The Elephant in AppSec

The Elephant in AppSec

Time to discuss AppSec issues no one talks about.

  1. Aug 4

    The Docker mistakes everyone's still making and how to fix them with Advait Patel

    Today I'm joined by Advait Patel, Senior Site Reliability Engineer and the creator of DockSec, an open-source, AI-powered Docker security scanner that's now an official OWASP Incubator project. In this episode, we get into: Why dumping 200 container findings into a Jira ticket is the fastest way to get developers to fix nothing and how DockSec cuts that down to the 5 that actually matter The AI support agent that got hijacked by a single malicious ticket and emailed customer data straight to an attacker Why you should treat AI as an assistant on a leash, not an engineer with root access the Docker mistakes Advait sees everywhere (stale base images, root by default, and secrets baked right into the image) …and much more! Get ready, Advait doesn't hold back his opinions. Let's dive right in! Connect with Advait: https://www.linkedin.com/in/advaitpatel93/ Connect with Alexandra: https://www.linkedin.com/in/alexandra-charikova/ This podcast is brought to you by Escape: https://escape.tech  — Offensive security for the teams that are 100x outnumbered, combining ASM business-logic-aware DAST, and AI-powered pentesting solutions. Mentioned DockSec on GitHub (now the OWASP org repo): https://github.com/OWASP/DockSec OWASP project page: https://owasp.org/www-project-docksec/ Open Policy Agent (his "open policy" reference): https://www.openpolicyagent.org/ OWASP Top 10 for LLM Applications: https://genai.owasp.org/

    The Docker mistakes everyone's still making and how to fix them with Advait Patel

About

Time to discuss AppSec issues no one talks about.