Podcast Episodes
Back to Search
Figuring Out Where Appsec Fits When Starting a Cybersecurity Program - Tyler VonMoll - ASW #277
Lots of companies need cybersecurity programs, as do non-profits. Tyler Von Moll talks about how to get small organizations started on security and h…
1 year, 11 months ago
More API Calls, More Problems: The State of API Security in 2024 - Lebin Cheng - ASW #276
A majority of internet traffic now originates from APIs, and cybercriminals are taking advantage. Increasingly, APIs are used as a common attack vect…
2 years ago
The Simple Mistakes and Complex Seeds of a Vulnerability Management Program - Emily Fox - ASW #275
The need for vuln management programs has been around since the first bugs -- but lots of programs remain stuck in the past. We talk about the traps …
2 years ago
Creating the Secure Pipeline Verification Standard - Farshad Abasi - ASW #274
Farshad Abasi joins us again to talk about creating a new OWASP project, the Secure Pipeline Verification Standard. (Bonus points for not being a top…
2 years ago
Redefining Threat Modeling - Security Team Goes on Vacation - Jeevan Singh - ASW Vault
Check out this interview from the ASW Vault, hand picked by main host Mike Shema! This segment was originally published on Dec 13, 2022.
Threat model…
2 years ago
Creating Code Security Through Better Visibility - Christien Rioux - ASW #273
We've been scanning code for decades. Sometimes scanning works well -- it finds meaningful flaws to fix. Sometimes it distracts us with false positiv…
2 years, 1 month ago
Starting an OWASP Project (That's Not a List!) - Grant Ongers - ASW #272
We can't talk about OWASP without talking about lists, but we go beyond the lists to talk about a product security framework. Grant shares his insigh…
2 years, 1 month ago
Getting Your First Conference Presentation - Sarah Harvey - ASW #271
We return to the practice of presentations, this time with a perspective from a conference organizer. And we have tons of questions! What makes a top…
2 years, 1 month ago
Dealing with the Burden of Bad Bots - Sandy Carielli - ASW #270
Where apps provide something of value, bots are sure to follow. Modern threat models need to include scenarios for bad bots that not only target user…
2 years, 1 month ago
Communicating Technical Topics Without Being Boring - Eve Maler - ASW #269
It's time to start thinking about CFPs and presentations for 2024! Eve shares advice on delivering technical topics so that an audience can understan…
2 years, 2 months ago