The Elephant in AppSec cover art

All Episodes

The Elephant in AppSec — 87 episodes

#
Title
1

The Lethal Trifecta or why your AI agent knows too much - Jason Fernandes

2

25 years of the same problem in Application Security - Sam Stepanyan

3

Should security belong in every AI strategy meeting? with Amol Deshpande

4

What Mindset Shift Developers Need to Break Into Security? with Aleksandra Kornecka

5

Is the AI–API interaction the biggest security blind spot? with Gowtham Sundar

6

What best drives the adoption of secure software practices? with Enrique Larios Vargas

7

Why AppSec Needs More Than Just a Checkbox ⎢ Marcos Vinicius Cassel

8

The Supply Chain Crisis We Created: How AI, Extensions, and Dependencies Became the New Attack Surface with Aamiruddin Syed

9

Why AppSec Is breaking: Vibe Coding, DevSecOps backlogs & the new OWASP Top 10 (with Tanya Janca)

10

Secure by Design: Who’s Really Responsible? with Abhijeth Dugginapeddi

11

The Pressure of Security Leadership: What SLAs Actually Work? with Terry O'Daniel

12

Can We Make AI Agents Smarter Than Security Teams? with Anshuman Bhartiya

13

Why DevSecOps isn't enough without deep cloud context with Anjali Singh Shukla

14

Decoding a Healthy Security Program: What Does "Healthy" Even Mean? with Maxwell Zhou

15

Why SAP Security Can be a Hidden Weakness for Enterprises with Oumaima Baira

16

Latin America’s AppSec Culture: What’s Lost (and Found) in Translation?

17

OWASP SAMM vs BSIMM: Which Maturity Model Reigns Supreme?

18

Security Culture: When Are We Really Creating Change? with Marisa Fagan

19

Security Wins Only When Institutionalized – Here’s Why!⎜Kevan Bard

20

Why Your Security Program Might Be Failing Before It Even Starts with Sean Finley

21

The Future of Pentesting: Can AI Replace Human Expertise?

22

How to Fix the Lack of Clear Guidance in Building Effective Security Programs | Luís Fontes

23

AI Security: Do You Need a Dedicated Vendor? | Insights with James Berthoty

24

Why AppSec isn’t just for tech — Surprising Insights ⎜ Olga Dzięgielewska

25

Are Traditional WAFs Dead? The Impact of OpenAPI Specs on Web Security with Nathan Byrd

26

Finding AppSec tools that developers love — is it possible? with Linda Fay

27

What Most Security Teams Miss: An Engineering Manager’s Take on AppSec with Desmond Lamptey

28

Compliance in Cyber: Can Regulation and Innovation coexist?⎜Chris Hughes

29

The Future of Product Security: Quality Engineering or something more? with Michael Novack

30

Should We Fix All Bad Code? with Eitan Worcel

31

AI, Speed, and Startup Chaos: Is ‘Minimum Viable Security’ the Fix? ⎜ Kalyani Pawar

32

Security IDE Plugins: Can They Really Boost Your Coding Security? ⎜Jamie Scott

33

DAST Tools: Can We Change the AppSec Community Perception? with Chris Lindsey

34

Secure Coding — Can we make it happen? with Tanya Janca

35

How Psychology Really Shapes AppSec Wins & Fails ⎢ Curtis Koenig

36

The Open Source Security Crisis: Is Trust the Weakest Link in Supply Chain? with François Proulx

37

Are we truly managing Third-Party risks, or just playing security theater? ⎢Rachel Curran

38

Hyped or Helpful? The Truth About Reachability & Developer Buy-In ⎢ Nir Valtman

39

DevSecOps vs. Reality: What You REALLY Need to Succeed!

40

Unpacking Opengrep—A Deep Dive with Its Backing Teams

41

Is There a Secret to Mastering Threat Modeling at Scale? Ashwini Siddhi (GoDaddy)

42

Can You Really Quantify AppSec ROI? Here’s the Truth! ⎜Irfaan Santoe

43

How to Fix API Security Before It’s Too Late ⎜ Confidence Staveley

44

The Untold Benefits of Continuous Threat Modeling You Didn’t Know About ⎜Izar Tarandach

45

What does “collaborate with engineering” actually mean in AppSec? ⎜Koen Hendrix (Zendesk)

46

Is your organization mature enough for its first AppSec hire?⎢Akira Brand

47

Are we overlooking Kubernetes security in the race to deploy applications - Raunaq Arora

48

Is it actually realistic to see everyone as the greatest ally in security? - Alina Yakubenko

49

Can DevSecOps Maturity Models Fail? The Hidden Gaps in AppSec Programs ⎜Timo Pagel

50

Risk, Product Management, and Supply Chain Security: Is There a Connection? ⎜Jesus Cuadrado

51

How hard is it to make DevSecOps work in a Hybrid Cloud? ⎜Michael Tayo

52

Is It Possible to Maximize the Effectiveness of Security Champions? ⎜ Magdalena Modric

53

Hacker Turned Policy Builder: What They Don’t Want You to Know

54

Why Is Transforming Company Culture for Product Security So Challenging? ⎜ Ariel Shin

55

The API Governance Problem: Why Your API Security Is at Risk (And How to Fix It) ⎜Akansha Shukla

56

AI Chatbots: Security Disaster or Can We Build Them Securely? ⎜Ante Gojsalic & Benjamin Dulieu

57

Open Source vs. Commercial Software: The Ultimate Showdown⎜Kyle Kelly

58

Privacy vs. Application Security: Can They Truly Coexist? | Kim Wuyts

59

From PhD to AppSec: How to Bridge the Gap Between Research & Security Tools | Diego Sempreboni

60

AppSec for Startups: Critical or Overlooked? | Rob Picard

61

What are the risks associated with open source? | Kaiwen Jiang

62

Season 2 The Elephant in AppSec Podcast Trailer

63

AI Security - How hard is it to develop secure AI? ⎪Rob van der Veer

64

We Don’t Let the Bad Guys Win: Is It Possible with All Third-Party Apps in Oil & Gas? ⎜Catharina "DD" Budiharto

65

Why “shift-left” isn’t good enough ⎪Chris Romeo

66

What are the Non-Human Identity challenges? ⎪Andrew Wilder and Amir Shaked

67

API Security: Are Vendors Just Blowing Smoke? ⎪David Homoney

68

The Truth About Software Supply Chain Risks ⎪Cassie Crossley

69

How secure are your digital wallets? ⎪Max Imbiel (Bitpanda)

70

How security research can earn you $20m in tokens ⎪Swan Beaujard

71

Securing cloud native applications: how hard is it? ⎪Mihir Shah

72

Are custom security tests a product security superpower? ⎜Keshav Malik (LinkedIn)

73

The art and science of product security ⎥Jacob Salassi (Snowflake)

74

Security Consultant vs. In-House Engineer: The Showdown⎜Ric Campo

75

Developers and security training: can they co-exist?⎜Laura Bell Main

76

Adversarial machine learning: what is it and are we ready? ⎜Anmol Agarwal

77

AppSec vendors and CISOs: a love - hate relationship? ⎜Olivia Rose

78

Pentesting: What are the actual benefits?⎥Harsh Modi

79

Security champion program: A must or completely useless? ⎥Dustin Lehr

80

Is Gen AI your new AppSec weapon?

81

Security training: Necessary investment or overrated expense?⎥Mel Reyes

82

What is ASPM: A breakdown of the current state and its future

83

SCADA systems: How secure are the systems running our infrastructure? ⎥Malav Vyas

84

Threat modeling: the future of cybersecurity or another buzzword⎥Derek Fisher

85

Security experience: top-down vs bottom-up⎥Jeevan Singh (Rippling, Twilio)

86

Lack of effective DAST tools⎥Aleksandr Krasnov (Meta, Thinkific, Dropbox)

87

The Elephant in AppSec Podcast Trailer | Escape