
Go offline with the Player FM app!
#510: 20–30% Of Attacks Use AI: John Hammond details today’s hybrid attacks
Manage episode 505695464 series 3191527
To try everything Brilliant has to offer for free for a full 30 days, visit brilliant.org/davidbombal or scan the QR code onscreen – You’ll also get 20% off an annual premium subscription.
In this 2025 deep-dive, David Bombal sits down with John Hammond to map the real state of hacking: classic ransomware/infostealers meet AI-assisted malware (including code that leverages LLMs). We unpack the ClickFix and FileFix social-engineering patterns, fake CAPTCHA and “save/upload” flows that trick users into running payloads, and the practical Windows mitigations (policy/registry ideas) you should know.
John shares why he estimates 20–30% of attacks now have some AI touch, how social engineering scales, and where defenders can push back. For your career, he argues opportunities are expanding: use CTFs, show your work on GitHub/video, and consider OSCP for signaling. He also introduces Just Hacking Training (JHT), handson hack-alongs, archived CTFs, free upskill challenges, and pay-what-you-want courses with industry all-stars.
What you’ll learn:
• How ClickFix/FileFix actually trick users
• Realistic mitigation tactics you can apply
• The current role of AI in malware
• Career roadmap: CTFs → OSCP → portfolio
• Where to get hands-on: JHT resources
// John Hammond’s SOCIALS //
YouTube: / @_johnhammond
X: x.com/_johnhammond
LinkedIn: / johnhammond010
Discord: / discord
Instagram: / _johnhammond
TikTok: / johnhammond010
GitHub: github.com/JohnHammond
Humble Bundle: www.humblebundle.com/?partner...
Just Hacking Training: www.justhacking.com/
ClickFix Website: clickfix-wiki.github.io/
// YouTube video REFERENCE //
Linux got hacked with this AI Image: • Linux got Hacked with this AI image!
Hackers trick everyone to run malware (FileFix): • hackers trick everyone to run malware (Fil...
OSINT Tools to track you down: • OSINT tools to track you down. You cannot ...
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: [email protected]
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
508 episodes
Manage episode 505695464 series 3191527
To try everything Brilliant has to offer for free for a full 30 days, visit brilliant.org/davidbombal or scan the QR code onscreen – You’ll also get 20% off an annual premium subscription.
In this 2025 deep-dive, David Bombal sits down with John Hammond to map the real state of hacking: classic ransomware/infostealers meet AI-assisted malware (including code that leverages LLMs). We unpack the ClickFix and FileFix social-engineering patterns, fake CAPTCHA and “save/upload” flows that trick users into running payloads, and the practical Windows mitigations (policy/registry ideas) you should know.
John shares why he estimates 20–30% of attacks now have some AI touch, how social engineering scales, and where defenders can push back. For your career, he argues opportunities are expanding: use CTFs, show your work on GitHub/video, and consider OSCP for signaling. He also introduces Just Hacking Training (JHT), handson hack-alongs, archived CTFs, free upskill challenges, and pay-what-you-want courses with industry all-stars.
What you’ll learn:
• How ClickFix/FileFix actually trick users
• Realistic mitigation tactics you can apply
• The current role of AI in malware
• Career roadmap: CTFs → OSCP → portfolio
• Where to get hands-on: JHT resources
// John Hammond’s SOCIALS //
YouTube: / @_johnhammond
X: x.com/_johnhammond
LinkedIn: / johnhammond010
Discord: / discord
Instagram: / _johnhammond
TikTok: / johnhammond010
GitHub: github.com/JohnHammond
Humble Bundle: www.humblebundle.com/?partner...
Just Hacking Training: www.justhacking.com/
ClickFix Website: clickfix-wiki.github.io/
// YouTube video REFERENCE //
Linux got hacked with this AI Image: • Linux got Hacked with this AI image!
Hackers trick everyone to run malware (FileFix): • hackers trick everyone to run malware (Fil...
OSINT Tools to track you down: • OSINT tools to track you down. You cannot ...
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: [email protected]
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
508 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.