1. EachPod
EachPod
Application Security Weekly (Audio) - Podcast

Application Security Weekly (Audio)

About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

Tech News News Technology
Update frequency
every 7 days
Average duration
67 minutes
Episodes
361
Years Active
2018 - 2025
Share to:
Building a Scanner and a Community with Zed Attack Proxy - Simon Bennetts - ASW #254

Building a Scanner and a Community with Zed Attack Proxy - Simon Bennetts - ASW #254

Zed Attack Proxy is an essential tool for web app pentesting. The project just recently moved from OWASP to the Secure Software Project. Hear about the challenges of running an OSS security project, …

01:13:02  |   Tue 12 Sep 2023
Broadening What We Call AppSec - Christien Rioux - ASW Vault

Broadening What We Call AppSec - Christien Rioux - ASW Vault

Check out this interview from the ASW Vault, hand picked by main host Mike Shema! This segment was originally published on January 10, 2022. There's an understandable focus on "shift left" in modern …

00:35:36  |   Tue 05 Sep 2023
How Can Security Be Smart About Using AI? - Jeff Pollard - ASW #253

How Can Security Be Smart About Using AI? - Jeff Pollard - ASW #253

We go deep on LLMs and generative AIs to shine a light on areas that security leaders should focus on. There are technical concerns like prompt injection and access controls, and privacy concerns in …

01:13:57  |   Tue 29 Aug 2023
Security in a Cloud Native World & Mobile App Attacks - ASW #252

Security in a Cloud Native World & Mobile App Attacks - ASW #252

Two featured interviews from this year's Black Hat. In the news, Discord.io ceases to be, Azure AD breach to get scrutiny from the CSRB, Zoom's AI stumbles show security concerns, model confusion att…

00:37:30  |   Tue 22 Aug 2023
Pointers and Perils for Presentations - Josh Goldberg - ASW #251

Pointers and Perils for Presentations - Josh Goldberg - ASW #251

A key part of modern appsec is communication. From interpersonal skills for fostering collaborations to presentation skills for delivering a message, the ability to tell a story and engage an audienc…

01:24:48  |   Tue 15 Aug 2023
You've Got Appsec, But Do You Have ArchSec? - Merritt Baer - ASW #250

You've Got Appsec, But Do You Have ArchSec? - Merritt Baer - ASW #250

Mature shops should be looking to a security architecture process to help scale their systems and embrace security by design. We talk about what it means to create a security architecture process, wh…

01:15:19  |   Tue 08 Aug 2023
Identity and Verifiable Credentials in Cars - Eve Maler - ASW #249

Identity and Verifiable Credentials in Cars - Eve Maler - ASW #249

Identity isn't new, but we do have new ways of presenting and protecting identity with things like payment wallets and verifiable credentials. But we also have identity in surprising places -- like c…

01:13:46  |   Tue 01 Aug 2023
Navigating the Complexities of Development to Create Secure APIs - Kristen Bell - ASW #248

Navigating the Complexities of Development to Create Secure APIs - Kristen Bell - ASW #248

Appsec teams and developers must both understand the consequences of what they're doing when building APIs. Appsec teams need to push for collaboration and help implement tools that augment the devel…

01:17:31  |   Tue 25 Jul 2023
Securing Non-Election Election Systems, Modernizing AppSec Education - Brian Glas - ASW #247

Securing Non-Election Election Systems, Modernizing AppSec Education - Brian Glas - ASW #247

While much has been written and argued about the security of election systems - the things that do the actual ballot counting - there's other systems that have to be in place and secured before the v…

01:20:50  |   Tue 18 Jul 2023
Software Trust & Adversaries, Developer-Focused Security - Shannon Lietz, Melinda Marks - ASW #246

Software Trust & Adversaries, Developer-Focused Security - Shannon Lietz, Melinda Marks - ASW #246

Infosec is still figuring out useful metrics, how to talk about risk, and how to make resilience more relevant. Shannon talks about a new community effort to measure software trust. She also covers t…

01:16:40  |   Tue 11 Jul 2023
The Psychology of Training - Matias Madou - ASW Vault

The Psychology of Training - Matias Madou - ASW Vault

Check out this interview from the ASW Vault, hand picked by main host Mike Shema! This segment was originally published on May 23, 2022.

Developers want bug-free code -- it frees up their time and is…

00:35:01  |   Wed 05 Jul 2023
Latest Web Vulnerability Trends & Best Practices - Patrick Vandenberg - ASW #245

Latest Web Vulnerability Trends & Best Practices - Patrick Vandenberg - ASW #245

Without visibility and continuous monitoring, dangerous threats expose our blind spots and create risk. Invicti, who brought together Acunetix and Netsparker, analyzes common web application vulns ac…

01:14:56  |   Wed 28 Jun 2023
Policy Momentum in Coordinated Vulnerability Disclosure - Amit Elazari - ASW Vault

Policy Momentum in Coordinated Vulnerability Disclosure - Amit Elazari - ASW Vault

Security is one of the most evolving and impactful landscapes in the regulatory sphere. Proposed initiatives in the areas of Incident Response, Software and Product Assurance, Coordinated Vulnerabili…

00:37:58  |   Tue 20 Jun 2023
Enhancing Security: App Modernization, Identity Orchestration, & Big IAM Challenge - Eric Olden - ASW #244

Enhancing Security: App Modernization, Identity Orchestration, & Big IAM Challenge - Eric Olden - ASW #244

Eric Olden, CEO and Co-Founder of Strata Identity, discusses the concept of Identity Orchestration. He covers the evolving identity landscape and how it has evolved to keep pace with modern apps, the…

01:19:57  |   Wed 14 Jun 2023
What's the Deal with API Security? - Sandy Carielli - ASW #243

What's the Deal with API Security? - Sandy Carielli - ASW #243

Walking the show floor at RSA Conference, you couldn't trip without falling into an application security vendor booth ... and API security specialists were especially plentiful. Join Forrester Princi…

01:17:13  |   Tue 06 Jun 2023
Doing Application Security Right – Farshad Abasi – ASW VAULT

Doing Application Security Right – Farshad Abasi – ASW VAULT

Check out this interview from the ASW VAULT, hand picked by main host Mike Shema! This segment was originally published on March 14, 2022.

Cybersecurity is a large and often complex domain, tradition…

00:35:46  |   Tue 30 May 2023
Ten Things I Hate About Lists - ASW #242

Ten Things I Hate About Lists - ASW #242

The OWASP Top 10 dates back to 2003, when appsec was just settling on terms like cross-site scripting and SQL injection. It's a list that everyone knows about and everyone talks about. But is it stil…

01:16:36  |   Tue 23 May 2023
Securing the App Lifecycle: Strategies for Long-Term Software Security and Mitigating the Threat of Malicious Packages - ASW #241

Securing the App Lifecycle: Strategies for Long-Term Software Security and Mitigating the Threat of Malicious Packages - ASW #241

What happens to an app's security after six months? What about a year or two years? A Secure SDLC needs to maintain security throughout an app's lifetime, but too often the rate of new flaws can outp…

01:07:38  |   Tue 16 May 2023
From Security Theater to Resilience: Unveiling New Approaches to Application Security - ASW #240

From Security Theater to Resilience: Unveiling New Approaches to Application Security - ASW #240

What does software resilience mean? Why is status quo application security unfit for the modern era of software? How can we move from security theater to security chaos engineering? This segment answ…

01:10:35  |   Tue 09 May 2023
Navigating the Complexities of Application Security: Vulnerability Management, Risk Mitigation, and Business Logic Attacks - ASW #239

Navigating the Complexities of Application Security: Vulnerability Management, Risk Mitigation, and Business Logic Attacks - ASW #239

Application security is messy and is getting messier. Modern application security teams are struggling to identify what's more important to fix. Cloud security and application security is getting squ…

01:20:42  |   Tue 02 May 2023
Disclaimer: The podcast and artwork embedded on this page are the property of Security Weekly Productions. This content is not affiliated with or endorsed by eachpod.com.