Episode 179: OWASP Top 10 Part 1 - Broken Access Control, IDOR, and CORS Explained episode artwork

EPISODE · Apr 30, 2026 · 28 MIN

Episode 179: OWASP Top 10 Part 1 - Broken Access Control, IDOR, and CORS Explained

from The Cyber Threat Perspective · host SecurIT360

In Episode 179 of the Cyber Threat Perspective podcast, host Brad Causey and web app pen tester Jordan Natter kick off a multi-part series on the OWASP Top 10, the newly updated list of the most common and critical web application security risks, with a fresh version released in 2025.Before diving in, Brad sets the record straight on something that's been bugging him for 20 years: the OWASP Top 10 is an awareness document, not a compliance framework, not a pen test checklist, and not a comprehensive defense guide. If your vendor claims they "comply with the OWASP Top 10," that's a red flag — you can't comply with an awareness document.Part 1 focuses entirely on A01: Broken Access Control — the most dangerous and most common category on the list — and the conversation goes deep with real-world stories from active engagements.Topics covered include:What OWASP actually is — and why the Top 10 is both invaluable and widely misunderstoodBroken Access Control — what it means, why it tops the list, and how it manifests in real applicationsJWT validation failures — a healthcare application where improper JWT handling allowed unauthorized access to admin functionalityMFA bypass via broken access control — a university application where MFA codes weren't properly scoped, enabling account takeoverCORS misconfigurations — how Cross-Origin Resource Sharing policies fail in modern Node and React applications, including a real story of bypassing CORS by allowing AWS resourcesInsecure Direct Object References (IDOR) — why IDOR isn't just about changing integer IDs, including a university app where changing a student ID number led to staff-level privilege escalationS3 bucket IDOR — how a modern web application exposed PHI by returning GUIDs in JSON responses that could be enumerated directlyHidden functionality as false security — why hiding admin URLs from the navigation bar is obscurity, not security, and how Jordan accessed an entire admin PDF panel as an unauthenticated user just by copying a URLOWASP Top 10: https://owasp.org/Top10/2025/0x00_2025-Introduction/ Blog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

Episode metadata supplied by the publisher feed · Published Apr 30, 2026

Embed this episode

In Episode 179 of the Cyber Threat Perspective podcast, host Brad Causey and web app pen tester Jordan Natter kick off a multi-part series on the OWASP Top 10, the newly updated list of the most common and critical web application security risks, with a fresh version released in 2025. Before diving in, Brad sets the record straight on something that's been bugging him for 20 years: the OWASP Top 10 is an awareness document, not a compliance framework, not a pen test checklist, and not a compr...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Episode 179: OWASP Top 10 Part 1 - Broken Access Control, IDOR, and CORS Explained

0:00 28:48

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Cyber Threat Perspective?

This episode is 28 minutes long.

When was this The Cyber Threat Perspective episode published?

This episode was published on April 30, 2026.

Can I download this The Cyber Threat Perspective episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!