262 episodes

The Application Security Weekly podcast delivers interviews and news from the worlds of AppSec, DevOps, DevSecOps, and all the other ways people find and fix software flaws.

Join hosts Mike Shema, John Kinsella, and Akira Brand on a journey through modern security practices for apps, clouds, containers, and more.

Application Security Weekly (Audio‪)‬ Security Weekly

    • Technology
    • 4.9 • 11 Ratings

The Application Security Weekly podcast delivers interviews and news from the worlds of AppSec, DevOps, DevSecOps, and all the other ways people find and fix software flaws.

Join hosts Mike Shema, John Kinsella, and Akira Brand on a journey through modern security practices for apps, clouds, containers, and more.

    Stopping Business Logic Attacks: Why a WAF is no Longer Enough - Karl Triebes - ASW #255

    Stopping Business Logic Attacks: Why a WAF is no Longer Enough - Karl Triebes - ASW #255

    The majority of attacks are now automated, with a growing number of attacks targeting business logic via APIs, which is unique to every organization. This shift makes traditional signature-based defenses insufficient to stop targeted business logic attacks on their own. In this discussion, Karl Triebes shares how flaws in business logic design can leave applications and APIs open to attack and what tools organizations need to effectively mitigate these threats.
    This segment is sponsored by Imperva. Visit https://securityweekly.com/imperva to learn more about them!
    In the news segment, a slew of XSS in Azure's HDInsights, CNCF releases fuzzing and security audits on Kyverno and Dragonfly2, CISA shares a roadmap for security open source software, race conditions and repojacking in GitHub, and more!
    Visit https://securityweekly.com/asw for all the latest episodes!
    Follow us on Twitter: https://www.twitter.com/secweekly
    Like us on Facebook: https://www.facebook.com/secweekly
    Show Notes: https://securityweekly.com/asw-255

    • 1 hr 15 min
    Building a Scanner and a Community with Zed Attack Proxy - Simon Bennetts - ASW #254

    Building a Scanner and a Community with Zed Attack Proxy - Simon Bennetts - ASW #254

    Zed Attack Proxy is an essential tool for web app pentesting. The project just recently moved from OWASP to the Secure Software Project. Hear about the challenges of running an OSS security project, why Simon got involved in the first place, and why successful projects are about more than just code.
    Segment Resources: - https://www.zaproxy.org/
     - https://softwaresecurityproject.org/blog/welcoming-zap-to-the-software-security-project/
     - https://owasp.org/www-project-vulnerable-web-applications-directory/
     In the news segment, a key compromised from a crash dump (and the many, many lessons that followed), more examples of mishandling secrets, URL parsing mismatches show path traversal works well in Rust, an old Linux kernel bug shows how brittle code can be (even when it's heavily audited), an example of keeping OSS projects alive, a quick note on BLASTPASS, and a look at privacy in cars, and more!
    Visit https://securityweekly.com/asw for all the latest episodes!
    Follow us on Twitter: https://www.twitter.com/secweekly
    Like us on Facebook: https://www.facebook.com/secweekly
    Show Notes: https://securityweekly.com/asw-254

    • 1 hr 13 min
    Broadening What We Call AppSec - Christien Rioux - ASW Vault

    Broadening What We Call AppSec - Christien Rioux - ASW Vault

    Check out this interview from the ASW Vault, hand picked by main host Mike Shema! This segment was originally published on January 10, 2022. There's an understandable focus on "shift left" in modern DevOps and appsec discussions. So what does it take to broaden what we call appsec into something effective for modern apps, whether they're on the web, mobile, or cloud? We'll talk about moving on from niche offerings into successful appsec programs.
    Show Notes: https://securityweekly.com/vault-asw-4 

    • 35 min
    How Can Security Be Smart About Using AI? - Jeff Pollard - ASW #253

    How Can Security Be Smart About Using AI? - Jeff Pollard - ASW #253

    We go deep on LLMs and generative AIs to shine a light on areas that security leaders should focus on. There are technical concerns like prompt injection and access controls, and privacy concerns in training and usage. But there are also areas where security tools are starting to address these concerns as well as areas where security tools are adopting AI themselves. We'll share where we see AI showing promise, as well as where we suspect it's still premature. In the news, a Go Crypto presentation from Real World Crypto, Excel releases support for Python, protecting users from malware like the Luna Grabber and WinRAR RCE, DARPA's V-SPELLS project, and more!
    Visit https://securityweekly.com/asw for all the latest episodes!
    Follow us on Twitter: https://www.twitter.com/secweekly
    Like us on Facebook: https://www.facebook.com/secweekly
    Visit https://securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-253

    • 1 hr 13 min
    Security in a Cloud Native World & Mobile App Attacks - ASW #252

    Security in a Cloud Native World & Mobile App Attacks - ASW #252

    Two featured interviews from this year's Black Hat. In the news, Discord.io ceases to be, Azure AD breach to get scrutiny from the CSRB, Zoom's AI stumbles show security concerns, model confusion attacks, a look at how far we have -- and haven't -- come with XSS flaws, an approachable article on AI, and more!
    Visit https://securityweekly.com/asw for all the latest episodes!
    Follow us on Twitter: https://www.twitter.com/secweekly
    Like us on Facebook: https://www.facebook.com/secweekly
    Show Notes: https://securityweekly.com/asw-252
     

    • 37 min
    Pointers and Perils for Presentations - Josh Goldberg - ASW #251

    Pointers and Perils for Presentations - Josh Goldberg - ASW #251

    A key part of modern appsec is communication. From interpersonal skills for fostering collaborations to presentation skills for delivering a message, the ability to tell a story and engage an audience is a skill that doesn't appear on top ten lists and that doesn't come up in secure coding checklists. Josh shares his path to becoming a presenter on technical topics, including stumbles he's made along the way and how he helps others develop their skills for slides.
    Resources: - https://www.joshuakgoldberg.com/blog/how-i-apply-to-conferences
    https://www.joshuakgoldberg.com/blog/how-i-apply-to-conferences-faqs
    https://www.joshuakgoldberg.com/blog/how-i-apply-to-conferences-faqs/#what-are-your-favorite-conference-talks-youve-seen
    https://www.youtube.com/watch?v=mPPZ-NUnR-4&t=25743s&ab_channel=JSWORLDConference
     Then in the news segment, DARPA unleashes an AI Cyber Challenge to find flaws, CISA asks for input on securing open source software and memory safety, what five years of vuln research shows for vuln management programs, siphoning security tokens from VS Code, and more!
    Follow us on Mastodon: https://infosec.exchange/@AppSecWeekly 
    Follow us on Twitter: https://www.twitter.com/secweekly 
    Like us on Facebook: https://www.facebook.com/secweekly
    Visit https://securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-251
     

    • 1 hr 24 min

Customer Reviews

4.9 out of 5
11 Ratings

11 Ratings

DMLou ,

Great show

Amazing show with great news and tips on making sure you code is secure.

jrod d ,

Great show

Best show I’ve found so far related to AppSec

Top Podcasts In Technology

Jason Calacanis
Lex Fridman
The New York Times
NPR
Ben Gilbert and David Rosenthal
Jack Rhysider

You Might Also Like

N2K Networks
CISO Series
Johannes B. Ullrich
Security Weekly
ITWC
Jack Rhysider