EPISODE · Jul 21, 2026 · 52 MIN
José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Why do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling? Okta's José Carlos Chávez joins Chris to explain what changed in the 2025 list—and what stubbornly did not. Drawing on his path from software engineering and observability into security, José examines why ownership and root causes matter more than another scanner. They explore the rise of supply-chain and software-integrity failures, the fragile security model around downloaded AI skills and agent permissions, and the continuing need for immutable, trustworthy logging. Along the way, José uses museum heists to make the Top 10 memorable and shows how its categories connect. The result is a practical look at where AppSec teams should focus when familiar vulnerabilities persist and autonomous tools gain more access.Connect with José Carlos Chávez:→ José Carlos Chávez on LinkedIn→ OWASP CorazaMentioned in this episode:→ OWASP Top 10:2025→ OWASP Coraza→ Traceable→ tj-actions/changed-files advisory (CVE-2025-30066)→ Apache Kafka→ Istio→ Falco→ OpenTelemetry→ lodash→ The left-pad incidentFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet José Carlos Chávez01:19 From software engineering to application security04:54 Observability as a security foundation10:32 Museums, heists, and teaching the OWASP Top 1013:50 What changed in the OWASP Top 10 for 202517:31 Why broken access control is still number one24:59 Why injection refuses to disappear30:05 Supply chain risk vs. software integrity failures34:11 Can you trust downloaded AI skills?35:13 When an agent quietly controls your computer38:29 Immutable logging and incident evidence43:46 Root causes across the Top 1049:08 Ownership is the key takeaway52:07 Closing thoughts
Embed this episode
What this episode covers
Why do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling? Okta's José Carlos Chávez joins Chris to explain what changed in the 2025 list—and what stubbornly did not. Drawing on his path from software engineering and observability into security, José examines why ownership and root causes matter more than another scanner. They explore the rise of supply-chain and software-integrity failures, the fragile security model around downloaded AI skill...
Ready to play
José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.