The Application Security Podcast podcast artwork

PODCAST · technology

The Application Security Podcast

Chris Romeo and Robert Hurlbut dig into the tips, tricks, projects, and tactics that make various application security professionals successful. They cover all facets of application security, from threat modeling and OWASP to DevOps+security and security champions. They approach these stories in an educational light, explaining the details in a way those new to the discipline can understand. Chris Romeo is the CEO of Devici and a General Partner at Kerr Ventures, and Robert Hurlbut is a Principal Application Security Architect focused on Threat Modeling at Aquia.

Publisher-supplied feed metadata · PodParley refreshed Jun 11, 2026 · Source feed

  1. 301

    How Agentic AI Fails—and Which Controls Actually Stop It

    Most fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents. Petra traded emergency medicine for application security and now heads information security at Numan — and she joins Chris Romeo and Robert Hurlbut to make the case for fault tree analysis (FTA), the deductive method that picks up exactly where threat modeling stops. Petra walks through a "wrong customer refund" AI agent scenario step by step, showing how AND/OR gates and minimal cut sets turn vague worry into ranked, data backed probabilities. They dig into where AI helps build a tree, and where garbage in, garbage out still applies, why "comprehensive test coverage" is a myth, and how attaching real dollar figures to failure paths makes it easier to sell security controls to leadership.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Petra Vukmirovic:→ Petra Vukmirovic on LinkedIn→ OWASP Threat Model LibraryMentioned in this episode:→ Adam Shostack: "Stop Trying to 'Manage Risk'" (keynote)→ OWASP Global AppSec USA 2026 (San Francisco, Nov 5–6)Follow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — the math behind where to put your controls01:09 Meet Petra Vukmirovic01:28 Petra's origin story: from ER doctor to AppSec02:50 Career path: engineer to Head of InfoSec at Numan04:18 What is fault tree analysis, and where threat modeling ends06:22 Can AI actually do fault tree analysis?08:12 Walking the "wrong customer refund" agent example12:33 Storing your trees: JSON vs. Markdown16:08 Why conjunctive failures trip up narrow thinking17:27 Top 3 failure modes when agents touch downstream systems19:29 Real story: an agent pushed code to main without approval21:27 Testing: why "comprehensive coverage" is a myth23:54 How rough is rough? Assigning probabilities28:08 Getting started without a six week science project31:35 Using FTA to sell controls and build credibility33:43 The epiphany: FTA is about controls, not faults34:48 The one thing every agentic team should add today35:48 Closing thoughts and OWASP Global AppSec USA preview

  2. 300

    Your AppSec Bottleneck Is a People Problem

    Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a champions community so the whole thing doesn't stall the week security goes on vacation. We also get into cutting security wait times, winning organizational support, what AI does and doesn't change here, and why she will tell you never to record the champions meeting.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Lisi Hocke:→ Lisi Hocke on LinkedIn→ A Tester's Journey — Lisi's blogMentioned in this episode:→ Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano)→ OWASP Juice ShopFollow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — what psychological safety actually means00:56 Meet Lisi Hocke02:25 Lisi's security origin story05:42 "That place was taken" — becoming a champion anyway07:39 Moving into a full-time product security role08:39 Meeting Björn Kimminich, the Juice Shop project lead09:23 Why role play instead of a normal conference talk12:27 Security and development, disconnected14:19 The first full-time security role15:14 Making people wait is the real damage17:10 Cutting the backlog and the turnaround time19:31 What Lisi got dead wrong20:08 What testing and quality work taught her21:31 The four things that make champions programs work22:07 One: fostering psychological safety24:50 Champions without their manager's blessing28:45 Two: managing cognitive load29:46 Three kinds of load, and which one to cut31:21 Three: power sources when you have no formal authority33:03 Four: build a champions community34:38 Keeping security people from burning out36:37 How AI changes who you recruit and what you need39:32 Should AI change champions programs at all?40:33 Psychological safety when a bot joins the meeting42:25 Don't record the champions meetings43:26 Programs that outlive the person who started them45:59 Key takeaway and homework47:21 Closing thoughts

  3. 299

    AI Pen Testing Killed Traditional DAST

    Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generated with context about your actual application, agents that chase findings the way a human tester would, and results a scanner was never going to produce. We get into what it costs once tokens enter the picture, who pays for them, whether a pentest on every pull request is realistic, and what stops an autonomous tester from going further than it should. Then we look further out: the future of bug bounties, what happens when cloud and model providers absorb today's security tooling, and who is accountable when an agent deletes your production database.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with James Berthoty:→ James Berthoty on LinkedIn→ Latio→ Latio PulseMentioned in this episode:→ Latio's free reports→ James on the podcast the first time: Is DAST Dead? And the future of API securityFollow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — the results speak for themselves01:01 Meet James Berthoty and the "Is DAST dead?" fallout01:31 Chickens, eggs, and getting away from screens03:46 Why we're revisiting the DAST question04:14 A working definition of AI pentesting05:47 Contextual payloads and application awareness06:47 Determinism, repeatability, and what buyers actually want07:46 Can you run an AI pentest on every code change?09:43 What it really costs10:40 Incumbents vs. AI-native vendors13:27 Who pays for the tokens?14:29 Bundling, platforms, and competitive pressure16:25 AI across the whole development workflow18:22 Agents that run all the way to deployment19:21 A pentest on every pull request21:52 What stops a pentest from going too far?23:10 Permission scoping and guardrails26:07 Where the findings actually land28:02 The future of bug bounties30:50 Why pentests command more budget than DAST31:45 Could the cloud providers absorb security tooling?34:38 What model providers could build instead36:36 The same story on the code scanning side39:24 Accountability when the tool misses something40:22 Shared responsibility when an agent deletes production41:23 The verdict on DAST42:19 Where to find Latio's free reports43:15 Closing thoughts

  4. 298

    AI Security: OWASP Meets Global Standards

    AI security has no shortage of standards — the problem is turning them into something a team can actually use. Rob van der Veer has spent 34 years in AI and security, founded the OWASP AI Exchange, and created MOSAIC, the agreement that brought eight standards bodies together with SANS to stop the fragmentation. Rob explains what responsible AI really means, what the EU AI Act actually asks of you, and why most AppSec teams are still missing the point on AI-generated code. We also get into agentic red teaming, what happens when agents quietly exceed their scope, and whether AI finally levels the playing field between attackers and defenders. If you build software with AI in it — or with AI — this one is worth your time.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Rob van der Veer:→ Rob van der Veer on LinkedIn→ OWASP AI Exchange→ MOSAICMentioned in this episode:→ OpenCRE→ Luna and the Magic AI PaintbrushFollow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — don't be surprised when the AI breaks out of the cage01:15 Meet Rob van der Veer: music, cycling, and the Hoodoo 50005:24 Defining responsible AI07:41 Fairness, protected attributes, and transparency09:34 The EU AI Act and what regulation actually asks of you11:27 How AI changes every part of software development13:23 Where responsibility lands15:20 You're not defending your own data center17:19 What traditional AppSec teams consistently miss about AI18:18 Finding vulnerabilities in AI-generated code19:19 Too many standards — and using AI to write them20:51 MOSAIC: eight standards bodies, one agreement22:09 One machine-readable taxonomy with OpenCRE23:06 Can AI level the field between attackers and defenders?25:59 When AI security becomes security theater26:56 What agentic red teaming actually looks like29:44 When agents exceed their scope32:43 Luna and the Magic AI Paintbrush33:40 Do we sandbox the agents?34:40 Guardrails without killing creativity36:39 Skill atrophy when AI is your only way forward40:04 "How do we hit this quarter?" and the pressure to ship43:16 Everyone is selling agentic security45:07 Key takeaways and where to start with the AI Exchange47:12 Closing thoughts

  5. 297

    The Future of Open-Source Threat Modeling

    You don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. Vikram created Precogly, an open-source threat modeling platform now running as an OWASP project, and he walks us through what it took to build a free tool on par with commercial vendors. We dig into the tension among speed, compliance, and real risk; whether the Threat Modeling Manifesto needs amending for AI; and what it means to "fight the AI" so critical thinking stays sharp. If you care about AppSec, AI, and the future of threat modeling, this conversation will give you a lot to think about.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Vikram Narayan:→ Vikram Narayan on LinkedIn→ Precogly — open-source threat modeling (OWASP project)Mentioned in this episode:→ Threat Modeling Manifesto→ ThreatModConFollow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — the threat model that "feels wrong"01:22 Welcome and introductions02:17 Vikram's security origin story05:43 From machine learning research into LLMs06:42 Hospital chatbots, hallucination, and knowing when to escalate07:51 ThreatModCon and the case for an open-source threat modeling tool09:35 IoT, emergence, and the traffic-light problem11:17 The OWASP Vienna talk and the Threat Modeling Manifesto12:26 Why "AI, just do the threat model" falls apart15:14 What AI is actually good at in threat modeling18:07 Human discomfort vs. the machine's confident answer20:29 Inside Precogly: accelerant, not replacement20:58 Library packs and the skills layer24:50 Where AI kicks in — and where it shouldn't27:48 Should the Threat Modeling Manifesto be amended for AI?30:28 Where Chris and Robert land31:36 Wi-Fi sensing, privacy, and modeling what you can't see33:15 If you can't explain it, can you trust it?35:11 Beyond checklists — design-level questions35:59 Fight the AI — Vikram's key takeaway39:10 Closing thoughts

  6. 296

    Isaac Evans - AppSec in the Age of AI

    AI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it? Semgrep co-founder and CEO Isaac Evans explains why deep background analysis and real-time agent plugins may replace universal rule sets with organization-specific security controls. He and Chris explore how security engineering roles will change, why independent verification still matters, and where business-logic flaws may become the next major battleground. The conversation also covers vibe coding at enterprise scale, the limits of reasoning about model behavior, open source in an agent-built world, and why Isaac sees more opportunity than threat even as AI creates a fresh wave of vulnerabilities and cleanup work.Connect with Isaac Evans:→ Isaac Evans on LinkedIn→ SemgrepMentioned in this episode:→ Semgrep→ DeepSeek→ Cursor→ OpenAI Codex→ Claude Code→ Boston Dynamics→ DARPA Robotics Challenge→ Reflections on Trusting Trust→ uutils/coreutils→ RustFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Isaac Evans01:11 From cryptography to the DARPA Robotics Challenge03:43 Founding Semgrep04:05 How AI is reshaping AppSec06:15 Attackers, defenders, and model choice08:02 Regenerating code until it clears the security bar10:30 Organization-specific rules beat universal rules14:18 The changing role of the security engineer17:53 Career advice for security practitioners19:47 Will foundation models absorb security vendors?24:18 Getting secure changes across an enterprise26:40 Trusting Trust becomes the easy problem27:41 How much should we trust agent-generated code?29:38 Independent verification and competing models34:50 Business logic flaws after SQL injection36:56 Protecting the new wave of citizen developers39:40 Vibe coding and disposable software42:05 Open source in an agent-built world44:10 Can the exponential pace continue?44:41 Key takeaways and calls to action

  7. 295

    José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists

    Why do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling? Okta's José Carlos Chávez joins Chris to explain what changed in the 2025 list—and what stubbornly did not. Drawing on his path from software engineering and observability into security, José examines why ownership and root causes matter more than another scanner. They explore the rise of supply-chain and software-integrity failures, the fragile security model around downloaded AI skills and agent permissions, and the continuing need for immutable, trustworthy logging. Along the way, José uses museum heists to make the Top 10 memorable and shows how its categories connect. The result is a practical look at where AppSec teams should focus when familiar vulnerabilities persist and autonomous tools gain more access.Connect with José Carlos Chávez:→ José Carlos Chávez on LinkedIn→ OWASP CorazaMentioned in this episode:→ OWASP Top 10:2025→ OWASP Coraza→ Traceable→ tj-actions/changed-files advisory (CVE-2025-30066)→ Apache Kafka→ Istio→ Falco→ OpenTelemetry→ lodash→ The left-pad incidentFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet José Carlos Chávez01:19 From software engineering to application security04:54 Observability as a security foundation10:32 Museums, heists, and teaching the OWASP Top 1013:50 What changed in the OWASP Top 10 for 202517:31 Why broken access control is still number one24:59 Why injection refuses to disappear30:05 Supply chain risk vs. software integrity failures34:11 Can you trust downloaded AI skills?35:13 When an agent quietly controls your computer38:29 Immutable logging and incident evidence43:46 Root causes across the Top 1049:08 Ownership is the key takeaway52:07 Closing thoughts

  8. 294

    Michael Burch - AI-Enabled Citizen Developers

    When every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how AI is turning nondevelopers into citizen developers faster than enterprises can build guardrails around them. He and the hosts examine rollouts that hand GitHub and Claude Code to hundreds of employees, the danger of measuring adoption instead of business value, and why prompt libraries alone do not meet people where they work. Michael argues for sandboxed workflows, automated security controls, clear limits, and AI champion programs that quietly carry security practices into every team. The discussion closes on evaluating generated code, token-cost incentives, and the need to define a measurable outcome before buying licenses or opening production access.Connect with Michael Burch:→ Michael Burch on LinkedIn→ Security JourneyMentioned in this episode:→ SecureMyVibe→ Manicode Security→ The Security Champions Podcast→ OWASP Low-Code/No-Code Top 10→ Claude CodeFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Michael Burch02:12 From Army Ranger to AppSec education05:40 What is an AI-era citizen developer?06:52 When low-code guardrails disappear08:49 Giving GitHub to 200 nondevelopers12:16 The rollout is already underway13:23 What happens outside the pipeline17:20 Training gaps and adoption without outcomes20:03 Measuring ROI instead of usage22:28 Why prompt libraries are not enough25:28 Sandboxing citizen developers28:36 Are organizations waiting for a breach?29:56 Turn security champions into AI champions32:00 How AppSec teams need to change34:58 Guardrails, expectations, and saying no38:41 Can developers evaluate generated code?42:40 Token pricing and platform lock-in44:36 When token usage becomes the wrong incentive46:17 A practical plan for citizen development48:28 Closing thoughts

  9. 293

    Josh Grossman--AI & SAST: Is it a match?

    Traditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better? Bounce Security CTO Josh Grossman explains why he built AGHAST, an open-source framework that combines static discovery with LLM analysis to investigate authorization, business-logic, and organization-specific risks. He walks through reducing false positives, importing SARIF, controlling token costs, and deciding where AI-assisted checks belong in developer workflows and CI. Josh also shares how he used Claude Code to build most of the project while retaining the architecture, product judgment, and code-review responsibility himself. The episode closes with AGHAST's roadmap, supported languages, practical adoption advice, and a guided demonstration of the tool.Connect with Josh Grossman:→ Josh Grossman on LinkedIn→ OWASP AGHASTMentioned in this episode:→ OWASP AGHAST→ Semgrep→ Cursor→ Claude Code→ SARIF→ NDC Security→ Black Hat→ DEF CON→ ISACA→ Manicode SecurityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Josh Grossman01:11 Why Josh built AGHAST04:22 Will AI disrupt AppSec tooling?06:09 How AGHAST combines static analysis and AI08:48 Deterministic rules and pure AI checks10:23 Reducing SAST false positives11:49 Using SARIF from existing scanners12:46 Building AGHAST with Claude Code14:14 The product specification and human judgment17:48 How much code did the AI write?19:05 The architect and product-manager mindset21:08 Token economics becomes its own industry22:54 Authorization and business-logic checks25:55 Context makes custom rules valuable28:15 Where AGHAST belongs in the workflow30:11 Languages, frameworks, and COBOL32:10 The AGHAST roadmap34:20 Key takeaway and call to action36:56 Training and conference appearances37:29 AGHAST demonstration

  10. 292

    Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets

    GitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse? Principal Developer Advocate Dwayne McDaniel explains what the 2026 State of Secrets Sprawl report reveals about public and private repositories, AI coding tools, MCP server templates, and developer-targeted supply-chain attacks. He and Chris unpack why standing credentials persist, how private repositories create false confidence, and why frontier models may improve without solving the organizational problem. The conversation moves from detection to governance: short-lived identity, ownership, feedback loops, and the political will to remove embedded keys. Dwayne's core challenge is blunt—organizations already have better authentication patterns, so what will make them finally use them?Connect with Dwayne McDaniel:→ Dwayne McDaniel on LinkedIn→ State of Secrets Sprawl 2026Mentioned in this episode:→ GitGuardian State of Secrets Sprawl Report 2026→ LangChain→ OpenRouter→ DeepSeek→ Mistral AI→ Perplexity→ Ox Security→ SPIFFE→ CNCF→ AWS STS→ OpenID Connect→ GitHub Octoverse→ Claude CodeFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Dwayne McDaniel00:39 Dwayne's path into secrets security02:23 How GitGuardian builds the report05:10 Where the private-repository data comes from06:20 Twenty-nine million leaked secrets09:15 Why the problem persists12:37 Secrets, identity, and standing privilege15:21 Three ways AI makes leakage worse16:39 Explosive growth in AI-service credentials17:57 MCP templates teach insecure authentication20:08 Is Claude Code getting safer?22:55 Hope for frontier models24:36 What will the OWASP Top 10 become?27:27 AI-assisted attacks target developers30:29 Old supply-chain attacks at machine speed33:06 What are organizations protecting now?35:39 Private repositories are six times riskier38:48 Moving from the problem to solutions39:21 Does the organization have the will to fix it?40:53 Governance and short-lived credentials44:51 Closing thoughts

  11. 291

    Tanya Janca - Secure Vibe Coding

    If AI writes all the code and the developer barely reads it, where does AppSec fit? Tanya Janca returns to define vibe coding and explain why models trained on insecure public code do not understand secure design by default. She and the hosts build a practical secure-vibe-coding framework: explicit requirements, human-led threat modeling, reusable security prompts, iterative review, SAST, and independent testing. Tanya shares hard-earned examples of Claude removing error handling, models confidently reviewing their own insecure output, and developers accepting enormous finding backlogs for code they did not enjoy writing. The discussion also examines whether security tooling will consolidate into AI platforms, how AppSec must be reimagined, and why continuous, embedded guidance matters more than occasional training. Tanya closes by introducing her DevSecStation podcast.Connect with Tanya Janca:→ Tanya Janca on LinkedIn→ SecureMyVibe→ DevSecStationMentioned in this episode:→ SecureMyVibe→ OWASP Top 10→ Burp Suite→ OWASP ZAP→ DevSecStation→ Tanya Janca (SheHacksPurple)→ ChatGPT→ Stack Overflow→ The Security Table podcastFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Tanya Janca returns02:10 What vibe coding actually means04:03 AI adoption and how developers prompt05:57 Treating AI like an intern07:28 Do AI systems need parental controls?09:34 Security prompts for everyday development11:47 Models, memory, and protecting sensitive data14:11 What happens when Claude goes away?16:02 The most dangerous vibe-coding misconception18:06 Threat modeling before AI writes the code22:48 Using AI throughout the development lifecycle25:32 A reusable secure-prompt framework29:09 Expose security assumptions and challenge flattery32:30 Reviewing an AI-generated codebase36:09 Will AI platforms absorb security tooling?37:39 Five million findings for code nobody wrote42:19 The remaining pieces of secure vibe coding43:52 Reimagining AppSec45:25 Continuous guidance beats occasional training46:05 Introducing DevSecStation47:12 Closing thoughts

  12. 290

    Caroline Wong--The AI Cybersecurity Handbook

    AI is multiplying the amount of software organizations produce, but security teams are not multiplying with it. Caroline Wong, author of The AI Cybersecurity Handbook and Chief Strategy Officer at Axari, explains how AppSec must change when agents generate code, make decisions, and assemble systems at machine speed. She and the hosts examine the growing backlog, the need for architecture and visibility, and why trust must be evaluated through accuracy, reliability, explainability, and accountability. Caroline also describes AI-augmented security teams as a practical response to constrained headcount and budgets. The conversation closes on preserving foundational knowledge, identifying roles most likely to change, and preparing now for a future that is arriving faster than traditional security programs can absorb.Connect with Caroline Wong:→ Caroline Wong on LinkedIn→ AxariMentioned in this episode:→ The AI Cybersecurity Handbook→ Security Metrics: A Beginner's Guide→ Cobalt→ BSIMM→ PCI DSS→ ChatGPTFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Caroline Wong02:52 Competitive jiu-jitsu away from the screen05:41 Learning through discomfort and failure09:01 Writing The AI Cybersecurity Handbook11:41 Why the AI shift is different14:05 How AI-generated code changes AppSec15:55 The security backlog grows faster19:14 Do we need to re-architect everything?21:34 Keeping visibility into agent-built systems25:45 Trusting AI in security work27:12 Criteria for evaluating trust29:58 Explainability and losing foundational knowledge34:00 AI-augmented security teams36:25 Doing more with fewer people and dollars39:24 Understand how the technology works40:55 Which security roles change first?43:36 Caroline's key takeaway44:16 Closing thoughts

  13. 289

    Steve Wilson--OpenClaw and Advanced AI Agents

    OpenClaw makes always-on personal AI agents feel inevitable—and exposes how poorly prepared most organizations are for their autonomy. Steve Wilson, Chief AI and Product Officer at Exabeam and founder of the OWASP GenAI Security Project, returns to explain how advanced agents differ from chatbots and why their permissions, memory, and ability to act create a radically larger blast radius. He and the hosts explore source-code exposure, prompt injection, supply-chain risk, and the uncomfortable gap between rapid adoption and meaningful oversight. Steve also discusses the OWASP Agentic Security Initiative, emerging guidance for builders, and the limits of treating an agent like an intern. The episode closes with a practical challenge: learn how these systems work before trusting them with consequential access.Connect with Steve Wilson:→ Steve Wilson on LinkedIn→ OWASP GenAI Security ProjectMentioned in this episode:→ OpenClaw→ Peter Steinberger→ Lex Fridman Podcast — Peter Steinberger on OpenClaw→ NVIDIA NemoClaw→ Claude Code source leak→ Tay→ OWASP GenAI Security Project — Get Involved→ OWASP Agentic Security Initiative→ The Developer's Playbook for Large Language Model Security→ OWASP Top 10 for LLM Applications→ Claude Code→ The Security TableFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Steve Wilson02:34 A fifth visit to the podcast04:21 What is OpenClaw?07:03 From chatbot to always-on agent10:16 Why personal agents feel different13:16 The expanding blast radius16:29 Permissions, memory, and persistent access18:43 Security catches up to agent adoption21:28 New tension between security and development24:09 When an agent exposes source code26:12 Understanding consequential failures29:59 Threats that keep defenders awake32:41 Agentic security guidance from OWASP35:45 Why the intern metaphor falls short38:18 Supervision and human accountability41:41 Where advanced agents are headed45:28 The one thing practitioners should do now48:48 Closing thoughts

  14. 288

    Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows

    AppSec teams are drowning in repetitive triage while the work that requires judgment keeps piling up. Brad Geesaman, Principal Security Engineer at Ghost Security, explains how large language models can shrink that toil without handing security decisions to an unreliable black box. He walks through using LLMs for classification, evidence gathering, and contextual analysis, with humans retaining final authority. Brad and Chris examine prompt engineering, trust, market disruption, and the limits of incumbent tools built around producing ever-larger finding queues. They also explore AI-assisted remediation, code drift, and the changing day-to-day work of AppSec engineers. The result is a pragmatic model for gaining leverage from AI while preserving the expertise, accountability, and skepticism that effective security still demands.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide application security training for not just your developers, but for all roles in your SDLC.→ Learn more about Security JourneyConnect with Brad Geesaman:→ Brad Geesaman on LinkedIn→ Ghost Security ReaperMentioned in this episode:→ Ghost Security→ Reaper→ Security Compass→ OWASP ZAP→ Burp Suite Professional→ SQL Slammer→ Code Red→ Nimda→ Exodus Communications→ NetWitnessFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Brad Geesaman03:01 What toil means in AppSec05:20 Why triage drains security teams06:13 Where AI can create leverage09:29 Does an LLM need custom training?11:51 Prompt engineering for useful results13:33 Humans remain at the center15:23 Trusting probabilistic systems19:30 A seismic shift in AppSec tooling20:18 Escaping the pile of findings24:00 How incumbent vendors are responding25:46 Why platform shifts leave openings28:31 The AppSec engineer's changing day33:04 Moving from triage to code changes35:36 AI-generated code and application drift38:49 What Brad hopes comes next41:51 Closing thoughts

  15. 287

    OWASP Candidate Debate - 2025 Edition

    What should OWASP become, and which leaders have a credible plan to get it there? In this special 2025 Board of Directors candidate debate, nine candidates present their qualifications and answer the same questions about OWASP's future. The discussion tests concrete ideas for expanding education, improving global and chapter outreach, strengthening project support, finding sustainable funding, and making the Foundation's impact easier to measure. Candidates identify where OWASP performs well, where it falls short, and how they would balance ambitious programs against limited staff and volunteer capacity. Closing statements give each participant a final opportunity to define their priorities. The result is a direct comparison designed to help OWASP members make an informed choice before voting.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.→ Learn more about Security JourneyConnect with OWASP:→ OWASP Foundation→ 2025 Global Board ElectionsMentioned in this episode:→ OWASP 2025 Global Board Elections→ OWASP Global Board Candidates→ OWASP Foundation→ OWASP Dependency-Check→ OWASP Dependency-Track→ OWASP CycloneDX→ OWASP Nettacker→ OWASP ASVS→ OWASP Security Champions GuideFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The 2025 OWASP candidate debate01:22 Debate format and opening question02:24 Candidates introduce themselves13:50 Sam Stepanian's introduction16:05 Arunesh Salhotra's introduction18:17 Arvind Janardhanan's introduction22:02 How should OWASP increase its impact?28:12 Comparing ideas for greater impact31:59 What is OWASP doing poorly?35:27 Project support and Foundation operations38:57 Using data to increase influence41:19 Indexing projects and regional review44:01 Should OWASP grow more chapters?48:43 A regional ambassador program51:50 How would candidates fund their plans?55:03 Corporate support and new funding58:52 Candidate closing statements64:37 Education as an OWASP priority68:05 Debate conclusion

  16. 286

    Francesco Cipollone - Agentic AI Manifesto

    Most products labeled as AI agents are little more than chatbots with tools. Francesco Cipollone, founder and CEO of Phoenix Security, explains what makes an agent genuinely agentic and why his team uses multiple specialized models instead of one all-purpose system. He and the hosts unpack the Agentic AI Manifesto's principles, including responsible adoption, human augmentation, transparency, and resisting automation for its own sake. Francesco also shares the practical economics behind multi-agent systems and the difficulty of applying them safely to vulnerability remediation. The conversation cuts through inflated promises while preserving a realistic case for useful automation: agents should increase human capability, remain observable and bounded, and solve a defined problem instead of becoming another vague digital-transformation initiative.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results.→ Learn more about Security JourneyConnect with Francesco Cipollone:→ Francesco Cipollone on LinkedIn→ Phoenix SecurityMentioned in this episode:→ Phoenix Security→ Cursor→ ChatGPTFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Francesco Cipollone02:36 Are you sure Francesco is not a bot?04:41 Why create an Agentic AI Manifesto?07:08 Defining a true AI agent09:21 The agent is not the LLM09:43 Six models working as specialists12:12 Why not use one super agent?15:05 The manifesto's core principles18:27 Augment people instead of replacing them21:17 The emerging AI coach role23:37 Escaping digital-transformation theater24:23 Transformation never really ends27:46 Agents and vulnerability remediation31:27 Closing thoughts

  17. 285

    Simon Gibbs & Devika Gibbs -- Building Bridges with Games

    Security education often struggles because the people in the room are being talked at instead of invited to participate. Simon and Devika Gibbs, the duo behind CyberSec Games, explain how tabletop games can turn abstract security concepts into shared experiences that connect developers, security practitioners, and business teams. They trace their path from agile stationery into threat-modeling games, describe what they learned from Elevation of Privilege and OWASP Cornucopia, and discuss the community that helped shape their work. The pair also introduce the Cybersecurity Game Challenge, including who can enter, how ideas are judged, and what winning makes possible. Their larger argument is simple: play lowers barriers, creates conversation, and can make difficult security lessons memorable enough to change behavior.Today's episode is brought to you by Security Journey.About Security JourneyOur education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including the OWASP Top 10.→ Learn more about Security JourneyConnect with Simon and Devika Gibbs:→ Simon Gibbs on LinkedIn→ Devika Gibbs on LinkedIn→ CyberSec GamesMentioned in this episode:→ CyberSec Games→ Cybersecurity Game Challenge→ Elevation of Privilege→ OWASP Cornucopia→ Threat Modeling Manifesto→ Adam Shostack→ EU Cyber Resilience ActFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Simon and Devika Gibbs02:39 From business analysis to game design05:36 Printing the Threat Modeling Manifesto06:27 What is CyberSec Games?08:38 Games bring people together11:13 A welcome from the security community14:34 Building bridges across disciplines18:00 Discovering Elevation of Privilege19:35 The return on a simple card deck22:45 How popular are security games?26:21 The Cybersecurity Game Challenge28:43 Judges and community contributors30:33 What can the winner receive?32:12 A future security-game reality show33:29 How and when to enter35:07 The audience homework assignment

  18. 284

    Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

    APIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization. Akansha Shukla draws on more than a decade in application security and DevSecOps to explain why API security remains immature and what practitioners can do about it. She and the hosts examine the OWASP API Security Top 10, broken object-level authorization, API-specific threat modeling, and the role of posture management. The conversation also asks why foundational controls such as input validation remain difficult despite strong framework support, and whether declarations that shift left is dead reflect reality or marketing. Akansha closes with practical guidance for building developer understanding, integrating security throughout delivery, and treating APIs as first-class elements of architecture rather than invisible plumbing.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide diverse training content and easy-to-digest lessons to meet individual learner needs. Learners report improving their knowledge as much as 85% on AppSec topics.→ Learn more about Security JourneyConnect with Akansha Shukla:→ Akansha Shukla on LinkedIn→ Women4Cyber Mentorship ProgrammeMentioned in this episode:→ OWASP API Security Top 10→ Burp Suite Professional→ Women4Cyber Mentorship Programme→ OAuth 2.0Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Akansha Shukla03:11 Moving from engineering into security06:13 Why development knowledge matters09:09 Using the OWASP API Security Top 1011:55 Authorization and API guardrails14:46 Threat modeling APIs17:26 Why teams skip API threat models18:49 Is the barrier knowledge or process?21:15 The role of API security posture management22:25 Why API inventory is still difficult24:41 Framework support versus real adoption27:43 Did security make the paved road too hard?28:14 Why input validation remains unsolved29:39 Is shift left dead?33:04 Akansha's key takeaway34:55 Closing thoughts

  19. 283

    Getting Ready for the EU CRA

    The EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe. Application Security Architect and OWASP SAMM core team member Nariman Aga-Tagiyev explains what manufacturers need to know about product classes, conformity assessments, vulnerability handling, software components, and enforcement. He and the hosts explore why global software companies should care, how the rules apply to commercial uses of open source, and what implementation may look like as regulators and assessors mature. Nariman then connects compliance to practical improvement through OWASP SAMM, BSIMM, DSOMM, and openCRE. His recommendation is to start with a maturity assessment now, identify gaps team by team, and use the regulation as leverage for sustainable security rather than a last-minute paperwork exercise.Connect with Nariman Aga-Tagiyev:→ Nariman Aga-Tagiyev on LinkedIn→ OWASP SAMMMentioned in this episode:→ EU Cyber Resilience Act→ OWASP SAMM→ BSIMM→ OWASP DevSecOps Maturity Model→ openCRE→ Linux FoundationFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Nariman Aga-Tagiyev02:48 From competitive programming to AppSec05:40 Learning security through software architecture09:21 Nariman's work with OWASP09:49 What the EU Cyber Resilience Act changes13:12 Product classes and conformity assessment16:15 Will certification work across Europe?17:17 How complicated is CRA compliance?18:49 Does the Act reference OWASP SAMM?20:49 Why should companies care?21:44 Three perspectives on the regulation25:40 Assessing readiness team by team28:20 How the CRA treats open source30:04 Commercial activity in the supply chain34:19 How enforcement may develop36:37 Start with a maturity framework38:27 Mapping requirements with openCRE39:49 Closing thoughts

  20. 282

    Marisa Fagan - Measuring Security Culture

    Security champions programs rarely fail because the idea is bad; they fail because organizations launch without management support, meaningful incentives, or a plan to prove value. Marisa Fagan, Head of Product at Katilyst and a veteran security-culture practitioner, shares a practical blueprint for piloting and scaling a program that lasts. She explains how to recruit and motivate champions using status, access, power, and stuff, why a pilot should produce both learning and a business case, and which anti-patterns quietly destroy trust. Marisa and the hosts also examine metrics for security culture, the role of qualitative evidence, and how champion models can extend to privacy and accessibility. The episode offers concrete guidance for building participation without turning volunteers into unpaid security staff.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide application security training for not just your developers, but for all roles in your SDLC.→ Learn more about Security JourneyConnect with Marisa Fagan:→ Marisa Fagan on LinkedIn→ KatilystMentioned in this episode:→ Security Champion Success Guide→ OWASP Security Champions Guide→ People-Centric Security→ Katilyst→ Kim WuytsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Marisa Fagan03:02 What security culture means05:44 Why security champions programs matter08:36 Starting with organizational context11:26 Recruiting the right champions14:58 The components of an effective pilot18:00 Turning a pilot into a business case18:52 Motivating champions with SAPS22:06 Status, access, power, and stuff25:30 Common program anti-patterns29:16 Chris's biggest champions-program mistake32:15 Metrics that demonstrate success35:02 Qualitative evidence and culture change37:32 How security careers shape the advice41:33 Creating space to share challenges46:10 Beyond security champions49:04 Closing thoughts

  21. 281

    Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics

    A dashboard full of green indicators can still describe an insecure organization. Aram Hovsepyan, founder and CEO of Codific and an OWASP SAMM contributor, explains why vulnerability totals and unexamined CVSS scores often measure activity instead of security outcomes. He introduces the Goal Question Metric framework as a way to begin with an organizational goal, ask what must be understood, and choose measurements that answer those questions. Aram and the hosts distinguish precision, reliability, and accuracy, examine how metrics shape behavior, and identify overlooked indicators that show whether a program is actually moving. They also discuss redesigning executive dashboards and testing a long-standing metric from Chris. The takeaway: a useful metric must support a decision, reflect context, and make its limitations visible.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results.→ Learn more about Security JourneyConnect with Aram Hovsepyan:→ Aram Hovsepyan on LinkedIn→ CodificMentioned in this episode:→ Goal Question Metric framework→ LINDDUN→ Codific→ OWASP SAMM→ Kim Wuyts→ Security Compass→ ToreonFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Why your security dashboard may be lying01:25 Meet Aram Hovsepyan02:43 From privacy research to AppSec06:30 The inspiration behind the talk09:44 How common security metrics fail11:35 If every metric is green, are you secure?13:23 Metrics drive human behavior16:48 Introducing Goal Question Metric18:38 Precision, reliability, and accuracy22:05 Good numbers can answer the wrong question26:43 Why total vulnerability counts mislead28:30 The metrics teams overlook31:52 Measuring movement, not perfection33:13 Redesigning a security dashboard35:04 Testing Chris's long-standing metric38:22 What a useful metric must reveal40:09 Closing thoughts

  22. 280

    Sean Varga -- OWASP Top 10 for AppSec Sales

    We’re discussing the intersections of application security (AppSec) and sales strategy with our guest, Sean Varga. Sean shares the unique challenges and best practices in AppSec sales, like the importance of empathy, understanding customer needs, and community participation. Learn about the OWASP top 10 for AppSec Sales and discover how to achieve success by aligning with customer goals, maintaining detailed living documents, and fostering strong partnerships. AppSec meets sales strategy. This is not your typical security podcast, but a glimpse into how sales work in AppSec. As security practitioners, we must practice empathy. This is our chance. We're unpacking the OWASP Top 10, not for vulnerabilities, but for what drives successful AppSec sales.Today's episode is brought to you by Security Journey.About Security JourneyOur education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10.→ Learn more about Security JourneyConnect with Sean Varga:→ DevOpsDays→ BSidesMentioned in this episode:→ DevOpsDays→ BSides→ Crossing the Chasm→ Veracode→ Secure Code WarriorFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Sean Varga: OWASP Top 10 for AppSec Sales09:00 I guess I want to ask kind of another question on18:00 Yeah, I have a kind of a different perspective on this20:14 You hit on something that is part of the frustration. Right28:15 You're describing in my mind what is a consultative approach to30:11 Yeah. So then we get to know your solution. Wait, you33:51 Right34:46 Mm-hmm. Let's, uh, we can jump over the understand all stakeholders44:25 I'm going to give you a second to think about your

  23. 279

    Sarah-Jane Madden -- What AI means for AppSec

    Sarah-Jane Madden joins Chris and Robert to ask what AI actually changes in software development—and what foundational practices still matter. Drawing on her OWASP Global AppSec EU keynote, she challenges the idea that AI makes the SDLC obsolete or turns every prompt into production-ready software. The conversation examines vibe coding, the difficulty of operationalizing AI-generated prototypes, skill atrophy, hallucinations, and the quality problems hidden by code that merely passes generated tests. Sarah-Jane argues for treating AI as a useful assistant rather than an unquestioned authority: engineers must preserve critical thinking, understand their systems, and verify the output. The episode closes with practical guidance for engineering leaders who want teams to gain efficiency from AI without surrendering judgment, accountability, or software quality.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide diverse training content and easy-to-digest lessons to meet individual learner needs.→ Learn more about Security JourneyConnect with Sarah-Jane Madden:→ Sarah-Jane Madden on LinkedIn→ Nemo Resideo keynote at OWASP Global AppSec EUMentioned in this episode:→ Nemo Resideo keynote at OWASP Global AppSec EU→ Sarah-Jane Madden — Threat Modeling to Established Teams→ GitHub CopilotFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Sarah-Jane Madden: What AI Means for AppSec02:35 From an OWASP keynote to AI in software development04:59 The biggest misconception about AI-assisted development07:13 Why AI will not eliminate software development11:58 Vibe coding and the production-readiness gap15:46 Operationalizing AI-generated prototypes17:53 Where AI helps inside the SDLC23:58 Over-reliance, skill atrophy, and engineering judgment27:00 Using AI for grunt work without losing core skills29:38 Can developers trust large language model output?33:36 Practical guardrails for responsible AI use

  24. 278

    Dag Flachet -- Kaizen for your Appsec Program

    Dag Flachet joins us to discuss the concept of Kaizen and its application in improving application security. Dag shares his journey into the world of security, emphasizing the importance of iterative, small-step improvements. The conversation delves into how organizations can effectively implement maturity models to enhance their security programs, the limitations of compliance-focused frameworks like ISO 27,000 and SOC 2, and the practical application of Kaizen principles. They also explore the evolution and future updates of OWASP SAM, and the importance of empowering development teams through a bottom-up approach in security enhancement. Dag is the co-founder of Codific, a professor and board member at the Geneva Business School, and an active member of the OWASP Barcelona Chapter and the OWASP SAMM community.The Application Security Podcast is brought to you by Security Journey.About Security JourneyOur training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.→ Learn more about Security JourneyConnect with Dag Flachet:→ Codific→ OWASP SAMMMentioned in this episode:→ Codific→ OWASP SAMM→ OWASP SAMM→ OWASP DevSecOps Maturity Model (DSOMM)→ openCRE.org→ EU Cyber Resilience ActFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Dag Flachet: Kaizen for your Appsec Program01:39 The thing that we love. Well, uh, we're joined by Dag06:54 That'd be funny if she sent a message yet. Like, hey13:20 Yeah, very cool. Well, as we mentioned, we're going to be17:08 Which is, is DSOM part of SAM now or are they22:08 This is an interesting thing, but maturity models have also evolved24:44 Let's wrap this whole thing together now. We introduced Kaizen. We've27:00 If we were to kind of dive a little bit deeper

  25. 277

    Javan Rasokat and Andra Lezza -- When Chatbots Go Rogue - Lessons Learned from Building and Defending LLM Applications

    What happens when teams add large language models to real applications and discover that familiar AppSec controls are no longer enough? Andra Lezza and Javan Rasokat share lessons from building, breaking, and defending LLM-enabled systems at Sage and presenting their findings at DEF CON. They compare prompt injection with SQL injection, explain AI red teaming, and unpack hallucinations, retrieval-augmented generation, grounding, and model safeguards. The conversation also examines corporate data leaking through prompts, the limits of trusting model providers, and how the OWASP Top 10 for LLM Applications complements issues observed in production. Andra and Javan close with practical advice for developers, data scientists, and security teams: treat AI systems as a new attack surface, establish clear data boundaries, and test controls against realistic abuse cases.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Andra Lezza and Javan Rasokat:→ Andra Lezza on LinkedIn→ Javan Rasokat on LinkedIn→ Javan Rasokat→ AppSec VillageMentioned in this episode:→ Adversarial Misuse of Generative AI (Javan's blog article)→ TLDR newsletter→ The Cuckoo's Egg by Cliff Stoll→ AppSec Village→ DEF CON→ ChatGPT→ DeepSeek→ NIST AI Risk Management Framework→ OWASP Top Ten for LLM Applications project homepageFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 When Chatbots Go Rogue with Andra Lezza and Javan Rasokat01:49 Andra’s path into application security02:56 Javan’s path into application security04:38 Lessons from building and defending LLM applications08:22 Prompt injection compared with SQL injection11:46 Critical vulnerabilities found in real AI systems12:19 What AI red teaming actually means13:46 Hallucinations, RAG, and grounding19:51 Model safeguards and harmful requests20:35 Common AI development and deployment mistakes23:20 Corporate data exposure through prompts29:59 OWASP Top 10 for LLMs versus real-world findings32:02 Practical security advice for AI developers34:36 Bringing security practices to data scientists45:37 Key takeaways for defending LLM applications

  26. 276

    Jim Routh -- The CISO Transition to the rest of life

    Former CISO Jim Routh discusses his perspective on retirement and career fulfillment in cybersecurity. Rather than viewing retirement as simply stopping work, Routh describes his three-filter approach: working only with people he respects and admires, doing only work he finds fulfilling, and controlling when he works. He shares valuable lessons learned about which post-retirement opportunities truly bring satisfaction and explains why he avoids certain roles. Routh emphasizes the importance of cybersecurity professionals taking ownership of their career development, recommending they focus on developing two specific skills annually rather than using tenure to guide career moves. Jim Ralph is currently on the boards of Savvy Security, Accountable Digital Identity Association, and the Global Resiliency Federation.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.→ Learn more about Security JourneyConnect with Jim Routh:→ CISO Transition (LinkedIn article by Jim Routh)→ Jim Routh on TwitterMentioned in this episode:→ CISO Transition (LinkedIn article by Jim Routh)→ Jim Routh on TwitterFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Jim Routh: The CISO Transition to the rest of life03:15 Hey, I'm happy to be here, Chris. Appreciate the kind words04:50 Yeah, I was recently, I was introduced to pickleball this past07:12 Of course, it wasn't offered in school when I went to13:20 Jim, what does the word retirement mean to you16:02 Why16:58 There's a lot of inertia dealing with that resistance, and that's19:34 Yeah, that's very helpful just to get this kind of your32:16 I think this conversation is something that should be helpful for34:40 For instance, I wanted to serve on boards. Why38:16 Just listening to you as we've kind of gone through this42:05 Yeah, that's helpful. Unfortunately, no one has invented this time machine44:53 Like, you, as long as you, you know, performed well, you47:24 Opportunity that's helping you, enabling you to learn the skills you

  27. 275

    Henrik Plate -- OWASP Top 10 Open Source Risks

    Henrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies. The list includes risks like known vulnerabilities, compromised legitimate packages, name confusion attacks, and unmaintained software, providing developers and organizations a framework to assess and mitigate potential threats. Henrik offers insights on how developers and AppSec professionals can implement the guidelines. Our discussion also includes the need for a dedicated open-source risk list, and the importance of addressing known vulnerabilities, unmaintained projects, immature software, and more. Henrik Plate is the principal security researcher at Endor Labs. He formerly worked for SAP Security Research, where he led the focus topic open source security starting in 2014.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results.→ Learn more about Security JourneyConnect with Henrik Plate:→ The OWASP Top 10 Open Source Risks→ Endor LabsMentioned in this episode:→ The OWASP Top 10 Open Source Risks→ Endor Labs→ OpenSSFFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Henrik Plate: OWASP Top 10 Open Source Risks01:42 We're back on the world of OWASP. We've, we've been away04:39 Yeah, Henrik, uh, just curious. So, uh, we're talking about the08:17 The order in this list mean something, or are these all10:29 Yeah. So if I'm a developer, what, how do I use12:47 I wonder if we could start to walk through the list19:43 This, XZ was a more modern example of this, right22:13 Yeah. And that's, and that's a common problem in the open24:28 All right, so what is 428:28 Okay. So Robert, why don't you, uh, pick one between 831:57 All right, Henrik, we have 3 questions that we typically ask35:01 Uh, the 3rd question is, what's your top book recommendation and

  28. 274

    Tanya Janca -- A Secure SDLC from a Developer's Perspective

    Security expert Tanya Janca discusses her new book "Alice and Bob Learn Secure Coding" and shares insights on making security accessible to developers. In this engaging conversation, she explores how security professionals can better Tanya Jenka, aka She Hacks Purple, is the bestselling author of Alice and Bob Learn Secure Coding, Alice and Bob Learn Application Security, and Cards Against AppSec. Over her 28-year IT career, she's won countless awards, including the OWASP Lifetime Distinguished Member and Hacker of the Year. She has spoken all over the planet and is a prolific blogger. Tanya has trained thousands of software developers and IT security pros via her online academies, We Hack Purple and Semigroup Academy, and her live training programs.Today's episode is brought to you by Security Journey.About Security JourneyOur education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10.→ Learn more about Security JourneyConnect with Tanya Janca:→ Ranakhalil1→ Alice & Bob Learn Secure CodingMentioned in this episode:→ Alice & Bob Learn Secure Coding→ Confidence Staveley→ Ranakhalil1→ Laurabellmain→ Adam Shostack→ Liran Tal→ OWASP Application Security Verification Standard (ASVS)→ Tanya Janca (SheHacksPurple)Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Tanya Janca: A Secure SDLC from a Developer's Perspective02:28 Glad, glad to have you here. So we have an intro06:50 This is definitely a needed piece of literature. I can, Robert09:26 Really11:23 Wow. Wow. So Robert, why don't you take us into that23:26 I'm curious to see who comes to those talks. Is it24:33 That's a— that's a view of the— the way what we're28:10 See30:46 It makes me, just made me think of something that I35:05 About other areas43:49 Put it on a t-shirt. That's good stuff. Well, that's, that's46:03 Yeah, definitely. Definitely. Well, Tanya, how about a key takeaway for

  29. 273

    Mehran Koushkebaghi -- Security as a Systemic Concern: How to develop Anti-Requirements

    Mehran Koushkebaghi, a seasoned engineering expert, delves into the intricacies of systemic security. He draws parallels between civil engineering and IT systems, and explains the importance of holistic thinking in security design. Discover the difference between semantic and syntactic vulnerabilities and understand how anti-requirements play a critical role in system resilience. This episode offers fresh perspectives on application security. Mehran Koushkebaghi has 15 years of engineering experience across multiple industries, beginning as a structural engineer before discovering his passion for security. He sees parallels between designing resilient buildings and robust IT systems, applying a holistic engineering mindset in his work. With a master's in computer science and self-taught expertise in applied cryptography and cloud, Mehran continues shaping dependable IT solutions.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide diverse training content and easy-to-digest lessons to meet individual learner needs.→ Learn more about Security JourneyConnect with Mehran Koushkebaghi:→ Peter Checkland→ RSA ConferenceMentioned in this episode:→ Peter Checkland→ RSA Conference→ Black Hat→ Critical System Thinking Book→ The Fifth Discipline→ Understanding Complexity→ Nassim Taleb booksFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Mehran Koushkebaghi: Security as a Systemic Concern: How to develop Anti-Requirements01:32 Yeah, we're going to explore a topic that we started a07:31 Does resiliency mean in a civil engineering context14:25 Because if you don't, if you don't understand that though, then19:55 I did have a, I did have an odd question on21:48 Yeah. Let me see if this— tell me if this works24:11 Sure. So, Marin, let's take a look at semantic versus syntactic40:39 Okay. Second one is, if you could display a single message42:37 Yeah, they're dense. They're thick books. And there's a, you have

  30. 272

    Kalyani Pawar -- Shaping AppSec at Startups

    Kalyani Pawar shares critical strategies for integrating security early and effectively in AppSec for startups. She recommends that startups begin focusing on AppSec around the 30-employee mark, with an ideal ratio of one AppSec professional per 10 engineers as the company grows. Pawar emphasizes the importance of building a security culture through "culture as code" - implementing automated guardrails and checkpoints that make security an integral part of the development process. She advises startups to prioritize visibility into their systems, conduct pentests, develop thoughtful policies, and carefully vet third-party tools and open-source solutions. Ultimately, Pawar's approach is about making security a collaborative, integrated effort that doesn't impede innovation but instead supports the startup's long-term success and safety.The Application Security Podcast is brought to you by Security Journey.About Security JourneyOur training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.→ Learn more about Security JourneyConnect with Kalyani Pawar:→ The Alignment Problem→ ChatGPTMentioned in this episode:→ The Alignment Problem→ ChatGPTFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Kalyani Pawar: Shaping AppSec at Startups01:24 Yeah, we're going to talk about AppSec and how it intersects05:45 Then that's a conversation to be had, but you should absolutely09:11 Because that's, that's the, that's the results of that. But coming12:51 One of the things about startups, and we kind of hinted15:34 As the startup matures over time, we kind of, you took19:22 Okay. So, let's say now you've got an AppSec team at22:06 At a startup, they'll just step on you if you try24:44 Yeah. I want to double-click on this culture as code, because27:43 The advantage in the startup world is you're starting from scratch31:37 Here we go. All right, so we've got 3 questions, Kalyani34:44 That's a good gauge, yeah. And the third question is, what's37:55 Yeah, people always, always got to focus on the original, right

  31. 271

    Milan Williams -- AppSec Metrics

    Milan Williams discusses the importance of application security metrics and how to make them both meaningful and actionable. She explains that metrics are crucial for tracking progress in what can often feel like an overwhelming security landscape, and they're valuable for career advancement and securing resources. We discuss metrics categories and several specific metrics that are good to track. Milan shares important principles on the importance of making metrics actionable through storytelling and relating security impacts to real-world consequences for users. Milan Williams is a senior product manager at Semgrep, where she helps security engineers and developers work together to ship secure software. She recently graduated from Harvard University with degrees in computer science and physics.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide application security training for not just your developers, but for all roles in your SDLC.→ Learn more about Security JourneyConnect with Milan Williams:→ Quiet Influence→ SemgrepMentioned in this episode:→ Quiet Influence→ SemgrepFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Milan Williams: AppSec Metrics02:58 I like that idea. So, all right, Robert, where are we04:45 Do you think people associate metrics with boring07:13 Yeah. It's all about OKRs, objectives and key results. And I10:33 If you've got that perspective, because it's one of those things12:00 For the metrics framework, could you walk us through that a15:19 Then, is there, are there additional metrics in the framework16:48 Before we go to any of the remaining categories, metrics, so22:55 Yeah. So, I took a turn there in the middle. We25:54 If it's simple and it's easily, easy to calculate, whichever thing27:05 Because that's the one that it's easy to create metrics, but30:41 All right, Lon, we have 3 questions to ask about in32:23 Very cool. And the final question is around book recommendations. What's34:19 Very cool. So, Milan, what do you want to leave our

  32. 270

    MO Sadek -- Building an AppSec Program from Scratch

    Mo Sadek shares his unique journey of building an Application Security program from scratch at Roblox. Mo discusses his unconventional path, including temporarily joining the infrastructure team to truly understand engineering challenges. He emphasizes that security isn't about mandating rules, but about making processes easier and more secure by default. Mo shares his insights on how to build effective cross-team security relationships and approaches for gaining leadership buy-in. Mo Sadek is a security transformation leader, passionate about staying ahead of emerging threats. He's built and fine-tuned vulnerability programs, customized solutions through hands-on coding, and driven security-first approaches in AI initiatives. Known for translating complex security metrics into actionable insights, Mo excels at uniting engineers, executives, and cross-functional teams.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.→ Learn more about Security JourneyConnect with MO Sadek:→ Roblox→ I Have No Mouth and I Must ScreamMentioned in this episode:→ Roblox→ I Have No Mouth and I Must Scream→ Metasploit→ GitHub Dependabot→ Robert HurlbutFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet MO Sadek: Building an AppSec Program from Scratch01:33 I can see the snow in your background there from the06:02 Way back to the beginning of the story. So, so, so07:18 Very cool. So jumping into the AppSec program at Roblox, you12:41 Then, how does that, your experience working on those different disciplines14:18 What, what, quick refine the question. Were you dotted line to20:39 Security. And now you mentioned incident response. Did you security engineering21:46 Mo, when you talk about, you know, the different approaches in25:16 You talked about the importance of partnership and, you know, listening29:35 How, how do you communicate this with senior leadership31:47 There metrics36:38 You mentioned, you use the term security partnership. And we certainly38:37 There's multiple partners then in the way that you think about44:24 All right. So lightning round, we have 3 questions that we47:15 All right, I'm going to check that one out. That's good

  33. 269

    Brett Crawley -- Threat Modeling Gameplay with EoP

    Brett Crawley discusses the Elevation of Privilege (EoP) card game, a powerful tool for threat modeling in software development. The discussion explores recent extensions to the game including privacy-focused suits and TRIM (Transfer, Retention/Removal, Inference, Minimization) categories. Crawley emphasizes that threat modeling shouldn't end with the game but should be an ongoing process throughout an application's lifecycle, ideally starting before implementation. He also shares insights from his book, which provides detailed examples and guidance for teams new to threat modeling using EoP. On today's episode, we're excited to host Brett Crawley, a principal application security engineer with over 25 years in software engineering and more than a decade in AppSec.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results.→ Learn more about Security JourneyConnect with Brett Crawley:→ Brett on X→ Threat Modeling Gameplay with EoPMentioned in this episode:→ Brett on X→ Threat Modeling Gameplay with EoP→ Conscious Business by Fred Kofman→ Elevation of Privilege→ Adam Shostack→ Threat Modeling Manifesto→ MITRE CAPEC→ The Security Table (podcast)Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Brett Crawley: Threat Modeling Gameplay with EoP01:57 Yeah, it's like almost the only thing we ever talk about05:16 Okay. Very cool. So diving into our topic today, to get06:45 About the Elevation of Privilege card game08:44 There a, just to clarify here, make sure I understand, we13:26 Anybody win15:20 Um, just to go back and revisit, uh, who created the17:45 Well, insecure data flows or open data flows, for example, things20:11 Then people can say, well, we've got TLS everywhere now, which22:38 For example, privacy and trim, T-R-I-M. Could you describe those or25:49 Can I take these cards that are extensions and put them27:45 Um, so is the goal then that I finish the card29:51 You mentioned from, as a key to success for a threat38:45 All right, let's jump in the lightning round. So we have41:06 Yes, thank you. So next question is, if you could display

  34. 268

    Matin Mavaddat - Understanding Security as a Systemic Concern: The Role of Anti-Requirements

    Matin Mavaddat discusses his perspective on security as a systemic concern, developed from his background in requirements engineering and systems architecture. He introduces the concept of "anti-requirements" - defining what a system should not do - and distinguishes between "syntactic security" (addressing technical vulnerabilities that are always incorrect) and "semantic security" (context-dependent security emerging from system interactions). Mavaddat shares his perspective that security itself doesn't have independent existence but rather emerges from preventing undesirable states. The discussion concludes with practical implementation strategies, suggesting that while automated tools can handle syntactic security issues, organizations should focus more energy on semantic security by understanding business context and defining anti-requirements early in the development process.Today's episode is brought to you by Security Journey.About Security JourneyOur education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10.→ Learn more about Security JourneyConnect with Matin Mavaddat:→ Matin's article: Reframing Security: Unveiling Power Anti-Requirements→ Systems Thinking for Curious Managers by Russell AckoffMentioned in this episode:→ Matin's article: Reframing Security: Unveiling Power Anti-Requirements→ Systems Thinking for Curious Managers by Russell Ackoff→ Antifragile by Nassim Nicholas Taleb→ The Black Swan by Nassim Nicholas Taleb→ Nassim Taleb booksFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Matin Mavaddat: Understanding Security as a Systemic Concern: The Role of Anti-Requirements01:48 So I'm excited to have Mateen join us here. And Mateen04:17 One, one follow-up question. I read the, the article that is10:38 Mateen, can I give you a quick example11:42 There like, what would you say14:20 I like that example. I'm just imagining a pile of parts20:59 There's independent choices that drive it, right25:33 I'm going to ask you what I think of as the29:48 I see the challenge here, Mateen, is people that aren't going33:29 Happens, here's another million-dollar question. I often think about, in the41:26 All right. Well, I think we gotta, we gotta move on47:41 Yeah. Yeah, I agree. I, I've read some of, uh, Taleb's

  35. 267

    Kayra Otaner -- DevSecOps

    Kayra Otaner joins the podcast today to discuss DevSecOps and answer the question, is it dead? Kayra is the Director of DevSecOps at Roche and is highly involved in the DevSecOps community. Kayra states that DevSecOps in its traditional form is “dead” and that each organization should approach its needs based on their size. Otaner introduces the concept of "security as code" and "policy as code" as more effective approaches, where security functions are codified rather than relying on traditional documentation and checklists. Finally, they discuss the emergence of Application Security Posture Management (ASPM) tools as the "SIM for AppSec," suggesting these tools, especially when enhanced with AI, could help manage the overwhelming number of security alerts and issues that currently plague development teams.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide diverse training content and easy-to-digest lessons to meet individual learner needs.→ Learn more about Security JourneyConnect with Kayra Otaner:→ Books by Yuval Noah Harari→ RocheMentioned in this episode:→ Books by Yuval Noah Harari→ Roche→ CISA Zero Trust Maturity Model→ The Phoenix Project→ OWASP DefectDojo→ OWASP Dependency-Track→ Phoenix SecurityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Kayra Otaner: DevSecOps01:47 I like to be controversial about our discipline. And there was03:59 All right. Well, Kayra, I think we're going to dive right09:28 Right12:29 No, I agree with you there. I mean, there's definitely not16:17 Can you gimme an example of a problem in which security19:58 Makes sense. So what about zero trust23:12 Yeah, so lightning round are 3 questions that we typically ask25:34 Kero, what would be a key takeaway or a call to27:09 Yeah. And Defect Dojo is a commercial entity now. So I30:32 I'm going to disagree with you to some regard. I'm an

  36. 266

    François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages

    François Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain. To help address this, his team developed an open source scanner called Poutine that can identify vulnerable build pipelines at scale and provide remediation guidance. Francois has over 10 years of experience in building application security programs, he’s also the founder of the NorthSec conference in Montreal. François Proulx is a senior product security engineer at Boost Security, where he leads the supply chain research team. With over 10 years of experience building AppSec programs for companies like Intel and various startups, he's been instrumental in the DevSecOps movement, making numerous responsible disclosures to organizations such as AWS, Google, Red Hat, and ChainGuard, and speaking at conferences on the topic.The Application Security Podcast is brought to you by Security Journey.About Security JourneyOur training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.→ Learn more about Security JourneyConnect with François Proulx:→ LinkedIn→ PoutineMentioned in this episode:→ Poutine→ Living Off the Pipeline→ NorthSec→ Cooking for Geeks→ Grand Theft Actions Abusing Self Hosted GitHub Runners→ LinkedIn→ François Proulx -- Actionable Software Supply Chain Security→ TLDR newsletter→ CycloneDXFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet François Proulx: Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages01:51 We're joined by Francois Proulx, second-time visit slash visitor to the04:39 It always, I mean, it raises your game to have to06:46 Okay. Hey, Francois, I know you talked recently at a thing12:44 Let me, let me read this back to you and make15:53 So make sure, I wanna make sure I understand here. So19:46 Game over, right23:04 Okay. And then, yeah. So from there, the sky's the limit25:17 Okay. So it seems like when I think about solutions, and29:41 Yeah. I'm going to stick up for Microsoft for a minute32:45 I think there's hope for the future that, that somebody will35:13 Okay. So just to quickly touch on Poutine, if I am40:59 All right. Yeah, we have 3 questions as well as we've43:02 Great, very timely. Who is somebody that our listeners should know

  37. 265

    Steve Wilson -- The Developer's Playbook for Large Language Model Security: Building Secure AI Applications

    Steve Wilson, the author of 'The Developer's Playbook for Large Language Model Security’ is back to dive into topics from his book like AI hallucinations, trust, and the future of AI. Steve has been at the forefront of the explosion of activity at the intersection of AppSec, LLM, and AI. We discuss the biggest fears surrounding LLMs and AI, and explore advanced concepts like Retrieval Augmented Generation and prompt injection. Steve Wilson is the author of The Developer's Playbook for Large Language Model Security: Building Secure AI Applications. Steve wrote a book, and we explored some of the topics from the book, like AI hallucinations, trust, and the future of AI.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide application security training for not just your developers, but for all roles in your SDLC.→ Learn more about Security JourneyConnect with Steve Wilson:→ Steve on LinkedIn→ Chris VossMentioned in this episode:→ The Developer's Playbook for Large Language Model Security→ Steve on LinkedIn→ Steve Wilson -- OWASP Top Ten for LLMs→ Steve Wilson and Gavin Klondike -- OWASP Top Ten for LLM Applications Release→ Chris Voss→ Arshan Dabirsiaghi→ Never Split The Difference Chris Vosstahl Raz→ Pixee→ Jeff Williams on LinkedInFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Steve Wilson: The Developer's Playbook for Large Language Model Security: Building Secure AI Applications02:35 Very cool. Very cool. Which WTF, ITF, what federation04:52 Well, let me mention the name of the book. Uh, we'll10:42 The ability for the model slash the system that's providing the12:36 Has there been any reported stories of that happening at scale14:48 That's, that's, uh, thanks for sharing that perspective on hallucinations. Trust18:19 Can we use agents to police themselves20:22 Yeah. And it seems like people that are, that are spending26:19 Most definitely. Most definitely. So, last chapter, I want to throw29:51 All right. So yeah, new questions. The first one is shift32:58 Then, uh, last question is, uh, who is someone that our34:18 Very cool. Thanks for sharing that. So Steve, key takeaway, call

  38. 264

    Jeff Williams -- Application Detection & Response (ADR)

    Jeff Williams, a renowned pioneer in the field of application security is with us to discuss Application Detection and Response (ADR), detailing its potential to revolutionize security in production environments. Jeff shares stories from his career, including the founding of OWASP, and his take on security assurance. We cover many topics including; security assurance, life, basketball and plenty of AppSec as well. Jeff Williams is a veteran application security expert who founded and led OWASP, Aspect Security, and Contrast Security. Jeff also created several highly successful open source projects, including JBomb, JOT, OWASP Top 10, WebGoat, ESAPI, ASVS, and more. Jeff serves as an advisor to NIST, CISA, PCI Council, Oasis Seraph, OWASP CycloneDX, OWASP Foundation, Eclipse Foundation, and advises many companies and agencies on AppSec.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.→ Learn more about Security JourneyConnect with Jeff Williams:→ Jeff Williams on LinkedIn→ The Tech of Runtime SecurityMentioned in this episode:→ Jeff Williams on LinkedIn→ The Tech of Runtime Security→ Contrast Security→ Log4j→ OWASP ESAPIFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Jeff Williams: Application Detection & Response (ADR)01:45 I mean, what's to talk about05:18 Does the competitive firework when you're in a, like in a13:12 You, has your thinking or your approach changed over the decades16:05 I'm curious now, the comment you made about vulnerability scans and17:39 Now to, to completely overturn the apple cart here, does AI20:45 Yeah. I've had the same, I've drawn the same conclusion as29:30 You're describing a world where the, the, what I would think31:33 We think about the now classic technologies in a company's AppSec34:59 There any, um, in terms of, you know, business problems, uh38:56 Jeff, where do you see ADR going into the future42:13 All right. Yeah. So, uh, first question is, um, shift left46:23 Okay. Second question is a conference talk, or is there a49:44 Very cool. Thanks for sharing that pointer. Definitely look Naomi up

  39. 263

    Phillip Wylie -- Pen Testing from Somebody who Knows about Pen Testing

    Philip Wiley shares his unique journey from professional wrestling to being a renowned pen tester. We define pen testing and the role of social engineering in ethical hacking. We talk tools of the trade, share a favorite web app pentest hack and offer good advice on starting a career in cybersecurity. Philip shares some insights from his book, ‘The Pentester Blueprint: Starting a Career as an Ethical Hacker. ’ And we discuss the impact of AI on pen testing and where this field is headed in the next few years. Our guest in this episode is Phillip Wiley. We explore the definition of pentesting, its relationship with red team activities, and the role of social engineering in ethical hacking.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term measurable results.→ Learn more about Security JourneyConnect with Phillip Wylie:→ Phillipwylie→ Ranakhalil1Mentioned in this episode:→ The Pentester Blueprint: Starting a Career as an Ethical Hacker→ The Web Application Hacker's Handbook→ The Hacker Maker→ The Phillip Wylie Show→ @PhillipWylie→ Phillipwylie→ The Web Application Hacker→ The Pentester BluePrint: Starting A Career As An Ethical Hacker P 9781119684305→ Burp Suite→ OWASP ZAP→ Metasploit→ Nessus→ sqlmap→ Kali Linux→ Bugcrowd→ SANS Institute→ Ranakhalil1→ PCI DSSFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Phillip Wylie: Pen Testing from Somebody who Knows about Pen Testing02:33 Right. Oh, the typical story. No, unfortunately, I wish it was06:19 So one, one last wrestling question. This is quickly becoming the09:31 I gotta imagine that there's a certain amount of improv though11:19 Good decision there. So Phillip, how about security15:13 Mm-hmm. So pen testing, I think, is the, is the primary19:30 Yeah, that's a good, that's a good, good way to summarize22:45 You mentioned SQL injection. I'm always curious to understand from somebody24:12 Okay. So it's not something that's, uh, yeah, that's interesting that27:03 I wanted to circle back on, you mentioned social engineering and29:18 With payloads, like I said. Yeah. So if we think about32:52 Let's shift a little bit. Uh, I know that you've done35:47 We want to just mention and hear a little bit more38:36 Yeah, that's really cool. And I want to, um, I want39:31 I, and the pet peeve I have is Talk to a46:46 Yeah. How is, um, another just off the top of my50:11 Phillip, I want to just, I know you do podcasts and

  40. 262

    Steve Springett -- Software and System Transparency

    Steve Springett, an expert in secure software development and a key figure in several OWASP projects is back. Steve unpacks CycloneDX and the value proposition of various BOMs. He gives us a rundown of the BOM landscape and unveils some new BOM projects that will continue to unify the security industry. Steve is a seasoned guest of the show so we learn a bit more about Steve's hobbies, providing a personal glimpse into his life outside of technology. Steve Springett educates teams on the strategy and specifics of developing secure software. He practices security at every development lifecycle stage by leading sessions on threat modeling, secure architecture and design, static dynamic component analysis, offensive research, and defensive programming techniques.Today's episode is brought to you by Security Journey.About Security JourneyOur education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10.→ Learn more about Security JourneyConnect with Steve Springett:→ CycloneDX→ Software Transparency: Supply Chain Security in an Era of a Software-Driven SocietyMentioned in this episode:→ CycloneDX→ Software Transparency: Supply Chain Security in an Era of a Software-Driven Society→ JC Herz and Steve Springett -- SBOMs and software supply chain assurance→ OWASP Dependency-Track→ CycloneDX→ OWASP Foundation→ Log4j→ Apache Struts→ Open Threat Model (OTM)→ OWASP Threat Dragon Project→ LINDDUN→ PCI Security Standards Council→ Software Transparency: Supply Chain Security in an Era of a Software-Driven Society by Chris Hughes, Tony Turner→ OWASP Dependency-CheckFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Steve Springett: Software and System Transparency02:04 It's, uh, well, the City of Brotherly Love, isn't that what06:05 That's just, it's just another reminder that we all gotta find07:44 Um, Robert, where are we, where are we going with Steve11:00 And I think a lot of people in AppSec are going12:21 Right14:26 I'd love to get you kind of on the record giving19:08 Based on the Log4j, Log4Shell example, let's have it, let's, let's23:03 We've talked about some of the use cases, but are there24:52 We think about All of these different capabilities and different, I30:18 Let's say in relation to that transparency, but also, uh, commonalities33:19 I know you've been doing some work, Steve, on this idea36:32 I mean, it, it, I think if I, if I kind42:47 Okay. Yeah. So we have 3 questions. Do we, have we45:19 Last question, uh, what's your top book recommendation and why do

  41. 261

    Irfaan Santoe -- The Power of Strategy in AppSec

    Irfaan Santoe joins us for an in-depth discussion on the power of strategy in Application Security. We delve into measuring AppSec maturity, return on investment, and communicating technical needs to business leaders. Irfaan shares his unique journey from consulting to becoming an AppSec professional, and addresses the gaps between CISOs and AppSec knowledge. Irfaan shares valuable insights for scaling AppSec programs and aligning them with business objectives. Irfaan Santoe joins us to discuss the power of strategy in AppSec. We go deep on this one, on AppSec program maturity, how we can measure maturity, and even some tips for success. We talk about measuring return on investment and how to speak the language of the business as a technical person.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide diverse training content and easy-to-digest lessons to meet individual learner needs.→ Learn more about Security JourneyConnect with Irfaan Santoe:→ OWASP SAMM→ OWASP Security Champions GuideMentioned in this episode:→ OWASP SAMM→ OWASP Security Champions Guide→ BSIMM→ Jim Routh on Twitter→ OWASP Netherlands Chapter→ OWASP SAMMFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Irfaan Santoe: The Power of Strategy in AppSec03:12 That's kind of the— it's almost the opposite of what a06:35 A little bit about maturity. So, what is maturity within an09:30 We think about measuring maturity then, so let me read back12:20 Yeah. So, what is a part of that link then17:16 Okay. So, we talked a little bit about, you know, how20:59 I think there's a real disconnect between the business side and27:03 Because that seems like, I mean, that's return on investment to29:39 I've been waiting to ask this next question for a long31:49 Yeah. And, if we use your car example and if I33:51 Let's pull all this together. How do we scale an AppSec38:12 All right. So, we have 3 questions that we usually ask

  42. 260

    Andrew Van Der Stock -- The New OWASP Top Ten

    Andrew Van Der Stok, a leading web application security specialist and executive director at OWASP joins us for this episode. We discuss the latest with the OWASP Top 10 Project, the importance of data collection, and the need for developer engagement. Andrew gives us the methodology behind building the OWASP Top 10, the significance of framework security, and much more. Andrew Vanderstock is a seasoned web application security specialist and enterprise security architect. He's the executive director at OWASP, taking the foundation through organizational change and taking OWASP's mission to the next level. Andrew has worked in the IT industry for over 25 years, has researched and developed the web application security and architecture fields since 1998.The Application Security Podcast is brought to you by Security Journey.About Security JourneyOur training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.→ Learn more about Security JourneyConnect with Andrew van der Stock:→ The Crown Road by Iain Banks→ Edward TufteMentioned in this episode:→ The Crown Road by Iain Banks→ Edward Tufte→ OWASP Top Ten Project→ OWASP Developer Guide→ PCI DSS→ OWASP Top Ten for LLM Applications project homepage→ RSA ConferenceFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Andrew van der Stock: The New OWASP Top Ten01:41 We are about to go on a journey into the topic04:10 Phone goes with you probably just for emergency purposes, but so07:27 Probably get ways to deal with it, right13:08 Help me, help me remember what, what, what is the connection15:29 On the topic of OWASP Top 10, give us an update17:16 We talk about data and the need for data, I don't20:58 Then if— so the, the request for data is really more21:56 Now I'm curious. I want to dig a little deeper on26:00 Are the downsides of, potential downsides of this data collection approach30:23 That data weighted different in the model if it comes from33:33 Wrapping all of this kind of together, we've got the data35:14 I mean, or it used to be. Yeah. Or it used36:24 I can, I mean, just to second something you said a40:38 Yeah. So you already jumped ahead to controversial opinion, but before42:23 All right. Yes, we already talked about the controversial opinions. So45:59 Great. Last question is, what's your top book recommendation and why50:12 Andrew, what's, how about a key takeaway then

  43. 259

    Derek Fisher -- Hiring in Cyber/AppSec

    Derek Fisher, an expert in hardware, software, and cybersecurity with over 25 years of experience is back on the podcast. Derek shares his advice on cybersecurity hiring, specifically in application security, and dives into the challenges of entry-level roles in the industry. We discuss the value of certifications, the necessity of lifelong learning, and the importance of networking. Listen along for good advice on getting noticed in cybersecurity, resume tips, and the evolving landscape of AppSec careers. Mentioned in this episode: The Application Security Handbook by Derek Fisher Derek Fisher brings over 25 years of hardware, software, and cybersecurity expertise across multiple industries, including healthcare and finance.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide application security training for not just your developers, but for all roles in your SDLC.→ Learn more about Security JourneyConnect with Derek Fisher:→ The Application Security Handbook by Derek Fisher→ Cyber for Builders by Ross HaleliukMentioned in this episode:→ The Application Security Handbook by Derek Fisher→ Cyber for Builders by Ross Haleliuk→ Effective Vulnerability Management by Chris Hughes→ With the Old Breed by E.B. Sledge→ Derek Fisher – The Application Security Handbook→ WiCyS (Women in Cybersecurity)→ CISSP→ BSidesFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Derek Fisher: Hiring in Cyber/AppSec01:35 Yeah, we're joined by someone who's been on the podcast before03:48 What's your favorite thing to grow06:21 It's the, as you said, it's the therapeutic value of getting11:05 Which to your point, mid to senior level people are 100%13:15 With that in mind, I mean, how are people getting into17:32 I mean, if anything, it's the patterns, kind of the try20:03 Reminds me of something about Billy the Kid. Like, do you21:58 You mentioned resume reviews. I'm always curious. I've never participated in26:18 The last, you know, 5, 7 years, all the hiring I've33:16 I would say, you know, that's one way to stand out35:43 One of the we got to blame the hiring companies though37:00 You can apply something, yourself to something. And so that, I39:57 That, that I look back and say, I didn't necessarily use47:59 By doing a pen testing class and doing a forensics class52:17 All right. So yeah, 3 questions that we have. First of55:34 Makes sense. So number 3, what's your Top book recommendation and57:24 Yeah, he just wrote a new book on, yeah, it's the58:49 Excellent. Derek, what about a key takeaway or a call to

  44. 258

    Tanya Janca -- Secure Guardrails

    Tanya Janka, also known as SheHacksPurple, discusses secure guardrails, the difference between guardrails and paved roads, and how to implement both in application security. Tanya is an award-winning public speaker and head of education at SEMGREP and the best-selling author of ‘Alice and Bob Learn Application Security’. Tanya shares her insights on creating secure software and teaching developers in this episode. Tanya Jenka, also known as She Hacks Purple, is the bestselling author of Alice and Bob Learn Application Security. She's also the head of education and community at Semgrep, sharing content and training around teaching everyone to create secure software. Tanya's been coding and working in IT for over 25 years.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC.→ Learn more about Security JourneyConnect with Tanya Janca:→ Tanya Janca on LinkedIn→ Alice and Bob Learn Application SecurityMentioned in this episode:→ Alice and Bob Learn Application Security→ Semgrep→ Tanya Janca – What Secure Coding Really Means→ The Expanse Series→ Alice and Bob Learn Application Security→ Tanya Janca (SheHacksPurple)→ Azure DevOps→ Microsoft Security Response Center (MSRC)→ Microsoft Defender for Cloud→ Content-Security-Policy (MDN)→ Scott Helme→ Kim Wuyts→ Executive Order 14028→ OWASP SAMMFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Tanya Janca: Secure Guardrails05:09 Oh, that's so cool. So what, what are you excited about06:49 Oh, that's great. That's, yeah, it's a, that's a fun thing10:05 I was like, no, no, I'm good. And it was like12:05 So based on the example that you just shared there, Now15:55 Would you like to use the wrapper library17:36 Am I willing to break the build19:41 Oh, actually, you know what22:39 What's the role of making it easy with the paved road24:58 Right26:53 Makes sense. Makes sense. That's, that's, uh, it's helpful just to30:18 I have to go rotate the secret, yada, yada, yada, right32:58 Like, because getting into buildings when you should not is a34:18 No, no, it's good. It's good. So I guess one more37:48 Someone else told me she did that and it said, this40:19 All right. One more guardrail topic. And this is one that43:05 Right46:24 It's time for her to come back again. She has been47:38 No50:13 We've all gotten those though for, for plenty of times in53:34 Um, and so then we talked about it and I'm like57:14 So I'm going to do the top programming frameworks as well61:11 Oh, nice. Very cool. Very cool. So, just to kind of

  45. 257

    Jahanzeb Farooq -- Launching and executing an AppSec program

    Jahanzeb Farooq discusses his journey in cybersecurity and the challenges of building AppSec programs from scratch. Jahanzeb shares his experience working in various industries, including Siemens, Novo Nordisk, and Danske Bank, highlighting the importance of understanding developer needs and implementing the right tools. The conversation covers the complexities of cybersecurity in the pharmaceutical and financial sectors, shedding light on regulatory requirements and the role of software in critical industries. Learn about prioritizing security education, threat modeling, and navigating digital transformation. Jan Zeb Farouk currently serves as the head of application security at Danske Bank, the largest bank in Denmark. Before this, he was with Novo Nordisk, where he played a key role in building their application security program from scratch and in securing their digital health solutions.Today's episode is brought to you by Security Journey.About Security JourneyOur education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10.→ Learn more about Security JourneyConnect with Jahanzeb Farooq:→ The Power of Habit by Charles Duhigg→ BSIMMMentioned in this episode:→ The Power of Habit by Charles Duhigg→ BSIMM→ OWASP SAMMFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Jahanzeb Farooq: Launching and executing an AppSec program01:57 You could have told me that you painted it. I would07:12 From that perspective. So how do you get to AppSec then09:08 AppSec12:55 I have a question. I have a question about having never15:57 There's no central, so like they don't share services or share17:27 You're starting with these businesses that were non-IT. They made their25:46 Do you, what are you, what's the equation you're using to28:18 You mentioned maturity. Is that something that is based on, Are29:20 A little question about some of the experiences that you've had40:06 If I, if I kind of read that back to you42:58 Yeah, I think a well-tuned SAST tool is a good assessment45:29 Question 2, if you could display a single message on a47:14 Yeah, I think really cool. We'll put a link to that

  46. 256

    David Quisenberry -- Building Security, People, and Programs

    David Quisenberry shares about his journey into the security world, insights on building AppSec programs in small to mid-sized companies, and the importance of data-driven decision-making. The conversation delves into the value of mentoring and why it's important to build real relationships with the people you work with, the vital role of trust with engineering teams, and the significance of mental health and community in the industry. David Quisenberry leads security teams at Capri Health, where he's the senior manager of information security. He's a lifetime OWASP member, former chapter president of the Portland, Oregon OWASP chapter, and co-founder of the OWASP AppSec Days PNW.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide diverse training content and easy-to-digest lessons to meet individual learner needs.→ Learn more about Security JourneyConnect with David Quisenberry:→ SRE Engineering→ The Phoenix ProjectMentioned in this episode:→ SRE Engineering→ The Phoenix Project→ Security Chaos Engineering→ Wiring the Winning Organization→ The Body Keeps the Score→ Never Eat Alone→ How Leaders Create and Use Networks→ CISO Desk Reference Guide→ Intelligence Driven Incident Response→ Thinking Fast and Slow→ Do Hard Things→ BSIMM→ OWASP Application Security Verification Standard (ASVS)→ BSidesFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet David Quisenberry: Building Security, People, and Programs01:44 That's, uh, that's a t-shirt, t-shirt idea. I wish I had04:45 Yeah. It's, it's one of those things where we're never going06:56 Um, and I love that illustration you just made about comparing12:43 In your experience then doing this a couple of times, do17:28 I want to, I want to just acknowledge, I want to19:42 That's just me. I, I, uh, yeah, I had, I had22:52 Yeah. And I want to go there next. Um, I guess24:08 This idea of trust with the engineering teams, because it seems35:21 Let me, uh, let me, let me just summarize a couple38:17 I never hear from him again. He's like, this was kind40:54 About, let's just touch on this mental health point and just44:29 I was just going to bring that up because it's something47:30 We got to deal with this last one. Um, cause this48:53 So I just kind of, the sociologist in me, this happens

  47. 255

    Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People

    Matt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec. The conversation delves into the nuances of software supply chain security and exploring how different perceptions affect its understanding. Matt provides insights into the XZ compromise, critiques the buzzword 'shift left,' and discusses the role of digital twins and AI in enhancing the supply chain security. He emphasizes the need for a comprehensive approach beyond SCA, the relevance of threat modeling, and the potential risks and benefits of AI in security. Matt Rose is a technical AppSec testing leader with consistent accomplishments in sales and sales engineering management roles with more than 20 years of experience.The Application Security Podcast is brought to you by Security Journey.About Security JourneyOur training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.→ Learn more about Security JourneyConnect with Matt Rose:→ LinkedIn→ The Application Security Program Handbook by Derek FisherMentioned in this episode:→ The Application Security Program Handbook by Derek Fisher→ ReversingLabs→ YouTube video→ Stephen E Ambrose→ Mark Frost→ Fortify (OpenText)→ ChatGPT→ Pixee→ LinkedInFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Matt Rose: Software Supply Chain Security Means Many Different Things to Different People03:53 Let me ask you this question. How good are you at04:45 That's true. That is so true. That's, that's a good way11:33 Yeah, 100%. And I like to think of weaknesses in the14:56 You're, you just made me think of something. About when you17:12 Yeah, it seems like, it seems like there's a perfect storm19:09 I want to double-click on something that you mentioned earlier. And22:10 I mean, I think that's more of a startup growth problem24:55 It the first, is it the first thing you would like28:15 Yeah, I've never actually seen anybody do it. I've heard DJ30:38 About, uh, AI34:39 Yeah, I'm not, I'm not ready to embrace auto-remediation at this37:32 Yeah. And we're starting to see a whole cottage industry of40:14 Absolutely. The second question is, what would it say if you41:54 Our 3rd question is, uh, what's your top book recommendation and

  48. 254

    James Berthoty -- Is DAST Dead? And the future of API security

    James Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security. James highlights his career trajectory from IT operations to cloud security, his experiences with security tools like Snyk and StackHawk, and the evolving landscape of Dynamic Application Security Testing (DAST) and API security. They delve into the practical challenges of CVEs, reachability analysis, and the complexities of patching in mid-sized companies. James shares his views on the often misunderstood role of WAF and the importance of fixing issues over merely identifying them. James Berthoty has been in technology for over 10 years in engineering and security roles.The Application Security Podcast is brought to you by Security Journey.About Security JourneyWe provide application security training for not just your developers, but for all roles in your SDLC.→ Learn more about Security JourneyConnect with James Berthoty:→ AppSec Kool-Aid Statements I Disagree With→ What is Art by Leo TolstoyMentioned in this episode:→ AppSec Kool-Aid Statements I Disagree With→ What is Art by Leo Tolstoy→ Snyk→ StackHawk→ AppSec Kool-Aid Statements I Disagree With→ National Vulnerability Database (NVD)→ eBPF→ KubernetesFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet James Berthoty: Is DAST Dead? And the future of API security04:11 Mm-hmm. So when I think about your trajectory here, so you've06:48 Let's start with this idea of DAST. And so anyone who's10:02 So when you, when you're seeing these API scanners these days13:07 You still using the term DAST or have you replaced it14:49 What's your, what, what are your thoughts on this16:42 Okay. That's helpful. What about reachability analysis19:22 Patching really still that hard22:43 The million dollar question then, is AI going to solve the28:04 Yeah. I mean, fix it yourself and generate a PR, submit32:22 I'm, I mean, let's, let's just talk about WAF and, and36:12 Yeah, I think that's, uh, that's definitely true. Well, you got38:01 Okay. Next. Like, celebration time. Yep. We passed. All right. So41:29 Yeah. Yeah, definitely. So, all right, let's do a couple of42:29 Question is, if you could have display a single message on

  49. 253

    Mark Curphey and Simon Bennetts -- Riding the Coat Tails of ZAP, without Open Source Funding

    ZAP supports an enormous share of the application security ecosystem, but who pays for the people keeping it reliable? Project founder Simon Bennetts and OWASP co-founder Mark Curphey join Chris to examine the uncomfortable economics of widely used open-source security tools. Simon describes the nontechnical work behind maintaining ZAP, from community support to managing companies that build commercial offerings on top of it. Mark explores funding structures, foundations, and the incentives that leave critical infrastructure dependent on too few people. They connect those pressures to the XZ backdoor and ask whether licenses can require commercial users to contribute. The episode makes the sustainability problem concrete: open source may be free to consume, but healthy projects still require money, time, governance, and long-term institutional support.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Mark Curphey and Simon Bennetts:→ Mark Curphey on LinkedIn→ Simon Bennetts on LinkedIn→ ZAP→ The Software Security ProjectMentioned in this episode:→ ZAP→ Linux Foundation→ The Software Security Project→ Crash Override→ OpenSSLFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Sustaining ZAP and open-source security00:35 From OWASP to the Linux Foundation and independence08:48 Balancing CISO priorities with practitioner needs11:42 Fifteen years of maintaining ZAP12:21 The business challenges behind open-source projects18:08 The XZ backdoor as a case study in underfunding20:30 Commercial products built on top of ZAP22:55 What a sustainable funding model could look like27:56 Independent foundation or collaborative community34:38 Can licensing require commercial users to contribute?41:07 Final recommendations for open-source sustainability

  50. 252

    Devin Rudnicki -- Expanding AppSec

    Devon Rudnicki, the Chief Information Security Officer at Fitch Group, shares her journey of developing an application security program from scratch and advancing to the CISO role. She emphasizes the importance of collaboration, understanding the organization's business, and using metrics to drive positive change in the security program. Devin Rudnicki, the Chief Information Security Officer at Fitch Group, developed an application security program and advanced to the CISO role after years in security governance. She holds a BS in mathematics from DePaul University and multiple certifications, including CISSP, GSTRT, GSEC, and GCSA. Outside work, she enjoys group fitness, global travel, and mentoring in cybersecurity.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term measurable results.→ Learn more about Security JourneyConnect with Devin Rudnicki:→ Alice and Bob Learn Application Security→ RSA ConferenceMentioned in this episode:→ Alice and Bob Learn Application Security→ RSA Conference→ Black Hat→ Walter IsaacsonFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Devin Rudnicki: Expanding AppSec03:05 Very cool. So the internship, security and governance, does that lead05:03 Is that What's that approval look like as far as, is07:28 What's the first thing that you focus on with this program10:17 You're kind of, you're learning a little bit about the personalities11:41 Yes, I think that's an important tactical thing that we can14:54 Yeah. Okay. So when we, if we break the program, then17:54 Okay. So, that's the vulnerability management side. How about developer education20:23 In the past, I would say no to that question, and21:18 That's, you know, you can minimize. But yeah, I mean, pen24:49 Tracking the work. What metrics and KPIs did you use to27:05 Yeah, and I had a similar situation in my previous time30:03 Devin, we have 3 questions that we typically ask in the32:59 The gene splicing therapy. We'll find it and put it in

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Chris Romeo and Robert Hurlbut dig into the tips, tricks, projects, and tactics that make various application security professionals successful. They cover all facets of application security, from threat modeling and OWASP to DevOps+security and security champions. They approach these stories in an educational light, explaining the details in a way those new to the discipline can understand. Chris Romeo is the CEO of Devici and a General Partner at Kerr Ventures, and Robert Hurlbut is a Principal Application Security Architect focused on Threat Modeling at Aquia.

HOSTED BY

Chris Romeo and Robert Hurlbut

Frequently Asked Questions

How many episodes does The Application Security Podcast have?

The Application Security Podcast currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is The Application Security Podcast about?

Chris Romeo and Robert Hurlbut dig into the tips, tricks, projects, and tactics that make various application security professionals successful. They cover all facets of application security, from threat modeling and OWASP to DevOps+security and security champions. They approach these stories in an...

How often does The Application Security Podcast release new episodes?

The Application Security Podcast has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to The Application Security Podcast?

You can listen to The Application Security Podcast on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts The Application Security Podcast?

The Application Security Podcast is created and hosted by Chris Romeo and Robert Hurlbut.
URL copied to clipboard!