- What: A discussion on securing AI agent attack surfaces.
- Impact: Relevant to organizations adopting AI and LLMs.
Subscribe Share Full episode and show notes Application security , AI benefits/risks , Generative AI Discovering & Securing Your AI Agent Attack Surface – Jeremy Snyder – ASW #391 While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order to help orgs understand and prioritize their attack surface. A lot of orgs don’t have to deal with model-specific threats or building their own GPU architecture, but every org adopting LLMs and agents should be aware of how those agents are being invoked and the output those agents are producing. That awareness of input and output helps in identifying and mitigating prompt injection attacks, ensuring agents are working within their expected boundaries, and taming token budget... July 14, 2026 Full Segment Notes While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order to help orgs understand and prioritize their attack surface. A lot of orgs don't have to deal with model-specific threats or building their own GPU architecture, but every org adopting LLMs and agents should be aware of how those agents are being invoked and the output those agents are producing. That awareness of input and output helps in identifying and mitigating prompt injection attacks, ensuring agents are working within their expected boundaries, and taming token budgets. Resources: https://genai.owasp.org/llm-top-10/ https://github.com/rtk-ai/rtk https://docs.aws.amazon.com/bedrock/latest/userguide/prompt-caching.html https://www.firetail.ai/blog/beyond-the-spectacle-rsac-2026-and-the-5-layers-of-ai-security Guest Jeremy Snyder Founder and CEO at FireTail.io https://www.firetail.io/ Jeremy Snyder is the Founder and CEO of FireTail.io. He thrives on solving complex challenges in the cloud, cybersecurity, and robotics domains. With a specialty in cloud security, M&A, and international business strategy, Jeremy has helped numerous rapidly growing companies navigate new markets. He is fluent in five languages and possesses a unique ability to analyze emerging industries and recognize key security patterns. Jeremy is a recognized expert making significant contributions to the digital security sector, particularly in the realm of API security and cloud-native environments. Hosts Mike Shema https://dangerouserrors.com Tyler Shields https://www.90degree.vc/ Announcements AppSec teams, your backlog is growing faster than you can fix it. SAST and DAST tools are flooding you with findings, developers are pushing back, and prioritizing what actually matters in code is getting harder. So how do you reduce risk without slowing releases? Join the Vulnerability Management Virtual Cybersecurity Summit to learn how teams are prioritizing real exploitable issues, reducing noise, and integrating remediation into modern development workflows. Security Weekly listeners can register for free at https://securityweekly.com/vulnmanagement using the promo code: CSS26-SW CyberRisk TV is proud to be an official media partner of Black Hat USA 2026! We'll be broadcasting live from the Black Hat LIVEWIRE Studio, where application security innovators can showcase the technologies, research, and strategies shaping the future of secure software development. Our Executive Interviews and Event Momentum Packages help you stay in front of developers and AppSec teams long after Black Hat ends. Fewer than 10 interview opportunities remain, so visit https://securityweekly.com/exec today and reserve your spot before they're gone. List of Articles Mike Shema GhostApproval: AI Coding Assistant Trust Boundary Flaw | Wiz Blog AI coding agents vulnerability: GuardFall shell injeciton | Adversa AI GPT-5.5-Cyber built a zlib fuzzing lab in a day – The Trail of Bits Blog GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos – Noma Security Show More Stay in the Know, No Smoke and Mirrors – Join Our Newsletter Get expert insights and technical breakdowns straight to your inbox. Join Now Related Segments DevSecOps Hungry? We talk Smoked Meat, Poutine, and Bagel – also, Identiverse Interviews! – François Proulx, John Pritchard, Cassie Christensen, Jaime Lewis-Gross, Kim Brown – ESW #467 Application security Defense-in-depth strategies for securing mobile applications – Ryan Lloyd – ASW #390 Application security AI is Writing Your Code… And It’s Insecure | The New AppSec Reality – WC #1 Related Content AI/ML ‘GitLost’ prompt injection leaks private repos via GitHub Agentic Workflows Application security Your edge infrastructure has no witness AI/ML Malicious websites trick AI agents into crypto payments, context poisoning You can skip this ad in 5 seconds