The Application Security Podcast cover art

All Episodes

The Application Security Podcast — 309 episodes

#
Title
1

How Agentic AI Fails—and Which Controls Actually Stop It

2

Your AppSec Bottleneck Is a People Problem

3

AI Pen Testing Killed Traditional DAST

4

AI Security: OWASP Meets Global Standards

5

The Future of Open-Source Threat Modeling

6

Isaac Evans - AppSec in the Age of AI

7

José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists

8

Michael Burch - AI-Enabled Citizen Developers

9

Josh Grossman--AI & SAST: Is it a match?

10

Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets

11

Tanya Janca - Secure Vibe Coding

12

Caroline Wong--The AI Cybersecurity Handbook

13

Steve Wilson--OpenClaw and Advanced AI Agents

14

Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows

15

OWASP Candidate Debate - 2025 Edition

16

Francesco Cipollone - Agentic AI Manifesto

17

Simon Gibbs & Devika Gibbs -- Building Bridges with Games

18

Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

19

Getting Ready for the EU CRA

20

Marisa Fagan - Measuring Security Culture

21

Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics

22

Sean Varga -- OWASP Top 10 for AppSec Sales

23

Sarah-Jane Madden -- What AI means for AppSec

24

Dag Flachet -- Kaizen for your Appsec Program

25

Javan Rasokat and Andra Lezza -- When Chatbots Go Rogue - Lessons Learned from Building and Defending LLM Applications

26

Jim Routh -- The CISO Transition to the rest of life

27

Henrik Plate -- OWASP Top 10 Open Source Risks

28

Tanya Janca -- A Secure SDLC from a Developer's Perspective

29

Mehran Koushkebaghi -- Security as a Systemic Concern: How to develop Anti-Requirements

30

Kalyani Pawar -- Shaping AppSec at Startups

31

Milan Williams -- AppSec Metrics

32

MO Sadek -- Building an AppSec Program from Scratch

33

Brett Crawley -- Threat Modeling Gameplay with EoP

34

Matin Mavaddat - Understanding Security as a Systemic Concern: The Role of Anti-Requirements

35

Kayra Otaner -- DevSecOps

36

François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages

37

Steve Wilson -- The Developer's Playbook for Large Language Model Security: Building Secure AI Applications

38

Jeff Williams -- Application Detection & Response (ADR)

39

Phillip Wylie -- Pen Testing from Somebody who Knows about Pen Testing

40

Steve Springett -- Software and System Transparency

41

Irfaan Santoe -- The Power of Strategy in AppSec

42

Andrew Van Der Stock -- The New OWASP Top Ten

43

Derek Fisher -- Hiring in Cyber/AppSec

44

Tanya Janca -- Secure Guardrails

45

Jahanzeb Farooq -- Launching and executing an AppSec program

46

David Quisenberry -- Building Security, People, and Programs

47

Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People

48

James Berthoty -- Is DAST Dead? And the future of API security

49

Mark Curphey and Simon Bennetts -- Riding the Coat Tails of ZAP, without Open Source Funding

50

Devin Rudnicki -- Expanding AppSec

51

Dustin Lehr -- Culture Change through Champions and Gamification

52

Francesco Cipollone -- Application Security Posture Management and the Power of Working with the Business

53

Mukund Sarma -- Developer Tools that Solve Security Problems

54

Meghan Jacquot -- Assumed Breach Red Team Engagements for AppSec

55

Bill Sempf -- Development, Security, and Teaching the Next Generation

56

Hendrik Ewerlin -- Threat Modeling of Threat Modeling

57

Jason Nelson -- Three Pillars of Threat Modeling Success: Consistency, Repeatability, and Efficacy

58

Erik Cabetas -- Cracking Codes on Screen and in Contests: An Expert's View on Hacking, Vulnerabilities, and the Evolution of Cybersecurity Language

59

Justin Collins -- Enabling the Business to Move Faster, Securely

60

Kyle Kelly -- The Dumpster Fire of Software Supply Chain Security

61

Chris Hughes -- Software Transparency

62

Jay Bobo & Darylynn Ross -- App Sec Is Dead. Product Security Is the Future.

63

Eitan Worcel -- Is AI a Security Champion?

64

Björn Kimminich -- OWASP Juice Shop

65

Arshan Dabirsiaghi -- Security Startups, AI Influencing AppSec, and Pixee/Codemodder.io

66

Dr. Jared Demott -- Cloud Security & Bug Bounty

67

Katharina Koerner -- Security as Responsible AI

68

Ray Espinoza -- The AppSec CISO, Vendor Relationships, and Mentoring

69

Chris John Riley -- MVSP: Minimum Viable Secure Product

70

Steve Wilson and Gavin Klondike -- OWASP Top Ten for LLM Release

71

Tanya Janca -- What Secure Coding Really Means

72

Hasan Yasar -- Actionable SBOM via DevSecOps

73

Varun Badhwar -- The Developer Productivity Tax

74

OWASP Board of Directors Debate

75

Itzik Alvas -- Secrets Security and Management

76

Harshil Parikh -- Deep Environmental and Organizational Context in Application Security

77

Jeff Williams -- The Tech of Runtime Security

78

Mark Curphey and John Viega -- Chalk

79

Maril Vernon -- You Get What You Inspect, Not What You Expect

80

Dan Küykendall -- Why All Application Security Products Suck

81

Kevin Johnson -- Samurai Swords and Zap's Departure

82

Tony Quadros -- The Life of an AppSec Vendor

83

Steve Giguere -- Cloud AppSec

84

Paul McCarty -- The Burrito Analogy of the Software Supply Chain

85

Farshad Abasi -- Three Models for Deploying AppSec Resources

86

Kim Wuyts -- The Future of Privacy Threat Modeling

87

François Proulx -- Actionable Software Supply Chain Security

88

Steve Wilson -- OWASP Top Ten for LLMs

89

JB Aviat -- The State of Application Security

90

Joshua Wells -- Application Security in the Age of Zero Trust

91

Jeevan Singh -- The Future of Application Security Engineers

92

Tony Turner -- Threat Modeling and SBOM

93

Christian Frichot -- Threat Modeling with hcltm

94

Zohar Shachar -- Bug Bounty from Both Sides

95

Sarah-jane Madden -- Threat Modeling to established teams

96

Jet Anderson -- The AppSec Code Doctor

97

James Mckee -- Developer Security

98

Derek Fisher -- The Application Security Handbook

99

Rob van der Veer -- OWASP AI Security & Privacy Guide

100

Robyn Lundin -- Planning & organizing a penetration test as an AppSec team

101

Michael Bargury -- Low Code / No Code Security and an OWASP Top Ten

102

Alex Olsen -- Security champions, empowering developers, and AppSec training

103

Mark Curphey -- The future of OWASP

104

Tiago Mendo -- How to scan at scale with OWASP ZAP

105

Wolfgang Goerlich -- Security beyond vulnerabilities

106

Sam Stepanyan -- OWASP Nettacker Project

107

Nick Aleks and Dolev Farhi -- GraphQL Security

108

Guy Barhart-Magen -- Log4j and Incident Response

109

Brett Smith -- Security is a Necessary Evil

110

Chen Gour-Arie -- The AppSec Map

111

Dominique Righetto -- OWASP Secure Headers

112

Hillel Solow -- How to do AppSec without a security team

113

Chris Romeo -- The Security Journey Story

114

Kristen Tan and Vaibhav Garg -- Machine Assisted Threat Modeling

115

Patrick Dwyer -- CycloneDX and SBOMs

116

Omer Gil and Daniel Krivelevich -- Top 10 CI/CD Security Risks

117

Josh Grossman -- Building a High-Value AppSec Scanning Program

118

Alex Mor -- Application Risk Profiling at Scale

119

Brenna Leath -- Product Security Leads: A different way of approaching Security Champions

120

Will Ratner -- Centralized container scanning

121

Neil Matatall -- AppSec at Scale

122

Joern Freydank -- Security Design Anti Patterns Limit Security Debt

123

Ken Toler -- Blockchain, Cloud, and #AppSec

124

Jeroen Willemsen and Ben de Haan -- Dirty little secrets

125

Adam Shostack -- Fast, cheap and good threat models

126

Loren Kohnfelder -- Designing Secure Software

127

Ochaun Marshall -- IaC and SAST

128

Simon Bennetts -- Using OWASP Zap across an Enterprise

129

Timo Pagel -- DevSecOps Maturity Model

130

Mazin Ahmed -- Terraform Security

131

James Ransome and Brook Schoenfield -- trust and verify: Building in Security at Agile Speed

132

OWASP Top 10 2021 Peer Review

133

Anastasiia Voitova -- Encryption is easy, key management is hard

134

Eran Kinsbruner -- DevSecOps Continuous Testing

135

Mark Loveless -- Threat modeling in a DevSecOps environment.

136

Jeroen Willemsen -- Security automation with ci/cd

137

Thinking back, Looking forward - A Balanced Approach to Securing our Software Future

138

Jeevan Singh -- Threat modeling based in democracy

139

Dima Kotik -- Application Security and the Zen of Python

140

Dustin Lehr -- Advocating and being on the side of developers

141

Aaron Rinehart -- Security Chaos Engineering

142

Izar Tarandach and Matt Coles-- Threat Modeling: A Practical Guide for Development Teams

143

Charles Shirer -- The most positive person in security

144

Leif Dreizler -- Tactical tips to shift engineering right

145

Vandana Verma -- OWASP Spotlight Series

146

Dr. Anita D’Amico -- Do certain types of developers or teams write more secure code?

147

Alyssa Miller -- Bringing security to DevOps and the CI/CD pipeline

148

Liran Tal — Cloud native application security, what’s a developer to do?

149

Chris Romeo — DevSecOps Fails

150

Jim Routh — Secure software pipelines

151

Andrew van der Stock — Taking Application Security to the Masses

152

JC Herz and Steve Springett — SBOMs and software supply chain assurance

153

Brian Reed — Mobile Appsec: The Good, the Bad and the Ugly as We Head into 2021

154

The Threat Modeling Manifesto – Part 2

155

The Threat Modeling Manifesto – Part 1

156

Season 7 Guests — The best of Season 7

157

Aviat Jean-Baptiste — The AppSec report

158

Frank Rietta — The convergence of Ruby on Rails and #AppSec

159

Dmitry Sotnikov – REST API Security – there is no silver bullet

160

Caroline Wong — The state of Penetration Testing

161

Aaron Davis — LavaMoat — solving JavaScript software supply chain

162

Anastasiia Voitova — Use Cryptography; Don’t Learn It

163

Michael Furman — SameSite Cookies

164

Chris Romeo — The State of Security and the Importance of Empathy

165

Neil Matatall — Content Security Policy

166

Grant Ongers — Gamification of threat modeling

167

Elie Saad — OWASP WSTG, Cheat Sheets, and Integration

168

Graham Holmes — Adversarial Machine Learning

169

Ochaun Marshall — Securing Web applications in AWS

170

Drew Dennison – Security should make the computer sweat more

171

Aaron Guzman — IoTGoat

172

Adam Shostack — The Jenga View of Threat Modeling

173

Cindy Blake — Aligning security testing with Agile development

174

Jannik Hollenbach — Multijuicer: JuiceShop with a side of Kubernetes

175

Sebastien Deleersnyder and Bart De Win — OWASP SAMM

176

Marc French, Steve Lipner, Maya Kaczorowski, DJ Schleen, Kim Wuyts — Season Six Wrap up

177

Mark Merkow — Secure, Resilient, and Agile Software Development

178

Zsolt Imre — Fuzz testing is easy

179

Adam Shostack — Remote Threat Modeling

180

Kim Wuyts — Privacy Threat Modeling

181

John Martin — Preventing a Cyberpocalypse

182

Jeremy Long — It’s dependency check, not checker

183

Alyssa Miller — Experiences with DevOps + Automation and beyond

184

Vandana Verma — Support each other

185

DJ Schleen — DevOps: The Sec is Silent

186

Niels Tanis — 3rd Party Risk in a .NET World

187

Maya Kaczorowski — Container and Orchestration Security

188

Geoff Hill — AppSec, DevSecOps, and Diplomacy

189

Erez Yalon — The OWASP API Security Project

190

Steve Lipner — The Past, Present, and Future of SDL

191

David Kosorok — The Three Pillars of an AppSec Program: Prevent, Detect, and React

192

Chris and Robert: A Taste of Hi-5

193

Bill Dougherty — INCLUDES NO DIRT, practical threat modeling for healthcare and beyond

194

Marc French — The AppSec CISO

195

Season 5 Finale — A cross section of #AppSec

196

Ronnie Flathers — Security programs big and small

197

Brook Schoenfield — Security is a messy problem

198

Liran Tal — The state of open source software security

199

Liran Tal — Open Source Security — 5 Minute AppSec

200

Steve Springett — An insiders checklist for Software Composition Analysis

201

Steve Springett — OWASP Dependency Track — 5 Minute AppSec

202

Elissa Shevinsky — Static Analysis early and often

203

Elissa Shevinsky — Be Kind, Security People — 5 Minute AppSec

204

Matt McGrath — Security coaches

205

Erez Yalon and Liora Herman – The Application Security Village @ DefCon

206

Erez Yalon – AppSec Village – 5 Minute AppSec

207

Tommy Ross — The BSA Framework for Secure Software

208

Adam Shostack — Threat modeling layer 8 and conflict modeling

209

Adam Shostack – Threat Modeling – 5 Minute AppSec

210

Zoe Braiterman — AI, ML, AppSec, and a dose of data protection

211

Caroline Wong — Self-care and self-aware for security people

212

Björn Kimminich — The new JuiceShop, GSOC, and Open Security Summit

213

Björn Kimminich — JuiceShop — 5 minute AppSec

214

Nancy Gariché and Tanya Janca — DevSlop, the movement

215

Tanya Janca — Mentoring Monday — 5 Minute AppSec

216

Matt Clapham — A perspective on appsec from the world of medical software

217

Jon McCoy — Hacker outreach

218

Omer Levi Hevroni — K8s can keep a secret?

219

Izar Tarandach — Command line threat modeling with pytm

220

Simon Bennetts — OWASP ZAP: past, present, and future

221

Bill Sempf — Growing AppSec People and KidzMash

222

Georgia Weidman — Mobile, IoT, and Pen Testing

223

Conclusion: Season 4 Finale

224

Geoff Hill -- Rapid Threat Model Prototyping Process

225

Bill Wilder -- Running Azure Securely

226

Matt Konda -- OWASP Glue

227

Josh Grossman, Avi Douglen, and Ofer Maor -- AppSec in Israel and Three Talks to watch from AppSec USA

228

Daniel Miessler -- OWASP IoT Top 10

229

Travis McPeak -- SecOps Makes Developers Lives Easier

230

Chris Romeo -- Security Culture Hacking: Disrupting the Security Status Quo

231

Jim Manico -- The Extremely Unabridged History of SQLi and XSS

232

Jeff Williams -- The History of OWASP

233

Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop

234

Swaroop Yermalkar -- iGoat and iOS Mobile Pen Testing

235

Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program

236

Erlend Oftedal -- What You Require, You Must Also Retire

237

Abhay Bhargav -- Threat Modeling as Code

238

Tony UV -- Threat Libraries in the Cloud

239

Aaron Rinehart -- Chaos Engineering and #AppSec

240

Jessica Robinson and Vandana Verma-- WIA: Women in #AppSec

241

Karen Staley -- A Conversation with Karen

242

Mohammed Imran -- Back to the Lab Again with a DevOps

243

Niels Tanis -- A Slice of the Razor with ASP.Net Core

244

Ofer Maor -- A Pen Testers Transition to #AppSec: #VoteForOfer

245

Matt Tesauro -- #AppSec Pipeline as Toolbox

246

Stephen de Vries -- Threat Modeling with a bit of #Startup

247

Julien Vehent -- Securing DevOps

248

Christian Folini -- CRS and an Abstraction Layer

249

Sean Wright -- Google Chrome and the Case of the Disappearing HTTP

250

Conclusion: All the Pieces You Need for an #AppSec Program

251

Martin Knobloch -- OWASP, Reach Out; We Are Known and Misunderstood

252

Devin McMasters -- Bug Bounty with a Side of Empathy

253

Apollo Clark -- Malicious User Stories

254

Megan Roddie -- Neurodiversity in Security

255

Chase Schultz -- AppSec and Hardware

256

John Melton -- #OWASP AppSensor

257

David Habusha -- Third Party Software is not a Cathedral, It’s a Bazaar

258

Steve Springett -- Dependency Check and Dependency Track

259

Steven Wierckx -- The #OWASP Threat Modeling Project

260

Jim Manico -- The #OWASP Cheat Sheet Project

261

Neil Smithline -- OWASP Top 10 #10: Logging

262

Jim Routh -- Selling #AppSec Up The Chain

263

Chris and Robert -- #AppSec Recommendations

264

Magen Wu -- Hustle and Flow: Dealing With Burnout in Security

265

Katy Anton -- OWASP Top 10 #4 XXE

266

Pete Chestna -- SAST, DAST, and IAST. Oh My!

267

Irene Michlin -- We Are Not Making It Worse

268

Bill Sempf -- Insecure Deserialization

269

Chris and Robert -- Security Champions

270

Kevin Greene -- Shifting left

271

Conclusion: OWASP is for everyone

272

Brian Andrzejewski -- Containers Again

273

Tin Zaw -- ModSecurity and #AppSec

274

Aditya Gupta -- The Exploitation of IoT

275

Jim Manico and Katy Anton -- The Future of the OWASP Proactive Controls

276

Andrew van der Stock and Brian Glas -- The Future of the OWASP Top 10

277

Robert Hurlbut -- Threat Modeling

278

Chris and Robert -- Passwords, Identity, and #AppSec

279

Tanya Janca and Nicole Becher -- Hacking APIs and Web Services with DevSlop

280

Jon Mccoy and Jonathan Marcil -- Agile #AppSec

281

Jay Beale -- Docker Security and AppSec

282

Chris and Robert -- Proactive Controls, AppSec USA, and Gartners MQ on AppSec Testing

283

Robert Hurlbut -- Blackhat Security Conference

284

Dave Ferguson -- The OWASP Top 10 Proactive Controls

285

Jim Manico -- MORE OWASP!

286

Mike Goodwin -- The OWASP Threat Dragon

287

Mark Willis -- I Just Like Static Analysis. Static Analysis is My Favorite

288

Eric Johnson -- Continuous Integration in .NET

289

Matt Clapham -- The Technical Debt Ceiling

290

Chris and Robert -- Controversy within the OWASP Top 10 RC

291

Brook S.E. Schoenfield -- Security in the Design and Architecture

292

Conclusion: The End…of Season 1

293

Rafal Los, James Jardine, and Michael Santarcangelo -- #DtSR and What Makes a Good Security Consultant?

294

Adam Shostack -- Think like an Attacker or Accountant?

295

Jon McCoy -- The Mindset to Reverse Engineer

296

Chris Romeo -- AppSec Awareness: A Blue Print for Security Culture Change

297

Tracy Maleeff -- Natural Paranoia as a Career Path? A Transition to Security

298

Chris Romeo -- Security Community at Any Scale

299

Deidre Diamond -- The Soft Skills of AppSec

300

Tony UcedaVelez -- PASTA: Not Just for Breakfast Anymore

301

Glenn Leifheit -- An Inner Glimpse of the Microsoft SDL

302

Mike Landeck -- Security Must Meet the Needs of the Business

303

Daniel Ramsbrock -- Web Application Pen Testing – Part 2

304

Daniel Ramsbrock -- Web Application Pen Testing – Part 1

305

Matt Clapham -- Development Security Maturity

306

Elena Elkina -- Privacy and Data Protection

307

Chris and Robert -- Security in the Methodology

308

Chris and Robert -- The Activities of the Secure Development Lifecycle

309

Chris and Robert -- Introductions and why #AppSec?