Absolute AppSec
4.9(19)

Absolute AppSec

by Ken Johnson and Seth Law

334 episodesLatest 2 days agoEN-US
A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.
Recent reviews on Apple Podcasts (1)
  • If you’re into AppSec, this is required listening.

    I’ve been listening to Absolute AppSec for years now and, it’s one of my favorite ways to stay sharp on application security. Ken Johnson and Seth Law aren’t just talking heads reading headlines, they’re clearly in the trenches themselves, and it shows. Every episode digs into stuff that actually matters if you’re building, breaking, or defending apps for a living. What I really like is that it doesn’t feel like a one-way broadcast. The hosts are genuinely engaged with the community, and I’ve had great interactions with them directly, which is rare for a podcast at this point. It feels more like hanging out with sharp people who happen to know a ton about AppSec than sitting through a lecture. Whether you’re an engineer who wants to understand security better, or you’re already deep in AppSec and want to keep up with new concerns and trends, this show delivers.

    larrylewis ·

View all reviews on Apple Podcasts

Episodes (334)

  1. Episode 334 - w/ Ryan Lloyd - Mobile Application Security

    Sep 15, 2026

    In episode 334 of Absolute AppSec, hosts Ken Johnson and Seth Law interview Ryan Lloyd, Chief Product Officer at GuardSquare, to explore mobile application security and product management strategy. Lloyd details GuardSqu

  2. Episode 333 - LLM Patching Flaws, AI Code Regressions, Bug Bounty Economy

    Sep 8, 2026

    Sponsored by GuardSquare (guardsquare.com), the discussion of Episode 333 opens with an analysis of a 1Password academic paper evaluating how frontier LLMs perform at autonomous vulnerability patching. The research indic

  3. Episode 332 - AI SDLC, Call for Cyber Defense, Rumor as the Exploit

    Sep 1, 2026

    In episode 332, the discussion focuses on how artificial intelligence is reshaping the Software Development Lifecycle (SDLC). The episode analyzes Anthropic's blog post regarding an "AI-native SDLC," evaluating its visio

  4. Episode 331 - Being "Mythos" Ready, CRLF-Powered De-sync Attacks

    Aug 25, 2026

    Sponsored by Guardsquare (guardsquare.com), Episode 331 focuses heavily on the growing role of AI agents in application security and how organizations should build and defend against agentic systems. Ken and Seth argue t

  5. Episode 330 - w/ Jeevan Singh - Vulnerability Jail

    Aug 18, 2026

    In this special episode of Absolute AppSec, we cover a topic which started as a solution proposed by Rippling Security's Jeevan Singh: Vulnerability Jail. As Jeevan describes it: "In this new AI world, we have seen many

  6. Episode 329 - AI exploitability, IDOR prevention, Smart TV Proxies

    Jul 28, 2026

    In this episode, sponsored by GuardSquare (guardsquare.com), Ken Johnson and Seth Law discuss OpenAI's reported Hugging Face security incident, questioning whether the model demonstrated genuinely novel offensive capabil

  7. Episode 328 - Wordpress RCE, Vuln Prioritization, AI memory exfiltration

    Jul 21, 2026

    In episode 328 of Absolute AppSec, sponsored by GuardSquare (guardsquare.com), Seth and Ken start by highlighting a newly disclosed, pre-authentication WordPress core Remote Code Execution (RCE) vulnerability ("WP2Shell"

  8. Episode 327 - w/Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization

    Jul 14, 2026

    In episode 327 of Absolute AppSec, co-hosts Ken Johnson and Seth Law present a highly anticipated quarterly crossover episode with Cameron and Kurt from the Coffee, Chaos, and ProdSec podcast. Sponsored by GuardSquare, t

  9. Episode 326 - AppSec Jobs, Benchmarking LLMs, Open Web Standards

    Jul 7, 2026

    In episode 326 of Absolute AppSec, sponsored by mobile application security provider GuardSquare (guardsquare.com), the hosts start with a deep-dive into pre-show discussions about the shifting macroeconomic landscape of

  10. Episode 325 - Simplified Threat Modeling, Defining A Vulnerability

    Jun 30, 2026

    In episode 325 of Absolute AppSec, co-hosts Ken Johnson and Seth Law first break down an informal guide to threat modeling, arguing that overly prescriptive frameworks like STRIDE induce a heavy cognitive load on develop

  11. Episode 324 - Three Week Trap, Malicious Extensions

    Jun 16, 2026

    In episode 324 of Absolute AppSec, co-hosts Ken Johnson and Seth Law share a mix of security model critiques. Starting with industry dynamics, Ken recaps his recent presentation at OWASP Nova regarding the limits of huma

  12. Episode 323 - Secrets Logs, Prompt Injection Risks

    Jun 9, 2026

    In episode 323 of Absolute AppSec, co-hosts Ken Johnson and Seth Law focus heavily on core application security vulnerabilities, legacy operational struggles, and the challenges of generative AI systems. After briefly di

  13. Episode 322 - Megalodon, Staged Package Publishing, AI Powered Honeypots

    May 26, 2026

    In episode 322, the co-hosts examine critical vulnerabilities, changing security standards, and adaptive defense mechanisms. They deep dive into the recent "Megalodon" breach, identifying it as a direct poisoned pipeline

  14. Episode 321 - The Future of AppSec

    May 19, 2026

    In episode 321 of Absolute AppSec, the co-hosts dive into a sprawling discussion about the future of Application Security amid the heavy noise of artificial intelligence and automated tools. The hosts start with a debate

  15. Episode 320 - Return of @lojikil - LLM Bug Hunting, AI OffSec, Defender Burnout

    May 12, 2026

    Ken is away, so Stefan Edwards (lojikil) joins Seth to talk all things AppSec. This episode starts by exploring the acceleration of AI on the offensive side of security, enabling threat actors to automate complex tasks l

  16. Episode 319 - Vercel Breach, Security vs. Compliance, Pull Request Flows w/ AI Agents

    Apr 21, 2026

    Episode 319 covers a range of industry developments, primarily focusing on the recent Vercel security incident and the evolving landscape of AI-driven compliance. The hosts detail how a Vercel employee's use of a consume

  17. Episode 318 - Slack Impersonation, Mythos, Vulnerability Research Future

    Apr 14, 2026

    Episode 318 examines critical vulnerabilities and the evolving impact of AI on the security industry. The episode details a recent sophisticated impersonation and malware attack targeting open-source Slack communities, i

  18. Episode 317 - (Post-RSAC/BSidesSF), Supply Chain Security, Future of SDLC

    Mar 31, 2026

    Ken Johnson and Seth Law reflect on the 2026 RSA Conference and BSidesSF, noting an industry-wide "awakening" regarding the high costs and engineering complexities of operationalizing AI security tools. A major focus is

  19. Episode 316 - w/Coffee, Chaos, and ProdSec - Agentic Development Lifecycle

    Mar 17, 2026

    In episode 316 of Absolute AppSec, hosts Ken Johnson and Seth Law participate in a crossover with Kurt Hendle and Cameron Walters from the Coffee, Chaos, and ProdSec podcast to discuss the radical transformation of secur

  20. Episode 315 - Risks of "AI-Native" Security Products, Rapid Software Development

    Mar 3, 2026

    In episode 315 of Absolute AppSec, Ken Johnson and Seth Law discuss the rapidly evolving challenges of securing software in an era of AI-assisted development. The hosts provide updates on their "Harnessing LLMs for Appli

  21. Episode 314 - LLM AppSec Disruption, Limitations of AI in Security, AppSec Oversight

    Feb 24, 2026

    In this episode, the hosts discuss the seismic shift in the application security landscape triggered by the rise of Large Language Models (LLMs) and Anthropic’s "Claude Code". They highlight the massive economic repercus

  22. Episode 313 - AppSec Role Evolution, AI Skills & Risks, Phishing AI Agents

    Feb 17, 2026

    Ken Johnson and Seth Law examine the intensifying pressure on security practitioners as AI-driven development causes an unprecedented acceleration in industry velocity. A primary theme is the emergence of "shadow AI," wh

  23. Episode 312 - Vibe Coding Risks, Burnout, AppSec Scorecards

    Feb 10, 2026

    In episode 312 of Absolute AppSec, the hosts discuss the double-edged sword of "vibe coding", noting that while AI agents often write better functional tests than humans, they frequently struggle with nuanced authorizati

  24. Episode 311 - Transformation of AppSec, AI Skills, Development Velocity

    Feb 3, 2026

    Ken Johnson and Seth Law examine the profound transformation of the security industry as AI tooling moves from simple generative models to sophisticated agentic architectures. A primary theme is the dramatic surge in dev

  25. Episode 310 - w/ Mohan Kumar and Naveen K Mahavisnu - AI Agent Security

    Jan 27, 2026

    In this episode of Absolute AppSec, hosts Ken Johnson and Seth Law interview Mohan Kumar and Naveen K Mahavisnu, the practitioner-founders of Aira Security, to explore the critical challenges of securing autonomous AI ag