The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Security Weekly Podcast Network
Security Weekly Podcast Network artwork

Reducing Attack Surface & Evaluating Efficiency in Agents - Itamar Apelblat, David Goldschlag - ASW #389

Security Weekly Podcast Network · 2026-06-30 · 1h 13m

0:00--:--

Episode notes

SquidBleed reveals another vuln that's been lurking for decades, but its real lesson is in managing an attack surface. Regardless of whatever programming language you use, removing code is one of the best security steps you can take, followed by changing default configs to turn off uncommon features and ancient protocols. The Linux kernel's removal of strncpy is another example of managing attack surface by replacing a notoriously misused and ambiguous function with more specific versions that better match the developers intent. It was a six-year journey for the kernel, but one that should remove a class of vulns and, importantly, improve performance. Then it's on to agents with a discussion of the newly released OWASP AISVS and yet another example of evaluating LLMs as code reviewers. Agentic AI Has an Identity Problem AI agents are already running inside enterprise environments, operating on credentials, API tokens, and cloud roles that most security teams have never inventoried. When an agent acts autonomously across production systems, the security question is no longer just what it can do but who it is and whether that identity is governed at all.

More from Security Weekly Podcast Network

All episodes →
  • Performance Through People as Executives Struggle and Mentorship Matters - Greg Hoffman - BSW #45459 / 100
  • Linux Tech Segment & Vulnerabilities Galore - PSW #933
  • AI Cocaine Recipes, Russian Hack, Scattered Spider, Cisco, Amazon Q - Aaran Leyland - SWN #594
  • Fixing pentesting, Meta is destroying its engineering org, the weekly news - Adriel Desautels - ESW #465
  • AI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8, Josh Marpet - SWN #593
Explore the best B2B Engineering & DevTools podcasts →
All Security Weekly Podcast Network episodes →