1. EachPod
EachPod
Application Security Weekly (Audio) - Podcast

Application Security Weekly (Audio)

About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

Tech News News Technology
Update frequency
every 7 days
Average duration
67 minutes
Episodes
361
Years Active
2018 - 2025
Share to:
Modernizing AppSec - Melinda Marks - ASW #307

Modernizing AppSec - Melinda Marks - ASW #307

In this week's interview, Melinda Marks' joins us to discuss her latest research. Her recent report Modernizing Application Security to Scale for Cloud-Native Development delves into many aspects an…

01:09:29  |   Tue 12 Nov 2024
Bug bounties, vulnerability disclosure, PTaaS, fractional pentesting - Grant McCracken - ASW #306

Bug bounties, vulnerability disclosure, PTaaS, fractional pentesting - Grant McCracken - ASW #306

After spending a decade working for appsec vendors, Grant McKracken wanted to give something back. He saw a gap in the market for free or low-cost services for smaller organizations that have real ap…

01:05:35  |   Tue 05 Nov 2024
Making TLS More Secure, Lessons from IPv6, LLMs Finding Vulns - Arnab Bose, Shiven Ramji - ASW #305

Making TLS More Secure, Lessons from IPv6, LLMs Finding Vulns - Arnab Bose, Shiven Ramji - ASW #305

Better TLS implementations with Rust, fuzzing, and managing certs, appsec lessons from the everlasting transition to IPv6, LLMs for finding vulns (and whether fuzzing is better), and more!

Also check…

01:22:48  |   Tue 29 Oct 2024
The Complexities, Configurations, and Challenges in Cloud Security - Scott Piper - ASW #304

The Complexities, Configurations, and Challenges in Cloud Security - Scott Piper - ASW #304

Building cloud native apps doesn't mean you're immune to dealing with legacy systems. Cloud services have changed significantly over the last decade, both in the security controls available to them a…

01:17:25  |   Mon 21 Oct 2024
The Future of Zed Attack Proxy - Simon Bennetts, Ori Bendet - ASW #302

The Future of Zed Attack Proxy - Simon Bennetts, Ori Bendet - ASW #302

Zed Attack Proxy has been a crucial web app testing tool for decades. It's also had a struggle throughout 2024 to obtain funding that would enable the tool to add more features while remaining true t…

01:12:35  |   Tue 08 Oct 2024
More Car Hacks, CUPS Vulns, Microsoft's SFI, Memory Safety, Password Complexity - Farshad Abasi - ASW #301

More Car Hacks, CUPS Vulns, Microsoft's SFI, Memory Safety, Password Complexity - Farshad Abasi - ASW #301

More remote car control via web interfaces, an RCE in CUPS, Microsoft reduces attack surface, migrating to memory safety, dealing with dependency confusion, getting rid of password strength calculato…

00:45:57  |   Wed 02 Oct 2024
Vulnerable APIs and Bot Attacks: Two Interconnected, Growing Security Threats - David Holmes - ASW #300

Vulnerable APIs and Bot Attacks: Two Interconnected, Growing Security Threats - David Holmes - ASW #300

APIs are essential to modern application architectures, driving rapid development, seamless integration, and improved user experiences. However, their widespread use has made them prime targets for a…

01:07:51  |   Tue 24 Sep 2024
Bringing Secure Coding Concepts to Developers - Dustin Lehr - ASW #299

Bringing Secure Coding Concepts to Developers - Dustin Lehr - ASW #299

When a conference positioned as a day of security for developers has to be canceled due to lack of interest from developers, it's important to understand why there was so little interest and why apps…

01:02:26  |   Tue 17 Sep 2024
Paying Down Tech Debt, Rust in Firmware, EUCLEAK, Deploying SSO - ASW #298

Paying Down Tech Debt, Rust in Firmware, EUCLEAK, Deploying SSO - ASW #298

Considerations in paying down tech debt, make Rust work on bare metal, ECDSA side-channel in Yubikeys, trade-offs in deploying SSO quickly, and more!

Visit https://www.securityweekly.com/asw for all …

00:56:25  |   Tue 10 Sep 2024
Close the Security Theater: Enter Resilience - Kelly Shortridge - ASW Vault

Close the Security Theater: Enter Resilience - Kelly Shortridge - ASW Vault

Check out this interview from the ASW Vault, hand picked by main host Mike Shema! This segment was originally published on May 9, 2023.

What does software resilience mean? Why is status quo applicati…

00:37:48  |   Mon 02 Sep 2024
Changing the Course of IoT's Future from Its Insecure Past - Paddy Harrington - ASW #297

Changing the Course of IoT's Future from Its Insecure Past - Paddy Harrington - ASW #297

IoT devices are notorious for weak designs, insecure implementations, and a lifecycle that mostly ignores patching. We look at external factors that might lead to change, like the FCC's cybersecurity…

01:04:28  |   Tue 27 Aug 2024
The Fallout and Lessons Learned from the CrowdStrike Fiasco - Shimon Modi, Jeff Pollard, Allie Mellen, Boaz Barzel - ASW #296

The Fallout and Lessons Learned from the CrowdStrike Fiasco - Shimon Modi, Jeff Pollard, Allie Mellen, Boaz Barzel - ASW #296

This week, Jeff Pollard and Allie Mellen join us to discuss the fallout and lessons learned from the CrowdStrike fiasco. They explore the reasons behind running in the kernel, the challenges of softw…

01:21:54  |   Tue 20 Aug 2024
When Appsec Needs to Start Small - Kalyani Pawar, Danny Jenkins, Nikos Kiourtis - ASW #295

When Appsec Needs to Start Small - Kalyani Pawar, Danny Jenkins, Nikos Kiourtis - ASW #295

Startups and small orgs don't have the luxury of massive budgets and large teams. How do you choose an appsec approach that complements a startup's needs while keeping it secure. Kalyani Pawar shares…

01:08:53  |   Tue 13 Aug 2024
Building Successful Security Champions Programs - Marisa Fagan - ASW #294

Building Successful Security Champions Programs - Marisa Fagan - ASW #294

Even though Security Champions programs look very different across organizations and maturity levels, they share core principles for becoming successful. Marisa shares her experience in building thes…

01:10:17  |   Tue 06 Aug 2024
A CISO's Perspective on AI, Appsec, and Changing Behaviors - ASW #293

A CISO's Perspective on AI, Appsec, and Changing Behaviors - ASW #293

Modern appsec isn't modern because security tools got shifted in one direction or another, or because teams are finding and fixing more vulns. It's modern because appsec is meeting developer needs an…

00:45:18  |   Tue 30 Jul 2024
Where Generative AI Can Actually Help Security (And Where It Doesn't) - Farshad Abasi, Allie Mellen - ASW #292

Where Generative AI Can Actually Help Security (And Where It Doesn't) - Farshad Abasi, Allie Mellen - ASW #292

Generative AI has produced impressive chatbots and content generation, but however fun or impressive those might be, they don't always translate to value for appsec. Allie brings some realistic expec…

01:05:00  |   Tue 23 Jul 2024
Producing Secure Code by Leveraging AI - Stuart McClure - ASW #291

Producing Secure Code by Leveraging AI - Stuart McClure - ASW #291

How can LLMs be valuable to developers as an assistant in finding and fixing insecure code? There are a lot of implications in trusting AI or LLMs to not only find vulns, but in producing code that f…

01:09:02  |   Tue 16 Jul 2024
State Of Application Security 2024 - Sandy Carielli, Janet Worthington - ASW #290

State Of Application Security 2024 - Sandy Carielli, Janet Worthington - ASW #290

Sandy Carielli and Janet Worthington, authors of the State Of Application Security 2024 report, join us to discuss their findings on trends this year! Old vulns, more bots, and more targeted supply c…

01:12:41  |   Tue 09 Jul 2024
OAuth 2.0 from Protecting APIs to Supporting Authorization & Authentication - Aaron Parecki - ASW #289

OAuth 2.0 from Protecting APIs to Supporting Authorization & Authentication - Aaron Parecki - ASW #289

OAuth 2.0 is more than just a single spec and it's used to protect more than just APIs. We talk about challenges in maintaining a spec over a decade of changing technologies and new threat models. No…

01:01:09  |   Tue 25 Jun 2024
Learning EBPF - Liz Rice - ASW Vault

Learning EBPF - Liz Rice - ASW Vault

Check out this interview from the ASW Vault, hand picked by main host Mike Shema! This segment was originally published on April 4, 2023.

Following on from her successful title "Container Security", …

00:37:16  |   Tue 18 Jun 2024
Disclaimer: The podcast and artwork embedded on this page are the property of Security Weekly Productions. This content is not affiliated with or endorsed by eachpod.com.