575 episodes

The Application Security Weekly podcast delivers interviews and news from the worlds of AppSec, DevOps, DevSecOps, and all the other ways people find and fix software flaws.

Join hosts Mike Shema, John Kinsella, and Akira Brand on a journey through modern security practices for apps, clouds, containers, and more.

Application Security Weekly (Video‪)‬ Security Weekly

    • News
    • 4.2 • 5 Ratings

The Application Security Weekly podcast delivers interviews and news from the worlds of AppSec, DevOps, DevSecOps, and all the other ways people find and fix software flaws.

Join hosts Mike Shema, John Kinsella, and Akira Brand on a journey through modern security practices for apps, clouds, containers, and more.

    • video
    Random Problems, Protecting Packages, and Vulns in Designs, Defaults & Data Leaks - ASW #283

    Random Problems, Protecting Packages, and Vulns in Designs, Defaults & Data Leaks - ASW #283

    Misusing random numbers, protecting platforms for code repos and package repos, vulns that teach us about designs and defaults, and more!
    Show Notes: https://securityweekly.com/asw-283

    • 38 min
    • video
    Why Companies Continue to Struggle with Supply Chain Security - Melinda Marks - ASW #283

    Why Companies Continue to Struggle with Supply Chain Security - Melinda Marks - ASW #283

    Companies deploy tools (usually lots of tools) to address different threats to supply chain security. Melinda Marks shares some of the chaos those companies still face when trying to prioritize investments, measure risk, and scale their solutions to keep pace with their development. Not only are companies still figuring out supply chain, but now they're bracing for the coming of genAI and how that will just further highlight the current struggles they're having with data security and data privacy.
    Segment Resources:
    Complete Survey Results: The Growing Complexity of Securing the Software Supply Chain
    https://research.esg-global.com/reportaction/515201781/Toc 
    Show Notes: https://securityweekly.com/asw-283

    • 41 min
    • video
    XZ & Open Source, PuTTY's Private Keys, LeakyCLI, LLMs Writing Exploits - ASW #282

    XZ & Open Source, PuTTY's Private Keys, LeakyCLI, LLMs Writing Exploits - ASW #282

    CISA chimes in on the XZ Utils backdoor, PuTTY's private keys and maintaining a secure design, LeakyCLI and maintaining secure secrets in CSPs, LLMs and exploit generation, and more!
    Show Notes: https://securityweekly.com/asw-282

    • 38 min
    • video
    Sustainable Funding of Open Source Tools - Simon Bennetts, Mark Curphey - ASW #282

    Sustainable Funding of Open Source Tools - Simon Bennetts, Mark Curphey - ASW #282

    How can open source projects find a funding model that works for them? What are the implications with different sources of funding? Simon Bennetts talks about his stewardship of Zed Attack Proxy and its journey from OWASP to OpenSSF to an Open Source Fellowship with Crash Override. Mark Curphy adds how his experience with OWASP and the appsec community motivated him to create Crash Override and help projects like ZAP gain the support they deserve.
    Segment resources:
    https://crashoverride.com/blog/welcome-zap-to-the-open-source-fellowship https://www.zaproxy.org https://crashoverride.com/blog/are-there-too-many-bubbles-of-similar-security-efforts Show Notes: https://securityweekly.com/asw-282

    • 39 min
    • video
    Arg Parsing in Rust, End of Life Hardware, CSRB & MS, Chrome’s V8 Sandbox - ASW #281

    Arg Parsing in Rust, End of Life Hardware, CSRB & MS, Chrome’s V8 Sandbox - ASW #281

    A Rust advisory highlights the perils of parsing and problems of inconsistent approaches, D-Link (sort of) deals with end of life hardware, CSRB recommends practices and processes for Microsoft, Chrome’s V8 Sandbox increases defense, and more!
    Show Notes: https://securityweekly.com/asw-281

    • 28 min
    • video
    Demystifying Security Engineering Career Tracks - Karan Dwivedi - ASW #281

    Demystifying Security Engineering Career Tracks - Karan Dwivedi - ASW #281

    There are as many paths into infosec as there are disciplines within infosec to specialize in. Karan Dwivedi talks about the recent book he and co-author Raaghav Srinivasan wrote about security engineering. There's an appealing future to security taking on engineering roles and creating solutions to problems that orgs face. We talk about the breadth and depth of security engineering and ways to build the skills that will help you in your appsec career.
    Segment resources:
    https://kickstartseceng.com Show Notes: https://securityweekly.com/asw-281

    • 35 min

Customer Reviews

4.2 out of 5
5 Ratings

5 Ratings

jdtangney ,

Occasional good content

Keith occasionally has something worth saying, but he lacks solid experience with hardcore software development, and knows almost nothing about lean/agile. He approaches software like an operations problem.

Paul is unpleasant to listen to and seldom adds anything of value. I wouild not listent to this podcast at all if Paul was the only contributor.

This week's episode is particularlt vexing, as the bros bray on about American Football. Please find another forum for that. Your listeners are here to bone up on AppSec.

Top Podcasts In News

The Daily
The New York Times
Serial
Serial Productions & The New York Times
Up First
NPR
The Tucker Carlson Podcast
Tucker Carlson Network
Pod Save America
Crooked Media
The Ben Shapiro Show
The Daily Wire

You Might Also Like

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
Cyber Security Headlines
CISO Series
Malicious Life
Malicious Life
CyberWire Daily
N2K Networks
The Application Security Podcast
Chris Romeo and Robert Hurlbut
Future of Application Security
Tromzo