Attack Surface Management in 2025: Why Continuous Visibility is Essential
Why continuous attack surface management is critical in 2025, covering AI-driven discovery, shadow IT, and zero trust integration.
Representative Foreword
The representative foreword of this blog: security now fails less at finding issues than at absorbing, sustaining, and acting on what has already been found.
This essay frames the entire site first. The posts on technical analysis, method, and governance all start from this same problem statement.

Detection, Method, Governance
Why continuous attack surface management is critical in 2025, covering AI-driven discovery, shadow IT, and zero trust integration.
Theoretical RCE risks in OpenStack Nova’s exception serialization via oslo.messaging, with PoC scenarios and defense patterns.
In-depth analysis of the 2025 SKT breach, telecom authentication mechanisms, and 5G SA vs NSA security architecture differences.
Technical analysis of CVE-2019-17570 deserialization RCE in Apache XML-RPC, with patch comparison and secure implementation guidance.