BadHost, Dead CTFs, Exploding NPMs, and the Verizon DBIR - ASW #385 episode artwork

EPISODE · Jun 2, 2026 · 45 MIN

BadHost, Dead CTFs, Exploding NPMs, and the Verizon DBIR - ASW #385

from Application Security Weekly (Audio)

We dedicate an episode to catching up on appsec news with Kalyani Pawar. We see parsing problems that led to the BadHost vuln, which exposed lots of LLMs, MCPs, and agents to potential compromise. We wonder where to look for security education and practice as the camaraderie of the CTF community becomes infiltrated by LLMs. We talk about the tradeoffs in trust between using public packages vs. having agents write replacements from scratch. And we examine some of the appsec details that the Verizon DBIR reveals about how orgs are being attacked -- and how orgs might use that information to protect themselves. Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-385

NOW PLAYING

BadHost, Dead CTFs, Exploding NPMs, and the Verizon DBIR - ASW #385

0:00 45:22

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of Application Security Weekly (Audio)?

This episode is 45 minutes long.

When was this Application Security Weekly (Audio) episode published?

This episode was published on June 2, 2026.

What is this episode about?

We dedicate an episode to catching up on appsec news with Kalyani Pawar. We see parsing problems that led to the BadHost vuln, which exposed lots of LLMs, MCPs, and agents to potential compromise. We wonder where to look for security education and...

Can I download this Application Security Weekly (Audio) episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!