1. EachPod
EachPod
Application Security Weekly (Audio) - Podcast

Application Security Weekly (Audio)

About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

Tech News News Technology
Update frequency
every 7 days
Average duration
67 minutes
Episodes
361
Years Active
2018 - 2025
Share to:
ASW #220 - Daniel Krivelevich

ASW #220 - Daniel Krivelevich

CosMiss in Azure, $70k bounty for a Pixel Lock Screen bypass, finding path traversal with Raspberry Pi-based emulators, NSA guidance on moving to memory safe languages, implementing phishing-resistan…

01:27:32  |   Tue 15 Nov 2022
ASW #219 - Karl Triebes

ASW #219 - Karl Triebes

While APIs enable innovation, they’re increasingly targeted as a pathway to data. API abuses are often carried out through automated attacks, in which a botnet floods the API with unwanted traffic—se…

01:21:07  |   Tue 08 Nov 2022
ASW #218 - Sandy Carielli, Martha Bennett

ASW #218 - Sandy Carielli, Martha Bennett

A critical OpenSSL vuln is coming this Tuesday, a SQLite vuln, Apple blogs about memory safety and bug bounties, determining a random shuffle

 

The Web3 ecosystem is chock full of applications and pr…

01:21:07  |   Tue 01 Nov 2022
ASW #217 - Kong Yew Chan

ASW #217 - Kong Yew Chan

Learn what keeps DevOps and SecOps up at night when securing Kubernetes, container, and cloud native applications, what tactics are best for developers and application architects to consider when sec…

01:18:26  |   Tue 25 Oct 2022
ASW #216 - Jason Recla

ASW #216 - Jason Recla

Exploiting FortiOS with HTTP client headers, mishandling memory in Linux kernel Wi-Fi stack, a field guide to security communities, secure coding resources from the OpenSSF, Linux kernel exploitation…

01:19:28  |   Tue 18 Oct 2022
ASW #215 - Akira Brand

ASW #215 - Akira Brand

We talk with Akira Brand about appsec educational resources and crafting better resources for developers to learn about secure coding.

Segment Resources:

- www.akirabrand.com

- www.wehackpurple.com

-…

01:17:54  |   Tue 11 Oct 2022
ASW #214 - Dean Agron

ASW #214 - Dean Agron

The core focus of this podcast is to provide the listeners with food for thoughts for what is required for releasing secured cloud native applications

- Continuous, Multi-layer, and Multi-service ana…

01:18:16  |   Tue 04 Oct 2022
ASW #213 - Janet Worthington

ASW #213 - Janet Worthington

Applications are the most frequent external attack vector for companies. However, application security can improve only if developers either code securely or remediate existing security flaws — unfor…

01:22:48  |   Tue 27 Sep 2022
ASW #212 - Sam Placette

ASW #212 - Sam Placette

Appsec places a lot of importance on secure SDLC practices, API security, integrating security tools, and collaborating with developers. What does this look like from a developer's perspective? We'll…

01:21:41  |   Tue 20 Sep 2022
ASW #211 - Sonali Shah

ASW #211 - Sonali Shah

Go releases their own curated vuln management resources, OSS-Fuzz finds command injection, Microsoft gets rid of Basic Auth in Exchange, NSA provides guidance on securing SDLC practices, reflections …

01:17:34  |   Tue 13 Sep 2022
ASW #210 - Doug Dooley

ASW #210 - Doug Dooley

We will review the primary needs for cloud security: - Guardrails against misconfiguration - Continuously Identify and Remediate Vulnerabilities in Cloud APIs, Apps, and Services - Observability, Pro…

01:22:26  |   Tue 30 Aug 2022
ASW #209 - Kiran Kamity

ASW #209 - Kiran Kamity

The unique nature of cloud native apps, Kubernetes, and microservices based architectures introduces new risks and opportunities that require AppSec practitioners to adapt their approach to security …

01:18:56  |   Tue 23 Aug 2022
ASW #208 - Tanya Janca

ASW #208 - Tanya Janca

Let's talk about adding security tools to a CI/CD, the difference between "perfect" and "good" appsec, and my upcoming book. Segment Resources: https://community.wehackpurple.com #CyberMentoringMonda…

01:16:06  |   Wed 17 Aug 2022
ASW #207 - Chen Gour Arie

ASW #207 - Chen Gour Arie

In today's high-tech industries, security is struggling to keep up with rapidly changing production systems and the chaos that agile development introduces into workflows. Application security (AppSe…

01:18:18  |   Tue 09 Aug 2022
ASW #206 - Manish Gupta

ASW #206 - Manish Gupta

In our first segment, we are joined by Manish Gupt, the CEO and Co-Founder of ShiftLeft for A discussion of how the changes and advancements in static application security testing (SAST) and intellig…

01:15:23  |   Thu 04 Aug 2022
ASW #199 - Nikhil Gupta

ASW #199 - Nikhil Gupta

Nikhil will be discussing the pain points that leaders in the application security space are facing, which can cover how software development has evolved, as well as how this has impacted development…

01:16:36  |   Thu 28 Jul 2022
ASW #205 - Ferruh Mavituna

ASW #205 - Ferruh Mavituna

Vuln in an Atlassian Confluence app, "Dirty Dancing" in OAuth flows, security audits of sigstore and slf4j, flaws in fleet management app, conducting tabletop exercises.

 

Pressured by the speed of i…

01:16:46  |   Mon 25 Jul 2022
ASW #204 - Larry Maccherone

ASW #204 - Larry Maccherone

0-day vulnerabilities pose a high risk because cybercriminals race to exploit them and vulnerable systems are exposed until a patch is issued & installed. These types of software vulnerabilities can …

01:14:18  |   Wed 20 Jul 2022
ASW #203 - Farshad Abasi

ASW #203 - Farshad Abasi

This week in the AppSec News: Apple introduces Lockdown Mode, PyPI hits 2FA trouble, cataloging cloud vulns, practical attacks on ML, NIST's post-quantum algorithms, & more!

 

Appsec starts with the …

01:09:56  |   Fri 15 Jul 2022
ASW #202 - Mike Benjamin

ASW #202 - Mike Benjamin

Both GraphQL and template engines have the potential for injection attacks, from potentially exposing data due to weak authorization in APIs to the slew of OGNL-related vulns in Java this past year. …

01:15:00  |   Thu 14 Jul 2022
Disclaimer: The podcast and artwork embedded on this page are the property of Security Weekly Productions. This content is not affiliated with or endorsed by eachpod.com.