Reducing Attack Surface & Evaluating Efficiency in Agents – Itamar Apelblat, David Goldschlag – ASW #389
Itamar Apelblat is the Co-Founder and CEO of Token Security, with over 15 years of technical and leadership experience in cybersecurity. A second-time entrepreneur, he previously co-founded a successful fintech startup and served as an officer and R&D group manager in Israel’s elite Unit 8200, where he led cutting-edge cybersecurity initiatives. Itamar has deep experience building enterprise-grade security solutions and works closely with CISOs to tackle complex identity and infrastructure challenges; like agents already running in their environments, often without visibility, governance, or any clear owner, and helps them build the foundation to secure them before the next incident.
David Goldschlag is the co-founder and CEO of Aembit. He is an experienced security entrepreneur, having previously co-founded New Edge Labs (Zero Trust Network Access) and MobileSpaces (mobile security). He has held prior roles as VP at Netskope (which acquired New Edge Labs), SVP Strategy & CTO at Pulse Secure (which acquired MobileSpaces), VP for Mobile at McAfee (which acquired Trust Digital), and CTO of USinternetworking. Early in his career, David worked at the NSA. At the Naval Research Laboratory, he co-invented Onion Routing, which later became Tor. David holds a Ph.D. from the University of Texas at Austin.
AppSec teams, your backlog is growing faster than you can fix it. SAST and DAST tools are flooding you with findings, developers are pushing back, and prioritizing what actually matters in code is getting harder.
So how do you reduce risk without slowing releases?
Join the Vulnerability Management Virtual Cybersecurity Summit to learn how teams are prioritizing real exploitable issues, reducing noise, and integrating remediation into modern development workflows.
Security Weekly listeners can register for free at https://securityweekly.com/vulnmanagement using the promo code: CSS26-SW
Mike Shema
- Squidbleed (CVE-2026-47729) – Calif
- GitHub – OWASP/AISVS: The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to verify the security of AI-driven applications.
- Beyond Fable: Can a Local LLM Replace Cloud AI for Security Code Reviews – SRLabs Research
- Linux Finally Eliminates The strncpy API After Six Years Of Work, 360+ Patches – Phoronix
For more details of the changes, check out the final commit.
- One for all the models out there!
- CISO Version 2.0
- FYI: Harness, Scaffold, and the AI Agent Terms Worth Getting Right









