Podcast Episodes
Back to SearchAvoiding Appsec's Worst Practices - ASW #324
We take advantage of April Fools to look at some of appsec's myths, mistakes, and behaviors that lead to bad practices. It's easy to get trapped in a…
11 months, 2 weeks ago
Finding a Use for GenAI in AppSec - Keith Hoodlet - ASW #323
LLMs are helping devs write code, but is it secure code? How are LLMs helping appsec teams? Keith Hoodlet returns to talk about where he's seen value…
11 months, 2 weeks ago
Redlining the Smart Contract Top 10 - Shashank . - ASW #322
The crypto world is rife with smart contracts that have been outsmarted by attackers, with consequences in the millions of dollars (and more!). Shash…
11 months, 3 weeks ago
CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321
Just three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s…
1 year ago
Keeping Curl Successful and Secure Over the Decades - Daniel Stenberg - ASW #320
Curl and libcurl are everywhere. Not only has the project maintained success for almost three decades now, but it's done that while being written in …
1 year ago
Developer Environments, Developer Experience, and Security - Dan Moore - ASW #319
Minimizing latency, increasing performance, and reducing compile times are just a part of what makes a development environment better. Throw in usefu…
1 year ago
Top 10 Web Hacking Techniques of 2024 - James Kettle - ASW #318
We're getting close to two full decades of celebrating web hacking techniques. James Kettle shares which was his favorite, why the list is important …
1 year ago
Code Scanning That Works With Your Code - Scott Norberg - ASW #317
Code scanning is one of the oldest appsec practices. In many cases, simple grep patterns and some fancy regular expressions are enough to find many o…
1 year, 1 month ago
Threat Modeling That Helps the Business - Akira Brand, Sandy Carielli - ASW #316
Threat modeling has been in the appsec toolbox for decades. But it hasn't always been used and it hasn't always been useful. Sandy Carielli shares wh…
1 year, 1 month ago
Security the AI SDLC - Niv Braun - ASW #315
A lot of AI security boils down to the boring, but important, software security topics that appsec teams have been dealing with for decades. Niv Brau…
1 year, 1 month ago