Rephonic
Artwork for Surfacing Security

Surfacing Security

Assetnote
Attack Surface Management
Servicenow
Cybersecurity
Vulnerabilities
Remote Code Execution
Asset Discovery
DNS Resolution
Security Research
Cloud Security
Open Source Tools
Mitigation Strategies
Cloud-Hosted Solutions
Database Security
Enterprise Software
Magento
Reconnaissance
Bug Bounty
Security Scanning
DNS Poisoning
Networking

In "Surfacing Security," we explore a variety of cybersecurity topics relevant to Attack Surface Management and beyond. Your co-hosts are Michael Gianarakis (Assetnote Co-Founder/CEO) and Shubham Shah (Assetnote Co-Founder/CTO).

PublishesTwice weeklyEpisodes11Foundeda year ago
Categories
TechnologyBusiness

Listen to this Podcast

Artwork for Surfacing Security

Latest Episodes

Running an effective bug bounty program requires balancing an attractive scope and payout to hunters with an attack surface that challenges hunters to do more than automated scans. Program managers want to pay for skillful findings, not automated one... more

In this episode, we discuss the blindspots of IP-centric approaches to asset discovery and the importance of understanding the full attack surface of an organization.

We unpack the challenges posed by modern cloud architectures, load balancers, and ... more

This week's episode dives deep into the concept of shadow exposure and how it relates to third-party software, often overlooked in discussions about shadow IT. We explore the historical context of shadow IT, its evolution, and the real risks associat... more

In this more technical episode, we dive deep into the complexities of DNS and DNS resolution in the context of Attack Surface Management (ASM). Join us as we explore the unseen challenges that arise when scaling asset discovery, particularly when dea... more

Key Facts

Contact Information
Podcast Host

Similar Podcasts

People also subscribe to these shows.

Critical Thinking - Bug Bounty Podcast
Critical Thinking - Bug Bounty PodcastJustin Gardner (Rhynorater) & Joseph Thacker (Rez0)

Recent Guests

Adam Kues
Security researcher at Assetnote.
Assetnote
Episode: A Deep Dive into Three ServiceNow Vulnerabilities (with Adam Kues)

Hosts

Michael Gianarakis
Co-founder and CEO of Assetnote, also co-host for discussions on cybersecurity, focusing on Attack Surface Management and practical security solutions.
Shubham Shah
Co-founder and CTO of Assetnote, co-host discussing intricate aspects of Attack Surface Management and software vulnerabilities.

Chart Rankings

How this podcast ranks in the Apple Podcasts, Spotify and YouTube charts.

Apple Podcasts
#19
Saudi Arabia/Technology

Talking Points

Recent interactions between the hosts and their guests.

Chaining Three Bugs to Access All Your ServiceNow Data (Live Q&A)
Q: Why did you look at ServiceNow as a target for your security research?
The focus was on widely deployed enterprise software, especially given that ServiceNow is critical infrastructure for many customers and has significant impact and risk.
Chaining Three Bugs to Access All Your ServiceNow Data (Live Q&A)
Q: How long did it take you to find the full ServiceNow chain?
It took Adam about four weeks; the first week was learning the platform and the bugs materialized within about a week after that, with lots of experimentation.
Chaining Three Bugs to Access All Your ServiceNow Data (Live Q&A)
Q: What versions were affected by the bug?
Versions Washington and Vancouver were vulnerable to the full bug chain, while Utah and earlier versions had patches for bugs that didn't form the complete chain.
Chaining Three Bugs to Access All Your ServiceNow Data (Live Q&A)
Q: What was the most impact you could get from the template injection?
The template injection could let attackers leak usernames, password hashes, and even pull the entire database if misconfigured, leveraging service connections for internal network access.
Chaining Three Bugs to Access All Your ServiceNow Data (Live Q&A)
Q: How did you figure out the page title was something that would lead to template injection?
Adam explored the ServiceNow codebase, initially looking for cross-site scripting vulnerabilities, and discovered unusual template-based errors when inputting payloads, leading him down a path that revealed the deeper vulnerabilities.

Audience Metrics

Listeners, social reach, demographics and more for this podcast.

Gender Skew
Location
Interests
Professions
Age Range
Household Income
Social Media Reach

Frequently Asked Questions About Surfacing Security

What is Surfacing Security about and what kind of topics does it cover?

With a strong focus on cybersecurity, particularly on the nuances of Attack Surface Management (ASM), the content examines the evolving challenges and methodologies in modern security practices. Key discussions span bug bounty programs, DNS resolution complexities, and vulnerabilities in popular software such as ServiceNow and Magento. The co-hosts often share their insights based on their professional experiences as co-founders of a significant player in the cybersecurity landscape, emphasizing a practical, research-based approach to understanding and managing security exposure. Unique to this podcast is the blend of technical analysis with a business perspective, making it appealing to both cybersecurity professionals and those in busines... more

Where can I find podcast stats for Surfacing Security?

Rephonic provides a wide range of podcast stats for Surfacing Security. We scanned the web and collated all of the information that we could find in our comprehensive podcast database. See how many people listen to Surfacing Security and access YouTube viewership numbers, download stats, audience demographics, chart rankings, ratings, reviews and more.

How many listeners does Surfacing Security get?

Rephonic provides a full set of podcast information for three million podcasts, including the number of listeners. View further listenership figures for Surfacing Security, including podcast download numbers and subscriber numbers, so you can make better decisions about which podcasts to sponsor or be a guest on. You will need to upgrade your account to access this premium data.

What are the audience demographics for Surfacing Security?

Rephonic provides comprehensive predictive audience data for Surfacing Security, including gender skew, age, country, political leaning, income, professions, education level, and interests. You can access these listener demographics by upgrading your account.

How many subscribers and views does Surfacing Security have?

To see how many followers or subscribers Surfacing Security has on Spotify and other platforms such as Castbox and Podcast Addict, simply upgrade your account. You'll also find viewership figures for their YouTube channel if they have one.

Which podcasts are similar to Surfacing Security?

These podcasts share a similar audience with Surfacing Security:

1. Critical Thinking - Bug Bounty Podcast

How many episodes of Surfacing Security are there?

Surfacing Security launched a year ago and published 11 episodes to date. You can find more information about this podcast including rankings, audience demographics and engagement in our podcast database.

How do I contact Surfacing Security?

Our systems regularly scour the web to find email addresses and social media links for this podcast. We scanned the web and collated all of the contact information that we could find in our podcast database. But in the unlikely event that you can't find what you're looking for, our concierge service lets you request our research team to source better contacts for you.

Where can I see ratings and reviews for Surfacing Security?

Rephonic pulls ratings and reviews for Surfacing Security from multiple sources, including Spotify, Apple Podcasts, Castbox, and Podcast Addict.

View all the reviews in one place instead of visiting each platform individually and use this information to decide if a show is worth pitching or not.

How do I access podcast episode transcripts for Surfacing Security?

Rephonic provides full transcripts for episodes of Surfacing Security. Search within each transcript for your keywords, whether they be topics, brands or people, and figure out if it's worth pitching as a guest or sponsor. You can even set-up alerts to get notified when your keywords are mentioned.

What guests have appeared on Surfacing Security?

Recent guests on Surfacing Security include:

1. Adam Kues

To view more recent guests and their details, simply upgrade your Rephonic account. You'll also get access to a typical guest profile to help you decide if the show is worth pitching.

Find and pitch the right podcasts

We help savvy brands, marketers and PR professionals to find the right podcasts for any topic or niche. Get the data and contacts you need to pitch podcasts at scale and turn listeners into customers.
Try it free for 7 days