Absolute AppSec

Ken Johnson and Seth Law

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

  1. 1d ago

    Episode 334 - w/ Ryan Lloyd - Mobile Application Security

    In episode 334 of Absolute AppSec, hosts Ken Johnson and Seth Law interview Ryan Lloyd, Chief Product Officer at GuardSquare, to explore mobile application security and product management strategy. Lloyd details GuardSquare's evolution from the open-source Java optimizer ProGuard—which introduced basic name obfuscation—into a commercial suite offering multi-layered code hardening, control flow flattening, encryption, and automated runtime application self-protection (RASP) to detect dynamic tampering, hooking tools like Frida, and rooted devices. The discussion examines the product strategy behind balancing customer feature requests against core security engineering, emphasizing evidence-based decision-making over opinion. Addressing the broader mobile threat landscape, Lloyd highlights how attack vectors have expanded beyond financial services into retail, delivery, and loyalty apps, where attackers manipulate business logic or exploit open platform APIs like Android accessibility services for account takeovers. To track emerging threats, GuardSquare's research arm monitors reverse-engineering forums, academic compiler research, and dark web channels. Finally, the conversation evaluates how automated AI tools accelerate the velocity of reverse engineering and vulnerability discovery, underscoring that mobile security defenses must continually evolve to increase the time and cost required for attackers to tamper with client-side applications. Episode sponsored by GuardSquare (guardsquare.com).

  2. Sep 8

    Episode 333 - LLM Patching Flaws, AI Code Regressions, Bug Bounty Economy

    Sponsored by GuardSquare (guardsquare.com), the discussion of Episode 333 opens with an analysis of a 1Password academic paper evaluating how frontier LLMs perform at autonomous vulnerability patching. The research indicates that LLMs successfully generate functional, side-effect-free patches only 26% of the time, often introducing new security flaws, breaking application behavior, or hallucinating fixes due to a lack of environmental context and "correctness collapse". The hosts critique the industry push toward auto-remediation, arguing that automated patch generation fails to address root causes like noisy tooling or organizational culture issues, and they emphasize that human domain expertise remains necessary for reliable patching. Turning to real-world AI security risks, the episode examines a Snowflake vulnerability where an AI coding tool (GitHub Copilot Autofix) regressed a GitHub Actions workflow into an unauthenticated Remote Code Execution (RCE) flaw via command injection, which was subsequently discovered and validated within five days by Wiz's automated "Red Agent". Finally, the hosts cover Dark Reading reporting on how the AI-driven "vulnpocalypse" is repricing the bug bounty economy. As automated scanning harnesses double report volumes, companies face budget constraints that reduce payout amounts per finding, forcing organizations to narrow program scopes toward high-priority assets.

  3. Sep 1

    Episode 332 - AI SDLC, Call for Cyber Defense, Rumor as the Exploit

    In episode 332, the discussion focuses on how artificial intelligence is reshaping the Software Development Lifecycle (SDLC). The episode analyzes Anthropic's blog post regarding an "AI-native SDLC," evaluating its vision of replacing traditional development bottlenecks with AI workflows. The commentary critiques Anthropic's reliance on simple Markdown files for tracking development decisions, noting that replacing deterministic tools with probabilistic LLMs in core SDLC processes introduces significant reliability risks, context drift, and excessive token costs. The conversation turns to OpenAI's "Collective Call for Cyber Defense" initiative, examining its push for frontier AI model regulation and critiques of open-weight models, which are viewed as an effort to establish vendor lock-in. Exploring the concept of "Rumor as the Exploit," the discussion highlights how public mentions or minor disclosures of vulnerabilities now allow AI-driven testing harnesses to rapidly discover and generate working exploits across unmaintained software ecosystems. To counter this accelerated threat landscape, the episode evaluates defensive strategies, including runtime verification, reachability analysis, and cooling-off periods for new package releases, emphasizing that security defenders must move beyond thin wrapper solutions and build robust systems combining deterministic controls with model capabilities. Episode sponsored by Guardsquare (guardsquare.com).

  4. Jul 14

    Episode 327 - w/Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization

    In episode 327 of Absolute AppSec, co-hosts Ken Johnson and Seth Law present a highly anticipated quarterly crossover episode with Cameron and Kurt from the Coffee, Chaos, and ProdSec podcast. Sponsored by GuardSquare, the group begins with lighthearted banter about their personal footwear choices before tackling heavy architectural debates. The primary focus shifts to Application Security Posture Management (ASPM) consolidation. Cameron strongly advocates for utilizing ASPM as a distinct, single pane of glass dashboard to deduplicate vulnerabilities and streamline executive reporting by product suite. However, the hosts contrast this ideal against the messy reality of organizations dealing with a "Frankenstein" mix of loosely bootstrapped open-source scanning tools and competing vendor plugins. The discussion deepens into prioritization strategies amid a massive, AI-driven surge in vulnerability research that threatens to double annual CVE counts. Cameron and Kurt stress the necessity of shifting away from abstract CVSS scores toward custom, runtime-informed risk appetites and impact analysis—prioritizing the hardening of high-risk corporate assets over low-reachability internal flaws. They also examine the critical line separating standard software bugs from intentionally malicious open-source packages that target developer endpoint systems. Ultimately, the panel laments that AppSec teams are effectively functioning as corporate incident responders because Security Operations Center (SOC) analysts lack product-level insight. The episode concludes with a review of automated agent statistics and a fun look ahead to the future emergence of meta OWASP top-ten risk lists.

Ratings & Reviews

4.9
out of 5
19 Ratings

About

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

You Might Also Like