Application Security Weekly (Audio)
by Mike Shema
© 2024 CyberRisk Alliance
Jul 21, 2026Recent reviews on Apple Podcasts (3)
Yes
It’s the best.
Alpha Gay ·
Great show
Amazing show with great news and tips on making sure you code is secure.
DMLou ·
Great show
Best show I’ve found so far related to AppSec
jrod d ·
Episodes (406)

MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
Jul 21, 20261h 12m
Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how

Discovering & Securing Your AI Agent Attack Surface - Jeremy Snyder - ASW #391
Jul 14, 20261h 7m
While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order

Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390
Jul 7, 202647m
Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'

Reducing Attack Surface & Evaluating Efficiency in Agents - Itamar Apelblat, David Goldschlag - ASW #389
Jun 30, 20261h 12m
SquidBleed reveals another vuln that's been lurking for decades, but its real lesson is in managing an attack surface. Regardless of whatever programming language you use, removing code is one of the best security steps

How AI Is Reshaping Identity Security at the Infrastructure Layer - Amit Masand, Neha Duggal, Ev Kontsevoy - ASW #388
Jun 23, 20261h 10m
Appsec has seen machine identities from daemons and processes to services, microservices, and cloud accounts. And now we have agents. Ev Kontsevoy talks about what it means to have engineers and agents interacting in an

Why Does It Matter Who or What Created the Code? - Matias Madou - ASW #387
Jun 16, 20261h 6m
Agents and LLMs are creating and reviewing code. They're a new tool to help developers write software and they're a new abstraction layer for expressing what code should do. But if we're focused on determining whether co

Scanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386
Jun 9, 20261h 16m
Most AppSec teams are working through more findings than their teams can validate. SAST surfaces thousands of potential issues. DAST generates alert volume that outpaces triage capacity. Somewhere in that output are the

BadHost, Dead CTFs, Exploding NPMs, and the Verizon DBIR - ASW #385
Jun 2, 202645m
We dedicate an episode to catching up on appsec news with Kalyani Pawar. We see parsing problems that led to the BadHost vuln, which exposed lots of LLMs, MCPs, and agents to potential compromise. We wonder where to look

AppSec Conversations on Agents, LLMs, and OWASP from RSAC - Merritt Maxim, Scott Clinton, Janet Worthington - ASW #384
May 26, 202659m
We showcase recordings from this year's RSAC. At RSAC Conference 2026, Scott Clinton, Co-Chair and co-founder of the OWASP GenAI Security Project, shares insights from the project's latest research, including new landsca

The State of AI & AppSec - Keith Hoodlet - ASW #383
May 19, 20261h 2m
This year has been a dichotomy of established secure design fundamentals and burgeoning chaos of LLM-driven vuln discovery. Keith Hoodlet returns to share his latest observations on what the recent news about Mythos, mod

Why Basic Security Practices Still Work - Rob Allen - ASW #382
May 12, 20261h 11m
If you have to ditch your entire appsec strategy because you expect 2026 to bring more vulns more quickly, then you probably didn't have a good strategy in the first place. Rob Allen shares how the mentality of "assume b

Keeping Up With the OWASP GenAI Project - Scott Clinton - ASW #381
May 5, 20261h 9m
Speed is the most common theme among developers and appsec teams working with LLMs and agents, from trying to keep up with patterns for deploying agents to dealing with more code faster to how the latest models impact co

Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 - James Kettle - ASW #380
Apr 28, 202644m
Portswigger's list of web hacking techniques is a long-running celebration of curiosity and research from the web hacking community. James Kettle shares his thoughts on the entries from 2025 and how he expects LLMs and a

The Human Aspect of Red Teams - Brian Fox, Tom Tovar, T. Gwyddon 'Data' Owen - ASW #379
Apr 21, 20261h 13m
Red team exercises set goals to see if a particular outcome can be accomplished through a simulated attack, but the ultimate outcome should be educating the org about how to improve tools and processes that make attacks

Securing Software's Journey with the OWASP SPVS - Ido Geffen, Rohan Ravindranath, Cameron W., Farshad Abasi - ASW #378
Apr 14, 20261h 9m
It's one thing to write secure code, it's another to release it into the wild. That code needs to be designed, built, tested, released, and maintained. Farshad Abasi and Cameron Walters explain how the OWASP Secure Pipel

AppSec News Roundup on Claude Code Leak, Axios NPM Compromise, Secure Design - Idan Plotnik, Raj Mallempati - ASW #377
Apr 7, 20261h 8m
Security problems aren't changing very much even though security teams are. We catch up on the implications of the Claude Code source leak, the very human lessons from the axios NPM compromise, and what secure design loo

Developing the Skills Needed for Modern Software Development - Keith Hoodlet, Shashwat Sehgal, Ron Rasin - ASW #376
Mar 31, 20261h 15m
The future of secure software is going through a mix of skills expected of humans and skills files created for LLMs. We might even posit that appsec as a discipline will fade (and that might not even be a bad thing!). Ke

Why Proactive Security Is Far Better Than Patching - Erik Nost - ASW #375
Mar 24, 202638m
So much of appsec's efforts can be consumed by vuln management and a race to patch security flaws. But that's more a symptom of the ease of scanning and the volume of CVEs. Erik Nost walks through the principles behind p

Creating Better Security Guidance and Code with LLMs - Mark Curphey - ASW #374
Mar 17, 20261h 4m
What happens when secure coding guidance goes stale? What happens LLMs write code from scratch? Mark Curphy walks us through his experience updating documentation for writing secure code in Go and recreating one of his o

Making Medical Devices Secure - Tamil Mathi - ASW #373
Mar 10, 20261h 3m
Medical devices are a special segment of the IoT world where availability and patient safety are paramount. Tamil Mathi explains why many devices need to fail open -- the opposite of what traditional appsec approaches mi

Modern AppSec that keeps pace with AI development - James Wickett - ASW #372
Mar 3, 202647m
As more developers turn to LLMs to generate code, more appsec teams are turning to LLMs to conduct security code reviews. One of the biggest themes in all the discussion around LLMs, agents, and code is speed -- more cod

Helping Users with Practical Advice to Protect their Digital Devices - Runa Sandvik - ASW #371
Feb 24, 20261h 0m
Journalists put a lot of effort into collecting information and protecting their sources, but everyone can benefit from having a digital environment that's more secure and more privacy protecting. Runa Sandvik shares her

Conducting Secure Code Analysis with LLMs - ASW #370
Feb 17, 202646m
A major premise of appsec is figuring out effective ways to answer the question, "What security flaws are in this code?" The nature of the question doesn't really change depending on who or what wrote the code. In other

Bringing Strong Authentication and Granular Authorization for GenAI - Dan Moore - ASW #369
Feb 10, 20261h 9m
When it comes to agents and MCPs, the interesting security discussion isn't that they need strong authentication and authorization, but what that authn/z story should look like, where does it get implemented, and who imp

Focusing on Proactive Controls in the Face of LLM-Assisted Malware - Rob Allen - ASW #368
Feb 3, 20261h 7m
Everyone is turning to LLMs to generate code, including attackers. Thus, it's no great surprise that there are now examples of malware generated by LLMs. We discuss the implications of more malware with Rob Allen and wha