Skip to main content
Attack surface

Attack surface

Search complete. 46 mentions across 10 episodes found for "Attack surface".

Oct 1, 2026

speaker_0HOST
11:06
Right? What if they don't need to decipher a complex API architecture? What if they just use the one protocol every organization on Earth leaves wide open by default? Email.
speaker_1HOST
11:18
When a service is explicitly designed to accept unsolicited outside data, the attack surface becomes functionally infinite.
speaker_0HOST
11:25
Exactly.
speaker_0HOST
11:26
This brings us to Microsoft Security Research's report on the exploitation of the Zimbra Collaboration Suite.
Anna AnisinHOST
1:49
And today, we're asking a pretty important question.
Anna AnisinHOST
1:52
What happens when AI isn't just a tool we're protecting, but becomes part of the attack surface itself, which is kind of scary, right? And we'll talk about LLM security, prompt injection, agentic AI, adversarial attacks, AI loss of control risk, red teaming, which I would like to learn more about that one myself, and what security teams need to start doing differently as AI systems become increasingly autonomous.
Anna AnisinHOST
2:19
Ritika, it's such a pleasure to have you with us today.
Anna AnisinHOST
2:22
Let's

11 MINS LATER

Ritika VermaGUEST
12:53
So like, what is the system supposed to do? What tools access does it have? Then what guardrails are in place? And then what do they seem to be looking for? After that, once you have all of that, then it comes chaining.
Ritika VermaGUEST
13:05
So building context across turns, then establishing the framing early and then getting the model into a state that, you know, whatever the desired state you have in your mind becomes possible.
Ritika VermaGUEST
13:17
the system perspective like yeah the persistence contextual then i think so the last thing was that you know while conducting such attacks you understand that model is like one part of the attack surface so often like breaking the model isn't like the most interesting part so maybe you manipulate like you know what data enters into the retrieval pipeline then maybe you influence a tool's response maybe the output is like passed downstream from obviously one system to another so you see what how the model is working in coherence with the infrastructure.
Ritika VermaGUEST
13:49
These were my takeaways
Andrzej OlchawaGUEST
9:31
works.
Andrzej OlchawaGUEST
9:33
I think the most important thing is to understand that The actual space attack surface is very narrow and it's very small.
Andrzej OlchawaGUEST
9:44
Even if we are talking about constellations, all those spacecraft are always the same.
Andrzej OlchawaGUEST
9:51
There might be thousands of spacecraft flying in the constellation, but they are pretty much the same and they represent like one attack surface, like one node in the whole system.
Andrzej OlchawaGUEST
10:01
And most of the system actually is present in the ground segment.
Andrzej OlchawaGUEST
10:09
And that is a compilation of many, many different technologies, many different infrastructure, hardware and software.

6 MINS LATER

Milenko StarcikGUEST
16:20
That's also a question people ask.
Milenko StarcikGUEST
16:22
It's like, do I need to know about radio? Do I need to have an antenna to do this kind of stuff? And realistically, no.
speaker_1HOST
21:10
Are we just helping them?
speaker_0HOST
21:12
Exactly.
speaker_0HOST
21:13
Are our complex, deeply integrated security infrastructures actually becoming the most vulnerable attack surfaces we own? Are we spending millions of dollars to build the very rulebook the intruders need to bypass the guards?
speaker_1HOST
21:26
It's a terrifying thought.
speaker_0HOST
21:28
Something to think about as you reviewed your logs today.

Unknown podcast

A Zero-Day in Meta's AI Agent Muse Shows What 'Permissions' Really Mean

Sep 22 · 2 Mentions

speaker_2HOST
4:23
It's an outside real world data point rather than a company's self-reported metric, and it points the same direction.
speaker_2HOST
4:31
Agent permissions are a genuine attack surface.
speaker_2HOST
4:34
Rare failures matter once you're operating at scale, and vigilance from the vendor plus fast patching is currently the main defense we have.
speaker_2HOST
4:42
Nothing here tells us the agent itself acted with any independent intent.
speaker_2HOST
6:06
This is a mundane, familiar kind of software vulnerability wearing an AI costume.
speaker_2HOST
6:12
Serious for the people whose accounts could have been exposed, but not evidence of an AI system doing anything on its own.
speaker_2HOST
6:19
What it does tell you is that giving AI agents real-world permissions creates real-world attack surfaces, and that's exactly the kind of control question this show exists to keep tracking.
speaker_2HOST
6:30
Not because it's dramatic, but because it's the boring, practical stuff that will actually determine whether we manage this technology safely.
U.S.HOST
6:48
Segment three, $7.7 million in RSE safe exploit.
U.S.HOST
6:55
Automation expands your wallet's attack surface.
U.S.HOST
6:58
Our third story isn't technically an AI agent attack, but it demonstrates exactly why we're watching wallet automation and AI agents so closely.
U.S.HOST
7:08
On September 15th, an attacker targeted a safe wallet holding roughly 2,900 RSEs worth approximately $7.7 million.
U.S.HOST
8:15
Crazy story, but the security lesson matters more than the plot twist.
U.S.HOST
8:21
Every module you attach to a wallet adds functionality.
U.S.HOST
8:25
It may also add authority, and authority is an attack surface.
U.S.HOST
8:30
We're moving towards wallets where software agents rebalance assets, execute trades, bridge funds, claim rewards, and interact with DeFi automatically.
Sec GuyHOST
0:00
Welcome back to the SecGuide channel.
Sec GuyHOST
0:02
In this section, we're covering threat vectors and attack surfaces.
Sec GuyHOST
0:06
This is not theory.
Sec GuyHOST
0:08
This is identification.
Sec GuyHOST
0:24
A threat vector is the path an attacker uses to gain access.
Sec GuyHOST
0:28
An attack surface is the total number of exposed entry points that attacker can use.
Sec GuyHOST
0:34
One environment can have many attack surfaces, and each surface can be targeted through different vectors.
Sec GuyHOST
0:41
If you can identify the vector, you are usually one step away from identifying the correct control, the correct mitigation, and the correct answer on the exam.
speaker_0NARRATOR
0:00
Theoretical recap.
speaker_0NARRATOR
0:01
The attack surface is the sum of all points where an unauthorized actor can attempt to enter, extract, or manipulate data within a system.
speaker_0NARRATOR
0:08
It includes entry points, HTTP endpoints, forms, APIs, file uploads, cookies, headers, data flows, crossing trust boundaries, and the assets those flows expose.
speaker_0NARRATOR
0:20
A useful mental model.
speaker_0NARRATOR
0:24
Doors, windows, air vents, and delivery hatches are your entry points.
speaker_0NARRATOR
0:29
The trust boundaries are the walls separating public zones from restricted rooms, and the valuables inside are your assets.
speaker_0NARRATOR
0:35
Reducing the attack surface means having fewer doors, stronger walls, and knowing exactly what each door leads to.
speaker_0NARRATOR
0:41
A practical way to enumerate the surface is to walk every input a user, authenticated or not, can control, then map it to the component that processes it and the data it touches.
speaker_0NARRATOR
0:00
The attack surface is one of the most important concepts in application security and threat modeling.
speaker_0NARRATOR
0:05
Now that you have practiced drawing data flow diagrams, applying the stride methodology, building threat matrices, and evaluating applications against secure design principles such as least privilege and defense in depth, you are ready to formalize the notion that ties all of these together.
speaker_0NARRATOR
0:19
The attack surface.
speaker_0NARRATOR
0:21
Understanding it is essential because it directly answers a practical question you will face constantly as a pentester and DevSecOps specialist.
speaker_0NARRATOR
0:28
Where can an attacker actually reach my application, and what should I test or protect first? Definition The attack surface of an application is the complete set of points through which an attacker, called a threat agent, can attempt to enter data into, extract data from, or otherwise interact with a system.
speaker_0NARRATOR
0:45
In simpler terms, it is the sum of all the ways an outsider or insider can try to influence or abuse the system.
speaker_0NARRATOR
0:51
Every input field, every network port, every application programming interface endpoint, every file upload, every cookie, every configuration parameter, and every trusted external dependency is part of the attack surface.
speaker_0NARRATOR
1:04
A key principle to remember, the larger the attack surface, the greater the risk.
Mr. NHIHOST
5:47
Okay.
Mr. NHIHOST
5:49
And the final question, and this will be hopefully a good segue into our main discussion, but do you think we're underestimating the attack surface that's being created by thousands of agents that are being spawned up every day?
Henrique TeixeiraGUEST
6:05
I think we are underestimating it a little bit.
Henrique TeixeiraGUEST
6:08
But like I said, it's a mix of hype and reality.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.