1. EachPod
EachPod
Application Security Weekly (Audio) - Podcast

Application Security Weekly (Audio)

About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

Tech News News Technology
Update frequency
every 7 days
Average duration
67 minutes
Episodes
361
Years Active
2018 - 2025
Share to:
ASW #201 - IE11 Goes to Zero

ASW #201 - IE11 Goes to Zero

This week in the AppSec News: SynLapse shows shell injection via ODBC, Java deserialization example, MFA for Ruby Gems ecosystem, simple flaws in firmware, the decade-long journey of a Safari vuln, &…

01:03:45  |   Tue 12 Jul 2022
ASW #200 - Keith Hoodlet

ASW #200 - Keith Hoodlet

HTTP RFCs have evolved: A Cloudflare view of HTTP usage trends, Career Advice and Professional Development, Active Exploitation of Confluence CVE-2022-26134

Seamlessly Connect & Protect Entire IT Eco…

01:08:25  |   Fri 08 Jul 2022
ASW #198 - Matias Madou

ASW #198 - Matias Madou

Developers want bug-free code -- it frees up their time and is easier to maintain. They want secure code for the same reasons. Matias Madou joins to talk about how the definition of secure coding var…

01:11:49  |   Wed 22 Jun 2022
ASW #197 - Brian Glas

ASW #197 - Brian Glas

This week, in the first segment, Brian Glas answers the questions surrounding the next generations of AppSec professionals: What does it look like to try teaching cybersecurity at an undergraduate le…

01:19:39  |   Fri 20 May 2022
ASW #196 - Christoph Nagy

ASW #196 - Christoph Nagy

This week, Mike and John kick off the show with an interview of Christoph Nagy, the CEO of SecurityBridge! Then, in the AppSec News: Secure coding practices and smart contracts, lessons from the Hero…

01:13:06  |   Tue 10 May 2022
ASW #195 - Lynn Marks

ASW #195 - Lynn Marks

This week, Mike and John interview Lynn Marks, Product Manager at Imperva, & discuss Bad Bots: The Automated Threat Targeting Your Websites, Apps, & APIs! In the AppSec News: ExtraReplica in Azure, C…

01:13:32  |   Tue 03 May 2022
ASW #194 - Dr. Chenxi Wang

ASW #194 - Dr. Chenxi Wang

How should we empower developers to embrace the NIST software development practices? Because from here on out, developers need to view themselves as the front lines of defense for the end-consumer. A…

01:10:43  |   Tue 26 Apr 2022
ASW #193 - AppSec (& adjacent) Metrics

ASW #193 - AppSec (& adjacent) Metrics

We can create top 10 lists and we can count vulns that we find with scanners and pen tests, but those aren't effective metrics for understanding and improving an appsec program. So, what should we fo…

01:17:06  |   Tue 19 Apr 2022
ASW #192 - William Morgan

ASW #192 - William Morgan

The zero trust approach can be applied to almost every technology choice in the modern enterprise, and Kubernetes is no exception. For Kubernetes network security particularly, adopting a zero trust …

01:16:42  |   Tue 12 Apr 2022
ASW #191 - Eric Allard

ASW #191 - Eric Allard

Making a positive impact to how we package software to make developer's lives easier in how they have to manage security. FORCEDENTRY implications for the BlastDoor sandbox, Spring RCE, Zlib flaw res…

01:18:50  |   Tue 05 Apr 2022
ASW #190 - Harshil Parikh

ASW #190 - Harshil Parikh

Developers ignore security issues. But can we really blame them? After all, security folks bombard them with an endless stream of issues that need to be addressed with no way for them to separate wha…

01:17:31  |   Tue 29 Mar 2022
ASW #189 - Alvaro Muñoz

ASW #189 - Alvaro Muñoz

This week in the AppSec News: A great escape isn't always as great as it sounds, Solana cryptocurrency logic isn't always as great as intended, some people's idea of "peace" isn't that great at all, …

01:15:58  |   Tue 22 Mar 2022
ASW #188 - Farshad Abasi

ASW #188 - Farshad Abasi

Cybersecurity is a large and often complex domain, traditionally focused on the infrastructure and general information security, with little or no attention to Application Security. Security provider…

01:16:28  |   Wed 16 Mar 2022
ASW #187 - Lebin Cheng

ASW #187 - Lebin Cheng

As the volume of API traffic increases, it becomes a greater threat to an organization’s sensitive data. Motivated attackers will increasingly target APIs as the pathway to the underlying infrastruct…

01:07:28  |   Tue 08 Mar 2022
Good People - ASW #186

Good People - ASW #186

This week, we welcome Steve Wilson, Chief Product Officer at Contrast Security, to discuss Integrating Appsec Tools for DevOps Teams! In the AppSec news: Salesforce reveals their bounty totals for 20…

01:18:19  |   Tue 01 Mar 2022
The DIY Lab - ASW #185

The DIY Lab - ASW #185

Lots of web hacking can be done directly from the browser. Throw in a proxy like Burp plus the browser's developer tools window and you've got a nearly complete toolkit. But nearly complete means the…

01:04:04  |   Tue 22 Feb 2022
Tasty Beverage - ASW #184

Tasty Beverage - ASW #184

Doug Kersten, CISO of Appfire, will discuss how the nature of vulnerabilities today makes it critical for developers to make sure they’re building projects in a secure manner in order to quickly miti…

01:21:04  |   Tue 15 Feb 2022
Internal Jokes - ASW #183

Internal Jokes - ASW #183

Security is one of the most evolving and impactful landscapes in the regulatory sphere. Proposed initiatives in the areas of Incident Response, Software and Product Assurance, Coordinated Vulnerabili…

01:16:36  |   Tue 08 Feb 2022
Perfect Direction - ASW #182

Perfect Direction - ASW #182

This week, we welcome Larry Maccherone, DevSecOps Transformation at Contrast Security, to discuss Shift Left, NOT S#!T LEFT! In the AppSec News: PwnKit LPE in Linux, two different smart contract logi…

01:15:38  |   Tue 01 Feb 2022
Cheesy Tomato Dreams - ASW #181

Cheesy Tomato Dreams - ASW #181

It is hard, if not impossible, to secure something you don’t know exists. While security professionals spend countless hours on complex yet interesting issues that *may* be exploitable in the future,…

01:09:42  |   Tue 25 Jan 2022
Disclaimer: The podcast and artwork embedded on this page are the property of Security Weekly Productions. This content is not affiliated with or endorsed by eachpod.com.