CyberWire Daily - Earth’s expanding attack surface. [T-Minus: Space-Cyber Briefing]

Episode Date: October 4, 2026

As space infrastructure expands, so too does the need for cybersecurity expertise beyond securing traditional spacecraft. Host Maria Varmazis speaks with ⁠Milenk Starcevic⁠, Head of Cybersecurity... at ⁠Vision Space⁠, and ⁠Andrzej “Andy” Olchawa⁠, Senior Cybersecurity Engineer also at Vision Space, about the growing space cybersecurity field. They discuss the role of compliance and auditing, how cybersecurity professional can develop space-specific skills, and how emerging capabilities are expanding the attack surface. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠⁠⁠⁠⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠⁠⁠⁠⁠⁠⁠ Key Sources: ⁠The Spacecraft Hacker's Handbook.⁠ Space cybersecurity starts on the ground. Hack the Box. Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠⁠⁠⁠⁠⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠⁠⁠⁠⁠⁠⁠ T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K⁠⁠⁠⁠⁠⁠⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠⁠⁠⁠⁠⁠⁠n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠. Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. When initial access vulnerabilities are cheap and automated, attackers can hit everything all the time. But at Black Hat, OpenAI's Clint Gibler and Spectorops's Robbie Winchester reminded me that we don't have to just fight AI with AI at machine speed. By taking a preventative mindset, defenders can mitigate attack pathways, so there's far less occurring at machine speed in the first place. Listen to our full black hat conversation at explore.
Starting point is 00:00:40 thecyberwire.com slash specterops. DLP sucks. Every CISO knows it. 20 years of rules and reg X built for another era. Jazz is the DLP that deeply understands your business. Melody, Jazz's agentic investigator, weighs every data movement against the data, systems, people, and process, then provides analysts with the few incidents fully investigated. In 30 days, 2 million signals in, about 80 investigated incidents out.
Starting point is 00:01:19 No rules written. Jazz won the 26 CrowdStrike AWS and NVIDIA startup accelerator from a nearly thousand applicants. See Melody in Action at jazz.com security slash NB. It used to be sci-fi just a few years ago, but looking at the things, how they are right now and how much is there is a push to go back to the moon. I think it's not only cyber. It's going to happen within next couple of years. Welcome. I'm Maria Varmazes, and you are listening to T-minus space cyber briefing. In this show, we examine the evolution of cybersecurity in the global and orbital infrastructure that powers, protects, and connects. our lives. Hello, everyone. I appreciate you joining me today. Our episode today picks up where last week's left off. In other words, this is part two of two. And if you haven't listened to
Starting point is 00:02:48 part one just yet, I highly recommend you go and do that first. Link is in the show notes for you. But to refresh your memory, I am speaking with two foundational experts in space cybersecurity today, and they are Milanko Star Trek, Cybersecurity Lead at Vision Space, and Andy O'Kowler, a space cybersecurity researcher, also at VisionSpace. Their new book is Hot Off the Presses, and it is called the spacecraft hackers handbook, Exploiting Ground Stations, Flight Software, and Satellite Terminals. I just got my copy, and it is on my desk right now.
Starting point is 00:03:24 It's out from No Starch Press, which is, as far as I'm concerned, an endorsement in and of itself. And no, I have no affiliation, nor am I being paid to say any of this. This is me genuinely recommending this book to you as someone who's listening to this podcast. The book is targeted at IT security professionals and has a great deal of technical content to sink your teeth into.
Starting point is 00:03:45 It also has a lot of essential information on how space missions work from the inside out. So if you are an Infosec Pro who hasn't yet had a chance to see space really up close, you are not alone by a long shot, by the way. This book fills in a lot of gaps that you might have in terms of industry-specific knowledge. So back to the show, my conversation with Milenko and Andy last week touched on some of the more technical aspects of what this book covers.
Starting point is 00:04:13 And what we've saved for today's show is more high level. My first question was one that likely Melenko and Andy get more than any other. And that is, what advice do they give people looking for a job in the space industry as an infosec professional? The voice you'll hear first is Milenko answering the question. Realistically, in the space industry, the space industry is very compliance driven. So as was most of cybersecurity, most of the jobs will actually not be in testing the system,
Starting point is 00:04:47 which is, of course, the interesting part and what everyone wants to focus on. But I would say that the majority of the jobs will actually be in compliance and auditing of these systems. There might be like a testing component to that, but in the end, it's you need to meet the requirements, and that's what the space industry is very famous for, I would say. And now with more security being applied, this is what they come up with to solve the same problem.
Starting point is 00:05:16 There's more security requirements, testing them, auditing them. So I think that's maybe a point or a warning. People who are excited about finally hacking space systems and more cybersecurity there. But it is like with every side of security, if it grows also the overhead for compliance grows. Yeah. And that's what we see. Yeah, from the technical perspective, we already discussed about the base, the skill sets required that it could be pretty much anything. But from the space specific skills, I would try to do some awesome and try to find that.
Starting point is 00:06:03 out what different agencies are using for their space missions. And then it just happens that most of the information is open source. All the standards, many software applications are open source as well. I would probably start with that and play with those. And see what it is. It's not that difficult to have your own space mission digital queen on your own laptop and see how it works, see what are the telecommands, see what is the telemetry. Of course it requires some time and, you know, not only is advertising that.
Starting point is 00:06:44 So that's why we probably could get the book and learn how to do it quicker. But most of the information is open source and what we are actually try. So when we started publishing our findings on space systems, systems. For us it was very easy because we come from a space background. So we have developed some of the stuff that we are now hacking on. So for us it's easy. But when we started publishing our findings and our vulnerabilities in space systems, every single time we were going somewhere, people were asking how do we start with this? How did you find out what is the system? And for us, it's experience.
Starting point is 00:07:30 Yeah. But we were trying to answer all those questions. And that's pretty much impossible with like 20, you know, 20 slides or 30 slides for a 20 or 13 in stock. So that's why, that was the main reason why we decided to write a book about it so that, you know, we can put everything we know into this one piece and share with anyone who is interested I and I so appreciate that you've done that because I often think about who's really building the community around, you know, space cyber and the two of you are at the top of my list of people
Starting point is 00:08:11 who are doing that hard work. So thank you for doing that. So many people are very interested in this and it can be a bit of a mystery about how to figure out your way in there, which is part of the fun. But at the same time, you know, it's nice to know that there are guys that you can go to that help walk you through it. Time for a quick break. You're right back. Calculating route to avoid seeing poverty. Turn left to bypass the unhoused youth sleeping on the street. Then keep right to skip by the lines of people waiting for food. Steer clear of the crowded shelter turning people away, then take the next exit.
Starting point is 00:09:06 Let's stop looking away and get in the way of rising poverty. Your donations help the United Way fight poverty in thousands of ways, like providing food, shelter, and crisis prevention. Donate today at United Way G. every time your team deploys a new cloud workload or AI agent another identity gets permanent access to your critical systems legacy tools were built to manage human employees leaving modern machine and AI access largely unmanaged that's where IDERA by Palo Alto networks comes in human machine AI one identity platform for all idira replaces permanent permissions with dynamic
Starting point is 00:09:52 access so you can lock down every identity without slowing down your business. Secure every identity with IDERA by Palo Alto Networks. Visit Palo Alto Networks slash IDERA. Again, that's Palo Alto Networks.com slash IDIRA. In Toronto, every arrival is a statement, and nothing says it better than this. Cadillac Optic was the number one selling luxury EV in Canada for 2025. Find your rhythm across a seamless 33-inch display and an immersive 19-speaker AKG surround audio system.
Starting point is 00:10:31 This city demands agility and optic delivers with precision to make every drive extraordinary. Let's take the Cadillac. Find out more at Cadillac Canada.ca. Luxury sales claim based on S&P Global Mobility Canadian New Vehicle Total Registrations for calendar year 2025 for the Cadillac definition of luxury. And now a word from our sponsor, SpectorOps.
Starting point is 00:10:56 Today, AI is rapidly adding non-human and agentic identities to modern enterprise environments, creating new trust relationships and attack paths. Bloodhound Enterprise helps defenders map attack paths across AWS and hybrid environments as one connected graph, identify the choke points that matter most, and bring trusted attack path intelligence into approved AI workflows with Bloodhound Hunter.
Starting point is 00:11:24 See how SpectorOps helps teams secure the AI-driven identity era at specterops.io. All right, welcome back. Let's jump back into my chat with Andy Olcawa and Milanko Starchick of VisionSpace. I have a curiosity question about just given where you both are in space cyber and how much you're seeing in terms of like the practical realities of things, I'm just curious if there's anything going on
Starting point is 00:12:02 in terms of general space capabilities that you are keeping an eye on with any kind of. with any kind of personal or professional interest, anything that you see coming down over the next five, ten years, you're like, that could be really interesting. Or are you just more living in the moment right now? I think currently people are experiencing the adoption of space technology, for example, with Starlink terminals at their homes, or if they have a caroline or something.
Starting point is 00:12:30 But I think what will shock people's mind at some point is when you get this direct-to-device communication with mobile communication and you get actually satellite internet on your mobile phone in the next years, which is a capability that is currently being developed and slowly rolled out. And I think this is when also the security of these systems and any outages will have millions of people affected. Right now it is often just a secondary effect if something fails in a space system. but with that big number of constellations being built up
Starting point is 00:13:06 and the number of services and people depending on it growing not just for critical infrastructure, but for everyday use, I think the impacts will grow exponentially in the coming years on everyday people. Absolutely. And Andy, over to you. I started saying that at the beginning of the conversation, that the attack surface in space is extremely,
Starting point is 00:13:31 small because there might be a spacecraft or there might be a constellation of spacecraft. But there's this movement now of having much more assets in space which are not necessarily spacecraft the way we understand, but people started thinking and talking about data centers in space or the moment we go back or get back to the moment, there will be, there will be, will be infrastructure there and suddenly this attack surface will become pretty much what we have on the ground. So that's, I think it's going to be very interesting to see how security will play into that. And whether it is, people will pay much more attention because it's an actual infrastructure on the moon. They will pay much more attention to security or it will be just like any other space asset,
Starting point is 00:14:31 vulnerable and when I look at it there will be a security flow which someone can exploit it's a fun sci-fi but not so sci-fi thing of imagining somebody hacking a moon base but at the same time
Starting point is 00:14:47 it used to be sci-fi it used to be sci-fi just a few years ago but looking at the things how they are right now and how much is there is a push to go back to the moon I think it's It's not only ever sci-fi. It's going to happen within the next couple of years.
Starting point is 00:15:05 It is a fascinating prospect. It truly, this sci-fi is becoming reality very quickly, much more quickly than I would have thought. I want to make sure I give you that opportunity to promote or conclude in any way you like. So I guess last words for either of you? Anything you want to add? I think, okay, Lansion,
Starting point is 00:15:23 we have recently teamed up with Hark the Box. and a couple of guys from our team launched the whole spacecraft or satellite hacking truck. We hacked the box. I think it would be interesting for anyone who would like to start with space service security. They could also give it a try and do some challenges. I will make sure that we have links to hack the box in our show notes as well.
Starting point is 00:15:53 So everyone who's listening who is interested and who wants to learn more can follow that along. So Milenko and Andy, thank you both so much for not just joining me today, but truly for everything you're doing for space cyber understanding and the community in general. So thank you for all that you've been doing. And congratulations on the launch of your book. I really can't wait to get my hands on it.
Starting point is 00:16:14 So thank you for joining me today. Thank you very much. Thank you for Google. And that's T-Mina space cyber briefing. Brought to you by N2K Cyberwire. If you like what you heard today, you will also enjoy our newsletter. signals in space. You'll get research and notes pulled together by our producer Ethan Cook and me, along with this week's top space cyber news stories. We will also be sure to put in a link to
Starting point is 00:16:45 last week's episode, which again was part one of today's conversation, just in case you missed it. Subscribe by visiting thecyberwire.com slash newsletters. We'd love to know what you think of our podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing cybersecurity landscape. If you like the show, please share a rating and review in your podcast app. Please also fill up the survey in the show notes or send an email to space at n2k.com. We're proud that N2K Cyberwire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies. N2K helps cybersecurity professionals grow, learn,
Starting point is 00:17:33 and stay informed. As the nexus for discovery and connection, we bring you the people, the technology, and the ideas shaping the future of secure innovation. Learn how at n2k.com. Thank you for listening to T-Minus. I am your host, Maria Vermazas.
Starting point is 00:17:51 This show is produced by Ethan Cook and Liz Stokes. We're mixed by Elliot Peltzman and Trey Hester, with original music by Elliot Peltzman. Our executive producer is Jennifer Iben, with content strategy by Mayan Plout.
Starting point is 00:18:05 Peter Kilphee is our publisher. See you next week. Calculating route to avoid seeing poverty. Turn left to bypass the unhoused youth sleeping on the street. Then keep right to skip by the lines of people waiting for food. Steer clear of the crowded shelter turning people away, then take the next exit. Let's stop looking away and get in the way of rising poverty. Your donations help the United Way fight poverty in thousands of ways,
Starting point is 00:18:55 providing food, shelter, and crisis prevention. Donate today at United WayGT.org. Maybe that's an urgent email from your CEO, or maybe it's a deep faith targeting your business. Dopple is the AI-Native social engineering defense platform fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Dopple uses it to fight back,
Starting point is 00:19:25 automatically dismantling cross-channel attacks, building team resilience, and providing agentic email protection. Dopple, outpacing what's next in social engineering. Learn more at doppel.com. That's doppel.com.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.