
Earth’s expanding attack surface. [T-Minus: Space-Cyber Briefing]
Get every episode summarized
Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
CyberWire Daily is made possible by:
“When initial access vulnerabilities are cheap and automated, attackers can hit everything all the time. But at Black Hat, open AI's Clint Gibler and Spectorops' Robby Winchester reminded me that we don't have to just fight AI with AI at machine speed.”From the transcript
Get every episode summarized
Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
290 searchable segments. Every word is indexed and playable.
Full transcript
CyberWire Daily — Earth’s expanding attack surface. [T-Minus: Space-Cyber Briefing]. Machine-transcribed; use the interactive transcript above to jump the player to any line.
You're listening to the CyberWire network, powered by N2K. When initial access vulnerabilities are cheap and automated, attackers can hit everything all the time. But at Black Hat, open AI's Clint Gibler and Spectorops' Robby Winchester reminded me that we don't have to just fight AI with AI at machine speed. By taking a preventative mindset, defenders can mitigate attack pathways so there's far less occurring at machine speed in the first place. Listen to our full Black Hat conversation at explore.thecyberwire.com slash Spectorops. DLP sucks. Every syso knows it. 20 years of rules and reg X built for another era. Jazz is the DLP that deeply understands your business.
Melody, Jazz's agentic investigator, weighs every data movement against the data, systems, people, and process, then provides analyst with the few incidents fully investigated. In 30 days, 2 million signals in about 80 investigated incidents out. No rules written. Jazz won the 2026 CrowdStrike AWS and Nvidia Startup Accelerator from a nearly thousand applicants. See Melody in action at jazz.security slash N2K. It used to decipher just a few years ago that looking at the things how they are right now and how much is the result push to go back to the moon. I think it's not a cyber-size. It's going to happen within next couple of years.
Welcome. I'm Maria Varmozis and you are listening to T-minus Space Cyber Briefing. In this show, we examine the evolution of cyber security in the global and orbital infrastructure that powers, protects, and connects our lives. Hello everyone. I appreciate you joining me today. Our episode today picks up where last week's left off. In other words, this is part two of two. And if you haven't listened to part one just yet, I highly recommend you go and do that first. Link is in the show notes for you. But to refresh your memory, I am speaking with two foundational experts in space cyber security today and they are Melanco-Star chick, Cyber Security Lead at Vision Space, and Andy Olcawa,
Space Cyber Security researcher also at Vision Space. Their new book is Hot Off the Presses and it is called The Space Craft Hacker's Handbook Explaining Ground Stations, Flight Software and Satellite Terminals. I just got my copy and it is on my desk right now. It's out from no-starch press, which is as far as I'm concerned, an endorsement in and of itself, and no, I have no affiliation, nor am I being paid to say any of this. This is me genuinely recommending this book to you as someone who's listening to this podcast. The book is targeted at IT security professionals and has a great deal of technical content to sink your teeth into. It also has a lot of essential information on how space missions work from the inside out. So if you are an InfoSec Pro who hasn't yet had a chance to see space really up close, you are not alone by a long shot, by the way. This book fills in a lot of gaps that you might have in terms of industry-specific knowledge. So back to the show.
My conversation with Melenco and Andy last week touched on some of the more technical aspects of what this book covers. And what we've saved for today's show is more high level. My first question was one that likely Melenco and Andy get more than any other. And that is, what advice do they give people looking for a job in the space industry as an InfoSec Professional? The voice you'll hear first is Melenco answering the question. I mean, realistically in the space industry is very compliance driven. So as was most of cybersecurity, the most of the jobs will actually not be in testing. The system, which is of course the interesting part in what everyone wants to focus on. But I would say that the majority of the jobs will actually be in compliance and auditing of these systems. There might be like a testing component to that. But in the end, it's you need to meet the requirements. And that's what the space industry is.
Very famous for, I would say. And now is more security being applied. This is what they come up with to solve the same problem. It's more more security requirements testing than auditing them. So I think that's maybe a point or a warning for people. We're excited about finally hacking space systems and more cybersecurity there. But it is like with every cybersecurity, if it grows also the overhead for compliance grows. Yeah. And that's what we see. Yeah, from the technical perspective, we already discussed about the base, the skill sets required that it could be pretty much anything. But from the space, it's specific skillless. I would try to do some all-sint and try to find out what different agencies are using for their space missions. And then it just happens that most of the information
is open source of the standards. Many software applications are open source as well. I would probably start with that and play with those. And see what it is. It's not that difficult to have your own space mission, digital screen on your own laptop and see how it works, see what the telecommands, see what is the telemetry. Of course, it requires some time. You know, not on the server, but on that. So that's why we probably could get the book and learn how to do it quicker. But most of the information is open source. And what we actually try. So when we started publishing our findings on the space systems, for us it was very easy because we come from a space background. So we have developed some of the stuff that we are now hacking on.
So for us it's easy. But when we started publishing our findings and our vulnerabilities in the space systems, and every single time we were going somewhere people were asking how do we start with this, how did you find out what is the system. And for us it's experience. But we were trying to ask all those questions. And that's pretty much impossible. We were 20 slides or 30 slides for 20 or 13 in the stock. So that's why that was the main reason why we decided to write a book about it. So that we can put everything we know into this world piece and share with anyone who is interested in this. And I so appreciate that you've done that because I often think about who's really building the community around space cyber. And the two of you are at the top of my list of people who are doing that hard work.
So thank you for doing that. So many people are very interested in this. It can be a bit of a mystery about how to figure out your way in there which is part of the fun. But at the same time, you know, it's nice to know that there are guys that you can go to that help walk you through it. Time for a quick break. You right back. Instagram teen accounts come with automatic protections that limit who can contact teens, the content they can see, and the time they spend on the app. Learn more about teen accounts and Instagram's ongoing work to protect teens online at Instagram.com slash teen accounts.
Every time your team deploys a new cloud workload or AI agent, another identity gets permitted access to your critical systems. Legacy tools were built to manage human employees, leaving modern machine and AI access largely unmanaged. That's where IDIRA by Palo Alto Networks comes in. Human, machine, AI, one identity platform for all. IDIRA replaces permanent permissions with dynamic access, so you can lock down every identity without slowing down your business. Secure every identity with IDIRA by Palo Alto Networks. Visit Palo Alto Networks slash IDIRA. Again, that's Palo Alto Networks.com slash IDIRA. This episode is brought to you by Subaru. You know that place your mind always wanders to?
The lake, the mountains, the homes of the people you love most. The completely redesigned 2026 Subaru Outback is built to help you get there. With legendary capability, standard symmetrical all-wheel drive and the confidence to go further. The 2026 Subaru Outback. Love never looked so good. Visit Subaru.com slash IDIRA to learn more. And now a word from our sponsor, SpectorOps. Today, AI is rapidly adding non-human and agentic identities to modern enterprise environments creating new trust relationships and attack paths. Bloodhound Enterprise helps defenders map attack paths across AWS and hybrid environments as one connected graph. Identify the choke points that matter most and bring trusted attack path intelligence into approved AI workflows with Bloodhound Hunter. See how SpectorOps helps teams secure the AI-driven identity
era at SpectorOps.io. All right, welcome back. Let's jump back into my chat with Andy Olcawa and Melanco Star chick of Vision Space. I have a curiosity question about just given where you both are in space cyber and how much you're seeing in terms of the practical realities of things. I'm just curious if there's anything going on in terms of general space capabilities that you are keeping an eye on with any kind of personal or professional interest. Anything that you see coming down over the next five, ten years that you're like, that could be really interesting. Or are you just more living in the moment right now? I think currently people are experiencing the adoption of space technology. For example, with styling terminals at their homes or if they have a caravan or something.
But I think what will shock people's mind at some point is when you get this direct to device communication with mobile communication. And you will get actually satellite internet on your mobile phone in the next years, which is a capability that is currently being developed and slowly rolled out. And I think this is when also the security of these systems and any outages will have millions of people affected. Right now it is often just a secondary effect if something fails in a space system. But was that big number of constellations being built up and the number of services and people depending on it, growing not just for critical infrastructure, but for everyday use? I think the impacts will grow exponentially in the coming years on everyday people. Absolutely. And Andy, over to you. I started saying that at the beginning of the conversation, the attack surface in space is extremely small because there might be a spacecraft
or there might be a constellation of spacecraft. But this movement now of having much more assets in space, which are not necessarily the spacecraft that we understand, but people started thinking and talking about data centers in space. Or the moment we go back or get back to the moment, there will be no infrastructure there. And suddenly this attack surface will become a fairly much on the ground. So that's I think it's going to be very interesting to see how security will play into that. And whether it is people will pay much more attention because it's an actual infrastructure. On the known, they will pay much more attention to security. Or it will be just like any other space asset or a vulnerability.
And whenever you look at it, there will be security flow which someone can exploit. It's a fun sci-fi, but not so sci-fi thing of imagining somebody hacking a moon base. But at the same time, it used to be sci-fi, just a few years ago. But looking at the things, how they are right now and how much is the rest of the push to go back to the moon, I think it's not a sci-fi. It's going to happen within a couple of years or maybe years. It is a fascinating prospect. It's truly this sci-fi is becoming reality very quickly, much more quickly than I would have thought. I want to make sure I give you that opportunity to promote or conclude in any way you like. So I guess last words for either of you, anything you want to add? I thought we could learn from the last few years. We have recently teamed up with Hark the Box. And a couple of guys from our team launched the whole spacecraft or satellite hacking truck.
We've had the box. I think it would be interesting for anyone who would like to start with space security. They could also give it a try and do some challenges. I will make sure that we have links to Hark the Box in our show notes as well. So everyone who's listening who is interested and wants to learn more can follow that along. So Milenko and Andy, thank you both so much for not just joining me today, but truly for everything you're doing, for space cyber understanding and the community in general. So thank you for all that you've been doing and congratulations on the launch of your book. I really can't wait to get my hands on it. So thank you for joining me today. Thank you very much. And that's T-Mina Space Cyber Briefing. Brought to you by N2K CyberWire. If you like what you heard today, you will also enjoy our newsletter, Signals in Space. You'll get research and notes pulled together by our producer Ethan Cook and me,
along with this week's top space cyber news stories. We will also be sure to put in a link to last week's episode, which again was part one of today's conversation, just in case you missed it. Subscribe by visiting the cyberwire.com slash newsletters. We'd love to know what you think of our podcast, your feedback, and sure as we deliver the insights that keep you a step ahead and the rapidly changing cyber security landscape. If you like this show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to space at n2k.com. We're proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies. N2K helps cybersecurity professionals grow, learn, and stay informed. As the nexus for discovery and connection, we bring you the people, the technology, and the ideas
shaping the future of secure innovation. Learn how at n2k.com. Thank you for listening to T-minus. I am your host, Marie of Armazas. This show is produced by Ethan Cook and Liz Stokes. We're mixed by Elliot Peltzmann and Trehester with original music by Elliot Peltzmann. Our executive producer is Jennifer Iben, with content strategy by Mayan Plout. Peter Kielpie is our publisher. See you next week. Music T-minus T-minus T-minus T-minus T-minus T-minus T-minus This episode is brought to you by Born in Roma fragrances by Valentino Beauty, the iconic fragrance duo. Donna Born in Roma O'Deparfum is a feminine fragrance featuring juicy black current, central jasmine,
woody cashmurren, and warm vanilla. Its masculine counterpart, Womow Born in Roma O'Depoilette, has notes of fresh violet leaf, and a classic sage, green vetiver, spicy ginger, and mineral salt. Shop at macy's.com Maybe that's an urgent email from your CEO or maybe it's a deepfake targeting your business. Doppel is the AI native social engineering defense platform, fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Doppel uses it to fight back, automatically dismantling cross-channel attacks, building team resilience, and providing agentic email protection. Doppel, outtacing what's next in social engineering. Learn more at Doppel.com. That's D-O-P-P-E-L.com.
More episodes

