Absolute AppSec
by Ken Johnson and Seth Law
Episodes (328)

Episode 328 - Wordpress RCE, Vuln Prioritization, AI memory exfiltration
Jul 21, 2026
In episode 328 of Absolute AppSec, sponsored by GuardSquare (guardsquare.com), Seth and Ken start by highlighting a newly disclosed, pre-authentication WordPress core Remote Code Execution (RCE) vulnerability ("WP2Shell"

Episode 327 - w/Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization
Jul 14, 2026
In episode 327 of Absolute AppSec, co-hosts Ken Johnson and Seth Law present a highly anticipated quarterly crossover episode with Cameron and Kurt from the Coffee, Chaos, and ProdSec podcast. Sponsored by GuardSquare, t

Episode 326 - AppSec Jobs, Benchmarking LLMs, Open Web Standards
Jul 7, 2026
In episode 326 of Absolute AppSec, sponsored by mobile application security provider GuardSquare (guardsquare.com), the hosts start with a deep-dive into pre-show discussions about the shifting macroeconomic landscape of

Episode 325 - Simplified Threat Modeling, Defining A Vulnerability
Jun 30, 2026
In episode 325 of Absolute AppSec, co-hosts Ken Johnson and Seth Law first break down an informal guide to threat modeling, arguing that overly prescriptive frameworks like STRIDE induce a heavy cognitive load on develop

Episode 324 - Three Week Trap, Malicious Extensions
Jun 16, 2026
In episode 324 of Absolute AppSec, co-hosts Ken Johnson and Seth Law share a mix of security model critiques. Starting with industry dynamics, Ken recaps his recent presentation at OWASP Nova regarding the limits of huma

Episode 323 - Secrets Logs, Prompt Injection Risks
Jun 9, 2026
In episode 323 of Absolute AppSec, co-hosts Ken Johnson and Seth Law focus heavily on core application security vulnerabilities, legacy operational struggles, and the challenges of generative AI systems. After briefly di

Episode 322 - Megalodon, Staged Package Publishing, AI Powered Honeypots
May 26, 2026
In episode 322, the co-hosts examine critical vulnerabilities, changing security standards, and adaptive defense mechanisms. They deep dive into the recent "Megalodon" breach, identifying it as a direct poisoned pipeline

Episode 321 - The Future of AppSec
May 19, 2026
In episode 321 of Absolute AppSec, the co-hosts dive into a sprawling discussion about the future of Application Security amid the heavy noise of artificial intelligence and automated tools. The hosts start with a debate

Episode 320 - Return of @lojikil - LLM Bug Hunting, AI OffSec, Defender Burnout
May 12, 2026
Ken is away, so Stefan Edwards (lojikil) joins Seth to talk all things AppSec. This episode starts by exploring the acceleration of AI on the offensive side of security, enabling threat actors to automate complex tasks l

Episode 319 - Vercel Breach, Security vs. Compliance, Pull Request Flows w/ AI Agents
Apr 21, 2026
Episode 319 covers a range of industry developments, primarily focusing on the recent Vercel security incident and the evolving landscape of AI-driven compliance. The hosts detail how a Vercel employee's use of a consume

Episode 318 - Slack Impersonation, Mythos, Vulnerability Research Future
Apr 14, 2026
Episode 318 examines critical vulnerabilities and the evolving impact of AI on the security industry. The episode details a recent sophisticated impersonation and malware attack targeting open-source Slack communities, i

Episode 317 - (Post-RSAC/BSidesSF), Supply Chain Security, Future of SDLC
Mar 31, 2026
Ken Johnson and Seth Law reflect on the 2026 RSA Conference and BSidesSF, noting an industry-wide "awakening" regarding the high costs and engineering complexities of operationalizing AI security tools. A major focus is

Episode 316 - w/Coffee, Chaos, and ProdSec - Agentic Development Lifecycle
Mar 17, 2026
In episode 316 of Absolute AppSec, hosts Ken Johnson and Seth Law participate in a crossover with Kurt Hendle and Cameron Walters from the Coffee, Chaos, and ProdSec podcast to discuss the radical transformation of secur

Episode 315 - Risks of "AI-Native" Security Products, Rapid Software Development
Mar 3, 2026
In episode 315 of Absolute AppSec, Ken Johnson and Seth Law discuss the rapidly evolving challenges of securing software in an era of AI-assisted development. The hosts provide updates on their "Harnessing LLMs for Appli

Episode 314 - LLM AppSec Disruption, Limitations of AI in Security, AppSec Oversight
Feb 24, 2026
In this episode, the hosts discuss the seismic shift in the application security landscape triggered by the rise of Large Language Models (LLMs) and Anthropic’s "Claude Code". They highlight the massive economic repercus

Episode 313 - AppSec Role Evolution, AI Skills & Risks, Phishing AI Agents
Feb 17, 2026
Ken Johnson and Seth Law examine the intensifying pressure on security practitioners as AI-driven development causes an unprecedented acceleration in industry velocity. A primary theme is the emergence of "shadow AI," wh

Episode 312 - Vibe Coding Risks, Burnout, AppSec Scorecards
Feb 10, 2026
In episode 312 of Absolute AppSec, the hosts discuss the double-edged sword of "vibe coding", noting that while AI agents often write better functional tests than humans, they frequently struggle with nuanced authorizati

Episode 311 - Transformation of AppSec, AI Skills, Development Velocity
Feb 3, 2026
Ken Johnson and Seth Law examine the profound transformation of the security industry as AI tooling moves from simple generative models to sophisticated agentic architectures. A primary theme is the dramatic surge in dev

Episode 310 - w/ Mohan Kumar and Naveen K Mahavisnu - AI Agent Security
Jan 27, 2026
In this episode of Absolute AppSec, hosts Ken Johnson and Seth Law interview Mohan Kumar and Naveen K Mahavisnu, the practitioner-founders of Aira Security, to explore the critical challenges of securing autonomous AI ag

Episode 309 - w/ Nathan Hunstad - Compliance, Security Governance
Jan 20, 2026
In this episode of Absolute AppSec, Nathan Hunstad, Director of Security at Vanta, discusses the intersection of security policy, governance, and technical defense. Drawing on his unique background in political science a

Episode 308 - w/Avi Douglen - Privacy, AppSec Conferences, OWASP
Jan 13, 2026
Ken Johnson (cktricky on social media) and Seth Law are happy to announce a special episode of Absolute AppSec with Avi Douglen (sec_tigger on X), long-time OWASP Global Board of Directors member, founder and CEO of Boun

Episode 307 - 2025 Retrospective, Supply Chain, MCP and APIs
Dec 23, 2025
In episode 307 of Absolute AppSec, hosts Ken and Seth conduct a retrospective on the application security landscape of 2025. They conclude that their previous predictions were largely accurate, particularly regarding the

Episode 306 - w/ Paul McCarty - Open Source Malware
Dec 2, 2025
Given the spate of recent npm news stories, we've arranged a topical show with software supply-chain security researcher and npm hacker Paul McCarty (find Paul on bsky https://bsky.app/profile/6mile.githax.com) . Paul is

Episode 305 - Career Impact of GenAI, SEO/GEO, More Supply Chain Attacks
Nov 25, 2025
The latest episode of Absolute AppSec is here, with Ken Johnson and Seth Law checking in during the busy Q4 holiday season to share some fascinating insights on the evolving landscape of security and technology. They kic

Episode 304 - More OWASP Top 10, AI Dynamic Testing
Nov 18, 2025
This episode, the 304th of Absolute AppSec, features hosts Ken Johnson (@cktricky) and Seth Law (@sethlaw) discussing the crush of Q4 expectations, upcoming training opportunities, the recent updates to the OWASP Top Ten