All Episodes
The OWASP Podcast Series — 191 episodes
ep2024-12 Tanya Janca: Happy Holidays are Secure Code
ep2024-10 Don't be Scared, It's just a Pen Test with Brad Causey
ep2024-09 Threat Modeling with Takaharu
ep2024-08 OWASP Projects Roundup
ep2024-07 Safety belts for AppSec with Lisa Plaggemier
ep2023-09 Vulnerable Data Gathering for AI with Arturo Buanzo Busleiman
ep2023-08 Finding Next Gen Cybersecurity Professionals with Brad Causey
ep2023-07 What's Audit got to do with IT
SBOMS, CycloneDX and Dependency Track: Automation for Survival with Steve Springett
AppSec at 40,000 feet
2023-04 Rethinking WAFs: OWASP Coraza
2023-03 Point of Scary - the POS ecosystem
2023-02 Isolation is just PEACHy
OWASP Ep 2023-01: Audit, Compliance and automation, Oh my!
2022 Year in Review
You've got some Kubernetes in my AppSec!
Little Zap of Horrors
Breaching the wirefall with community
Going Way Beyond 2FA
Getting Lean and Mean in the DefectDojo
Giving a jot about JWTs: JWT Patterns and Anti-Patterns - OWASP Podcast e002
Threat Modeling using the Force with Adam Shostack - OWASP Podcast e001
The Void: Verica Open Incident Database
Fast Times at SBOM High with Wendy Nather and Matt Tesauro
SAFe or UnSAFe at Any Speed
Tanya Janca - She Hacks Purple
New Ideas. New Voices. New Hosts.
The InfoSec Color Wheel with Jasmine Henry
CYA - Cover Your Assets with Chris Roberts
OWASP Flagship Projects - Episode 02
OWASP Flagship Projects - Episode 01
The Cyber Defense Matrix Project with Sounil Yu
2021 OWASP Top 10 with Andrew van der Stock
The Ops Side of DevSecOps w/ Damon Edwards
A Note from the Executive Producer
A New Vision for the Future of OWASP, with Executive Director, Andrew van der Stock
Exploring the LinkedIn Algorithm
The Demise of Symantec by Richard Stiennon
Equifax and the Road Ahead w/ Bryson Koehler
Making Everyone Visible in Tech - Jaclyn Damiano
How to Engage 4000 Developers in One Day
Code Rush, DevOps and Google: Software in the Fast Lane
The Unicorn Project w/ Gene Kim
DevOps, DevSecOps and the Year Ahead w/ Sacha Labourey
Is it time to trust Equifax again? You decide.
2019 Global AppSec Conference DC w/ Ben Pick
2019 State of the Software Supply Chain Report
The Vanity of Diversity
Create and Manage Internal Tech Conferences
Securing the Software Supply Chain - Live Panel for International Conference on Cyber Engagement
Tel Aviv and the 2019 Global AppSec Conference
Persectives on the "Sec" in DevSecOps w/ Tanya Janca
2019 Open Security Summit Preview
What is an SBOM and Why Should You Care? w/ Allan Friedman
What is Chaos Engineering, an Interview with Casey Rosenthal
Ladies of London Hacking Society w/ Eliza-May Austin
Anticipating Failure through Threat Modeling w/ Adam Shostack
We Are All Special Snowflakes with Chris Roberts
A Concise Introduction to DevSecOps
What's In Store for the AppSec Cali Conference w/ Richard Greenberg
Epic Failures in DevSecOps w/ Aubrey Stearn
Strategic Asymetry - Leveling the Playing Field w/ Chetan Conikee
Threat Modeling - A Disaster Story with Edwin Kwan
The DevSecOps Unicorn Rodeo w/ Stefan Streichsbier
The DevSecOps Experiment
Open Source Vulnerabilities - Who is Ultimately Responsible
event-stream: Analysis of a Compromised npm Package
Spy vs Spy in Application Security: Harvesting Adversaries
Moving from Projects to Products w/ Mik Kersten
The Journey to Open Source at Capital One w/ Tapabrata "Topo" Pal
The Future of Software and DevOps / with Sacha Labourey
How to Build Chapter Engagement at OWASP
A Message from the Executive Producer
2018 AppSec EU London - Conference Preview
Steps to Responsible Disclosure with Bas van Schaik,Man Yue Mo and Brian Fox
RSAC 2018 - Preview of Opening Session for DevOps Connect: DevSecOps Day
HackNYC 2018: Preview with Kevin E. Greene
HackNYC 2018: Preview with Dr. Bill Curtis
The OpenChain Project with Shane Coughlan
Expanding Community Engagement at OWASP w/ Greg Anderson
Thoughts on Security in the Modern Software Supply Chain
Security Processes at the Apache Software Foundation w/ Mark Thomas and Brian Fox
Struts2 Vulnerabilities: Who Is Responsible?
What you should know about the latest Struts2 vulnerability announcement
OWASP Hacker Kids in Bangalore
Less than 10 Minutes Series: OWASP DockerHub with Simon Bennetts
Less than 10 Minutes Series - ModSecurity Core Rule Set Project
Less than 10 Minutes Series: OWASP Summit 2017
Less than 10 Minutes Series: WebGoat Project
Less than 10 Minutes Series: Vicnum Project
Less than 10 Minutes Series: Defect Dojo Project
Less than 10 Minutes Series: Virtual Village Project
Less than 10 Minutes Series: The Juice Shop Project
AppSec EU 2017, Belfast Keynote Preview with Jaya Baloo
Struts 2 Vulnerability Analysis
AppSec EU 2017 Belfast - What to Expect
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World
Shannon Lietz - Keynote Preview for AppSec EU 2017, Belfast
2016 AppSec USA - An Update on the WebGoat Project
2016 AppSec USA: The Core Rule Set Project w/ Chaim Sanders
The Future of DevSecOps w/ Shannon Lietz and Chris Swan, Live From IP Expo London
2016 Board Election Interviews - Part Four of Four - Members, Projects, Conferences, Chapters
2016 Board Election Interviews - Part Three of Four - Most Important Issues
2016 Board Election Interviews - Part Two of Four - Vendor Neutrality
2016 OWASP Board Election Interviews - Part One of Four - Developer Participation
AppSec USA 2016 Pre-Conference Update
Security as Part of Continuous Delivery with Sacha Labourey
Unicorns on an Aircraft Carrier: DevOps Security at Scale with Sanjeev Sharma
2016 State of the Software Supply Chain Report with Derek Weeks
Security as Part of DevOps and Development with Jason Schmitt
2016 AppSecEU - Update On The ASVS Project with Andrew van der Stock
2016 AppSecEU - The University Challenge
Jim Manico's 100th Episode, featuring Mark Miller, Executive Producer of OWASP 24/7
AppSec Europe 2016 - What To Expect
Communication Patterns in Open Source Component Supply Chains
Active Deception as a Methodology for Cybersecurity w/ Lawrence Pingree from Gartner
DevOps, Security and Engineering at Slack
Security War Games with Sam Guckenheimer at Rugged DevOps RSAC 2016
Guns, Germs and Steel at RSAC 2016 with John Willis
Equal Respect: Women in Technology with Chenxi Wang
DevOps: Politics, People and Process with Paula Thrasher
OWASP Top 10 Proactive Controls Project with Jim Manico and Katy Anton
The OWASP WebGoat Project, version 7.0, with Bruce Mayhew
Johanna Curiel on the Growing Pains of OWASP and Management of Project Reviews
2016 - What's in Store for the OWASP 24/7 Podcast Series
OWASP Shark Tank - Could You Convince Someone to Invest in Your Project?
OWASP Application Security Verification Standard Project w/ Andrew van der Stock
OWASP Benchmark Project w/ Dave Wichers
OWASP Security Shepherd Project w/ Mark Denihan and Paul McCann
DevOps, Security and Development w/ Matt Tesauro, Shannon Lietz and Jez Humble
OWASP Board Candidate Interview - Abbas Naderi, Michael Coates, Jonathan Carter
OWASP Board Candidate Interview - Bil Corry and Josh Sokol
OWASP Board Candidate Interview - Milton Smith, Tobias Gondrom, Tom Brennan
OWASP Security Knowledge Framework Project w/ Glenn Ten Cate
OWASP Summer of Code Sprint 2015 with Fabio Cerullo
OWASP Project Funding Part 2 w/ Johanna Curiel and Claudia Casanovas
OWASP Project Funding w/ Josh Sokol, Dinis Cruz and Andrew van der Stock
The OWASP Online Academy with John Patrick Lita and Jerry Hoff
AppSec USA 2015 Overview with Ben Hagen and Michael Coates
Paul Ritchie, Executive Director, Talks Present, Past and Future of OWASP
OWASP Offensive Web Testing Framework with Bharadwaj Machiraju and Abraham Aranguren
Tobias Gondrom on the OWASP Strategic Goals for 2015
2015 AppSecEU Pre Conference Update
OWASP Project Reviews with Johanna Curiel
2015 OWASP Project Summit in NYC with Tom Brennan
Seba Deleersnyder Discusses SAMM (Software Assurance Maturity Model) Summit in Dublin, Ireland
2015 AppSec California Post Mortem with Richard Greenberg and Neil Matatall
John Melton and the OWASP AppSensor Project
Moxie Marlinspike on Open Source Security for Mobile Devices
Dibbe Edwards - DevOps and Open Source at IBM
The WebGoat Project with Rick Lawson and Jason White
Kevin E. Greene on OWASP and the SWAMP Project
AppSec USA 2014, Denver - Damon Edwards, Matt Tesauro, Eoin Keary, Martin Knobloch
OWASP Board Candidate Interviews - Mateo Martinez
OWASP Board Candidate Interviews - Jim Manico, Timur Khrotko
OWASP Board Candidate Interviews - Andrew van der Stock, Nigel Phair, Abbas Naderi
OWASP 2014 Board Candidate Interviews - Israel Bryski, Matt Konda, Bil Corry and Tahir Khan
Jonathan Carter - OWASP and Mobile Security
Sarah Baso - The Final Interview
Wait! Wait! Don't pwn me! from AppSec Europe 2014
Eoin Keary on Women in Security and Growing an OWASP Chapter
Achim Hoffmann and the o-Saft Project for Scanning SSL Connections
OWASP Top 10 Privacy Risks Project with Florian Stahl and Stefan Burgmair
The Run Up to a Massive Cyber Security Month with Tom Brennan
Wolfgang Goerlich on a Real World Example of The Phoenix Project in Action
Dwayne Melancon - What InfoSec Can Learn from Video Games
Melissa Elliot on the HeartBleed Bug at Yahoo
2014 AppSec APAC - Post Mortem (English)
The OWASP Hacky Easter Challenge with Ivan Bütler
The OWASP Top Ten Proactive Controls Project with Jim Bird
The OWASP Cornucopia Project with Colin Watson
The OWASP WebSpa Project with Yiannis Pavlosoglou and Jim Manico
2014 AppSec APAC - History and Overview (Japanese and English)
AppSec Europe 2014 - What To Expect with Host Adrian Winckles
AppSec USA 2013 – Mark Arnold Talks about the Boston OWASP Chapter
OWASP Statement on the Security of the Internet 2014
AppSec APAC 2014 with Tobias Gondrom – What To Expect
AppSec USA 2013 - Larry Conklin and the Code Review Book Project
AppSec USA 2013: Jim Manico - Life after OWASP Podcasting
AppSec USA 2013 - Abbas Naderi and the OWASP PHP Security Project
AppSec USA 2013: Zed Attack Proxy Project with Simon Bennetts
AppSec USA 2013 - Michael Coates on the AppSensor Project
AppSec USA 2013 - The OWASP Application Security CISO Guide with Marco Morana and Tobias Gondrom
AppSec USA 2013 - The Purpose of OWASP, an Interview with Co-Founder Dennis Groves
AppSec USA 2013 - OWASP Panel on Using Components with Known Vulnerabilities
AppSec USA 2013 - Wait, Wait... Don't Pwn Me!
Tom Brennan - What to expect at AppSecUSA 2013
Kelly Santalucia - Growing OWASP and the Outreach Programs
Kate Hartmann - The Future of Virtual Chapter Meetings
Sarah Baso - What does it take to support 43,000 members in 100+ countries?
Samantha Groves - Getting the Most from OWASP Projects