1. EachPod
EachPod
Application Security Weekly (Audio) - Podcast

Application Security Weekly (Audio)

About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

Tech News News Technology
Update frequency
every 7 days
Average duration
67 minutes
Episodes
361
Years Active
2018 - 2025
Share to:
Microsoft Recall's Security & Privacy, Hacking Web APIs, Secure Design Pledge - ASW #288

Microsoft Recall's Security & Privacy, Hacking Web APIs, Secure Design Pledge - ASW #288

Looking at use cases and abuse cases of Microsoft's Recall feature, examples of hacking web APIs, CISA's secure design pledge, what we look for in CVEs, a nod to PHP's history, and more!

Visit https:…

00:38:36  |   Tue 11 Jun 2024
Open Source Software Supply Chain Security & The Real Crisis Behind XZ Utils - Idan Plotnik, Luis Villa, Erez Hasson - ASW #287

Open Source Software Supply Chain Security & The Real Crisis Behind XZ Utils - Idan Plotnik, Luis Villa, Erez Hasson - ASW #287

Open source has been a part of the software supply chain for decades, yet many projects and their maintainers remain undersupported by the companies that consume them. The security responsibilities f…

01:12:08  |   Tue 04 Jun 2024
Securing Shadow Apps & Protecting Data - Guy Guzner, Pranava Adduri - ASW Vault

Securing Shadow Apps & Protecting Data - Guy Guzner, Pranava Adduri - ASW Vault

With hundreds or thousands of SaaS apps to secure with no traditional perimeter, Identity becomes the focal point for SaaS Security in the modern enterprise. Yet with Shadow IT, now recast as Busines…

00:30:32  |   Tue 28 May 2024
Collecting Bounties and Building Communities - Ben Sadeghipour - ASW Vault

Collecting Bounties and Building Communities - Ben Sadeghipour - ASW Vault

Check out this interview from the ASW Vault, hand picked by main host Mike Shema! This segment was originally published on April 18, 2023.

We talk with Ben about the rewards, hazards, and fun of bug …

00:36:23  |   Tue 28 May 2024
Node.js Secure Coding - Oliver Tavakoli, Chris Thomas, Liran Tal - ASW #286

Node.js Secure Coding - Oliver Tavakoli, Chris Thomas, Liran Tal - ASW #286

Secure coding education should be more than a list of issues or repeating generic advice. Liran Tal explains his approach to teaching developers through examples that start with exploiting known vuln…

01:09:05  |   Tue 21 May 2024
Inside the OWASP Top 10 for LLM Applications - Sandy Dunn, Mike Fey, Josh Lemos - ASW #285

Inside the OWASP Top 10 for LLM Applications - Sandy Dunn, Mike Fey, Josh Lemos - ASW #285

Everyone is interested in generative AIs and LLMs, and everyone is looking for use cases and apps to apply them to. Just as the early days of the web inspired the original OWASP Top 10 over 20 years …

01:06:40  |   Tue 14 May 2024
AI & Hype & Security (Oh My!) & Hacking AI Bias - Caleb Sima, Keith Hoodlet - ASW #284

AI & Hype & Security (Oh My!) & Hacking AI Bias - Caleb Sima, Keith Hoodlet - ASW #284

A lot of AI security has nothing to do with AI -- things like data privacy, access controls, and identity are concerns for any new software and in many cases AI concerns look more like old-school API…

01:04:57  |   Tue 07 May 2024
Why Companies Continue to Struggle with Supply Chain Security - Melinda Marks - ASW #283

Why Companies Continue to Struggle with Supply Chain Security - Melinda Marks - ASW #283

Companies deploy tools (usually lots of tools) to address different threats to supply chain security. Melinda Marks shares some of the chaos those companies still face when trying to prioritize inves…

01:19:42  |   Tue 30 Apr 2024
Sustainable Funding of Open Source Tools - Mark Curphey, Simon Bennetts - ASW #282

Sustainable Funding of Open Source Tools - Mark Curphey, Simon Bennetts - ASW #282

How can open source projects find a funding model that works for them? What are the implications with different sources of funding? Simon Bennetts talks about his stewardship of Zed Attack Proxy and …

01:17:57  |   Tue 23 Apr 2024
Demystifying Security Engineering Career Tracks - Karan Dwivedi - ASW #281

Demystifying Security Engineering Career Tracks - Karan Dwivedi - ASW #281

There are as many paths into infosec as there are disciplines within infosec to specialize in. Karan Dwivedi talks about the recent book he and co-author Raaghav Srinivasan wrote about security engin…

01:03:23  |   Mon 15 Apr 2024
Lessons That The XZ Utils Backdoor Spells Out - Farshad Abasi - ASW #280

Lessons That The XZ Utils Backdoor Spells Out - Farshad Abasi - ASW #280

We look into the supply chain saga of the XZ Utils backdoor. It's a wild story of a carefully planned long con to add malicious code to a commonly used package that many SSH connections rely on. It h…

01:00:18  |   Tue 09 Apr 2024
Infosec Myths, Mistakes, and Misconceptions - Adrian Sanabria - ASW #279

Infosec Myths, Mistakes, and Misconceptions - Adrian Sanabria - ASW #279

Sometimes infosec problems can be summarized succinctly, like "patching is hard". Sometimes a succinct summary sounds convincing, but is based on old data, irrelevant data, or made up data. Adrian Sa…

01:00:57  |   Tue 02 Apr 2024
Successful Security Needs a Streamlined UX - Benedek Gagyi - ASW #278

Successful Security Needs a Streamlined UX - Benedek Gagyi - ASW #278

One of the biggest failures in appsec is an attitude that blames users for security problems. A lot of processes and workflows break down because of an insecure design or insecure defaults. Benedek G…

01:09:03  |   Tue 26 Mar 2024
Figuring Out Where Appsec Fits When Starting a Cybersecurity Program - Tyler VonMoll - ASW #277

Figuring Out Where Appsec Fits When Starting a Cybersecurity Program - Tyler VonMoll - ASW #277

Lots of companies need cybersecurity programs, as do non-profits. Tyler Von Moll talks about how to get small organizations started on security and how to prioritize initial investments. While an app…

01:13:20  |   Tue 19 Mar 2024
More API Calls, More Problems: The State of API Security in 2024 - Lebin Cheng - ASW #276

More API Calls, More Problems: The State of API Security in 2024 - Lebin Cheng - ASW #276

A majority of internet traffic now originates from APIs, and cybercriminals are taking advantage. Increasingly, APIs are used as a common attack vector because they’re a direct pathway to access sens…

01:12:17  |   Tue 12 Mar 2024
The Simple Mistakes and Complex Seeds of a Vulnerability Management Program - Emily Fox - ASW #275

The Simple Mistakes and Complex Seeds of a Vulnerability Management Program - Emily Fox - ASW #275

The need for vuln management programs has been around since the first bugs -- but lots of programs remain stuck in the past. We talk about the traps to avoid in VM programs, the easy-to-say yet hard-…

01:19:26  |   Tue 05 Mar 2024
Creating the Secure Pipeline Verification Standard - Farshad Abasi - ASW #274

Creating the Secure Pipeline Verification Standard - Farshad Abasi - ASW #274

Farshad Abasi joins us again to talk about creating a new OWASP project, the Secure Pipeline Verification Standard. (Bonus points for not being a top ten list!) We talk about what it takes to pitch a…

00:56:59  |   Tue 27 Feb 2024
Redefining Threat Modeling - Security Team Goes on Vacation - Jeevan Singh - ASW Vault

Redefining Threat Modeling - Security Team Goes on Vacation - Jeevan Singh - ASW Vault

Check out this interview from the ASW Vault, hand picked by main host Mike Shema! This segment was originally published on Dec 13, 2022.

Threat modeling is an important part of a security program, bu…

00:38:29  |   Tue 20 Feb 2024
Creating Code Security Through Better Visibility - Christien Rioux - ASW #273

Creating Code Security Through Better Visibility - Christien Rioux - ASW #273

We've been scanning code for decades. Sometimes scanning works well -- it finds meaningful flaws to fix. Sometimes it distracts us with false positives. Sometimes it burdens us with too many issues. …

01:23:48  |   Tue 13 Feb 2024
Starting an OWASP Project (That's Not a List!) - Grant Ongers - ASW #272

Starting an OWASP Project (That's Not a List!) - Grant Ongers - ASW #272

We can't talk about OWASP without talking about lists, but we go beyond the lists to talk about a product security framework. Grant shares his insights on what makes lists work (and not work). More i…

01:14:25  |   Tue 06 Feb 2024
Disclaimer: The podcast and artwork embedded on this page are the property of Security Weekly Productions. This content is not affiliated with or endorsed by eachpod.com.