Mark Curphey and John Viega -- Chalk
Mark Curphey and John Viega join Chris and Robert to explain the details of Chalk, Crash Override's new tool.
Listen to the episode304 episodes, going back to 2016. Showing 73–96.
Mark Curphey and John Viega join Chris and Robert to explain the details of Chalk, Crash Override's new tool.
Listen to the episodeMaril Vernon is passionate about Purple teaming and joins Robert and Chris to discuss the intricacies of purple teaming in cybersecurity.
Listen to the episodeDan Küykendall visits The Application Security Podcast to discuss his series "Why All AppSec Products Suck" and explain why software companies should…
Listen to the episodeKevin Johnson is the CEO of Secure Ideas. He began his career as a developer but turned toward security when he discovered that the interface for an…
Listen to the episodeTony Quadros, the AppSec Lumberjack, shares the unique career path that led him to find his passion in Application Security.
Listen to the episodeCloud security is on an evolutionary path, with newer platforms embracing secure-by-default settings.
Listen to the episode"Visualizing the Software Supply Chain" is a project which aims to kick off a discussion about the scope and breadth of the software supply chain.
Listen to the episodeFarshad Abasi shares three models for deploying resources within application security teams: The Dedicated AppSec Person Model involves assigning an AppSec person to work with each team.
Listen to the episodeKim Wuyts discusses her work in privacy threat modeling with LINDDUN, a framework inspired by Microsoft's STRIDE for security threat modeling.
Listen to the episodeSoftware supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole.
Listen to the episodeHow do we do security in the world of AI and LLMs? A great place to start is with an OWASP project tasked with creating a standardized guideline for…
Listen to the episodeWhat is the state of application security? JB Aviat answered that question, by creating the state of application security report based on data from Datadog…
Listen to the episodeWhat is zero trust, and how does it impact the world of applications and application security?
Listen to the episodeJeevan Singh, the director of product security at Twilio, discusses the future of application security engineers.
Listen to the episodeHave you ever considered using an SBOM to inform your threat modeling? Tony Turner has. Tony joins us to discuss SBOMs, threat modeling, and the importance of Cyber Informed Engineering.
Listen to the episodeChristian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built.
Listen to the episodeZohar Shachar joins us to discuss the bug bounty process from both sides. Zohar has spent time as a bug bounty hunter and shares wisdom on avoiding bug bounty-causing issues for your AppSec posture.
Listen to the episodeSarah-Jane Madden is the Chief Information Security Officer of Sensing Technology Group. - part of Fortive.
Listen to the episodeJet Anderson's passion is teaching today's software developers to write secure code as part of modern DevOps pipelines, at speed and scale, without missing a beat.
Listen to the episodeJames Mckee is a developer (MCPDEA) and security advocate (CISSP) whose biggest responsibility is leading developer security practices.
Listen to the episodeDerek is the author of “The Application Security Handbook.” He is a university instructor at Temple University, where he teaches software development security to undergraduate and graduate students.
Listen to the episodeRob van der Veer has a 30-year background in software engineering, building AI businesses, creating software, and assessing software.
Listen to the episodeRobyn Lundin started working in tech after a coding boot camp as a developer for a small startup.
Listen to the episodeMichael Bargury is the Co-Founder and CTO of Zenity, where he helps companies secure their low-code/no-code apps.
Listen to the episode