José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists episode artwork

EPISODE · Jul 21, 2026 · 52 MIN

José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Why do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling? Okta's José Carlos Chávez joins Chris to explain what changed in the 2025 list—and what stubbornly did not. Drawing on his path from software engineering and observability into security, José examines why ownership and root causes matter more than another scanner. They explore the rise of supply-chain and software-integrity failures, the fragile security model around downloaded AI skills and agent permissions, and the continuing need for immutable, trustworthy logging. Along the way, José uses museum heists to make the Top 10 memorable and shows how its categories connect. The result is a practical look at where AppSec teams should focus when familiar vulnerabilities persist and autonomous tools gain more access.Connect with José Carlos Chávez:→ José Carlos Chávez on LinkedIn→ OWASP CorazaMentioned in this episode:→ OWASP Top 10:2025→ OWASP Coraza→ Traceable→ tj-actions/changed-files advisory (CVE-2025-30066)→ Apache Kafka→ Istio→ Falco→ OpenTelemetry→ lodash→ The left-pad incidentFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet José Carlos Chávez01:19 From software engineering to application security04:54 Observability as a security foundation10:32 Museums, heists, and teaching the OWASP Top 1013:50 What changed in the OWASP Top 10 for 202517:31 Why broken access control is still number one24:59 Why injection refuses to disappear30:05 Supply chain risk vs. software integrity failures34:11 Can you trust downloaded AI skills?35:13 When an agent quietly controls your computer38:29 Immutable logging and incident evidence43:46 Root causes across the Top 1049:08 Ownership is the key takeaway52:07 Closing thoughts

Episode metadata supplied by the publisher feed · Published Jul 21, 2026

Embed this episode

Why do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling? Okta's José Carlos Chávez joins Chris to explain what changed in the 2025 list—and what stubbornly did not. Drawing on his path from software engineering and observability into security, José examines why ownership and root causes matter more than another scanner. They explore the rise of supply-chain and software-integrity failures, the fragile security model around downloaded AI skill...

Distinct summary based on available episode metadata or transcript content.

Ready to play

José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists

0:00 52:39

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 52 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on July 21, 2026.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!