Hi everyone,
This week, we sat down with Jay Beale — founder of InGuardians, Black Hat trainer, and one of the people behind the Kubernetes CTF at DEF CON.
The episode starts exactly where a good security conversation should: with old-school stories about physical penetration testing, social engineering, bad assumptions, and the kind of “how did you even get in there?” moments that still teach useful lessons today.
But the conversation quickly moves into today’s infrastructure problems. Jay explains why Kubernetes is such an important security platform to understand, how he teaches attack and defense hands-on, and why the DEF CON Kubernetes CTF is built not just for competitors but also for people who want to learn in a guided, welcoming way.
The big takeaway: AI systems do not float in magic AI space. They run on real infrastructure. If that infrastructure is Kubernetes, attackers can abuse service accounts, storage access, and vector databases just like any other target. And when a RAG system trusts a poisoned vector store, indirect prompt injection becomes more than a clever demo — it can become a persistent attack path.
Links from the episode
Jay Beale on LinkedIn: https://www.linkedin.com/in/jaybeale/
InGuardians: https://www.inguardians.com/
DEF CON: https://defcon.org/
Jay's Black Hat USA Course: Agentic AI-aided Kubernetes Attack and Defense: https://blackhat.com/us-26/training/schedule/index.html?day=4daysattue#agentic-ai-aided-kubernetes-attack-and-defense-51318
Quote from this week’s episode
Your job is to make it, and my job is to break it.
— Jay Beale
Tom’s take
What I loved about this conversation is that Jay connects the old and the new. The physical pentest stories are hilarious (yes, I did actually hire Jay to break into a building), but the lesson is the same one we keep relearning with AI: attackers follow trust, shortcuts, and excessive access. Whether it is a lobby kiosk, a training-room computer, a Kubernetes service account, or a vector store full of “trusted” documents, the weak point is often the assumption that nobody will look at the system sideways.
Also worth your attention this week
Age verification laws keep expanding into the open web. The Intercept and EFF have been warning that online age-verification mandates can chill anonymous speech, journalism, whistleblowing, and access to information. The privacy issue is not just “adult sites” — it is whether more of the internet starts requiring identity checks by default. Source: https://theintercept.com/ and https://www.eff.org/
Flock license plate reader abuse keeps surfacing. 404 Media and related reporting continue to document allegations of police misuse of Flock ALPR systems, including stalking-related abuse. It is a strong reminder that surveillance databases are only as safe as the people and policies controlling access. Source: https://www.404media.co/
AI coding agents can be tricked by “clean” repositories. Recent BleepingComputer/Bluesky signals highlighted research showing that a repo that appears safe can hide behaviors that agentic coding tools execute or trust. As more developers hand tasks to agents, repo trust and execution boundaries matter a lot more. Source: https://www.bleepingcomputer.com/
Listen / Watch
🎧 Audio Podcast: https://sharedsecurity.net/2026/06/29/jay-beale-on-kubernetes-def-con-and-ai-attack-paths/
▶️ YouTube Version: https://youtu.be/aMHk62dprDA
We’d love your feedback
Reply and tell us what you thought of this episode. Have you seen AI agents or Kubernetes security show up in your work yet? We would also appreciate a rating/review in your podcast app and a comment on YouTube — both help more listeners find the show.
Thank you to our sponsors!
🎁 Get 10% off your order of high quality faraday products built to protect your privacy from SLNT! Visit: https://slnt.com and use discount code "sharedsecurity" at checkout.
Closing
If this episode helped you, please subscribe on YouTube, consider supporting the channel through YouTube membership, follow Shared Security on your favorite social platform, and share the episode with someone who works on cloud, Kubernetes, or AI security.
Stay safe, stay secure, and stay private.
Tom Eston
Founder and Host, Shared Security Podcast

