All Episodes
The Application Security Podcast — 309 episodes
How Agentic AI Fails—and Which Controls Actually Stop It
Your AppSec Bottleneck Is a People Problem
AI Pen Testing Killed Traditional DAST
AI Security: OWASP Meets Global Standards
The Future of Open-Source Threat Modeling
Isaac Evans - AppSec in the Age of AI
José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists
Michael Burch - AI-Enabled Citizen Developers
Josh Grossman--AI & SAST: Is it a match?
Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets
Tanya Janca - Secure Vibe Coding
Caroline Wong--The AI Cybersecurity Handbook
Steve Wilson--OpenClaw and Advanced AI Agents
Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows
OWASP Candidate Debate - 2025 Edition
Francesco Cipollone - Agentic AI Manifesto
Simon Gibbs & Devika Gibbs -- Building Bridges with Games
Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps
Getting Ready for the EU CRA
Marisa Fagan - Measuring Security Culture
Aram Hovsepyan -- Your Security Dashboard is Lying to You: The Science of Metrics
Sean Varga -- OWASP Top 10 for AppSec Sales
Sarah-Jane Madden -- What AI means for AppSec
Dag Flachet -- Kaizen for your Appsec Program
Javan Rasokat and Andra Lezza -- When Chatbots Go Rogue - Lessons Learned from Building and Defending LLM Applications
Jim Routh -- The CISO Transition to the rest of life
Henrik Plate -- OWASP Top 10 Open Source Risks
Tanya Janca -- A Secure SDLC from a Developer's Perspective
Mehran Koushkebaghi -- Security as a Systemic Concern: How to develop Anti-Requirements
Kalyani Pawar -- Shaping AppSec at Startups
Milan Williams -- AppSec Metrics
MO Sadek -- Building an AppSec Program from Scratch
Brett Crawley -- Threat Modeling Gameplay with EoP
Matin Mavaddat - Understanding Security as a Systemic Concern: The Role of Anti-Requirements
Kayra Otaner -- DevSecOps
François Proulx - Arbitrary Code Execution 0-day in Build Pipeline of Popular Open Source Packages
Steve Wilson -- The Developer's Playbook for Large Language Model Security: Building Secure AI Applications
Jeff Williams -- Application Detection & Response (ADR)
Phillip Wylie -- Pen Testing from Somebody who Knows about Pen Testing
Steve Springett -- Software and System Transparency
Irfaan Santoe -- The Power of Strategy in AppSec
Andrew Van Der Stock -- The New OWASP Top Ten
Derek Fisher -- Hiring in Cyber/AppSec
Tanya Janca -- Secure Guardrails
Jahanzeb Farooq -- Launching and executing an AppSec program
David Quisenberry -- Building Security, People, and Programs
Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People
James Berthoty -- Is DAST Dead? And the future of API security
Mark Curphey and Simon Bennetts -- Riding the Coat Tails of ZAP, without Open Source Funding
Devin Rudnicki -- Expanding AppSec
Dustin Lehr -- Culture Change through Champions and Gamification
Francesco Cipollone -- Application Security Posture Management and the Power of Working with the Business
Mukund Sarma -- Developer Tools that Solve Security Problems
Meghan Jacquot -- Assumed Breach Red Team Engagements for AppSec
Bill Sempf -- Development, Security, and Teaching the Next Generation
Hendrik Ewerlin -- Threat Modeling of Threat Modeling
Jason Nelson -- Three Pillars of Threat Modeling Success: Consistency, Repeatability, and Efficacy
Erik Cabetas -- Cracking Codes on Screen and in Contests: An Expert's View on Hacking, Vulnerabilities, and the Evolution of Cybersecurity Language
Justin Collins -- Enabling the Business to Move Faster, Securely
Kyle Kelly -- The Dumpster Fire of Software Supply Chain Security
Chris Hughes -- Software Transparency
Jay Bobo & Darylynn Ross -- App Sec Is Dead. Product Security Is the Future.
Eitan Worcel -- Is AI a Security Champion?
Björn Kimminich -- OWASP Juice Shop
Arshan Dabirsiaghi -- Security Startups, AI Influencing AppSec, and Pixee/Codemodder.io
Dr. Jared Demott -- Cloud Security & Bug Bounty
Katharina Koerner -- Security as Responsible AI
Ray Espinoza -- The AppSec CISO, Vendor Relationships, and Mentoring
Chris John Riley -- MVSP: Minimum Viable Secure Product
Steve Wilson and Gavin Klondike -- OWASP Top Ten for LLM Release
Tanya Janca -- What Secure Coding Really Means
Hasan Yasar -- Actionable SBOM via DevSecOps
Varun Badhwar -- The Developer Productivity Tax
OWASP Board of Directors Debate
Itzik Alvas -- Secrets Security and Management
Harshil Parikh -- Deep Environmental and Organizational Context in Application Security
Jeff Williams -- The Tech of Runtime Security
Mark Curphey and John Viega -- Chalk
Maril Vernon -- You Get What You Inspect, Not What You Expect
Dan Küykendall -- Why All Application Security Products Suck
Kevin Johnson -- Samurai Swords and Zap's Departure
Tony Quadros -- The Life of an AppSec Vendor
Steve Giguere -- Cloud AppSec
Paul McCarty -- The Burrito Analogy of the Software Supply Chain
Farshad Abasi -- Three Models for Deploying AppSec Resources
Kim Wuyts -- The Future of Privacy Threat Modeling
François Proulx -- Actionable Software Supply Chain Security
Steve Wilson -- OWASP Top Ten for LLMs
JB Aviat -- The State of Application Security
Joshua Wells -- Application Security in the Age of Zero Trust
Jeevan Singh -- The Future of Application Security Engineers
Tony Turner -- Threat Modeling and SBOM
Christian Frichot -- Threat Modeling with hcltm
Zohar Shachar -- Bug Bounty from Both Sides
Sarah-jane Madden -- Threat Modeling to established teams
Jet Anderson -- The AppSec Code Doctor
James Mckee -- Developer Security
Derek Fisher -- The Application Security Handbook
Rob van der Veer -- OWASP AI Security & Privacy Guide
Robyn Lundin -- Planning & organizing a penetration test as an AppSec team
Michael Bargury -- Low Code / No Code Security and an OWASP Top Ten
Alex Olsen -- Security champions, empowering developers, and AppSec training
Mark Curphey -- The future of OWASP
Tiago Mendo -- How to scan at scale with OWASP ZAP
Wolfgang Goerlich -- Security beyond vulnerabilities
Sam Stepanyan -- OWASP Nettacker Project
Nick Aleks and Dolev Farhi -- GraphQL Security
Guy Barhart-Magen -- Log4j and Incident Response
Brett Smith -- Security is a Necessary Evil
Chen Gour-Arie -- The AppSec Map
Dominique Righetto -- OWASP Secure Headers
Hillel Solow -- How to do AppSec without a security team
Chris Romeo -- The Security Journey Story
Kristen Tan and Vaibhav Garg -- Machine Assisted Threat Modeling
Patrick Dwyer -- CycloneDX and SBOMs
Omer Gil and Daniel Krivelevich -- Top 10 CI/CD Security Risks
Josh Grossman -- Building a High-Value AppSec Scanning Program
Alex Mor -- Application Risk Profiling at Scale
Brenna Leath -- Product Security Leads: A different way of approaching Security Champions
Will Ratner -- Centralized container scanning
Neil Matatall -- AppSec at Scale
Joern Freydank -- Security Design Anti Patterns Limit Security Debt
Ken Toler -- Blockchain, Cloud, and #AppSec
Jeroen Willemsen and Ben de Haan -- Dirty little secrets
Adam Shostack -- Fast, cheap and good threat models
Loren Kohnfelder -- Designing Secure Software
Ochaun Marshall -- IaC and SAST
Simon Bennetts -- Using OWASP Zap across an Enterprise
Timo Pagel -- DevSecOps Maturity Model
Mazin Ahmed -- Terraform Security
James Ransome and Brook Schoenfield -- trust and verify: Building in Security at Agile Speed
OWASP Top 10 2021 Peer Review
Anastasiia Voitova -- Encryption is easy, key management is hard
Eran Kinsbruner -- DevSecOps Continuous Testing
Mark Loveless -- Threat modeling in a DevSecOps environment.
Jeroen Willemsen -- Security automation with ci/cd
Thinking back, Looking forward - A Balanced Approach to Securing our Software Future
Jeevan Singh -- Threat modeling based in democracy
Dima Kotik -- Application Security and the Zen of Python
Dustin Lehr -- Advocating and being on the side of developers
Aaron Rinehart -- Security Chaos Engineering
Izar Tarandach and Matt Coles-- Threat Modeling: A Practical Guide for Development Teams
Charles Shirer -- The most positive person in security
Leif Dreizler -- Tactical tips to shift engineering right
Vandana Verma -- OWASP Spotlight Series
Dr. Anita D’Amico -- Do certain types of developers or teams write more secure code?
Alyssa Miller -- Bringing security to DevOps and the CI/CD pipeline
Liran Tal — Cloud native application security, what’s a developer to do?
Chris Romeo — DevSecOps Fails
Jim Routh — Secure software pipelines
Andrew van der Stock — Taking Application Security to the Masses
JC Herz and Steve Springett — SBOMs and software supply chain assurance
Brian Reed — Mobile Appsec: The Good, the Bad and the Ugly as We Head into 2021
The Threat Modeling Manifesto – Part 2
The Threat Modeling Manifesto – Part 1
Season 7 Guests — The best of Season 7
Aviat Jean-Baptiste — The AppSec report
Frank Rietta — The convergence of Ruby on Rails and #AppSec
Dmitry Sotnikov – REST API Security – there is no silver bullet
Caroline Wong — The state of Penetration Testing
Aaron Davis — LavaMoat — solving JavaScript software supply chain
Anastasiia Voitova — Use Cryptography; Don’t Learn It
Michael Furman — SameSite Cookies
Chris Romeo — The State of Security and the Importance of Empathy
Neil Matatall — Content Security Policy
Grant Ongers — Gamification of threat modeling
Elie Saad — OWASP WSTG, Cheat Sheets, and Integration
Graham Holmes — Adversarial Machine Learning
Ochaun Marshall — Securing Web applications in AWS
Drew Dennison – Security should make the computer sweat more
Aaron Guzman — IoTGoat
Adam Shostack — The Jenga View of Threat Modeling
Cindy Blake — Aligning security testing with Agile development
Jannik Hollenbach — Multijuicer: JuiceShop with a side of Kubernetes
Sebastien Deleersnyder and Bart De Win — OWASP SAMM
Marc French, Steve Lipner, Maya Kaczorowski, DJ Schleen, Kim Wuyts — Season Six Wrap up
Mark Merkow — Secure, Resilient, and Agile Software Development
Zsolt Imre — Fuzz testing is easy
Adam Shostack — Remote Threat Modeling
Kim Wuyts — Privacy Threat Modeling
John Martin — Preventing a Cyberpocalypse
Jeremy Long — It’s dependency check, not checker
Alyssa Miller — Experiences with DevOps + Automation and beyond
Vandana Verma — Support each other
DJ Schleen — DevOps: The Sec is Silent
Niels Tanis — 3rd Party Risk in a .NET World
Maya Kaczorowski — Container and Orchestration Security
Geoff Hill — AppSec, DevSecOps, and Diplomacy
Erez Yalon — The OWASP API Security Project
Steve Lipner — The Past, Present, and Future of SDL
David Kosorok — The Three Pillars of an AppSec Program: Prevent, Detect, and React
Chris and Robert: A Taste of Hi-5
Bill Dougherty — INCLUDES NO DIRT, practical threat modeling for healthcare and beyond
Marc French — The AppSec CISO
Season 5 Finale — A cross section of #AppSec
Ronnie Flathers — Security programs big and small
Brook Schoenfield — Security is a messy problem
Liran Tal — The state of open source software security
Liran Tal — Open Source Security — 5 Minute AppSec
Steve Springett — An insiders checklist for Software Composition Analysis
Steve Springett — OWASP Dependency Track — 5 Minute AppSec
Elissa Shevinsky — Static Analysis early and often
Elissa Shevinsky — Be Kind, Security People — 5 Minute AppSec
Matt McGrath — Security coaches
Erez Yalon and Liora Herman – The Application Security Village @ DefCon
Erez Yalon – AppSec Village – 5 Minute AppSec
Tommy Ross — The BSA Framework for Secure Software
Adam Shostack — Threat modeling layer 8 and conflict modeling
Adam Shostack – Threat Modeling – 5 Minute AppSec
Zoe Braiterman — AI, ML, AppSec, and a dose of data protection
Caroline Wong — Self-care and self-aware for security people
Björn Kimminich — The new JuiceShop, GSOC, and Open Security Summit
Björn Kimminich — JuiceShop — 5 minute AppSec
Nancy Gariché and Tanya Janca — DevSlop, the movement
Tanya Janca — Mentoring Monday — 5 Minute AppSec
Matt Clapham — A perspective on appsec from the world of medical software
Jon McCoy — Hacker outreach
Omer Levi Hevroni — K8s can keep a secret?
Izar Tarandach — Command line threat modeling with pytm
Simon Bennetts — OWASP ZAP: past, present, and future
Bill Sempf — Growing AppSec People and KidzMash
Georgia Weidman — Mobile, IoT, and Pen Testing
Conclusion: Season 4 Finale
Geoff Hill -- Rapid Threat Model Prototyping Process
Bill Wilder -- Running Azure Securely
Matt Konda -- OWASP Glue
Josh Grossman, Avi Douglen, and Ofer Maor -- AppSec in Israel and Three Talks to watch from AppSec USA
Daniel Miessler -- OWASP IoT Top 10
Travis McPeak -- SecOps Makes Developers Lives Easier
Chris Romeo -- Security Culture Hacking: Disrupting the Security Status Quo
Jim Manico -- The Extremely Unabridged History of SQLi and XSS
Jeff Williams -- The History of OWASP
Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop
Swaroop Yermalkar -- iGoat and iOS Mobile Pen Testing
Adam Bacchus and Jon Bottarini -- Two Sides to a Bug Bounty: The Researcher and The Program
Erlend Oftedal -- What You Require, You Must Also Retire
Abhay Bhargav -- Threat Modeling as Code
Tony UV -- Threat Libraries in the Cloud
Aaron Rinehart -- Chaos Engineering and #AppSec
Jessica Robinson and Vandana Verma-- WIA: Women in #AppSec
Karen Staley -- A Conversation with Karen
Mohammed Imran -- Back to the Lab Again with a DevOps
Niels Tanis -- A Slice of the Razor with ASP.Net Core
Ofer Maor -- A Pen Testers Transition to #AppSec: #VoteForOfer
Matt Tesauro -- #AppSec Pipeline as Toolbox
Stephen de Vries -- Threat Modeling with a bit of #Startup
Julien Vehent -- Securing DevOps
Christian Folini -- CRS and an Abstraction Layer
Sean Wright -- Google Chrome and the Case of the Disappearing HTTP
Conclusion: All the Pieces You Need for an #AppSec Program
Martin Knobloch -- OWASP, Reach Out; We Are Known and Misunderstood
Devin McMasters -- Bug Bounty with a Side of Empathy
Apollo Clark -- Malicious User Stories
Megan Roddie -- Neurodiversity in Security
Chase Schultz -- AppSec and Hardware
John Melton -- #OWASP AppSensor
David Habusha -- Third Party Software is not a Cathedral, It’s a Bazaar
Steve Springett -- Dependency Check and Dependency Track
Steven Wierckx -- The #OWASP Threat Modeling Project
Jim Manico -- The #OWASP Cheat Sheet Project
Neil Smithline -- OWASP Top 10 #10: Logging
Jim Routh -- Selling #AppSec Up The Chain
Chris and Robert -- #AppSec Recommendations
Magen Wu -- Hustle and Flow: Dealing With Burnout in Security
Katy Anton -- OWASP Top 10 #4 XXE
Pete Chestna -- SAST, DAST, and IAST. Oh My!
Irene Michlin -- We Are Not Making It Worse
Bill Sempf -- Insecure Deserialization
Chris and Robert -- Security Champions
Kevin Greene -- Shifting left
Conclusion: OWASP is for everyone
Brian Andrzejewski -- Containers Again
Tin Zaw -- ModSecurity and #AppSec
Aditya Gupta -- The Exploitation of IoT
Jim Manico and Katy Anton -- The Future of the OWASP Proactive Controls
Andrew van der Stock and Brian Glas -- The Future of the OWASP Top 10
Robert Hurlbut -- Threat Modeling
Chris and Robert -- Passwords, Identity, and #AppSec
Tanya Janca and Nicole Becher -- Hacking APIs and Web Services with DevSlop
Jon Mccoy and Jonathan Marcil -- Agile #AppSec
Jay Beale -- Docker Security and AppSec
Chris and Robert -- Proactive Controls, AppSec USA, and Gartners MQ on AppSec Testing
Robert Hurlbut -- Blackhat Security Conference
Dave Ferguson -- The OWASP Top 10 Proactive Controls
Jim Manico -- MORE OWASP!
Mike Goodwin -- The OWASP Threat Dragon
Mark Willis -- I Just Like Static Analysis. Static Analysis is My Favorite
Eric Johnson -- Continuous Integration in .NET
Matt Clapham -- The Technical Debt Ceiling
Chris and Robert -- Controversy within the OWASP Top 10 RC
Brook S.E. Schoenfield -- Security in the Design and Architecture
Conclusion: The End…of Season 1
Rafal Los, James Jardine, and Michael Santarcangelo -- #DtSR and What Makes a Good Security Consultant?
Adam Shostack -- Think like an Attacker or Accountant?
Jon McCoy -- The Mindset to Reverse Engineer
Chris Romeo -- AppSec Awareness: A Blue Print for Security Culture Change
Tracy Maleeff -- Natural Paranoia as a Career Path? A Transition to Security
Chris Romeo -- Security Community at Any Scale
Deidre Diamond -- The Soft Skills of AppSec
Tony UcedaVelez -- PASTA: Not Just for Breakfast Anymore
Glenn Leifheit -- An Inner Glimpse of the Microsoft SDL
Mike Landeck -- Security Must Meet the Needs of the Business
Daniel Ramsbrock -- Web Application Pen Testing – Part 2
Daniel Ramsbrock -- Web Application Pen Testing – Part 1
Matt Clapham -- Development Security Maturity
Elena Elkina -- Privacy and Data Protection
Chris and Robert -- Security in the Methodology
Chris and Robert -- The Activities of the Secure Development Lifecycle
Chris and Robert -- Introductions and why #AppSec?