The AppSec Insiders

PODCAST · business

The AppSec Insiders

Welcome to The AppSec Insiders Podcast. This is a show where we discuss the hottest topics and latest trends in application and cloud security, and tell you what you need to know   For those who don’t know who we are, we are all software developers, white-hat hackers, and code security experts. When we’re not recording the podcast, we help organizations of all sizes with their cybersecurity needs. If you’re an AppSec professional looking for an opportunity to work with some of the best in the industry, or a developer with an interest in cybersecurity, be sure to check out our careers page at ForwardSecurity.com/careers We would greatly appreciate it if you subscribed to the podcast wherever you listen to the show, and be sure to follow us on LinkedIn and Twitter at Forward Security. Links are in the show notes. • https://www.ForwardSecurity.com• https://www.linkedin.com/company/fwdsec/mycompany/verification/• https://twitter.com/fwd_sec

  1. 19

    The Leakiest Year Ever: A Deep Dive into the 2026 State of Secret | The AppSec Insiders Podcast Ep.20

    In this episode, we sit down with Dwayne McDaniel, Principal Developer Advocate at GitGuardian, to discuss the alarming rise of secret sprawl in 2025. With over 28 million hard-coded secrets leaked on public GitHub last year alone — a 34% increase year-over-year — 2025 is officially the leakiest year on record. We dig into why it's getting worse, how AI coding tools like Claude Code are contributing to the problem, and what developers and enterprises can do about it. We also explore the future of workload identity, why long-lived credentials are a liability, and how frameworks like SPIFFE/SPIRE are paving the way toward a world without secrets altogether.

  2. 18

    LLM Vulnerabilities and Prompt Injection: AppSec News Deep Dive | The AppSec Insiders Podcast Ep.19

    In this episode, we explore the emerging security risks of AI and LLMs in modern applications. Iman shares real-world experiences bypassing AI guardrails like LlamaGuard and OpenAI Shield, while the team discusses prompt injection attacks, system prompt exposure, excessive agency vulnerabilities, and data poisoning. Learn about the OWASP Top 10 for LLMs, why AI usage policies are critical, and how attackers are exploiting everything from calendar invites to resume processors with hidden prompts.

  3. 17

    Fake Extensions to AI Bug Hunters: AppSec News Deep Dive | The AppSec Insiders Podcast Ep.18

    In this episode of The AppSec Insiders Podcast, we dive into two major security stories making headlines: a fake Solidity extension that drained a developer’s crypto wallets, and Google’s AI-powered tool “Big Sleep” uncovering a critical Chrome vulnerability. From malicious packages to AI-driven defenses, we break down what these cases reveal about today’s evolving AppSec landscape.

  4. 16

    SQL Injection to RCE: Fortinet's Critical Vulnerability Exposed | The AppSec Insiders Podcast Ep. 17

    On this episode of The AppSec Insiders Podcast, we dive into CVE-2025-25257, a Fortinet FortiWeb Fabric Connector SQL injection vulnerability that escalates to RCE. We break down how this exploit works, why it’s so impactful, and what lessons organizations can learn, from proper network segmentation to the importance of SAST in your pipeline. We also touch on broader trends, from IoT security issues to recurring mistakes in network management. Plus, we share upcoming events where you can meet us in person and give a quick update on the Eureka DevSecOps platform launch.

  5. 15

    Prompt Injection to RCE: When AI Gets Compromised | The AppSec Insiders Ep.16

    In this episode, we unpack CVE-2025-49596, where prompt injection, CSRF, and localhost access were chained to achieve RCE in the MCP Inspector AI tool. Learn how the exploit worked, what it reveals about LLM security risks, and how to defend against similar threats with sandboxing, access controls, and DevSecOps monitoring.  

  6. 14

    What Existing AWS Services are Important to AppSec? (Part 2 of 2) | The AppSec Insiders Ep.15

    Welcome to The AppSec Insiders Podcast. This is a show where we discuss the hottest topics and latest trends in application and cloud security, and tell you what you need to know   For those who don’t know who we are, we are all software developers, white-hat hackers, and code security experts. When we’re not recording the podcast, we help organizations of all sizes with their cybersecurity needs. If you’re an AppSec professional looking for an opportunity to work with some of the best in the industry, or a developer with an interest in cybersecurity, be sure to check out our careers page at ForwardSecurity.com/careers We would greatly appreciate it if you subscribed to the podcast wherever you listen to the show, and be sure to follow us on LinkedIn and Twitter at Forward Security. Links are in the show notes. • https://www.ForwardSecurity.com• https://www.linkedin.com/company/fwdsec/• https://twitter.com/fwd_sec• https://forwardsecurity.com/the-appsec-insiders-podcast/

  7. 13

    What Existing AWS Services are Important to AppSec? (Part 1 of 2) | The AppSec Insiders Ep.14

    Welcome to The AppSec Insiders Podcast. This is a show where we discuss the hottest topics and latest trends in application and cloud security, and tell you what you need to know   For those who don’t know who we are, we are all software developers, white-hat hackers, and code security experts. When we’re not recording the podcast, we help organizations of all sizes with their cybersecurity needs. If you’re an AppSec professional looking for an opportunity to work with some of the best in the industry, or a developer with an interest in cybersecurity, be sure to check out our careers page at ForwardSecurity.com/careers We would greatly appreciate it if you subscribed to the podcast wherever you listen to the show, and be sure to follow us on LinkedIn and Twitter at Forward Security. Links are in the show notes. • https://www.ForwardSecurity.com• https://www.linkedin.com/company/fwdsec/• https://twitter.com/fwd_sec• https://forwardsecurity.com/the-appsec-insiders-podcast/

  8. 12

    2023 Year-End Review

    In this episode, we discuss 2023 Security Threats & Newcomers Recap

  9. 11

    The AppSec Insiders Ep. 11 - Flipper Zero and IoT Security

    In this episode, we discuss the Flipper Zero and IoT Security. 

  10. 10

    Exploring the Challenges of Testing Against the ASVS Standard - Part 4

    In this episode, we return to the topic from the previous episodes and continue explore the challenges of testing against the ASVS standard.

  11. 9

    Exploring the Challenges of Testing Against the ASVS Standard - Part 3

    In this episode, we explore the challenges of testing against the ASVS standard - Part 3

  12. 8

    Exploring the Challenges of Testing Against the ASVS Standard - Part 2

    In this episode, we continue to explore the challenges of testing against the ASVS standard.

  13. 7

    Software Composition Analysis (SCA) & Supply Chain Security feat. Oscar van der Meer from MergeBase

    In this episode, we sit down with Oscar van der Meer, Founder and CEO of MergeBase to discuss Software Composition Analysis (SCA) and why it is important for supply chain security.

  14. 6

    Azure Security: Raising Alarms and Reducing the Blast Radius

    In this episode we explore Azure Security: Raising Alarms and Reducing the Blast Radius.

  15. 5

    AWS SRA (Secure Reference Architecture)

    In this episode we explore AWS SRA (Secure Reference Architecture).

  16. 4

    Exploring the Challenges of Testing Against the ASVS Standard

    In this episode, we explore the challenges of testing against the ASVS standard.

  17. 3

    Attacks on the CI/CD Pipeline (Part 2)

    In this episode, we continue our discussion about OWASP Top 10 and attacks on the CI/CD pipeline.

  18. 2

    Attacks on the CI/CD Pipeline (Part 1)

    In this episode, we explore OWASP Top 10 and the potential attacks on the CI/CD (part 1).

  19. 1

    ChatGPT and the Future of Application Security

    In this episode, we dive deep into the world of ChatGPT and AI technology. What does this mean for application security?

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Welcome to The AppSec Insiders Podcast. This is a show where we discuss the hottest topics and latest trends in application and cloud security, and tell you what you need to know   For those who don’t know who we are, we are all software developers, white-hat hackers, and code security experts. When we’re not recording the podcast, we help organizations of all sizes with their cybersecurity needs. If you’re an AppSec professional looking for an opportunity to work with some of the best in the industry, or a developer with an interest in cybersecurity, be sure to check out our careers page at ForwardSecurity.com/careers We would greatly appreciate it if you subscribed to the podcast wherever you listen to the show, and be sure to follow us on LinkedIn and Twitter at Forward Security. Links are in the show notes. • https://www.ForwardSecurity.com• https://www.linkedin.com/company/fwdsec/mycompany/verification/• https://twitter.com/fwd_sec

HOSTED BY

Farshad Abasi

CATEGORIES

URL copied to clipboard!