
Attack surface
46
MENTIONS
10
EPISODES
8
PODCASTS
Search complete. 46 mentions across 10 episodes found for "Attack surface".
Oct 1, 2026
Cyber Mornings Daily - October 1st, 2026
S
11:06speaker_0HOST
Right? What if they don't need to decipher a complex API architecture? What if they just use the one protocol every organization on Earth leaves wide open by default? Email.
S
11:18speaker_1HOST
When a service is explicitly designed to accept unsolicited outside data, the attack surface becomes functionally infinite.
S
11:25speaker_0HOST
Exactly.
S
11:26speaker_0HOST
This brings us to Microsoft Security Research's report on the exploitation of the Zimbra Collaboration Suite.
When AI Becomes the Attack Surface, Securing LLMs, Agents & the Enterprise
A
1:49Anna AnisinHOST
And today, we're asking a pretty important question.
A
1:52Anna AnisinHOST
What happens when AI isn't just a tool we're protecting, but becomes part of the attack surface itself, which is kind of scary, right? And we'll talk about LLM security, prompt injection, agentic AI, adversarial attacks, AI loss of control risk, red teaming, which I would like to learn more about that one myself, and what security teams need to start doing differently as AI systems become increasingly autonomous.
A
2:19Anna AnisinHOST
Ritika, it's such a pleasure to have you with us today.
A
2:22Anna AnisinHOST
Let's
11 MINS LATER
R
12:53Ritika VermaGUEST
So like, what is the system supposed to do? What tools access does it have? Then what guardrails are in place? And then what do they seem to be looking for? After that, once you have all of that, then it comes chaining.
R
13:05Ritika VermaGUEST
So building context across turns, then establishing the framing early and then getting the model into a state that, you know, whatever the desired state you have in your mind becomes possible.
R
13:17Ritika VermaGUEST
the system perspective like yeah the persistence contextual then i think so the last thing was that you know while conducting such attacks you understand that model is like one part of the attack surface so often like breaking the model isn't like the most interesting part so maybe you manipulate like you know what data enters into the retrieval pipeline then maybe you influence a tool's response maybe the output is like passed downstream from obviously one system to another so you see what how the model is working in coherence with the infrastructure.
R
13:49Ritika VermaGUEST
These were my takeaways
Space cybersecurity starts on the ground.
A
9:31Andrzej OlchawaGUEST
works.
A
9:33Andrzej OlchawaGUEST
I think the most important thing is to understand that The actual space attack surface is very narrow and it's very small.
A
9:44Andrzej OlchawaGUEST
Even if we are talking about constellations, all those spacecraft are always the same.
A
9:51Andrzej OlchawaGUEST
There might be thousands of spacecraft flying in the constellation, but they are pretty much the same and they represent like one attack surface, like one node in the whole system.
A
10:01Andrzej OlchawaGUEST
And most of the system actually is present in the ground segment.
A
10:09Andrzej OlchawaGUEST
And that is a compilation of many, many different technologies, many different infrastructure, hardware and software.
6 MINS LATER
M
16:20Milenko StarcikGUEST
That's also a question people ask.
M
16:22Milenko StarcikGUEST
It's like, do I need to know about radio? Do I need to have an antenna to do this kind of stuff? And realistically, no.
Cyber Mornings Daily - September 27th, 2026
S
21:10speaker_1HOST
Are we just helping them?
S
21:12speaker_0HOST
Exactly.
S
21:13speaker_0HOST
Are our complex, deeply integrated security infrastructures actually becoming the most vulnerable attack surfaces we own? Are we spending millions of dollars to build the very rulebook the intruders need to bypass the guards?
S
21:26speaker_1HOST
It's a terrifying thought.
S
21:28speaker_0HOST
Something to think about as you reviewed your logs today.
P
Unknown podcast
A Zero-Day in Meta's AI Agent Muse Shows What 'Permissions' Really Mean
Sep 22 · 2 Mentions
S
4:23speaker_2HOST
It's an outside real world data point rather than a company's self-reported metric, and it points the same direction.
S
4:31speaker_2HOST
Agent permissions are a genuine attack surface.
S
4:34speaker_2HOST
Rare failures matter once you're operating at scale, and vigilance from the vendor plus fast patching is currently the main defense we have.
S
4:42speaker_2HOST
Nothing here tells us the agent itself acted with any independent intent.
S
6:06speaker_2HOST
This is a mundane, familiar kind of software vulnerability wearing an AI costume.
S
6:12speaker_2HOST
Serious for the people whose accounts could have been exposed, but not evidence of an AI system doing anything on its own.
S
6:19speaker_2HOST
What it does tell you is that giving AI agents real-world permissions creates real-world attack surfaces, and that's exactly the kind of control question this show exists to keep tracking.
S
6:30speaker_2HOST
Not because it's dramatic, but because it's the boring, practical stuff that will actually determine whether we manage this technology safely.
Case File #79: Trust Is the Attack Surface
U
6:48U.S.HOST
Segment three, $7.7 million in RSE safe exploit.
U
6:55U.S.HOST
Automation expands your wallet's attack surface.
U
6:58U.S.HOST
Our third story isn't technically an AI agent attack, but it demonstrates exactly why we're watching wallet automation and AI agents so closely.
U
7:08U.S.HOST
On September 15th, an attacker targeted a safe wallet holding roughly 2,900 RSEs worth approximately $7.7 million.
U
8:15U.S.HOST
Crazy story, but the security lesson matters more than the plot twist.
U
8:21U.S.HOST
Every module you attach to a wallet adds functionality.
U
8:25U.S.HOST
It may also add authority, and authority is an attack surface.
U
8:30U.S.HOST
We're moving towards wallets where software agents rebalance assets, execute trades, bridge funds, claim rewards, and interact with DeFi automatically.
Threat Vectors & Attack Surfaces Explained
S
0:00Sec GuyHOST
Welcome back to the SecGuide channel.
S
0:02Sec GuyHOST
In this section, we're covering threat vectors and attack surfaces.
S
0:06Sec GuyHOST
This is not theory.
S
0:08Sec GuyHOST
This is identification.
S
0:24Sec GuyHOST
A threat vector is the path an attacker uses to gain access.
S
0:28Sec GuyHOST
An attack surface is the total number of exposed entry points that attacker can use.
S
0:34Sec GuyHOST
One environment can have many attack surfaces, and each surface can be targeted through different vectors.
S
0:41Sec GuyHOST
If you can identify the vector, you are usually one step away from identifying the correct control, the correct mitigation, and the correct answer on the exam.
Map the Blog's attack surface
S
0:00speaker_0NARRATOR
Theoretical recap.
S
0:01speaker_0NARRATOR
The attack surface is the sum of all points where an unauthorized actor can attempt to enter, extract, or manipulate data within a system.
S
0:08speaker_0NARRATOR
It includes entry points, HTTP endpoints, forms, APIs, file uploads, cookies, headers, data flows, crossing trust boundaries, and the assets those flows expose.
S
0:20speaker_0NARRATOR
A useful mental model.
S
0:24speaker_0NARRATOR
Doors, windows, air vents, and delivery hatches are your entry points.
S
0:29speaker_0NARRATOR
The trust boundaries are the walls separating public zones from restricted rooms, and the valuables inside are your assets.
S
0:35speaker_0NARRATOR
Reducing the attack surface means having fewer doors, stronger walls, and knowing exactly what each door leads to.
S
0:41speaker_0NARRATOR
A practical way to enumerate the surface is to walk every input a user, authenticated or not, can control, then map it to the component that processes it and the data it touches.
Attack surface — definition and identification
S
0:00speaker_0NARRATOR
The attack surface is one of the most important concepts in application security and threat modeling.
S
0:05speaker_0NARRATOR
Now that you have practiced drawing data flow diagrams, applying the stride methodology, building threat matrices, and evaluating applications against secure design principles such as least privilege and defense in depth, you are ready to formalize the notion that ties all of these together.
S
0:19speaker_0NARRATOR
The attack surface.
S
0:21speaker_0NARRATOR
Understanding it is essential because it directly answers a practical question you will face constantly as a pentester and DevSecOps specialist.
S
0:28speaker_0NARRATOR
Where can an attacker actually reach my application, and what should I test or protect first? Definition The attack surface of an application is the complete set of points through which an attacker, called a threat agent, can attempt to enter data into, extract data from, or otherwise interact with a system.
S
0:45speaker_0NARRATOR
In simpler terms, it is the sum of all the ways an outsider or insider can try to influence or abuse the system.
S
0:51speaker_0NARRATOR
Every input field, every network port, every application programming interface endpoint, every file upload, every cookie, every configuration parameter, and every trusted external dependency is part of the attack surface.
S
1:04speaker_0NARRATOR
A key principle to remember, the larger the attack surface, the greater the risk.
Henrique Teixeira is Mr NHI's Human Identity In The Hot Seat
M
5:47Mr. NHIHOST
Okay.
M
5:49Mr. NHIHOST
And the final question, and this will be hopefully a good segue into our main discussion, but do you think we're underestimating the attack surface that's being created by thousands of agents that are being spawned up every day?
H
6:05Henrique TeixeiraGUEST
I think we are underestimating it a little bit.
H
6:08Henrique TeixeiraGUEST
But like I said, it's a mix of hype and reality.