Uploaded June 2026 | Updated September 2026, 2 weeks ago
SquidBleed reveals another vuln that's been lurking for decades, but its real lesson is in managing an attack surface. Regardless of whatever programming language you use, removing code is one of the best security steps you can take, followed by changing default configs to turn off uncommon features and ancient protocols.
The Linux kernel's removal of strncpy is another example of managing attack surface by replacing a notoriously misused and ambiguous function with more specific versions that better match the developers intent. It was a six-year journey for the kernel, but one that should remove a class of vulns and, importantly, improve performance.
Then it's on to agents with a discussion of the newly released OWASP AISVS and yet another example of evaluating LLMs as code reviewers.
Agentic AI Has an Identity Problem
AI agents are already running inside enterprise environments, operating on credentials, API tokens, and cloud roles that most security teams have never inventoried. When an agent acts autonomously across production systems, the security question is no longer just what it can do but who it is and whether that identity is governed at all. Itamar Apelblat, Co-Founder and CEO of Token Security, discusses why identity is the right lens for understanding agentic AI risk and what practical steps security teams can take now.
Segment Resources:
- https://www.token.security/product
- https://www.token.security/lp/ai-agent-identity-security-buyers-guide-ebook
- https://www.token.security/enzo
- https://www.token.security/ai-agent-calculator
This segment is sponsored by Token Security. To lean more, visit securityweekly.com/tokenidv
Blended Identities and the challenge of IAM for AI
AI agents aren't quite human and aren't traditional machines. So how do you secure workflows that involve humans using AI to access sensitive data, and do it at machine speed and scale? David breaks down the challenges and discusses actual implementations of IAM for AI to explain how to solve them.
Segment Resources:
- aembit.io/case-study/a-300b-investment-firm-secures-claude-access-with-aembit
- aembit.io/blog/aembit-now-secures-microsoft-copilot-studio-agents
- youtube.com/watch?v=cSInzRUXvNc
This segment is sponsored by Aembit. Get the cloud security alliance survey on AI Identities at securityweekly.com/aembitidv
Visit securityweekly.com/asw for all the latest episodes!
Show Notes: securityweekly.com/asw-389
00:00:00 Welcome to ASW: Latest AppSec News
00:01:49 Decades-Old SquidBleed and Attack Surface
00:11:53 Six-Year Journey to Remove strncpy
00:19:41 New AI Security Verification Standard
00:27:52 Evaluating LLMs for Security Code Reviews
00:35:08 Deception, Pricing, and AI Agent Terminology
00:39:40 David Goldschlag on AI Agent Identity Problem
00:44:40 Understanding Risks and Securing Claude Access
00:48:35 Managing Blended Identities for AI Agents
00:51:05 Granular Access Control and CISO Enablement
00:57:27 Itamar Apelblat on AI Agent Inventory & Privilege
01:01:21 Discovering Shadow AI and Scaling Identity Tools
01:06:37 Managing Agent Life Cycle and Future AI Security
SquidBleed reveals another vuln that's been lurking for decades, but its real lesson is in managing an attack surface. Regardless of whatever programming language you use, removing code is one of the best security steps you can take, followed by changing default configs to turn off uncommon features and ancient protocols.
The Linux kernel's removal of strncpy is another example of managing attack surface by replacing a notoriously misused and ambiguous function with more specific versions that better match the developers intent. It was a six-year journey for the kernel, but one that should remove a class of vulns and, importantly, improve performance.
Then it's on to agents with a discussion of the newly released OWASP AISVS and yet another example of evaluating LLMs as code reviewers.
Agentic AI Has an Identity Problem
AI agents are already running inside enterprise environments, operating on credentials, API tokens, and cloud roles that most security teams have never inventoried. When an agent acts autonomously across production systems, the security question is no longer just what it can do but who it is and whether that identity is governed at all. Itamar Apelblat, Co-Founder and CEO of Token Security, discusses why identity is the right lens for understanding agentic AI risk and what practical steps security teams can take now.
Segment Resources:
- https://www.token.security/product
- https://www.token.security/lp/ai-agent-identity-security-buyers-guide-ebook
- https://www.token.security/enzo
- https://www.token.security/ai-agent-calculator
This segment is sponsored by Token Security. To lean more, visit securityweekly.com/tokenidv
Blended Identities and the challenge of IAM for AI
AI agents aren't quite human and aren't traditional machines. So how do you secure workflows that involve humans using AI to access sensitive data, and do it at machine speed and scale? David breaks down the challenges and discusses actual implementations of IAM for AI to explain how to solve them.
Segment Resources:
- aembit.io/case-study/a-300b-investment-firm-secures-claude-access-with-aembit
- aembit.io/blog/aembit-now-secures-microsoft-copilot-studio-agents
- youtube.com/watch?v=cSInzRUXvNc
This segment is sponsored by Aembit. Get the cloud security alliance survey on AI Identities at securityweekly.com/aembitidv
Visit securityweekly.com/asw for all the latest episodes!
Show Notes: securityweekly.com/asw-389
00:00:00 Welcome to ASW: Latest AppSec News
00:01:49 Decades-Old SquidBleed and Attack Surface
00:11:53 Six-Year Journey to Remove strncpy
00:19:41 New AI Security Verification Standard
00:27:52 Evaluating LLMs for Security Code Reviews
00:35:08 Deception, Pricing, and AI Agent Terminology
00:39:40 David Goldschlag on AI Agent Identity Problem
00:44:40 Understanding Risks and Securing Claude Access
00:48:35 Managing Blended Identities for AI Agents
00:51:05 Granular Access Control and CISO Enablement
00:57:27 Itamar Apelblat on AI Agent Inventory & Privilege
01:01:21 Discovering Shadow AI and Scaling Identity Tools
01:06:37 Managing Agent Life Cycle and Future AI Security










