1. EachPod
EachPod
Application Security Weekly (Audio) - Podcast

Application Security Weekly (Audio)

About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

Tech News News Technology
Update frequency
every 7 days
Average duration
67 minutes
Episodes
361
Years Active
2018 - 2025
Share to:
Getting Your First Conference Presentation - Sarah Harvey - ASW #271

Getting Your First Conference Presentation - Sarah Harvey - ASW #271

We return to the practice of presentations, this time with a perspective from a conference organizer. And we have tons of questions! What makes a topic stand out? How can an old, boring topic be give…

01:19:14  |   Tue 30 Jan 2024
Dealing with the Burden of Bad Bots - Sandy Carielli - ASW #270

Dealing with the Burden of Bad Bots - Sandy Carielli - ASW #270

Where apps provide something of value, bots are sure to follow. Modern threat models need to include scenarios for bad bots that not only target user credentials, but that will also hoard inventory a…

01:08:35  |   Tue 23 Jan 2024
Communicating Technical Topics Without Being Boring - Eve Maler - ASW #269

Communicating Technical Topics Without Being Boring - Eve Maler - ASW #269

It's time to start thinking about CFPs and presentations for 2024! Eve shares advice on delivering technical topics so that an audience can understand the points you want to make. Then we show how de…

00:35:37  |   Tue 16 Jan 2024
What's in Store for 2024? - ASW #268

What's in Store for 2024? - ASW #268

We kick off the new year with a discussion of what we're looking forward to and what we're not looking forward to. Then we pick our favorite responses to "appsec in three words" and set our sights on…

01:11:20  |   Tue 09 Jan 2024
HTTP RFCs Have Evolved, Breaking Into Cloud, Scaling AppSec at Netflix, & Confluence - Keith Hoodlet - ASW Vault

HTTP RFCs Have Evolved, Breaking Into Cloud, Scaling AppSec at Netflix, & Confluence - Keith Hoodlet - ASW Vault

HTTP RFCs have evolved: A Cloudflare view of HTTP usage trends, Career Advice and Professional Development, Active Exploitation of Confluence CVE-2022-26134

Visit https://securityweekly.com/asw for a…

00:33:32  |   Mon 01 Jan 2024
OWASP SAMM - Software Assurance Maturity Model - Sebastian Deleersnyder - ASW Vault

OWASP SAMM - Software Assurance Maturity Model - Sebastian Deleersnyder - ASW Vault

We will provide a short introduction to OWASP SAMM, which is a flagship OWASP project allowing organizations to bootstrap and iteratively improve their secure software practice in a measurable way. S…

00:34:24  |   Mon 25 Dec 2023
Making Service Meshes Work for People - Idit Levine - ASW #267

Making Service Meshes Work for People - Idit Levine - ASW #267

Service meshes create the opportunity to make security a team sport. They can improve observability and service identity. Turning monoliths into micro services sounds appealing, but maybe not every m…

01:17:40  |   Tue 19 Dec 2023
The ABCs of RFCs - Heather Flanagan - ASW #266

The ABCs of RFCs - Heather Flanagan - ASW #266

We have a lot of questions about standards. How do standards emerge? How do standards encourage adoption? How do they stay relevant as development patterns change and security threats evolve?

We have…

01:18:02  |   Tue 12 Dec 2023
All the News - Just Six Months Later - Application Security Weekly #265

All the News - Just Six Months Later - Application Security Weekly #265

We cover appsec news on a weekly basis, but sometimes that news is merely about the start of a new project, sometimes it's yet another example of a vuln class, and sometimes it's a topic we hope does…

01:10:21  |   Tue 05 Dec 2023
Starting with Appsec -- Is It More of a Position or a Process? - ASW #264

Starting with Appsec -- Is It More of a Position or a Process? - ASW #264

This year we've talked about vulns, clouds, breaches, presentations, and all the variations of Dev, Sec, and Ops. As we end the year, let's talk about starting things -- like starting an appsec progr…

01:13:48  |   Thu 30 Nov 2023
Platform Firmware Security - Maggie Jauregui - ASW Vault

Platform Firmware Security - Maggie Jauregui - ASW Vault

Firmware security is complex and continues to be an industry challenge. In this podcast we'll talk about the reasons firmware security remains a challenge and some best practices around platform secu…

00:34:16  |   Mon 20 Nov 2023
How 2023 Changed Application Security and What’s to Come in 2024 - Karl Triebes - ASW #263

How 2023 Changed Application Security and What’s to Come in 2024 - Karl Triebes - ASW #263

In the rapidly evolving landscape of application security, 2023 brought significant changes with the rise of generative AI tools and an increase in automated threats. In this discussion, Karl Triebes…

01:15:21  |   Tue 14 Nov 2023
Security from a Developer's Perspective - Josh Goldberg - ASW #262

Security from a Developer's Perspective - Josh Goldberg - ASW #262

A lot of appsec conferences have presentations for appsec audiences -- but that's not often the group that's building apps. What if more developer conferences had appsec content? We talk with Josh ab…

01:11:22  |   Tue 07 Nov 2023
How Security Tools Must Evolve - Dan Kuykendall - ASW #261

How Security Tools Must Evolve - Dan Kuykendall - ASW #261

The categories of security tools that we're most familiar with have struggled to keep up with how modern apps are designed and what modern devs need. What if instead of being beholden to categories, …

01:26:44  |   Wed 01 Nov 2023
OAuth, WebAuthn, & The Impact of Design Choices - Dan Moore - ASW #260

OAuth, WebAuthn, & The Impact of Design Choices - Dan Moore - ASW #260

We return to discussions of OAuth and all sorts of authentication. This time around we're looking at the design of authentication protocols, the kinds of trade-offs they weigh for adoption and securi…

01:18:22  |   Tue 24 Oct 2023
OT Security - Huxley Barbee - ASW #259

OT Security - Huxley Barbee - ASW #259

It's no surprise that OT security has fared poorly over the last 30+ years. To many appsec folks, these systems have uncommon programming languages, unfamiliar hardware, and brittle networking stacks…

01:18:56  |   Tue 17 Oct 2023
Shifting Focus to Make DevSecOps Successful - Janet Worthington - ASW #258

Shifting Focus to Make DevSecOps Successful - Janet Worthington - ASW #258

What if all these recommendations to shift left were more about shifting focus? It's all too easy to become preoccupied with vulns, whether figuring out how to find them earlier in the SDLC or spendi…

01:16:35  |   Wed 11 Oct 2023
Creating Presentations and Training That Engage an Audience - Lina Lau - ASW #257

Creating Presentations and Training That Engage an Audience - Lina Lau - ASW #257

Communication is a skill that doesn't appear on top 10 lists, rarely appears as a conference topic, and doesn't appear enough on job requirements. Yet communication is one of the critical ways that s…

01:26:02  |   Tue 03 Oct 2023
Supply Chain Security Security with Containers and CI/CD Systems - Kirsten Newcomer - #ASW 256

Supply Chain Security Security with Containers and CI/CD Systems - Kirsten Newcomer - #ASW 256

Supply chain has been a hot topic for a few years now, but so many things we need to do for a secure supply chain aren't new at all. We'll cover SBOMs, vuln management, and putting together a secure …

01:27:11  |   Tue 26 Sep 2023
Stopping Business Logic Attacks: Why a WAF is no Longer Enough - Karl Triebes - ASW #255

Stopping Business Logic Attacks: Why a WAF is no Longer Enough - Karl Triebes - ASW #255

The majority of attacks are now automated, with a growing number of attacks targeting business logic via APIs, which is unique to every organization. This shift makes traditional signature-based defe…

01:15:53  |   Tue 19 Sep 2023
Disclaimer: The podcast and artwork embedded on this page are the property of Security Weekly Productions. This content is not affiliated with or endorsed by eachpod.com.