCIAL // X: https://x.com/natashenka?lang=en Website: https://natashenka.ca/ // Website REFERENCE // Google Project Zero website: https://projectzero.google/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU// 0:00 - Intro 01:00 - ThreatLocker sponsor segment 02:10 - Natalie Silvanovich background 04:00 - Seth Jenkins background 04:49 - Zero click audio codec vulnerability 05:41 - Disclaimer 06:07 - Hacking using audio files // How it works 10:23 - What happens in the sandbox 13:27 - The next step 15:15 - Running into issues 22:55 - Would someone notice the hack? 26:20 - Not secure by default 27:44 - Using AI assistance 29:44 - How to reduce attack surface 34:57 - How to get into cybersecurity 39:05 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #google #bhusa2026 #pixel10
  • #600: This Free Tool Decodes Game Boy ROM From a Photograph 02.09.2026 41p
    Can you recover working software from a photograph of a microchip? Embedded systems reverse engineer Travis Goodspeed demonstrates how to extract the original Game Boy’s 256-byte boot ROM from a microscopic photograph of the mask ROM inside its CPU. The source image was created by combining 22 microscope photographs captured at 50x magnification. Using his free, open-source Mask ROM Tool, Travis marks 2,048 ROM bit locations, separates the ones from the zeros and checks for possible recognition errors. He then determines the logical order of the bits, disassembles the program and shows how it can be exported as a ROM file for use in an emulator. Travis also explains the Game Boy’s unusual copy-protection system. During startup, its boot ROM displays logo data supplied by the cartridge and compares it with Nintendo’s internal copy. If the logos do not match, the game does not boot. Requiring cartridges to contain Nintendo’s trademark gave the company legal leverage against unlicensed publishers. The video also explores techniques from Travis’s book, Microcontroller Exploits. These include extracting protected firmware from an access-control reader, chemically decapsulating chips while preserving their operation and using ultraviolet light with a nail-polish mask to remove memory protection without erasing the program. The Mask ROM Tool, Game Boy chip photograph and step-by-step tutorial are publicly available, allowing you to reproduce the ROM-decoding demonstration without owning a microscope or chemistry lab. // Sponsored SEGMENT // Big thank you to Proton Pass for sponsoring this video. Take your security to the next level by getting Proton Pass using the following be www.proton.me/davidbombal // Link to No Starch Website for Travis’ Book // Order Microcontroller Exploits and get the eBook free. https://nostarch.com/microcontroller-... Use Coupon Code GOODSPEED25 for 25% off Microcontroller Exploits at NoStarch.com // Travis Goodspeed SOCIAL // GitHub: https://github.com/travisgoodspeed // GitHub link to GameBoy ROM Tutorial // https://github.com/travisgoodspeed/gb... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU// 0:00 - Coming Up 0:40 - Intro 03:28 - Book Overview 05:27 - Proton Pass Ad 07:29 - Demonstration Context 09:56 - Demo Begins 12:48 - Marking the Chip Rows 18:27 - How Travis Wrote his Book 19:55 - Design Rule Check 23:11 - How to Decode the Binary 28:36 - Can the Binary Numbers Change? 30:30 - Why is this Method Useful? 34:24 - More book Overviews 40:48 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #gameboy #reverseengineering #rom
  • #599: This Pocket Tool Diagnoses Wi-Fi in 45 Seconds 02.09.2026 42p
    Your internet speed can look fine while your Wi-Fi is still failing. Packet loss, latency, congested channels, interference and poor configuration can all damage performance, but a normal speed test will not show you the full picture. In this video, I test the Ookla Speedtest Pulse, a pocket-sized Wi-Fi 7 diagnostic tool that measures more than 25 network metrics in around 45 seconds. We test Wi-Fi at the Natural History Museum in London and examine results from an Airbnb to identify whether the problem comes from the Wi-Fi network, wired connection or internet service provider. Matt explains how the device tests 2.4, 5 and 6 GHz Wi-Fi, detects channel problems, measures signal quality and gives you practical recommendations in plain English. We also compare Speedtest Pulse with the normal Speedtest application, laptopbased tools and the Ekahau Sidekick 2. You will see its current limitations, upcoming continuous monitoring features and how it could help technicians finally capture intermittent Wi-Fi problems. Big thanks to OOKLA for sponsoring this video. To get your own Speedtest Pulse please use the following link: https://wifi.ekahau.com/david-bombal-... // Matt Starling’s SOCIAL // LinkedIn: / matt-starling-03913633 X: https://x.com/mattstarling?s=21 // Ookla’s SOCIAL // LinkedIn: / ookla // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 0:58 - Testing Public Wi-Fi in London 01:40 - What Is the Speedtest Pulse? 03:40 - Pulse vs Speedtest vs Sidekick 2 06:19 - Making Wi-Fi Troubleshooting Easy 07:44 - Running a Wi-Fi Test 09:22 - Understanding Wi-Fi Performance Scores 11:16 - Reports and Cloud Results 13:00 - Active vs Continuous Pulse 15:14 - Wired and Wireless Network Testing 18:05 - Why Not Just Use a Laptop? 21:02 - Mobile Support and Wi-Fi 7 Hardware 23:17 - Understanding Your Wi-Fi Score 26:54 - Wi-Fi Security and PMF 29:03 - Signal Strength and Transmit Power 30:19 - Wi-Fi Channels and Interference 31:58 - How to Improve Your Wi-Fi 33:12 - WPA3 Best Practices 34:16 - Price and Coverage Mapping 35:59 - Pulse vs Sidekick 2 for Interference 38:36 - Solving Intermittent Wi-Fi Problems 40:32 - Cloud Monitoring and Multi-Site Management 42:12 - Final Thoughts Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ookla #speedtest #wifi
  • #598: AI Can’t Understand Intent. That’s a Security Problem 26.08.2026 26p
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal AI is changing cybersecurity, but simply using more AI to defend against AI attacks may not be the answer. David Bombal sits down with Danny Jenkins, CEO of ThreatLocker, to discuss the security risks created by AI, autonomous agents, zero-day vulnerabilities, ransomware, and the rapidly expanding attack surface businesses now have to deal with. Danny explains one of the fundamental problems with AI security: AI can understand what something does, but it may not understand the intent behind it. The same action could be performed legitimately by an administrator or maliciously by an attacker. They also discuss how AI is giving attackers capabilities that previously required significantly more expertise and resources, including vulnerability discovery and sophisticated phishing attacks. But AI creates another problem inside organizations. Autonomous agents can potentially access files, upload data, perform actions, and make mistakes extremely quickly. Every new piece of software adds attack surface, and powerful AI agents can dramatically increase that risk. Danny argues that the answer isn't simply AI versus AI. Instead, organizations need to rethink trust itself. The discussion covers deny by default, application control, restricting what software and AI agents are allowed to access, and why AI should be used as an additional security layer rather than becoming your primary defense. Topics include: • AI security risks • Autonomous and agentic AI • Why AI struggles with intent • How hackers are using AI • AI-powered vulnerability discovery • Zero-day vulnerabilities • Ransomware • AI attack surfaces • Application control • Deny by default security • Why AI alone can't solve AI security • Securing AI inside businesses // Danny Jenkins’ SOCIAL // LinkedIn: / dannyjenkinscyber // ThreatLocker’s SOCIAL // LinkedIn: https://www.linkedin.com/company/thre... X: https://x.com/threatlocker Instagram: / threatlocker Website: https://www.threatlocker.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 0:34 - Introduction 0:46 - Why Businesses Are Afraid of AI 02:17 - AI Can Be Used for Good or Bad 03:29 - The Race to Adopt AI 05:02 - AI Gives Attackers Nation-State Capabilities 06:09 - Why AI Can't Be Your Primary Defense 07:59 - How AI Is Expanding the Attack Surface 08:53 - Solving AI Security With Limited Access 11:04 - The Deny-by-Default Security Model 14:12 - AI-Powered Vulnerability Hunting 17:29 - How ThreatLocker Actually Uses AI 20:01 - Why Deny-by-Default Beats Chasing Zero-Days 21:15 - What Cybersecurity Customers Are Most Worried About 22:16 - AI Hype, Jobs & Closing Thoughts 24:55 - ThreatLocker Advert Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #threatlocker #bhusa2026 #blackhat
  • #597: The Hacking Gadgets You Need to Know 24.08.2026 42p
    Note: Hak5 did not pay me to make this video. But, I'm marking it as sponsored because Darren was kind enough to give me some cool Hak5 gadgets. Get your own using my link: https://davidbombal.wiki/gethak5 // Darren Kitchen SOCIAL // YouTube: https://www.youtube.com/darrenkitchen Website: https://hak5.org/pages/hack-across-america X: https://x.com/hak5darren // Hak5 WEBSITE (affiliate) // https://davidbombal.wiki/gethak5 // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU// 0:00 - Coming up 01:00 - 21 Years of Hak5 // Device overview 05:30 - USB Rubber Ducky 09:22 - Bash Bunny 12:41 - Plunder Bug 13:28 - Shark Jack & Shark Jack Display 16:28 - Packet Squirrel 18:51 - Key Croc 21:51 - Screen Crab 24:07 - Lan Turtle Hub 28:14 - WiFi Pineapple 33:16 - WiFi Pineapple Pager 37:32 - Hak5 books 39:15 - Darren's favourite tools 41:27 - Future projects // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #hak5 #hackinggadgets #hacktool
  • #596: This is the Real Cybersecurity Problem 20.08.2026 28p
    Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people. Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a software quality problem. For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place. They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it. Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders. Topics include: Why cybersecurity may be a software quality problem Why users are blamed for insecure software CISA’s Secure by Design initiative Why default passwords should disappear AI agents behaving in unexpected ways AI and the future of zero-day attacks Memory safety, C, C++ and Rust Government regulation and vendor accountability The EU Cyber Resilience Act Why Patch Tuesday may eventually become unacceptable How AI could help defenders find and fix vulnerabilities Jen Easterly’s advice for cybersecurity professionals If you work in cybersecurity, ethical hacking, software development, networking, AI security, or critical infrastructure, this is a conversation you don’t want to miss. // Jen Easterly’s SOCIAL // LinkedIn: / jen-easterly // Website REFERENCE // https://www.cisa.gov/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming up 0:55 - Jen Easterly introduction & background 04:20 - Advice for the youth 07:10 - Advice for ethical hackers and leadership 11:35 - Software security // Who's to blame? 17:39 - Power and responsibility 21:17 - Secure by design 26:38 - Is it important to attend RSAC? // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #rsac #bhusa2026 #securebydesign
  • #595: How to Detect Fake Cell Towers Near You 18.08.2026 1ó 2p
    Big thanks to Proton VPN for sponsoring this video. To sign up for Proton VPN please use the following link https://protonvpn.com/davidbombal and get 70% off. Learn how fake cell towers and Stingray-style devices can be used to track phones, capture metadata, and monitor cellular activity. OTW joins David Bombal to demonstrate how SDR tools such as HackRF, RTL-SDR, DragonOS, and Falcon can be used to scan nearby cell towers and investigate suspicious signals. They look at how 4G and 5G networks work, why mobile networks still expose valuable metadata, how IMSI catchers operate, and what suspicious or rogue cell towers may look like. They also discuss SS7 vulnerabilities, mobile network attacks, Signal, GrapheneOS, and practical steps you can take to better protect your communications. Topics covered: How to scan for nearby cell towers How fake cell towers and Stingrays work Detecting suspicious cell towers with SDR HackRF and RTL-SDR DragonOS and Falcon IMSI catchers and phone tracking 4G and 5G security SS7 vulnerabilities Mobile phone metadata Signal and GrapheneOS Mobile network security // Occupy The Web SOCIAL // X: / three_cube Website: https://hackers-arise.net/ // Occupy The Web Books // Linux Basics for Hackers 2nd Ed US: https://amzn.to/3TscpxY UK: https://amzn.to/45XaF7j Linux Basics for Hackers: US: https://amzn.to/3wqukgC UK: https://amzn.to/43PHFev Getting Started Becoming a Master Hacker US: https://amzn.to/4bmGqX2 UK: https://amzn.to/43JG2iA Network Basics for hackers: US: https://amzn.to/3yeYVyb UK: https://amzn.to/4aInbGK // OTW Discount // Use the code BOMBAL to get a 20% discount off anything from OTW's website: https://hackers-arise.net/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming up 0:37 - Mobile system vulnerability explained 12:29 - Proton VPN sponsor segment 15:07 - How to search cell towers in your area // CellSearch demo 19:45 - Cell tower frequencies explained 22:19 - CellSearch demo continued 32:41 - Discovering the identifiers 37:42 - Scanning for Stingrays/rogue cell towers // CellSearch demo continued 44:00 - Ordinary people being victims of WiFi hacking 47:28 - Authentication bypass on IoT devices 49:01 - Scanning higher frequencies with CellSearch 52:06 - Falcon demo // Discovering cellphones connecting to a cell tower 57:46 - Recommended protection from traffic interception 01:01:38 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #stingray #celltower #sdrhacking
  • #594: How to Protect Your Network From Insecure IoT Devices 30.07.2026 31p
    Hackers are using overlooked IoT devices such as IP cameras, printers and smart speakers to gain access to networks and spread ransomware. Philip Wylie explains how an outdated IP camera became a ransomware gateway, why default passwords and poor segmentation remain serious risks, and how to protect your network using separate VLANs, firmware updates, monitoring and zero-trust controls. The interview also explores medical devices, OT security, AI-enabled devices and the growing demand for IoT penetration-testing skills. Big thanks to ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal // Philip Wylie’s SOCIAL // X: https://x.com/phillipwylie LinkedIn: / phillipwylie YouTube: / @phillipwylie Instagram: / phillipwylie // Book REFERENCE // The Pentester Blueprint Phillip Wylie: US: https://amzn.to/4jkigAa UK: https://amzn.to/42vShPB // YouTube video REFERENCE // Pentester Blueprint: Your Road to Success: • Pentester Blueprint: Your road to success How to hack IP Cameras (Ethically) and learn IoT hacking: • How to hack IP Cameras (Ethically) and lea... // Website REFERENCE // https://training.brownfinesecurity.com/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 0:56 - Intro 03:08 - The Weakness in Pen-testing 07:38 - How Do Hackers Get Access? 11:30 - How To Protect IoT Devices 14:36 - Dangers of Medical IoT Devices 18:24 - Countries Banning IoT Devices 20:46 - Phillip's Recommendations 22:42 - What is Exploit DB 27:30 - How Vulnerable Are You? 28:28 - Advice To The Youth 29:40 - How To Start Learning 31:15 - Conclusion 31:23 - Threatlocker Advert Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #iot #iothacking #security
  • #593: How to pass the CCNA exam (advice from two Cisco instructors) 25.07.2026 36p
    Two Cisco training veterans break down how to know you are ready for the CCNA exam, what changes in CCNA 2.0, and whether the CCNA is still worth it in 2026. Brian Bays has been teaching official Cisco classes since 2000. Michael Aldridge has been writing practice exam content since 2001. In this interview they answer the questions I get asked constantly: how long should I study, do I need physical equipment, should I do Network Plus first, and is AI going to take these jobs away? Short answer on that last one: they have heard this before. Automation was going to end tech jobs. Then virtualization. Then cloud. Every time, it just made good engineers more productive. Junior engineers become senior engineers, and we cannot function without senior engineers. We also cover what is coming in CCNA 2.0, including more troubleshooting woven through every section, a dark mode option, a full screen CLI, and the ability to send a command to every device in a lab at once. This video is not sponsored. I have known Brian and Michael for years and I recommend them because I rate them, not because anyone paid for this. Get CCNA Certified with Boson’s comprehensive training solutions: https://boson.com/certifications/ccna/ // Bryan Baize SOCIAL // LinkedIn: / bbaize // Michael Aldridge SOCIAL // LinkedIn: / michael-aldridge-48125338a Reddit: / bosonmichael // Boson LinkedIn // LinkedIn: / boson // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming up 01:01 - Introductions 03:55 - When will you be ready for the CCNA exam? 08:34 - Overwhelming exam resources 11:14 - Do you need physical equipment for the CCNA exam? 13:52 - Mistakes preparing for the exam 16:56 - The learning never stops 17:57 - CCNA vs Network+ 19:52 - What is Boson NetSim? 20:53 - What is Boson ExSim? 21:37 - NetSim vs Packet Tracer 22:37 - Why trust Boson? 24:46 - Tips for passing the CCNA exam 25:37 - How long should you study for the CCNA exam? 27:34 - New CCNA exam expectations 29:27 - Mistakes when taking the exam 31:52 - Topics students struggle with 33:26 - Important resources 35:23 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #boson #ccna #networkengineer
  • #592: Why most enterprise AI fails (and how to succeed) 15.07.2026 37p
    Agentic AI is putting a 400x load on enterprise networks. Cisco and NTT Data experts reveal why only 13% of leaders successfully scale AI, the nightmare of quantum threats, and how to secure your infrastructure. Big thank you to NTT DATA for sponsoring this video. Book an AI Infrastructure Readiness Assessment using one of the following links: https://services.global.ntt/en-us/cam... or https://services.global.ntt/en-us/cam... // Vikesh Gumpalli’s SOCIAL // LinkedIn: / vgumpalli // Vance Baran’s SOCIAL // LinkedIn: / vancebaran // Website REFERENCE // https://www.nttdata.com/global/en/ https://www.nttdata.com/en-us/2026-gl... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming Up 01:09 - Introduction 03:04 - Enterprise AI Adoption: The Board-Level Challenge 05:02 - How AI Agents Are Reshaping Network Infrastructure 07:22 - AI Agent Access, Sensitive Data and Security Risks 10:24 - Cybersecurity at Machine Speed and Modernising Security 14:08 - AI Budgets, ROI and Business Readiness 15:00 - AI’s Impact on Jobs and an Insurance Case Study 19:08 - Data Sovereignty and Custom AI Models 22:18 - AI Factories, Edge Deployment and Public-Sector Use Cases 26:31 - Preparing for Quantum-Safe Security 28:43 - Managing Multi-Vendor Environments and Security Readiness 32:09 - Live Protect and Hybrid Mesh Firewalls 34:04 - Splunk, Galileo, AI Observability 36:33 - Where to Learn More Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only.

Népszerű itt:

Ez a podcast ezeknek az országoknak a podcast-listáin is szerepel.