Security News

Cybersecurity news aggregator

INFO News SC Media

Reducing Attack Surface & Evaluating Efficiency in Agents - Itamar Apelblat, David Goldschlag - ASW #389

  • What: Discussion on reducing attack surface and evaluating efficiency in AI agents
  • Impact: Security professionals are exploring ways to improve agent security and reduce vulnerabilities
Read Full Article →

Subscribe Share Full episode and show notes Application security , Identity , AI benefits/risks Reducing Attack Surface & Evaluating Efficiency in Agents – Itamar Apelblat, David Goldschlag – ASW #389 SquidBleed reveals another vuln that’s been lurking for decades, but its real lesson is in managing an attack surface. Regardless of whatever programming language you use, removing code is one of the best security steps you can take, followed by changing default configs to turn off uncommon features and ancient protocols. The Linux kernel’s removal of strncpy is another example of managing attack surface by replacing a notoriously misused and ambiguous function with more specific versions that better match the developers intent. It was a six-year journey for the kernel, but one that should remove a class of vulns and, importantly, improve performance. Then it’s on to agents with a discussion... June 30, 2026 This episode is sponsored by Full Segment Notes SquidBleed reveals another vuln that's been lurking for decades, but its real lesson is in managing an attack surface. Regardless of whatever programming language you use, removing code is one of the best security steps you can take, followed by changing default configs to turn off uncommon features and ancient protocols. The Linux kernel's removal of strncpy is another example of managing attack surface by replacing a notoriously misused and ambiguous function with more specific versions that better match the developers intent. It was a six-year journey for the kernel, but one that should remove a class of vulns and, importantly, improve performance. Then it's on to agents with a discussion of the newly released OWASP AISVS and yet another example of evaluating LLMs as code reviewers. Agentic AI Has an Identity Problem AI agents are already running inside enterprise environments, operating on credentials, API tokens, and cloud roles that most security teams have never inventoried. When an agent acts autonomously across production systems, the security question is no longer just what it can do but who it is and whether that identity is governed at all. Itamar Apelblat, Co-Founder and CEO of Token Security, discusses why identity is the right lens for understanding agentic AI risk and what practical steps security teams can take now. Segment Resources: https://www.token.security/product https://www.token.security/lp/ai-agent-identity-security-buyers-guide-ebook https://www.token.security/enzo https://www.token.security/ai-agent-calculator This segment is sponsored by Token Security. To lean more, visit https://securityweekly.com/tokenidv Blended Identities and the challenge of IAM for AI AI agents aren't quite human and aren't traditional machines. So how do you secure workflows that involve humans using AI to access sensitive data, and do it at machine speed and scale? David breaks down the challenges and discusses actual implementations of IAM for AI to explain how to solve them. Segment Resources: https://aembit.io/case-study/a-300b-investment-firm-secures-claude-access-with-aembit/ https://aembit.io/blog/aembit-now-secures-microsoft-copilot-studio-agents/ https://www.youtube.com/watch?v=cSInzRUXvNc This segment is sponsored by Aembit. Get the cloud security alliance survey on AI Identities at https://securityweekly.com/aembitidv Guests Itamar Apelblat Co Founder & CEO at Token Security Itamar Apelblat is the Co-Founder and CEO of Token Security, with over 15 years of technical and leadership experience in cybersecurity. A second-time entrepreneur, he previously co-founded a successful fintech startup and served as an officer and R&D group manager in Israel’s elite Unit 8200, where he led cutting-edge cybersecurity initiatives. Itamar has deep experience building enterprise-grade security solutions and works closely with CISOs to tackle complex identity and infrastructure challenges; like agents already running in their environments, often without visibility, governance, or any clear owner, and helps them build the foundation to secure them before the next incident. David Goldschlag CEO & Co-Founder at Aembit David Goldschlag is the co-founder and CEO of Aembit. He is an experienced security entrepreneur, having previously co-founded New Edge Labs (Zero Trust Network Access) and MobileSpaces (mobile security). He has held prior roles as VP at Netskope (which acquired New Edge Labs), SVP Strategy & CTO at Pulse Secure (which acquired MobileSpaces), VP for Mobile at McAfee (which acquired Trust Digital), and CTO of USinternetworking. Early in his career, David worked at the NSA. At the Naval Research Laboratory, he co-invented Onion Routing, which later became Tor. David holds a Ph.D. from the University of Texas at Austin. Hosts Mike Shema https://dangerouserrors.com Tyler Shields https://www.90degree.vc/ Announcements AppSec teams, your backlog is growing faster than you can fix it. SAST and DAST tools are flooding you with findings, developers are pushing back, and prioritizing what actually matters in code is getting harder. So how do you reduce risk without slowing releases? Join the Vulnerability Management Virtual Cybersecurity Summit to learn how teams are prioritizing real exploitable issues, reducing noise, and integrating remediation into modern development workflows. Security Weekly listeners can register for free at https://securityweekly.com/vulnmanagement using the promo code: CSS26-SW List of Articles Mike Shema Squidbleed (CVE-2026-47729) – Calif GitHub – OWASP/AISVS: The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to verify the security of AI-driven applications. Beyond Fable: Can a Local LLM Replace Cloud AI for Security Code Reviews – SRLabs Research Linux Finally Eliminates The strncpy API After Six Years Of Work, 360+ Patches – Phoronix For more details of the changes, check out the final commit . One for all the models out there! CISO Version 2.0 FYI: Harness, Scaffold, and the AI Agent Terms Worth Getting Right Show More Stay in the Know, No Smoke and Mirrors – Join Our Newsletter Get expert insights and technical breakdowns straight to your inbox. Join Now Related Segments Application security How AI Is Reshaping Identity Security at the Infrastructure Layer – Ev Kontsevoy, Neha Duggal, Amit Masand – ASW #388 Application security AI Code Security: Why AppSec Must Evolve for the Era of AI-Generated Code – WC #1 Application security Why Does It Matter Who or What Created the Code? – Matias Madou – ASW #387 Related Content DevSecOps MSSPs need to stop risk before it hits the SOC Identity No more blind trust: Identity controls for AI agents Application security India temporarily blocks Telegram over exam fraud concerns You can skip this ad in 5 seconds

Share this article