
#607: How Hackers Steal Your Accounts Even With 2FA Enabled
Get every episode summarized
Each time David Bombal publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
Is Microsoft Defender enough to protect your PC? Malware researcher Leo joins me at Black Hat to discuss antivirus, Windows security and how hackers steal your accounts.
We explore how infostealers target saved passwords and session tokens, why two-factor authentication cannot prevent every account takeover, and how a message from a compromised friend’s account can lead to an infection.
Leo shares practical starting points for investigating your computer, including Autoruns for startup entries, TCPView for linking connections to applications, and Wireshark for examining network traffic. We also discuss password managers, account recovery planning, Windows telemetry and why switching operating systems does not eliminate security risks.
In this interview:
• Microsoft Defender’s strengths and limitations
• Free tools for investigating suspicious Windows activity
• How infostealers and initial access brokers operate
• Stolen session tokens and the limits of 2FA
• Fake download sites, malicious ads and targeted phishing
• Preparing recovery options before your accounts are compromised
• Security and privacy trade-offs across Windows, Linux and macOS
// Leo’s SOCIAL //
YouTube: / @pcsecuritychannel
X: https://x.com/leotday
Discord: / discord
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: [email protected]
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
#malware #bhusa2026 #microsoftdefender
Get every episode summarized
Each time David Bombal publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from David Bombal

#608: Before You Deploy AI Agents, Understand These Attacks
David Bombal

#606: Is Cybersecurity Still Worth Learning in 2026?
David Bombal

#605: Flock Cameras: What They Can Reveal About Your Life
David Bombal

#604: How He Infiltrated LockBit and Helped Get Them Indicted
David Bombal