Application Security Weekly (Audio)
4.9(12)

Application Security Weekly (Audio)

by Mike Shema

414 episodesLatest 3 days agoEN
About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

© 2024 CyberRisk Alliance

Recent reviews on Apple Podcasts (3)
  • Yes

    It’s the best.

    Alpha Gay ·

  • Great show

    Amazing show with great news and tips on making sure you code is secure.

    DMLou ·

  • Great show

    Best show I’ve found so far related to AppSec

    jrod d ·

View all reviews on Apple Podcasts

Episodes (414)

  1. The AI Threat Multiplier: Securing Mobile Apps in the Automated Era - Ryan Lloyd, Jason Cortlund - ASW #400

    Sep 15, 202652m

    While agents and LLMs haven't fundamentally changed core mobile vulnerability types, they have supercharged speed, scale, and accessibility—democratizing threats like automated phishing, synthetic identity fraud, and eas

  2. Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Ido Geffen, Sean Murphy, Idan Plotnik - ASW #399

    Sep 8, 20261h 9m

    We showcase recordings from this year's Black Hat. The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island Agents can independently discover and install tools, but th

  3. Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398

    Sep 1, 20261h 8m

    AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective str

  4. Applying Zero Trust Principles to Agents - Kieran Human - ASW #397

    Aug 25, 20261h 6m

    Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate t

  5. Augmenting Threat Intel Analysis with Agents - Chris Wallis, Sai Kiran Uppu, Ramin Farassat - ASW #396

    Aug 18, 20261h 9m

    All sorts of cybersecurity disciplines are adopting agents to help humans save time and automate routine activities. Sai Kiran Uppu describes his work on creating a platform for agents to analyze external threat intel, e

  6. Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

    Aug 11, 20261h 9m

    Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating

  7. Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394

    Aug 4, 20261h 3m

    There's already an increase in volume of security flaws found by LLMs. And orgs are already turning to LLMs to write code. So, what happens when orgs lean on LLMs to create patches for those security flaws? Keith Hoodlet

  8. Inside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393

    Jul 28, 20261h 9m

    Orgs need to be able to use agents, MCPs, and LLMs in ways that don't lead to unexpected actions and undesirable outcomes. The OWASP Agent Security Regression Harness project is an approach for defining customizable scen

  9. MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392

    Jul 21, 20261h 12m

    Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how

  10. Discovering & Securing Your AI Agent Attack Surface - Jeremy Snyder - ASW #391

    Jul 14, 20261h 7m

    While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order

  11. Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390

    Jul 7, 202647m

    Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'

  12. Reducing Attack Surface & Evaluating Efficiency in Agents - Itamar Apelblat, David Goldschlag - ASW #389

    Jun 30, 20261h 12m

    SquidBleed reveals another vuln that's been lurking for decades, but its real lesson is in managing an attack surface. Regardless of whatever programming language you use, removing code is one of the best security steps

  13. How AI Is Reshaping Identity Security at the Infrastructure Layer - Amit Masand, Neha Duggal, Ev Kontsevoy - ASW #388

    Jun 23, 20261h 10m

    Appsec has seen machine identities from daemons and processes to services, microservices, and cloud accounts. And now we have agents. Ev Kontsevoy talks about what it means to have engineers and agents interacting in an

  14. Why Does It Matter Who or What Created the Code? - Matias Madou - ASW #387

    Jun 16, 20261h 6m

    Agents and LLMs are creating and reviewing code. They're a new tool to help developers write software and they're a new abstraction layer for expressing what code should do. But if we're focused on determining whether co

  15. Scanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386

    Jun 9, 20261h 16m

    Most AppSec teams are working through more findings than their teams can validate. SAST surfaces thousands of potential issues. DAST generates alert volume that outpaces triage capacity. Somewhere in that output are the

  16. BadHost, Dead CTFs, Exploding NPMs, and the Verizon DBIR - ASW #385

    Jun 2, 202645m

    We dedicate an episode to catching up on appsec news with Kalyani Pawar. We see parsing problems that led to the BadHost vuln, which exposed lots of LLMs, MCPs, and agents to potential compromise. We wonder where to look

  17. AppSec Conversations on Agents, LLMs, and OWASP from RSAC - Merritt Maxim, Scott Clinton, Janet Worthington - ASW #384

    May 26, 202659m

    We showcase recordings from this year's RSAC. At RSAC Conference 2026, Scott Clinton, Co-Chair and co-founder of the OWASP GenAI Security Project, shares insights from the project's latest research, including new landsca

  18. The State of AI & AppSec - Keith Hoodlet - ASW #383

    May 19, 20261h 2m

    This year has been a dichotomy of established secure design fundamentals and burgeoning chaos of LLM-driven vuln discovery. Keith Hoodlet returns to share his latest observations on what the recent news about Mythos, mod

  19. Why Basic Security Practices Still Work - Rob Allen - ASW #382

    May 12, 20261h 11m

    If you have to ditch your entire appsec strategy because you expect 2026 to bring more vulns more quickly, then you probably didn't have a good strategy in the first place. Rob Allen shares how the mentality of "assume b

  20. Keeping Up With the OWASP GenAI Project - Scott Clinton - ASW #381

    May 5, 20261h 9m

    Speed is the most common theme among developers and appsec teams working with LLMs and agents, from trying to keep up with patterns for deploying agents to dealing with more code faster to how the latest models impact co

  21. Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 - James Kettle - ASW #380

    Apr 28, 202644m

    Portswigger's list of web hacking techniques is a long-running celebration of curiosity and research from the web hacking community. James Kettle shares his thoughts on the entries from 2025 and how he expects LLMs and a

  22. The Human Aspect of Red Teams - Brian Fox, Tom Tovar, T. Gwyddon 'Data' Owen - ASW #379

    Apr 21, 20261h 13m

    Red team exercises set goals to see if a particular outcome can be accomplished through a simulated attack, but the ultimate outcome should be educating the org about how to improve tools and processes that make attacks

  23. Securing Software's Journey with the OWASP SPVS - Ido Geffen, Rohan Ravindranath, Cameron W., Farshad Abasi - ASW #378

    Apr 14, 20261h 9m

    It's one thing to write secure code, it's another to release it into the wild. That code needs to be designed, built, tested, released, and maintained. Farshad Abasi and Cameron Walters explain how the OWASP Secure Pipel

  24. AppSec News Roundup on Claude Code Leak, Axios NPM Compromise, Secure Design - Idan Plotnik, Raj Mallempati - ASW #377

    Apr 7, 20261h 8m

    Security problems aren't changing very much even though security teams are. We catch up on the implications of the Claude Code source leak, the very human lessons from the axios NPM compromise, and what secure design loo

  25. Developing the Skills Needed for Modern Software Development - Keith Hoodlet, Shashwat Sehgal, Ron Rasin - ASW #376

    Mar 31, 20261h 15m

    The future of secure software is going through a mix of skills expected of humans and skills files created for LLMs. We might even posit that appsec as a discipline will fade (and that might not even be a bad thing!). Ke