1. EachPod
EachPod
Application Security Weekly (Audio) - Podcast

Application Security Weekly (Audio)

About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

Tech News News Technology
Update frequency
every 7 days
Average duration
67 minutes
Episodes
361
Years Active
2018 - 2025
Share to:
Managing Secrets - Vlad Matsiiako - ASW #327

Managing Secrets - Vlad Matsiiako - ASW #327

Secrets end up everywhere, from dev systems to CI/CD pipelines to services, certificates, and cloud environments. Vlad Matsiiako shares some of the tactics that make managing secrets more secure as w…

01:03:03  |   Tue 22 Apr 2025
More WAFs in Blocking Mode and More Security Headaches from LLMs - Sandy Carielli, Janet Worthington - ASW #326

More WAFs in Blocking Mode and More Security Headaches from LLMs - Sandy Carielli, Janet Worthington - ASW #326

The breaches will continue until appsec improves. Janet Worthington and Sandy Carielli share their latest research on breaches from 2024, WAFs in 2025, and where secure by design fits into all this. …

01:14:45  |   Tue 15 Apr 2025
In Search of Secure Design - ASW #325

In Search of Secure Design - ASW #325

We have a top ten list entry for Insecure Design, pledges to CISA's Secure by Design principles, and tons of CVEs that fall into familiar categories of flaws. But what does it mean to have a secure d…

01:07:36  |   Tue 08 Apr 2025
Avoiding Appsec's Worst Practices - ASW #324

Avoiding Appsec's Worst Practices - ASW #324

We take advantage of April Fools to look at some of appsec's myths, mistakes, and behaviors that lead to bad practices. It's easy to get trapped in a status quo of chasing CVEs or discussing which di…

01:11:19  |   Tue 01 Apr 2025
Finding a Use for GenAI in AppSec - Keith Hoodlet - ASW #323

Finding a Use for GenAI in AppSec - Keith Hoodlet - ASW #323

LLMs are helping devs write code, but is it secure code? How are LLMs helping appsec teams? Keith Hoodlet returns to talk about where he's seen value from genAI, where it fits in with tools like sour…

00:54:08  |   Tue 25 Mar 2025
Redlining the Smart Contract Top 10 - Shashank . - ASW #322

Redlining the Smart Contract Top 10 - Shashank . - ASW #322

The crypto world is rife with smart contracts that have been outsmarted by attackers, with consequences in the millions of dollars (and more!). Shashank shares his research into scanning contracts fo…

00:53:01  |   Tue 18 Mar 2025
CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321

CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321

Just three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s. Common defenses have been known since the early …

01:13:50  |   Tue 11 Mar 2025
Keeping Curl Successful and Secure Over the Decades - Daniel Stenberg - ASW #320

Keeping Curl Successful and Secure Over the Decades - Daniel Stenberg - ASW #320

Curl and libcurl are everywhere. Not only has the project maintained success for almost three decades now, but it's done that while being written in C. Daniel Stenberg talks about the challenges in d…

01:09:02  |   Tue 04 Mar 2025
Developer Environments, Developer Experience, and Security - Dan Moore - ASW #319

Developer Environments, Developer Experience, and Security - Dan Moore - ASW #319

Minimizing latency, increasing performance, and reducing compile times are just a part of what makes a development environment better. Throw in useful tests and some useful security tools and you hav…

01:10:21  |   Tue 25 Feb 2025
Top 10 Web Hacking Techniques of 2024 - James Kettle - ASW #318

Top 10 Web Hacking Techniques of 2024 - James Kettle - ASW #318

We're getting close to two full decades of celebrating web hacking techniques. James Kettle shares which was his favorite, why the list is important to the web hacking community, and what inspires th…

00:44:57  |   Tue 18 Feb 2025
Code Scanning That Works With Your Code - Scott Norberg - ASW #317

Code Scanning That Works With Your Code - Scott Norberg - ASW #317

Code scanning is one of the oldest appsec practices. In many cases, simple grep patterns and some fancy regular expressions are enough to find many of the obvious software mistakes. Scott Norberg sha…

01:12:52  |   Tue 11 Feb 2025
Threat Modeling That Helps the Business - Akira Brand, Sandy Carielli - ASW #316

Threat Modeling That Helps the Business - Akira Brand, Sandy Carielli - ASW #316

Threat modeling has been in the appsec toolbox for decades. But it hasn't always been used and it hasn't always been useful. Sandy Carielli shares what she's learned from talking to orgs about what's…

01:11:39  |   Tue 04 Feb 2025
Security the AI SDLC - Niv Braun - ASW #315

Security the AI SDLC - Niv Braun - ASW #315

A lot of AI security boils down to the boring, but important, software security topics that appsec teams have been dealing with for decades. Niv Braun explains the distinctions between AI-related and…

01:08:34  |   Tue 28 Jan 2025
Appsec Predictions for 2025 - Cody Scott - ASW #314

Appsec Predictions for 2025 - Cody Scott - ASW #314

What’s in store for appsec in 2025? Sure, there'll be some XSS and SQL injection, but what about trends that might influence how appsec teams plan? Cody Scott shares five cybersecurity and privacy pr…

00:52:10  |   Tue 21 Jan 2025
Discussing Useful Security Requirements with Developers - Ixchel Ruiz - ASW #313

Discussing Useful Security Requirements with Developers - Ixchel Ruiz - ASW #313

There's a pernicious myth that developers don't care about security. In practice, they care about code quality. What developers don't care for is ambiguous requirements. Ixchel Ruiz shares her experi…

01:07:41  |   Tue 14 Jan 2025
DefectDojo and Bringing Quality Appsec Tools to Small Appsec Teams - Greg Anderson - ASW #312

DefectDojo and Bringing Quality Appsec Tools to Small Appsec Teams - Greg Anderson - ASW #312

All appsec teams need quality tools and all developers benefit from appsec guidance that's focused on meaningful results. Greg Anderson shares his experience in bringing the OWASP DefectDojo project …

01:07:10  |   Tue 07 Jan 2025
Applying Usability and Transparency to Security - Hannah Sutor - ASW #311

Applying Usability and Transparency to Security - Hannah Sutor - ASW #311

Practices around identity and managing credentials have improved greatly since the days of infosec mandating 90-day password rotations. But those improvements didn't arise from a narrow security view…

01:09:42  |   Mon 16 Dec 2024
Looking Back on 2024 - ASW #310

Looking Back on 2024 - ASW #310

We do our usual end of year look back on the topics, news, and trends that caught our attention. We covered some OWASP projects, the ongoing attention and promises of generative AI, and big events fr…

00:59:23  |   Tue 10 Dec 2024
Adding Observability with OpenTelemetry - Adriana Villela - ASW #309

Adding Observability with OpenTelemetry - Adriana Villela - ASW #309

Observability is a lot more than just sprinkling printf statements throughout a code base. Adriana Villela explains principles behind logging, traceability, and metrics and how the OpenTelemetry proj…

01:10:55  |   Tue 03 Dec 2024
Biometric Frontiers: Unlocking The Future Of Engagement - Andras Cser, Enza Iannopollo - ASW #308

Biometric Frontiers: Unlocking The Future Of Engagement - Andras Cser, Enza Iannopollo - ASW #308

This week's interview dives deep into the state of biometrics with two Forrester Research analysts!

This discussion compares and contrasts regional approaches to biometrics; examine the security chal…

01:10:32  |   Tue 19 Nov 2024
Disclaimer: The podcast and artwork embedded on this page are the property of Security Weekly Productions. This content is not affiliated with or endorsed by eachpod.com.