The AppSec bookshelf and toolbox
Useful things from the show notes
A normalized catalogue of references from the complete archive, ranked by the number of distinct episodes that link to each one. Inclusion reflects discussion, not endorsement.
545 resources
1,233 episode links
Bookshelf and toolbox
545 shown- 01Standards
OWASP Top 10
The OWASP Top 10 is the reference standard for the most critical web application security risks. Adopting the OWASP Top 10 is perhaps the most effective first step towards changing your software….
32 episodesVisit ↗ - 02Tools
OWASP ZAP
Welcome to ZAP! It provides a technical capability or reference that security practitioners can evaluate directly.
28 episodesVisit ↗ - 03Communities
OWASP Foundation
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
22 episodesVisit ↗ - 04Communities
DEF CON
The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest. It connects practitioners through a security community, event, or professional group.
18 episodesVisit ↗ - 05Tools
Docker
Docker is a platform designed to help developers build, share, and run container applications. We handle the tedious setup, so you can focus on the code.
18 episodesVisit ↗ - 06Projects
OWASP Juice Shop
The most modern and sophisticated insecure web application for security training, awareness demos, CTFs and security tool testing. Contains OWASP Top 10 vulnerabilities.
18 episodesVisit ↗ - 07Standards
OWASP Top 10 Proactive Controls
OWASP Top 10 Proactive Controls is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
18 episodesVisit ↗ - 08Projects
OWASP Proactive Controls
OWASP Top 10 Proactive Controls. It is maintained as an open or collaborative project.
17 episodesVisit ↗ - 09Projects
OWASP Dependency-Check
Dependency-Check is a Software Composition Analysis (SCA) tool suite that identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities. It is maintained as an open or collaborative project.
16 episodesVisit ↗ - 10Communities
Black Hat
Black Hat is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
15 episodesVisit ↗ - 11Standards
OWASP SAMM
Measure and improve your organization. It documents security requirements, practices, or guidance for practitioners and teams.
14 episodesVisit ↗ - 12Tools
Burp Suite
PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & identify the very latest vulnerabilities.
13 episodesVisit ↗ - 13Tools
Kubernetes
Kubernetes, also known as K8s, is an open source system for automating deployment, scaling, and management of containerized applications. It groups containers that make up an application into logical units for easy management and discovery.
13 episodesVisit ↗ - 14Tools
Semgrep
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions. It provides a technical capability or reference that security practitioners can evaluate directly.
12 episodesVisit ↗ - 15Standards
BSIMM
Benchmark your AppSec program with BSIMM assessment services from Black Duck. Get data-driven insights from 100+ organizations, identify security gaps, and build a customized Maturity Action Plan (MAP) to advance your software security posture.
11 episodesVisit ↗ - 16Standards
National Vulnerability Database (NVD)
National Vulnerability Database (NVD) is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
11 episodesVisit ↗ - 17Standards
OWASP Cheat Sheet Series
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
11 episodesVisit ↗ - 18Communities
OWASP Slack
Join the OWASP Foundation Slack workspace to connect with the global application security community. It connects practitioners through a security community, event, or professional group.
10 episodesVisit ↗ - 19Communities
RSA Conference
RSA Conference is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
9 episodesVisit ↗ - 20Tools
Brakeman
Brakeman is a static analysis security vulnerability scanner for Ruby on Rails applications. It provides a technical capability or reference that security practitioners can evaluate directly.
8 episodesVisit ↗ - 21Articles
Corgea
Corgea finds, triages, and fixes vulnerabilities across code, packages, infrastructure, and containers. It presents analysis, research, or practical guidance on its subject.
8 episodesVisit ↗ - 22Projects
OWASP Threat Dragon Project
OWASP Threat Dragon is a free, open-source, cross-platform threat modeling application used to draw threat modeling diagrams and to list threats for elements in the diagram. Threat Dragon is designed….
8 episodesVisit ↗ - 23Projects
OWASP Web Security Testing Guide (WSTG)
The Web Security Testing Guide (WSTG) Project produces the premier cybersecurity testing resource for web application developers and security professionals. It is maintained as an open or collaborative project.
8 episodesVisit ↗ - 24Articles
Terraform
Explore Terraform product documentation, tutorials, and examples. It presents analysis, research, or practical guidance on its subject.
8 episodesVisit ↗ - 25Articles
Attack Trees (Schneier)
Modeling security threats By Bruce Schneier Few people truly understand computer security, as illustrated by computer-security company marketing literature that touts “hacker proof software,” “triple-DES security,” and the like. In truth, unbreakable security is broken all the time, often in ways its designers never imagined.
7 episodesVisit ↗ - 26Articles
Content-Security-Policy (MDN)
The HTTP Content-Security-Policy response header allows website administrators to control resources the user agent is allowed to load for a given page. With a few exceptions, policies mostly involve specifying server origins and script endpoints.
7 episodesVisit ↗ - 27Articles
Log4j
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
7 episodesVisit ↗ - 28Tools
Microsoft Threat Modeling Tool
Overview of the Microsoft Threat Modeling Tool, containing information on getting started with the tool, including the Threat Modeling process. It provides a technical capability or reference that security practitioners can evaluate directly.
7 episodesVisit ↗ - 29Standards
MITRE ATT&CK Framework
MITRE ATT&CK Framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
7 episodesVisit ↗ - 30Tools
Node.js
Node. js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
7 episodesVisit ↗ - 31Projects
OWASP DevSlop Project
OWASP DevSlop - An OWASP incubator project. It is maintained as an open or collaborative project.
7 episodesVisit ↗ - 32Projects
WebGoat
OWASP WebGoat - An OWASP lab project. It is maintained as an open or collaborative project.
7 episodesVisit ↗ - 33Communities
BSides
BSides is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
6 episodesVisit ↗ - 34Articles
Claude Code
Anthropic's agentic coding tool for developers. Claude Code understands your codebase, edits files, runs commands, and helps you ship faster.
6 episodesVisit ↗ - 35Projects
CycloneDX
Know what’s inside. See how it connects.
6 episodesVisit ↗ - 36Projects
GitHub Copilot
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
6 episodesVisit ↗ - 37Projects
GitHub Dependabot
You can use Dependabot to keep the packages you use updated to the latest versions. It is maintained as an open or collaborative project.
6 episodesVisit ↗ - 38Communities
Linux Foundation
Helping open technology projects build world class open source software, communities and companies. It connects practitioners through a security community, event, or professional group.
6 episodesVisit ↗ - 39Standards
OWASP Top Ten for LLM Applications project homepage
OWASP Top 10 for Large Language Model Applications - An OWASP lab project. It documents security requirements, practices, or guidance for practitioners and teams.
6 episodesVisit ↗ - 40Standards
PCI DSS
A global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments. It documents security requirements, practices, or guidance for practitioners and teams.
6 episodesVisit ↗ - 41Projects
The Phoenix Project
The bestselling novel that introduced the world to DevOps and the Three Ways — an IT manager with 90 days to save his company. By Gene Kim, Behr & Spafford.
6 episodesVisit ↗ - 42Projects
Bandit
Bandit is a tool designed to find common security issues in Python code. - PyCQA/bandit.
5 episodesVisit ↗ - 43Articles
Fortify (OpenText)
OpenText Fortify SAST detects code vulnerabilities early with precise static code analysis, 45+ language support, and seamless CI/CD integration across the SDLC. It presents analysis, research, or practical guidance on its subject.
5 episodesVisit ↗ - 44Projects
ModSecurity
ModSecurity is the standard open-source web application firewall (WAF) engine. Originally designed as a module for the Apache HTTP Server, it has evolved to provide HTTP request and response….
5 episodesVisit ↗ - 45Projects
OWASP AppSensor
OWASP AppSensor - An OWASP incubator project. It is maintained as an open or collaborative project.
5 episodesVisit ↗ - 46Projects
OWASP Cornucopia
OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is maintained as an open or collaborative project.
5 episodesVisit ↗ - 47Projects
OWASP DefectDojo
The leading open source application vulnerability management tool built for DevOps and continuous security integration. It is maintained as an open or collaborative project.
5 episodesVisit ↗ - 48Standards
OWASP Password Storage Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
5 episodesVisit ↗ - 49Projects
OWASP pytm
pytm is a Pythonic framework for threat modeling. Define your system in Python using the elements and properties described in the pytm framework.
5 episodesVisit ↗ - 50Standards
OWASP SAMM
A Software Assurance Maturity Model (SAMM) that provides an effective and measurable way for all types of organizations to analyse and improve their software security posture. It documents security requirements, practices, or guidance for practitioners and teams.
5 episodesVisit ↗ - 51Articles
PASTA
PASTA threat modeling explained: the risk-centric, 7-stage methodology co-created by VerSprite's CEO to simulate real attacks and prioritize business risk. It presents analysis, research, or practical guidance on its subject.
5 episodesVisit ↗ - 52Projects
PyTM
A Pythonic framework for threat modeling. Contribute to OWASP/pytm development by creating an account on GitHub.
5 episodesVisit ↗ - 53Articles
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society by Chris Hughes, Tony Turner
Discover the new cybersecurity landscape of the interconnected software supply chain In Software Transparency: Supply Chain Security in an Era of a Software-Driven Society, a team of veteran information security professionals delivers an expert treatment of software supply chain security. In the book, you’ll explore real-world examples and guidance on how to defend your own organization against internal and ext.
5 episodesVisit ↗ - 54Books
Start With Why
This book is about how articulating your purpose can inspire you and those around you. Organizations and leaders that start with their purpose, or “why,” are….
5 episodesVisit ↗ - 55Books
The Application Security Program Handbook by Derek Fisher
Secure apps, fast. Your guide to a robust application security program.
5 episodesVisit ↗ - 56Standards
BSIMM
Benchmark your AppSec program with BSIMM assessment services from Black Duck. Get data-driven insights from 100+ organizations, identify security gaps, and build a customized Maturity Action Plan (MAP) to advance your software security posture.
4 episodesVisit ↗ - 57Courses
Cisco Security Ninja
Did you know that October is National Cyber Security Awareness Month? Here at Cisco, we understand how important cybersecurity is in today’s interconnected world.
4 episodesVisit ↗ - 58Communities
CodeMash conference
A volunteer-run developer conference at Kalahari Resort in Ohio and Virginia. Sessions, hands-on workshops, KidzMash, and the tech community you.
4 episodesVisit ↗ - 59Tools
Docker Hub
Welcome to the world's largest container registry built for developers and open source contributors to find, use, and share their container images. Build, push and pull.
4 episodesVisit ↗ - 60Articles
Executive Order 14028
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
4 episodesVisit ↗ - 61Projects
GitLab
The intelligent orchestration platform for DevSecOps, enabling teams and agents to ship trusted software at enterprise scale. It is maintained as an open or collaborative project.
4 episodesVisit ↗ - 62Articles
Mobile Testing Guide
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
4 episodesVisit ↗ - 63Projects
MultiJuicer
Host and manage multiple Juice Shop instances for security trainings and Capture The Flags - juice-shop/multi-juicer. It is maintained as an open or collaborative project.
4 episodesVisit ↗ - 64Projects
OWASP DevSecOps Maturity Model (DSOMM)
OWASP Devsecops Maturity Model - An OWASP lab project. It is maintained as an open or collaborative project.
4 episodesVisit ↗ - 65Standards
OWASP IoT Top 10
OWASP Internet of Things - An OWASP lab project. It documents security requirements, practices, or guidance for practitioners and teams.
4 episodesVisit ↗ - 66Projects
OWASP Women in AppSec (WIA)
Women in AppSec Respository. Contribute to OWASP/WIA development by creating an account on GitHub.
4 episodesVisit ↗ - 67Articles
PASTA (Process for Attack Simulation and Threat Analysis)
PASTA threat modeling explained: the risk-centric, 7-stage methodology co-created by VerSprite's CEO to simulate real attacks and prioritize business risk. It presents analysis, research, or practical guidance on its subject.
4 episodesVisit ↗ - 68Standards
PCI Security Standards Council
A global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments. It documents security requirements, practices, or guidance for practitioners and teams.
4 episodesVisit ↗ - 69Communities
Women in AppSec
This meetup is for anyone interested in supporting and mentoring women and minorities in cyber security. It is primarily the OWASP Foundation Women in Application Security (WIA), Diversity and Inclusion Committee & we also welcome all women and minorities in security.
4 episodesVisit ↗ - 70Articles
Aleph One's "Smashing The Stack for Fun and Profit"
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 71Books
Alice and Bob Learn Application Security
Learn application security from the very start, with this comprehensive and approachable guide! It offers longer-form guidance and context on its subject.
3 episodesVisit ↗ - 72Articles
Alice and Bob Learn Application Security
Learn application security from the very start, with this comprehensive and approachable guide! Alice and Bob Learn Application Security is an accessible and thorough resource for anyone seeking to incorporate, from the beginning of the System Development Life Cycle, best security practices in software development.
3 episodesVisit ↗ - 73Books
Applied Cryptography
Applied Cryptography Protocols, Algorithms, and Source Code in C A book by Bruce Schneier This second edition of the cryptography classic provides you with a comprehensive survey of modern cryptography. The book details how programmers and electronic communications professionals can use cryptography—the technique of enciphering and deciphering messages—to maintain the privacy of computer data.
3 episodesVisit ↗ - 74Articles
Artificial Intelligence
UNESCO is committed to a future where AI and emerging technologies work for the people. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 75Communities
B-Sides
B-Sides is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
3 episodesVisit ↗ - 76Tools
Burp Suite Professional
Burp Suite Professional is the world. It provides a technical capability or reference that security practitioners can evaluate directly.
3 episodesVisit ↗ - 77Projects
Chaos Monkey
Chaos Monkey is a resiliency tool that helps applications tolerate random instance failures. - Netflix/chaosmonkey.
3 episodesVisit ↗ - 78Articles
Cyber Kill Chain (Lockheed Martin)
Lockheed Martin's Cyber Kill Chain® strengthens cybersecurity. Prevent cyber intrusions with our Intelligence Driven Defense® model.
3 episodesVisit ↗ - 79Projects
DevSlop
DevSlop has 8 repositories available. Follow their code on GitHub.
3 episodesVisit ↗ - 80Articles
EU Cyber Resilience Act
The Cyber Resilience Act (CRA) aims to make sure all digital products are safe from cyber threats. This rulebook requires that devices and software are designed, updated, and maintained to protect users in our increasingly digital world.
3 episodesVisit ↗ - 81Articles
Maker's Schedule, Manager's Schedule
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 82Communities
Open Security Summit
Open Security Summit is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
3 episodesVisit ↗ - 83Projects
Open Threat Model (OTM)
The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system. - iriusrisk/OpenThreatModel.
3 episodesVisit ↗ - 84Articles
OpenID Connect
What is OpenID Connect OpenID Connect is an interoperable authentication protocol based on the OAuth 2. 0 framework of specifications (IETF RFC 6749 and 6750).
3 episodesVisit ↗ - 85Projects
OWASP Developer Guide
The OWASP Developer Guide provides an introduction to security concepts and an initial reference for application and system developers. The content of the Developer Guide aims to be accessible,….
3 episodesVisit ↗ - 86Communities
OWASP Triangle Chapter
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
3 episodesVisit ↗ - 87Projects
Pixi (DevSlop)
The Pixi module is a MEAN Stack web app with wildly insecure APIs! - DevSlop/Pixi.
3 episodesVisit ↗ - 88Articles
Security Compass
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 89Articles
Sqreen (now Datadog AAP)
Monitor threats targeting production system, leveraging the execution context provided by distributed traces. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 90Articles
SSLlabs.com
A comprehensive free SSL test for your public web servers. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 91Articles
Tay (Microsoft chatbot)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 92Books
The DevOps Handbook
This award-winning and bestselling business handbook for digital transformation is now fully updated and expanded with the latest research and new case studies. It offers longer-form guidance and context on its subject.
3 episodesVisit ↗ - 93Articles
The Tangled Web
Browsers are doing a lot of strange things under the hood. Security expert Michal Zalewski explains what and why.
3 episodesVisit ↗ - 94Books
The Web Application Hacker's Handbook
The highly successful security book returns with a new edition, completely updated Web applications are the front door to most organizations, exposing them to attacks that may disclose personal information, execute fraudulent transactions, or compromise ordinary users. This practical book has been completely updated and revised to discuss the latest step-by-step techniques for attacking and defending the range of eve.
3 episodesVisit ↗ - 95Articles
Tim Ferriss
The Tim Ferriss Show The Tim Ferriss Show is one of the most popular podcasts in the world, with more than one billion downloads. It has been selected for “Best of Apple Podcasts” three times.
3 episodesVisit ↗ - 96Articles
VulnDB (Flashpoint)
Flashpoint Vulnerability Intelligence helps teams discover vulnerabilities, prioritize threats and protect critical assets. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 97Projects
WebGoat
WebGoat is a deliberately insecure application. Contribute to WebGoat/WebGoat development by creating an account on GitHub.
3 episodesVisit ↗ - 98Tools
ZAP Heads Up Display (HUD)
The world’s most widely used web app scanner. Free and open source.
3 episodesVisit ↗ - 99Books
Agile Application Security
Agile Application Security is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 100Tools
Ansible Automation Platform
A platform for implementing enterprise-wide automation, no matter where you are in your automation journey. It provides a technical capability or reference that security practitioners can evaluate directly.
2 episodesVisit ↗ - 101Articles
AOL Search Data Leak
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 102Books
Application Security Program Handbook
Application Security Program Handbook is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 103Standards
AppScan Standard (HCL)
Protect applications with the HCL AppScan Application Security Testing Platform for SAST, DAST, IAST, API security, AI-powered remediation, and compliance. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 104Articles
ArcSight (OpenText)
SIEM security software to minimize MTTD and MTTR with industry-leading correlation, threat intelligence, native SOAR, and real-time threat detection. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 105Projects
Björn Kimminich on GitHub
IT Product Group Lead @kuehne-nagel, Project Leader @OWASP @juice-shop, Amateur MTG Player @mull2five - bkimminich. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 106Communities
Boston Application Security Conference
BASC 2027, the Boston Application Security Conference by OWASP Boston. One day of AppSec talks and workshops.
2 episodesVisit ↗ - 107Courses
Carnegie Mellon University Software Engineering Institute
Whether you work in the DoW, government, academia, or private industry, the SEI can partner with your organization to research and solve its hardest software challenges. It provides structured security learning or training material.
2 episodesVisit ↗ - 108Projects
ChaoSlingr
ChaoSlingr: Introducing Security into Chaos Testing - Optum/ChaoSlingr. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 109Articles
Chromium
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 110Articles
CISA Zero Trust Maturity Model
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 111Articles
CISSP
Gain the CISSP certification with ISC2 to demonstrate your expertise in cybersecurity leadership, implementation & management. Advance your career today!
2 episodesVisit ↗ - 112Articles
Code Red
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 113Communities
Converge Conference
Converge Conference brings together thinkers, builders and leaders for a day of keynotes, workshops and connection. Where ideas, people and industries converge.
2 episodesVisit ↗ - 114Articles
Core Software Security: Security at the Source
Core Software Security: Security at the Source [Ransome, James, Misra, Anmol] on Amazon. com.
2 episodesVisit ↗ - 115Articles
Crash Override
Software Observability for the AI era. The data plane for software, from prompt to production.
2 episodesVisit ↗ - 116Books
Crossing the Chasm
Amazon. com: Crossing the Chasm, 3rd Edition: The Updated Version of the Insightful Guide on Bringing Cutting-Edge Products to the Mainstream (Collins Business Essentials): 9780062292988: Moore, Geoffrey A.
2 episodesVisit ↗ - 117Articles
CSA IoT Working Group
CSA’s working groups develop best practices, research and tools for cloud security. Each group focuses on a unique topic or aspect of cloud security.
2 episodesVisit ↗ - 118Articles
CSSLP
Secure your cybersecurity career with ISC2’s CSSLP certification and gain expertise in software lifecycle security and secure coding practices. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 119Articles
Cyber For Builders
Helping security practitioners, entrepreneurs, investors and executives build the future of cybersecurity. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 120Projects
Damn Vulnerable Web App (DVWA)
Damn Vulnerable Web Application (DVWA). Contribute to digininja/DVWA development by creating an account on GitHub.
2 episodesVisit ↗ - 121Articles
DevSecOps Reference Architecture (Sonatype)
An interactive DevSecOps reference architecture illustrates manual and automated processes, plus interactions between systems, stakeholders, and security. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 122Articles
DoD STIG
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 123Articles
Dwarkesh Patel: "The Rise and Fall of Agent Civilizations"
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 124Articles
Elevation of Privilege
The Elevation of Privilege (EoP) threat modeling card game, created by Adam Shostack in 2010, is the easy way to get started threat modeling. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 125Articles
Exodus Communications
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 126Projects
Gauntlt
a ruggedization framework that embodies the principle "be mean to your code" - gauntlt/gauntlt. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 127Tools
Hacking Exposed Web Applications
Hacking exposed by Joel Scambray, 2011, McGraw-Hill edition, electronic resource : in English - 3rd ed. It provides a technical capability or reference that security practitioners can evaluate directly.
2 episodesVisit ↗ - 128Articles
IEEE Center for Secure Design
The world's leading society for computing and engineering. Access our research, certifications, and global community of tech innovators.
2 episodesVisit ↗ - 129Articles
INCLUDES NO DIRT paper
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 130Projects
IoTGoat
IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices. - OWASP/IoTGoat.
2 episodesVisit ↗ - 131Projects
James Wickett
wickett has 72 repositories available. Follow their code on GitHub.
2 episodesVisit ↗ - 132Projects
Jon McCoy on GitHub
theJonMccoy has 7 repositories available. Follow their code on GitHub.
2 episodesVisit ↗ - 133Projects
Kamus
An open source, git-ops, zero-trust secret encryption and decryption solution for Kubernetes applications - Soluto/kamus. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 134Tools
Kubernetes Admission Controllers
This page provides an overview of admission controllers. An admission controller is a piece of code that intercepts requests to the Kubernetes API server prior to persistence of the resource, but after the request is authenticated and authorized.
2 episodesVisit ↗ - 135Projects
LavaMoat
tools for sandboxing your dependency graph. Contribute to LavaMoat/LavaMoat development by creating an account on GitHub.
2 episodesVisit ↗ - 136Communities
Loco Moco Product Security Conference
Security Conference in Hawaiʻi. It connects practitioners through a security community, event, or professional group.
2 episodesVisit ↗ - 137Projects
multi-juicer GitHub
Host and manage multiple Juice Shop instances for security trainings and Capture The Flags - juice-shop/multi-juicer. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 138Books
Nassim Taleb books
Nassim Taleb books is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 139Communities
NDC Conferences
NDC Conferences has been delivering high-end events for software developers for more than 20 years. Our events range from large 5-day events with more than 2500 people to smaller niche events and workshops.
2 episodesVisit ↗ - 140Articles
Nessus
Find out more about Nessus - the trusted gold standard for vulnerability assessment, designed for modern attack surfaces - used by thousands of organizations. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 141Articles
Net.wars (Wendy Grossman)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 142Articles
Never Split The Difference Chris Vosstahl Raz
This international bestseller, with more than 5 million copies sold, offers a field-tested approach to high-stakes negotiations and conflict resolution—whet... It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 143Articles
New School Of Information Security 9780132800280
This is the eBook version of the printed book. "It is about time that a book like The New School came along.
2 episodesVisit ↗ - 144Standards
NIST AI Risk Management Framework
NIST AI Risk Management Framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 145Standards
NIST SP 800-53
This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. The controls are flexible and customiza.
2 episodesVisit ↗ - 146Standards
NIST SP 800-63
NIST SP 800-63 is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 147Standards
NIST SP 800-63B
NIST Special Publication 800-63B. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 148Projects
Node.js security working group
Node. js Ecosystem Security Working Group.
2 episodesVisit ↗ - 149Projects
nodejsscan
nodejsscan is a static security code scanner for Node. js applications.
2 episodesVisit ↗ - 150Articles
npm event-stream incident
npm Blog (Archive); updates from the npm team are now published on the GitHub Blog and the GitHub Changelog. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 151Articles
OAuth 2.0
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 152Articles
OWASP 2025 Global Board Elections
OWASP 2025 Global Board Elections on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
2 episodesVisit ↗ - 153Projects
OWASP AppSec Pipeline Project
OWASP Foundation Web Respository. Contribute to OWASP/www-project-appsec-pipeline development by creating an account on GitHub.
2 episodesVisit ↗ - 154Communities
OWASP Bangalore
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
2 episodesVisit ↗ - 155Projects
OWASP GenAI Security Project
Identifying and tackling the risks of Gen AI systems and applications OWASP GenAI Security Project A global community-driven and expert led initiative to create freely available open source guidance and resources for understanding and mitigating security and safety concerns for Generative AI applications and adoption. Join Now Members k+ Countries + AI Cybersecurity Publications + […].
2 episodesVisit ↗ - 156Articles
OWASP Global Board Candidates
OWASP Global Board Candidates on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
2 episodesVisit ↗ - 157Communities
OWASP Israel
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
2 episodesVisit ↗ - 158Standards
OWASP ISVS
OWASP IoT Security Verification Standard (ISVS). Contribute to OWASP/IoT-Security-Verification-Standard-ISVS development by creating an account on GitHub.
2 episodesVisit ↗ - 159Projects
OWASP Java Encoder Project
OWASP Java Encoder - An OWASP project. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 160Projects
OWASP Juice Shop
Probably the most modern and sophisticated insecure web application for security trainings, awareness demos and CTFs. Also great voluntary guinea pig for your security tools and DevSecOps pipelines!
2 episodesVisit ↗ - 161Articles
OWASP Juice Shop Jingle
Play OWASP Juice Shop Jingle by braimee on desktop and mobile. Play over 320 million tracks for free on SoundCloud.
2 episodesVisit ↗ - 162Standards
OWASP Low-Code/No-Code Top 10
The OWASP Low-Code/No-Code Top 10 is a documentation project aimed at helping organizations understand and manage security risks in Low-Code and No-Code applications. It highlights the main security challenges these types of applications face and provides guidance on how to tackle them.
2 episodesVisit ↗ - 163Communities
OWASP Montreal chapter
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
2 episodesVisit ↗ - 164Communities
OWASP Netherlands Chapter
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
2 episodesVisit ↗ - 165Projects
OWASP Nettacker
OWASP Nettacker is an automated penetration testing framework designed to help cyber security professionals and ethical hackers perform reconnaissance, vulnerability assessments, and network security…. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 166Projects
OWASP Project Spotlight Series
OWASP Foundation Web Respository. Contribute to OWASP/www-project-spotlight-series development by creating an account on GitHub.
2 episodesVisit ↗ - 167Standards
OWASP Security Knowledge Framework
Security Knowledge Framework (SKF) Python Flask / Angular project - blabla1337/skf-flask. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 168Standards
OWASP Security Knowledge Framework
OWASP Security Knowledge Framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 169Projects
OWASP SecurityRAT
OWASP SecurityRAT - An OWASP incubator project. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 170Standards
OWASP SQL Injection Prevention Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 171Standards
OWASP Top 10 project repository
Official OWASP Top 10 Document Repository. Contribute to OWASP/Top10 development by creating an account on GitHub.
2 episodesVisit ↗ - 172Articles
P200000007269
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 173Articles
PASTA Threat Modeling
PASTA threat modeling ties every step to business risk, not just technical findings. Here's why security leaders adopt it — and what it delivers.
2 episodesVisit ↗ - 174Articles
Patrick DeBois
Research notes, frameworks, and prototypes organized by stream — thoughts, tools, talks. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 175Projects
Puma Scan
Puma Scan is a software security Visual Studio extension that provides real time, continuous source code analysis as development teams write code. Vulnerabilities are immediately displayed in the development environment as spell check and compiler warnings, preventing security bugs from entering your applications.
2 episodesVisit ↗ - 176Tools
r2c / Semgrep Inc.
Semgrep is an industry leader that is profoundly improving software security and reliability, powering 75M+ source-code security scans. It provides a technical capability or reference that security practitioners can evaluate directly.
2 episodesVisit ↗ - 177Projects
RepoKid
AWS Least Privilege for Distributed, High-Velocity Deployment - Netflix/repokid. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 178Projects
retire.js
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
2 episodesVisit ↗ - 179Articles
Ron Rivest
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 180Projects
Roslyn (.NET Compiler Platform)
The Roslyn . NET compiler provides C# and Visual Basic languages with rich code analysis APIs.
2 episodesVisit ↗ - 181Courses
SANS SEC542
Build real-world web app offensive skills with a hands-on, repeatable process for finding, exploiting, and clearly proving the vulnerabilities that matter. It provides structured security learning or training material.
2 episodesVisit ↗ - 182Tools
SAST, DAST, IAST, and RASP: Pros, cons and how to choose
SAST, DAST, IAST, and RASP: Pros, cons and how to choose is a security tool or technical reference discussed on the podcast and available from learn. techbeacon.
2 episodesVisit ↗ - 183Books
Securing DevOps (Julien Vehent)
Integrate security into your DevOps pipeline and build safer cloud services. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 184Books
Securing Systems: Applied Security Architecture and Threat Models
Internet attack on computer systems is pervasive. It can take from less than a minute to as much as eight hours for an unprotected machine connected to the Inte.
2 episodesVisit ↗ - 185Books
Security Chaos Engineering
Security Chaos Engineering is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 186Books
Security Metrics: A Beginner's Guide
Security Metrics, A Beginner. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 187Articles
Segment
Collect, unify, and enrich customer data across any app or device with the Twilio Segment CDP, now available on Twilio. com.
2 episodesVisit ↗ - 188Communities
Slack
Boost productivity and save time with Slack — the AI work platform for managing projects, automating workflows, and connecting teams securely. Start working smarter today.
2 episodesVisit ↗ - 189Articles
Slides on SpeakerDeck
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 190Articles
Software Security
This is the Mobipocket version of the print book. "When it comes to software security, the devil is in the details.
2 episodesVisit ↗ - 191Articles
Software Security: Building Security In
Software Security: Building Security In [McGraw, Gary] on Amazon. com.
2 episodesVisit ↗ - 192Books
Software Transparency
Amazon. com: Software Transparency: Supply Chain Security in an Era of a Software-Driven Society: 9781394158485: Hughes, Chris, Turner, Tony, Springett, Steve, Friedman, Allan: Books.
2 episodesVisit ↗ - 193Books
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
Amazon. com: Software Transparency: Supply Chain Security in an Era of a Software-Driven Society: 9781394158485: Hughes, Chris, Turner, Tony, Springett, Steve, Friedman, Allan: Books.
2 episodesVisit ↗ - 194Articles
SonarQube
Modernize your AI workflows with code verification for the agentic era. Fight AI slop & improve reliability through automated, explainable, and compliant code reviews.
2 episodesVisit ↗ - 195Communities
Source Conference
June 15-17, 2021, HOUSTON Tehas State University (USA, Tehas, Houston) holds the 4th International Scientific and Practical Conference “Web Programming and Internet Technologies (WebConf2021)” on June 15-17, 2021. The Chairman of the Organizing Committee is academician of the National Academy of Sciences Anton Vladimirovich Abramenko.
2 episodesVisit ↗ - 196Projects
Spring Security
Level up your Java code and explore what Spring can do for you. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 197Books
SRE Engineering
Explore the world of site reliability engineering with top-rated sre books. Find resources on SRE principles, best practices and the role of a reliability engineer.
2 episodesVisit ↗ - 198Projects
Steve Springett on GitHub
I build stuff, I break stuff, I develop stuff to protect stuff. Creator of @DependencyTrack.
2 episodesVisit ↗ - 199Articles
The Cuckoo's Egg
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 200Books
The Cuckoo's Egg by Cliff Stoll
The Cuckoo. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 201Books
The Developer's Playbook for Large Language Model Security
The Developer's Playbook for Large Language Model Security is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 202Articles
The Hard Thing About Hard Things by Ben Horowitz
Ben Horowitz, cofounder of the venture capital firm Andreessen Horowitz and one of Silicon Valley’s most respected and experienced entrepreneurs, offers ess... It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 203Tools
The left-pad incident
The left-pad incident is a security tool or technical reference discussed on the podcast and available from en. wikipedia.
2 episodesVisit ↗ - 204Articles
The Pentester Blueprint: Starting a Career as an Ethical Hacker
JUMPSTART YOUR NEW AND EXCITING CAREER AS A PENETRATION TESTER The Pentester BluePrint: Your Guide to Being a Pentester offers readers a chance to delve deeply into the world of the ethical, or "white-hat" hacker. Accomplished pentester and author Phillip L.
2 episodesVisit ↗ - 205Articles
The Pentester BluePrint: Starting A Career As An Ethical Hacker P 9781119684305
JUMPSTART YOUR NEW AND EXCITING CAREER AS A PENETRATION TESTER The Pentester BluePrint: Your Guide to Being a Pentester offers readers a chance to delve deeply into the world of the ethical, or "white-hat" hacker. Accomplished pentester and author Phillip L.
2 episodesVisit ↗ - 206Books
The Phoenix Project
The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win [Gene Kim, Kevin Behr, George Spafford] on Amazon. com.
2 episodesVisit ↗ - 207Projects
The Software Security Project
Persiapkan kecepatan respons Anda. MAXWIN88 menyediakan koleksi permainan aksi yang intens untuk menguji keterampilan strategis dan mekanis Anda.
2 episodesVisit ↗ - 208Books
The Unicorn Project
The Unicorn Project is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 209Projects
The Unicorn Project
The highly anticipated follow-up to the bestselling title The Phoenix Project, this book unveils the Five Ideals of Software Development. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 210Books
Threat Modeling: A Practical Guide for Development Teams
Amazon. com: Threat Modeling: A Practical Guide for Development Teams: 9781492056553: Tarandach, Izar, Coles, Matthew J.
2 episodesVisit ↗ - 211Articles
TLDR newsletter
TLDR delivers byte sized daily emails on Tech, AI, Web Development, Information Security, Startups, Product Management, DevOps, Marketing, Design and more! It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 212Articles
Trusted Computer System Evaluation Criteria
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 213Articles
Twilio
Build amazing customer experiences on the Twilio platform with APIs for SMS, RCS, voice, and email, plus conversational AI for smarter engagement, and identity verification for trust. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 214Tools
VEX
VEX is a security tool or technical reference discussed on the podcast and available from cisa. gov.
2 episodesVisit ↗ - 215Standards
XSS Prevention Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 216Projects
0x Project
Developers’ one-stop shop to enable faster crypto trading, better prices, and superior UX. Get started now at 0x.
1 episodeVisit ↗ - 217Books
10 Steps Every CISO Should Take to Secure Next-Gen Software
10 Steps Every CISO Should Take to Secure Next-Gen Software is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 218Articles
2019 State of Open Source Security — developer ownership findings
A worrying 27% of respondents stated they do not have any proactive or automatic way to find out about newly discovered vulnerabilities in their applications. 37% of users of users don’t implement any sort of security testing during CI.
1 episodeVisit ↗ - 219Articles
7 Web Application Security Best Practices
This article contains a list of 7 web application security best practices that we believe should be considered in your web app security strategy. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 220Articles
9781260464009
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 221Articles
A Tester's Journey — Lisi's blog
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 222Projects
Aaron “kumavis” Davis on GitHub
kumavis has 514 repositories available. Follow their code on GitHub.
1 episodeVisit ↗ - 223Tools
Acunetix Web Scanner
Invicti Web + API is an end-to-end web security scanner that offers a 360 view of an organization’s security. Allowing you to take control of the security of all you web applications, web services, and APIs to ensure long-term protection.
1 episodeVisit ↗ - 224Articles
Aditya Gupta and Attify
Attify is a premium offensive security company founded by Aditya Gupta, author of The IoT Hacker's Handbook. Training, consulting, and research for IoT, mobile, and complex systems security.
1 episodeVisit ↗ - 225Articles
Adversarial Misuse of Generative AI (Javan's blog article)
We share our findings on government-backed and information operations threat actor use of the Gemini web application. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 226Articles
AICPA SOC for Service Organizations overview
This document provides an overview of SOC for Service Organizations Engagements. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 227Communities
Alpha-Omega
Alpha-Omega is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 228Articles
Amazon AWS outage caused by AI agent (Engadget)
A recent Amazon Web Services outage was reportedly caused by the company. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 229Tools
An Analysis of Open-source Automated Threat Modeling Tools and Their Extensibility from Security into Privacy
An Analysis of Open-source Automated Threat Modeling Tools and Their Extensibility from Security into Privacy is a security tool or technical reference discussed on the podcast and available from usenix. org.
1 episodeVisit ↗ - 230Articles
Anastasiia Voitova at Cossack Labs
Media coverage, press releases, company dates of Cossack Labs, data security solution company that builds software and custom solutions for innovative teams. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 231Articles
Andrew van der Stock at OWASP
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 232Books
Antifragile by Nassim Nicholas Taleb
NEW YORK TIMES BESTSELLER • Antifragile is a standalone book in Nassim Nicholas Taleb’s landmark Incerto series, an investigation of opacity,... It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 233Articles
Applied Cryptography
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 234Articles
Applied Cryptography
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 235Projects
AppSensor source code
A toolkit for building self-defending applications through real-time event detection and response - jtmelton/appsensor. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 236Articles
ArcSight ESM (OpenText)
ArcSight ESM analyzes and correlates every event that occurs across the organization--every login, logoff, file access, database query--to deliver accurate prioritization of security risks and compliance violations. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 237Articles
Atomic Habits
Packed with evidence-based strategies, Atomic Habits will teach you how to make small changes that will transform your habits and deliver amazing results. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 238Books
Austin Kleon books
Illustrated guides to creativity in the digital age by the New York Times bestselling author. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 239Projects
AWS Threat Composer
A simple threat modeling tool to help humans to reduce time-to-value when threat modeling - awslabs/threat-composer. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 240Tools
Azure Kubernetes Service
Discover Azure Kubernetes Service (AKS) for secure, scalable containerized app deployment and management with fast delivery on managed Kubernetes clusters. It provides a technical capability or reference that security practitioners can evaluate directly.
1 episodeVisit ↗ - 241Books
B09NRF399J
IDENTIFIED: A hacker thriller ripped from the headlines of today. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 242Communities
Becoming jaded with Security BSides’ Jack Daniel
Becoming jaded with Security BSides’ Jack Daniel is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 243Books
Being Henry Fonz And Beyond Henry Winkler
From Emmy-award winning actor, comedian, producer, and director Henry Winkler, a memoir of the effects of stardom and the struggle to become whole. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 244Articles
Bill Sempf’s developer profile
Stack Overflow. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 245Articles
Billion Laughs Attack
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 246Books
Black Hat GraphQL (book)
Written by hackers for hackers, this hands-on book shows how to identify vulnerabilities in apps that use GraphQL. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 247Articles
Blockchain Security A Need For Todays Businesses Complete Guide For Beginners
In this article we will know about Blockchain Security: A need for Today’s Businesses (Complete Guide for Beginners). It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 248Books
Books by Martin Fowler
Books by Martin Fowler is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 249Books
Books by Yuval Noah Harari
Prof. Yuval Noah Harari is a historian, philosopher and best-selling author of 'Sapiens' and 'Homo Deus'.
1 episodeVisit ↗ - 250Communities
Boston .NET Architecture Group
**Description****We are celebrating 22 years in December, 2025 / January, 2026! **We are a group of software developers and architects primarily in the Boston area that get together and discuss various topics about Patterns, .
1 episodeVisit ↗ - 251Communities
BSides Boulder
Official BSides Boulder Event Page. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 252Communities
BSides Las Vegas
BSides Las Vegas. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 253Communities
BSides San Antonio
General information about BSides SATX 2026. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 254Communities
BSides Singapore
Where Singapore. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 255Standards
BSIMM
BSIMM is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 256Books
Building In Security At Agile Speed
Building in Security at Agile Speed [Ransome, James, Schoenfield, Brook] on Amazon. com.
1 episodeVisit ↗ - 257Books
Building Secure and Reliable Systems
Building Secure and Reliable Systems is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 258Projects
Bundler Audit
Patch-level verification for Bundler. Contribute to rubysec/bundler-audit development by creating an account on GitHub.
1 episodeVisit ↗ - 259Articles
Can Kubernetes Keep a Secret? (blog)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 260Articles
CAWE
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 261Articles
Chalk
This is the main page for Chalk docs. Chalk is an open-source project created and maintained by Crash Override.
1 episodeVisit ↗ - 262Articles
Chrome 68 "Not Secure" HTTP Labeling
We're marking all sites that are not encrypted with HTTPS as “not secure”. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 263Projects
CI/CD Goat
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
1 episodeVisit ↗ - 264Tools
CIS Docker Benchmark
Download our step-by-step checklist to secure your platform: An objective, consensus-driven security guideline for Docker. It provides a technical capability or reference that security practitioners can evaluate directly.
1 episodeVisit ↗ - 265Articles
Cisco Secure
Defend users, apps, and data against today's threats. Enable your agentic enterprise at scale with an open, network-native platform.
1 episodeVisit ↗ - 266Books
CISO Desk Reference Guide
An easy to use guide written by experienced practitioners for recently-hired or promoted Chief Information Security Officers (CISOs), individuals aspiring to become a CISO, as well as business and technical professionals interested in the topic of cybersecurity, including Chief Technology Officers (CTOs), Chief Information Officers (CIOs), Boards of Directors, Chief Privacy Officers, and other executives responsible. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 267Articles
Claude Code source leak (VentureBeat)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 268Projects
CodeProject
An open or collaborative project discussed on the podcast and hosted at codeproject. com.
1 episodeVisit ↗ - 269Projects
Conflict Modeling (GitHub)
A place to gather and organize information about using threat modeling frameworks to deal with social conflict in online systems - adamshostack/conflictmodeling. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 270Articles
Conscious Business by Fred Kofman
Sitio Oficial de Fred Kofman, vicepresidente y asesor de desarrollo de liderazgo en Google, director del Centro de Liderazgo Consciente en Tecnológico de Monterrey, y fundador y presidente del Conscious Business Center International. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 271Articles
Consequence-driven Cyber-Informed Engineering (CCE)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 272Standards
Content Security Policy Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 273Books
Cooking for Geeks
Cooking for Geeks is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 274Articles
CORBA
CORBA is an open, vendor-independent architecture and infrastructure that computer applications use to work together over networks. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 275Books
Core Software Security
Core Software Security is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 276Projects
CrackQL
CrackQL is a GraphQL password brute-force and fuzzing utility. - nicholasaleks/CrackQL.
1 episodeVisit ↗ - 277Books
Critical System Thinking Book
Critical System Thinking Book is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 278Articles
Crossing The Chasm 3rd Edition Geoffrey A Moore
The bible for bringing cutting-edge products to larger markets is now revised and updated with new insights into the realities of high-tech marketing. With ...
1 episodeVisit ↗ - 279Articles
CSP is Dead, Long Live CSP (Google Research)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 280Standards
CVE-2017-5638
CVE-2017-5638 is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 281Standards
CWE-611
Common Weakness Enumeration (CWE) is a list of software weaknesses. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 282Articles
Cyber-Informed Engineering (INL)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 283Books
Cybersecurity First Principles: A Reboot of Strategy and Tactics
Cybersecurity First Principles: A Reboot of Strategy and Tactics [Howard, Rick] on Amazon. com.
1 episodeVisit ↗ - 284Articles
Cybersecurity Game Challenge
Build trust, shape a culture and kick start conversations. Physical games for in person threat modelling, training and fun.
1 episodeVisit ↗ - 285Projects
Damn Vulnerable GraphQL Application
Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security. - dolevf/Damn-Vulnerable-GraphQL-Application.
1 episodeVisit ↗ - 286Articles
DARPA Robotics Challenge
The DARPA Robotics Challenge (DRC) is a competition of robot systems and software teams vying to develop robots capable of assisting humans in responding to natural and man-made disasters. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 287Articles
Datadog State of Application Security report
We analyzed data from thousands of organizations to discover which vulnerabilities really matter, which threats present a risk, and other insights. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 288Articles
Dave Cheney: The Zen of Go
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 289Articles
Dave Kennedy
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 290Articles
David Habusha: Why did I join WhiteSource
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 291Articles
Designing Secure Software
An elegant, team-oriented guide for building security into the software design process. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 292Articles
Developers mentoring other developers: practices I've seen work well
How does mentoring work? I asked this question ten years into my software engineering career when I joined Uber.
1 episodeVisit ↗ - 293Books
DevSecOps Playbook (GitHub)
This is a step-by-step guide to implementing a DevSecOps program for any size organization - 6mile/DevSecOps-Playbook. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 294Projects
DevSecOps Studio
Virtual environment for learning DevSecOps. Contribute to secfigo/DevSecOps-Studio development by creating an account on GitHub.
1 episodeVisit ↗ - 295Articles
Difficult Conversations
Difficult Conversations, a New York Times best-seller by Douglas Stone & Sheila Heen, teaches effective communication skills & strategies for managing conflict. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 296Articles
Do Hard Things
A NATIONAL BESTSELLER \"In Do Hard Things, Steve Magness beautifully and persuasively reimagines our understanding of toughness. This is a must-read fo...
1 episodeVisit ↗ - 297Projects
DOMPurify
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks.
1 episodeVisit ↗ - 298Books
Drive
Drive is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 299Articles
DtSR Episode 204: On Changing Culture
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 300Articles
DZone: Introduction to DevSecOps
Learn key methods and techniques for implementing the DevSecOps methodology to ensure your cloud environments are secured effectively. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 301Articles
Effective Vulnerability Management by Chris Hughes
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 302Articles
Elastic (ELK) Stack
Reliably and securely take data from any source, in any format, then search, analyze, and visualize it in real time. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 303Articles
ENISA Securing Machine Learning Algorithms
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.
1 episodeVisit ↗ - 304Articles
Exploring container security
Exploring container security: This year, it’s all about security. Again.
1 episodeVisit ↗ - 305Books
Extreme Ownership
Looking for leadership courses? Online solutions help you learn key leadership principles on demand wherever you are.
1 episodeVisit ↗ - 306Projects
Faster Than Light (BugCatcher)
Faster Than Light has 14 repositories available. Follow their code on GitHub.
1 episodeVisit ↗ - 307Projects
Fennec.CLI
Fennec. NetCore - .
1 episodeVisit ↗ - 308Projects
Find the Document on the OWASP GitHub
OWASP API Security Project. Contribute to OWASP/API-Security development by creating an account on GitHub.
1 episodeVisit ↗ - 309Projects
FINOS Common Cloud Controls
View resources from FINOS Common Cloud Controls - an open standard project that describes consistent controls for compliant public cloud deployments in the financial services (FS) sector. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 310Projects
Flask
An open or collaborative project discussed on the podcast and hosted at flask. palletsprojects.
1 episodeVisit ↗ - 311Articles
FMCSA Hours of Service
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 312Books
Foundation by Isaac Asimov
Foundation [Asimov, Isaac] on Amazon. com.
1 episodeVisit ↗ - 313Standards
Framework
Align your product team and build products that people want to buy with Pragmatic's product management methodology. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 314Articles
Gene Hoffman
Gene Hoffman Chief Executive Officer and President Gene Hoffman has built and sold three companies to PGP, Inc. , Vivendi-Universal, and ...
1 episodeVisit ↗ - 315Articles
Gentoo GitHub Hack
News and information from Gentoo Linux. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 316Books
Georgia Weidman's book on penetration testing
Georgia Weidman wrote the book on pentesting. Literally.
1 episodeVisit ↗ - 317Articles
GIAC GWAPT
The GIAC Web Application Penetration Tester (GWAPT) certification validates a practitioner's ability to advance organization security through penetration testing and deep understanding of web application security issues. GWAPT certification holders are equipped with expertise in web application exploits and penetration testing methodology.
1 episodeVisit ↗ - 318Articles
GitGuardian State of Secrets Sprawl Report 2026
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 319Projects
GitHub
🧠 Socially Engineering LLMs 🤖 Hacking AI Agents 🦄 Node. js Secure Coding 🌟 @GitHub Star 🏅 @OpenJS Pathfinder award 4 Security 🥑 DevRel @snyksec - lirantal.
1 episodeVisit ↗ - 320Projects
GitHub
DJ is a DevOps pioneer and a security sommelier. djschleen has 34 repositories available.
1 episodeVisit ↗ - 321Articles
GitHub Octoverse
Insights into the state of open source on GitHub. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 322Projects
github/secure_headers
Manages application of security headers with many safe defaults - github/secure_headers. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 323Articles
Go html/template
Package template (html/template) implements data-driven templates for generating HTML output safe against code injection. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 324Standards
Goal Question Metric (GQM) framework
Goal Question Metric (GQM) framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 325Standards
Google Secure AI Framework (SAIF)
Building AI? Learn how to keep it secure with Google.
1 episodeVisit ↗ - 326Articles
Hackedu Acquires Security Journey
Combining content and experiments creates a platform that enhances learning for developers and product development professionals. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 327Books
Hacking Kubernetes (book)
Hacking Kubernetes (book) is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 328Articles
Hacking: The Art of Exploitation, Vol. 2
Hacking is creative problem solving: unconventional solutions, exploited weaknesses, and the technical foundation to pull it off. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 329Projects
hcltm (now threatcl) on GitHub
Documenting your Threat Models with HCL. Contribute to threatcl/threatcl development by creating an account on GitHub.
1 episodeVisit ↗ - 330Articles
Hi5
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 331Articles
Hi5signup
Read the Security Journey blog for expert insights on secure coding, application security trends, and developer-focused AppSec education. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 332Articles
How Leaders Create and Use Networks
Reprint: R0701C Most people acknowledge that networking—creating a fabric of personal contacts to provide support, feedback, insight, and resources—is an essential activity for an ambitious manager. Indeed, it’s a requirement even for those focused simply on doing their current jobs well.
1 episodeVisit ↗ - 333Articles
How to Measure Anything in Cybersecurity Risk, 2nd Edition
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 334Articles
HTTPS Everywhere (EFF)
You no longer need HTTPS Everywhere to set HTTPS by default! Major browsers now offer native support for an HTTPS only mode.
1 episodeVisit ↗ - 335Books
I Have No Mouth and I Must Scream
Amazon. com: I Have No Mouth & I Must Scream: 9781497643079: Ellison, Harlan: Books.
1 episodeVisit ↗ - 336Projects
iGoat Swift
OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS - OWASP/iGoat-Swift. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 337Articles
INCLUDES NO DIRT at Omada Health
INCLUDES NO DIRT: A Practical Threat Modeling Approach for Digital Healthcare and Beyond. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 338Articles
INCLUDES NO DIRT: A Practical Threat Modeling Approach for Digital Healthcare and Beyond
Omada - Resource Center Blog. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 339Communities
Information security needs community: 6 ways to build up your teams
Information security needs community: 6 ways to build up your teams is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 340Articles
InfoSec is Good People (Rob Graham)
For all that we complain about drama in our community, we are actually good people. At a small conference yesterday, I met "Kath".
1 episodeVisit ↗ - 341Articles
InfoSecSherpa
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 342Books
Intelligence Driven Incident Response
Intelligence Driven Incident Response is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 343Articles
Interest In Secure Design Practices Is Increasing Leading To Two Predictions
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 344Standards
Ipd
This NIST AI report develops a taxonomy of concepts and defines terminology in the field of adversarial machine learning (AML). The taxonomy is built on survey of the AML literature and is arranged in a conceptual hierarchy that includes key types of ML methods and lifecycle stage of attack, attacker goals and objectives, and attacker capabilities and knowledge of the learning process.
1 episodeVisit ↗ - 345Articles
iTextSharp
PLEASE NOTE: iTextSharp is EOL, and has been replaced by iText. Only security fixes will be added We HIGHLY recommend customers use iText for new projects, and to consider moving existing projects from...
1 episodeVisit ↗ - 346Projects
Java Observability Toolkit (JOT)
Java Observability Toolkit. Contribute to planetlevel/jot development by creating an account on GitHub.
1 episodeVisit ↗ - 347Articles
Jenga View of Threat Modeling whitepaper
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 348Projects
Jeremy Long on GitHub
Founder and project lead for dependency-check. jeremylong has 73 repositories available.
1 episodeVisit ↗ - 349Articles
Joe's Blog Post
HackEDU acquires Security Journey to create an industry-leading application security offering. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 350Projects
John Melton on GitHub
jtmelton has 15 repositories available. Follow their code on GitHub.
1 episodeVisit ↗ - 351Articles
John Willis
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 352Articles
Jon Callas
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 353Projects
Juice Shop source code
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application - juice-shop/juice-shop. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 354Books
Justin Rosenstein's original codemod on GitHub
Codemod is a tool/library to assist you with large-scale codebase refactors that can be partially automated but still require human oversight and occasional intervention. Codemod was developed at Facebook and released as open source.
1 episodeVisit ↗ - 355Articles
Kadrey v. Meta
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 356Articles
Kevin Greene on API security testing
Overcome software quality challenges & achieve continuous delivery at speed with Parasoft SOAtest, Virtualize, CTP, and DTP. Learn more!
1 episodeVisit ↗ - 357Articles
Kevin's article on Dark Reading
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 358Articles
KidzMash and the CodeMash experience
Part developer conference, part waterpark takeover. Deep technical sessions, hands-on workshops, the Makerspace, KidzMash, and 19 years of community.
1 episodeVisit ↗ - 359Articles
Latio's free reports
Compare 700+ cybersecurity tools and vendors with expert reviews, Latio scores, and AI-powered search. Find the right security tool for your stack.
1 episodeVisit ↗ - 360Projects
Lemur
Repository for the Lemur Certificate Manager. Contribute to Netflix/lemur development by creating an account on GitHub.
1 episodeVisit ↗ - 361Articles
Lex Fridman Podcast — Peter Steinberger on OpenClaw
Peter Steinberger is the creator of OpenClaw, an open-source AI agent framework that’s the fastest-growing project in GitHub history. Thank you for listening ❤ Check out our sponsors: https://lexfridman.
1 episodeVisit ↗ - 362Books
Life 3.0
Life 3. 0: Being Human in the Age of Artificial Intelligence [Tegmark, Max] on Amazon.
1 episodeVisit ↗ - 363Articles
LINDDUN research and publications
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 364Standards
LINQ to SQL
LINQ to SQL is a component of the . NET Framework that provides a runtime infrastructure for managing relational data as objects.
1 episodeVisit ↗ - 365Tools
lodash
lodash is a security tool or technical reference discussed on the podcast and available from npmjs. com.
1 episodeVisit ↗ - 366Books
Luna and the Magic AI Paintbrush
Amazon. com: Luna and the Magic AI Paintbrush: An AI Made Simple Book (Seriously Simple): 9789083414478: Schenk, Bessie, van der Veer, Rob, van Yperen, Mireille: Books.
1 episodeVisit ↗ - 367Books
Malware Analyst's Cookbook
Amazon. com: Malware Analyst.
1 episodeVisit ↗ - 368Articles
Mark Frost
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 369Communities
Mark Willis at RSA Conference
Mark Willis at RSA Conference is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 370Projects
Mark’s GitLab threat modeling article
As usual, we’re creating our own path in how we handle our threat modeling, approaching development both iteratively and collaboratively, and seriously shifting left with our framework and processes. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 371Books
Math Without Numbers
Buy Math Without Numbers on Amazon. com ✓ FREE SHIPPING on qualified orders.
1 episodeVisit ↗ - 372Articles
Matt Conover's "w00w00 on Heap Overflows"
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 373Articles
Maya's website
Maya Kaczorowski builds enterprise security tools that people actually want to use. Cofounder at Oblique, previously at Tailscale, GitHub, Google.
1 episodeVisit ↗ - 374Standards
Microsoft Responsible AI Standard, v2
Discover Microsoft AI tools, industry-specific governance solutions, and responsible AI practices to make smarter, more informed decisions about AI implementation. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 375Tools
Microsoft Safe C Library
An overview of secure CRT functions in the Microsoft C runtime. It provides a technical capability or reference that security practitioners can evaluate directly.
1 episodeVisit ↗ - 376Projects
Mike Goodwin on GitHub
mike-goodwin has 24 repositories available. Follow their code on GitHub.
1 episodeVisit ↗ - 377Projects
mike-goodwin/owasp-threat-dragon
An open source, online threat modelling tool from OWASP - mike-goodwin/owasp-threat-dragon. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 378Articles
Mitigating Risky Pull Requests With Monocle Risk Advisor Part 2 7013e1485bf2
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 379Projects
mitre-attack/attack-navigator
Web app that provides basic navigation and annotation of ATT&CK matrices - mitre-attack/attack-navigator. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 380Projects
Mono.Cecil
Cecil is a library to inspect, modify and create . NET programs and libraries.
1 episodeVisit ↗ - 381Articles
Monocle Part 1
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 382Standards
MOSAIC
MOSAIC is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 383Articles
Mozilla HTTP Observatory
Test your site’s HTTP headers, including CSP and HSTS, to find security problems and get actionable recommendations to make your website more secure. Test other websites to see how you compare.
1 episodeVisit ↗ - 384Articles
NASA Ingenuity Mars Helicopter
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 385Projects
Neil Smithline on GitHub
Appsec dude. OWASP Top-10 Co-Lead.
1 episodeVisit ↗ - 386Projects
Netflix Simian Army
Tools for keeping your cloud operating in top form. Chaos Monkey is a resiliency tool that helps applications tolerate random instance failures.
1 episodeVisit ↗ - 387Articles
NetWitness
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 388Books
Never Eat Alone
Keith Ferrazzi is an American entrepreneur and recognized global thought leader in the relational and collaborative sciences. As Chairman of Ferrazzi Greenlight and its Research Institute, he works to identify behaviors that block global organizations from reaching their goals and to transform them by coaching new behaviors that increase growth and shareholder value.
1 episodeVisit ↗ - 389Articles
Niels's blog
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 390Articles
Nimda
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 391Standards
NIST Digital Identity Guidelines
NIST Special Publication 800-63 Digital Identity Guidelines. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 392Standards
NIST OSCAL
NIST OSCAL is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 393Standards
NIST SP 800-190
Application container technologies, also known as containers, are a form of operating system virtualization combined with application software packaging. Containers provide a portable, reusable, and automatable way to package and run applications.
1 episodeVisit ↗ - 394Articles
NVIDIA NemoClaw
Agents are evolving from question-and-answer systems into long-running autonomous assistants that read files, call APIs, and drive multi-step workflows. However….
1 episodeVisit ↗ - 395Articles
NYDFS 23 NYCRR 500
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 396Articles
OECD AI Principles
OECD. AI helps countries and shape trustworthy AI with the OECD AI Principles.
1 episodeVisit ↗ - 397Projects
Omer Levi Hevroni on GitHub
Engineer @goledge , OSS maintainer and a proud father - omerlh. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 398Communities
Open Security Summit 2018 archive
Open Security Summit 2018 archive is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 399Articles
OpenAI Codex
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 400Projects
OpenClaw
The AI that really does things. Any OS.
1 episodeVisit ↗ - 401Projects
OpenVEX spec
OpenVEX Specification. Contribute to openvex/spec development by creating an account on GitHub.
1 episodeVisit ↗ - 402Articles
Operation ShadowHammer (Kaspersky)
Operation ShadowHammer is a newly discovered supply chain attack that leveraged ASUS Live Update software. While the investigation is still in progress and full results will be published during SAS 2019 conference, we would like to share some important details about the attack.
1 episodeVisit ↗ - 403Articles
OWASP Agentic Security Initiative
What’s New Resources Learning Videos Blog Download Now Download Now Download Now Download Now Download Now Download Now Project Audience – All Topics – Agentic Security More Events Audience – All Topics – Agentic Security More Training Audience – AI/Data Scientists, Developers, Practitioners Topics – Agentic Security More Events Audience – AI/Data Scientists, Architects, Developers, […]. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 404Projects
OWASP AISVS on GitHub
An open or collaborative project discussed on the podcast and hosted at github. com.
1 episodeVisit ↗ - 405Tools
OWASP AppSec Pipeline Toolbox
OWASP AppSec Pipeline Toolbox is a security tool or technical reference discussed on the podcast and available from appsecpipeline. org.
1 episodeVisit ↗ - 406Standards
OWASP Artificial Intelligence Security Verification Standard (AISVS)
OWASP Artificial Intelligence Security Verification Standard (AISVS) is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 407Communities
OWASP Bangalore
The OWASP Bangalore chapter is located in India and has been active since 2014, making it about 9 years old. It serves as a community for people interested in web security, offering public meetings that anyone can join without needing to be a member.
1 episodeVisit ↗ - 408Communities
OWASP Bay Area
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 409Communities
OWASP Bristol Chapter
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 410Communities
OWASP Chapters
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 411Projects
OWASP crAPI
completely ridiculous API (crAPI). Contribute to OWASP/crAPI development by creating an account on GitHub.
1 episodeVisit ↗ - 412Projects
OWASP Dependency-Check
Dependency-Check is a Software Composition Analysis (SCA) tool suite that identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 413Projects
OWASP Developer Guide
The Developer Guide provides an introduction to security concepts and an initial reference for application and system developers. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 414Articles
OWASP DevSecOps Guideline
OWASP Foundation Developer Guide project. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 415Projects
OWASP GenAI Security Project — Get Involved
T10 FOR GEN AI Project Contribute How to Contribute? The OWASP Top 10 for LLM Applications is an open source effort and we welcome all expert ideas, contributions, suggestions, and remarks.
1 episodeVisit ↗ - 416Communities
OWASP Global AppSec conferences
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 417Articles
OWASP Global AppSec USA 2026
Training Dates - November 2-4, 2026 / Conference Dates - November 5-6, 2026It's our 25th Anniversary year! Get ready for an unforgettable experience at the OWASP Global AppSec USA Conference!
1 episodeVisit ↗ - 418Articles
OWASP Global Board Candidates
OWASP Board of Directors election candidates. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 419Projects
OWASP Glue source code
Application Security Automation. Contribute to OWASP/glue development by creating an account on GitHub.
1 episodeVisit ↗ - 420Projects
OWASP iGoat
OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar - OWASP/igoat. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 421Communities
OWASP Israel
OWASP Israel is a large chapter that has been active for several years. It focuses on improving software security through various activities, including frequent meetings and organizing the AppSec Israel conference, with the next one scheduled for May 2025.
1 episodeVisit ↗ - 422Standards
OWASP Logging Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 423Communities
OWASP Maine
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 424Communities
OWASP Montreal
The Montreal Chapter has been active for several years and is part of a larger non-profit organization focused on improving cybersecurity. This chapter is open to everyone, and you do not need to be a member to attend their meetings.
1 episodeVisit ↗ - 425Projects
OWASP Secure Headers Project
The OWASP Secure Headers Project (OSHP) describes HTTP response headers that your application can use to increase the security of your application. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 426Projects
OWASP Security Shepherd
OWASP Security Shepherd is a web and mobile application security training platform. Security Shepherd has been designed to foster and improve security awareness among a varied skill-set demographic.
1 episodeVisit ↗ - 427Projects
OWASP Threat Model Library
OWASP Threat Model Library - An OWASP incubator project. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 428Standards
OWASP Top 10:2021
OWASP Top 10:2021 is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 429Standards
OWASP Top 10:2025
OWASP Top 10:2025. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 430Standards
OWASP Top 10:2025
OWASP Top 10:2025. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 431Communities
OWASP Triangle
The Triangle-North Carolina chapter of OWASP has been active for a while, fostering a community focused on web application security. It is led by Chris Romeo and Steve Pinkham, who keep members updated through platforms like Meetup and Twitter.
1 episodeVisit ↗ - 432Projects
OWASP WrongSecrets project
Examples with how to not use secrets. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 433Standards
OWASP XXE Prevention Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 434Articles
PASTA threat modeling
PASTA threat modeling explained: the risk-centric, 7-stage methodology co-created by VerSprite's CEO to simulate real attacks and prioritize business risk. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 435Articles
PBKDF2 (RFC 2898)
This document provides recommendations for the implementation of password-based cryptography, covering key derivation functions, encryption schemes, message-authentication schemes, and ASN. 1 syntax identifying the techniques.
1 episodeVisit ↗ - 436Books
People-Centric Security
People-Centric Security: Transforming Your Enterprise Security Culture: 9780071846776: Computer Science Books @ Amazon. com.
1 episodeVisit ↗ - 437Articles
Peter Checkland
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 438Projects
Peter Steinberger
Came back from retirement to mess with AI. Clawdfather @OpenClaw Previously: Founder of @PSPDFKit.
1 episodeVisit ↗ - 439Articles
Phantoms in the Brain: Probing the Mysteries of the Human Mind
Neuroscientist V. S.
1 episodeVisit ↗ - 440Articles
Phantoms in the Brain: Probing the Mysteries of the Human Mind
Neuroscientist V. S.
1 episodeVisit ↗ - 441Projects
Poutine
poutine, a supply chain vulnerability scanner for build pipelines - boostsecurityio/poutine. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 442Courses
Press Release: HackEDU Acquires Security Journey
Press Release: HackEDU Acquires Security Journey is a course, workshop, or training resource mentioned in episode show notes. It provides structured security learning or training material.
1 episodeVisit ↗ - 443Standards
PSIRT Services Framework (FIRST.org)
PSIRT Services Framework (FIRST. org) is a security standard, framework, or guidance reference discussed on the podcast.
1 episodeVisit ↗ - 444Standards
Purple Team Exercise Framework
Purple Team Exercise Framework. Contribute to scythe-io/purple-team-exercise-framework development by creating an account on GitHub.
1 episodeVisit ↗ - 445Articles
Pwning OWASP Juice Shop
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 446Projects
pytm GitHub page
A Pythonic framework for threat modeling. Contribute to izar/pytm development by creating an account on GitHub.
1 episodeVisit ↗ - 447Articles
Qualys Web Application Scanning
Qualys Web App Scanning security software and tools deliver automated vulnerability detection and continuous monitoring to protect your web applications from emerging threats. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 448Books
Quiet Influence
Quiet Influence is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 449Articles
Rails security guide
This guide describes common security problems in web applications and how to avoid them with Rails. After reading this guide, you will know: How to use the built-in authentication generator.
1 episodeVisit ↗ - 450Articles
Rakuten: Democratizing AppSec
Three of Rakuten’s cyber security professionals contributed topics on the theme of AppSec democratization at the OWASP 2022 Global AppSec APAC Conference. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 451Projects
Rapid Threat Model Prototyping documentation
This repository stores content that can be used to design a Rapid Threat Model Prototyping process for a software development group. - geoffrey-hill-tutamantic/rapid-threat-model-prototyping-docs.
1 episodeVisit ↗ - 452Articles
Rapid Threat Model Prototyping slides
Threat Modelling can be a laborious and time-consuming exercise, and is not a happy marriage with CI/DevOps methodologies. Introducing my Rapid Thre….
1 episodeVisit ↗ - 453Projects
Reaper
Live validation proxy tool for testing web app vulnerabilities - ghostsecurity/reaper. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 454Articles
Redefining Threat Modeling (Segment blog)
Explore technical topics, solutions, and resources for building with Twilio – and beyond. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 455Books
Ref=Sr 1 1
Building in Security at Agile Speed [Ransome, James, Schoenfield, Brook] on Amazon. com.
1 episodeVisit ↗ - 456Articles
Reflections on Trusting Trust
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 457Articles
Rekor (Sigstore)
The Rekor overview. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 458Articles
Release It! (2nd ed.)
Design your application for maximum uptime, performance, and return on investment in the face of the harsh realities of the real world. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 459Books
Ringworld by Larry Niven
Ringworld by Larry Niven is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 460Articles
Robert’s threat modeling resources
What kind of security threats are lurking in your software or business? You need threat modeling!
1 episodeVisit ↗ - 461Articles
Ronnie's blog
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 462Articles
Royal Holloway Information Security
Find out about our leading MSc degree, the world's oldest degree in information and cyber security. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 463Articles
S&P Global Ratings
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 464Articles
Saltzer and Schroeder: "The Protection of Information in Computer Systems"
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 465Articles
SARIF
This document defines SARIF, a standard format for the output of static analysis tools. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 466Articles
Scott Hanselman: Overposting/Mass Assignment
This little post is just a reminder that while Model Binding in ASP. NET is very ...
1 episodeVisit ↗ - 467Articles
Sean Wright’s blog
Personal blog of application security advocate, blogging about application security related topics, focused primarily on web based applications. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 468Articles
Secrets management deployment guidance
In a previous blog we talked about secure deployment. Secrets management is an important part of that.
1 episodeVisit ↗ - 469Articles
Secure Decisions
What's In The Name? We create the technologies that help you make sense of your security data.
1 episodeVisit ↗ - 470Books
Secure, Resilient, and Agile Software Development
Secure, Resilient, and Agile Software Development [Merkow, Mark] on Amazon. com.
1 episodeVisit ↗ - 471Articles
Securing Systems: Applied Security Architecture and Threat Models
Securing Systems: Applied Security Architecture and Threat Models [Schoenfield, Brook S. E.
1 episodeVisit ↗ - 472Books
Security Assurance Using the Common Criteria
Computer Security Assurance: 9781401862657: Computer Science Books @ Amazon. com.
1 episodeVisit ↗ - 473Articles
Security Coaches episode page
Security programs improve when developers have someone who can help them want to get better, not merely tell them what they did wrong. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 474Articles
Security Engineering by Ross Anderson
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 475Articles
Security in Computing
Search. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 476Projects
Security Monkey
Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time. - Netflix/security_monkey.
1 episodeVisit ↗ - 477Courses
segmentio/threat-modeling-training
Segment's Threat Modeling training for our engineers - segmentio/threat-modeling-training. It provides structured security learning or training material.
1 episodeVisit ↗ - 478Books
Seveneves by Neal Stephenson
Seveneves: A Novel [Stephenson, Neal] on Amazon. com.
1 episodeVisit ↗ - 479Articles
Shifting Engineering Right: What security engineers can learn from DevSecOps
The security industry generally agrees on the value of enabling developers in an agile environment—although we don’t agree on what to call it… “Shifting Left,” “Creating a Paved Path,” “DevSecOps.” Regardless of the name, we tend to focus on teaching developers how to Sec, but there’s less focus on security engineers learning how to Dev.
1 episodeVisit ↗ - 480Articles
Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano)
slides - The slides for the talks I've presented at various conferences and events (see https://www. lisihocke.
1 episodeVisit ↗ - 481Articles
SOAP 1.2 (W3C)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 482Books
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
Amazon. com: Software Transparency: Supply Chain Security in an Era of a Software-Driven Society: 9781394158485: Hughes, Chris, Turner, Tony, Springett, Steve, Friedman, Allan: Books.
1 episodeVisit ↗ - 483Articles
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 484Articles
Solve for Happy by Mo Gawdat
Discover the equation for happiness in this international bestseller. Solve for Happy is a startlingly original book about creating and maintaining happiness….
1 episodeVisit ↗ - 485Articles
SQL Slammer
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 486Projects
SSLyze
Fast and powerful SSL/TLS scanning library. Contribute to nabla-c0d3/sslyze development by creating an account on GitHub.
1 episodeVisit ↗ - 487Projects
Stackless Python
The Stackless Python programming language. Contribute to stackless-dev/stackless development by creating an account on GitHub.
1 episodeVisit ↗ - 488Articles
Stephen E Ambrose
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 489Articles
Systems Thinking for Curious Managers by Russell Ackoff
details of Triarchy. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 490Articles
TeamCity
TeamCity keeps your delivery reliable, repeatable, and under control for both the humans and AI agents on your team. Sign up now.
1 episodeVisit ↗ - 491Articles
Techstars London
Our London programs catalyse emerging startups from all over the world, across all verticals, leveraging the city's strengths in diversity, global outlook and talent. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 492Books
The AI Cybersecurity Handbook
The AI Cybersecurity Handbook [Wong, Caroline] on Amazon. com.
1 episodeVisit ↗ - 493Articles
The Alignment Problem
The Alignment Problem: Machine Learning and Human Values. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 494Books
The Black Swan by Nassim Nicholas Taleb
NEW YORK TIMES BESTSELLER • The most influential book of the past seventy-five years: a groundbreaking exploration of everything we know about what... It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 495Books
The Body Keeps the Score
#1 New York Times bestseller “Essential reading for anyone interested in understanding and treating traumatic stress and the scope of its impact... It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 496Articles
The Checklist Manifesto: How to Get Things Right
The Checklist Manifesto: How to Get Things Right [Gawande, Atul] on Amazon. com.
1 episodeVisit ↗ - 497Books
The Crown Road by Iain Banks
The Crow Road [Iain Banks] on Amazon. com.
1 episodeVisit ↗ - 498Books
The Cuckoo’s Egg by Clifford Stoll
The Cuckoo’s Egg by Clifford Stoll is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 499Articles
The Ethical Algorithm 9780190948207
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 500Books
The Fifth Discipline
The Fifth Discipline: The Art & Practice of The Learning Organization [Senge, Peter M. ] on Amazon.
1 episodeVisit ↗ - 501Articles
The Hard Thing About Hard Things Ben Horowitz
Ben Horowitz, cofounder of the venture capital firm Andreessen Horowitz and one of Silicon Valley’s most respected and experienced entrepreneurs, offers ess... It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 502Articles
The Hedge episode 048
Chris Romeo is a famous application security expert who has spent the last several years building a consulting and training company called Security Journey. Chris joins Tom and Russ to talk about the state of security and what network engineers need to know about security from an application perspective.
1 episodeVisit ↗ - 503Articles
The Metrics Manifesto by Richard Seiersen
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 504Articles
The Power of Habit by Charles Duhigg
Discover 'The Power of Habit' by Charles Duhigg and learn how to transform your habits to improve your personal and professional life. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 505Articles
The Register (Security)
Latest news and insight on information security and IT defenses. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 506Books
The Rust Programming Language
The Rust Programming Language is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 507Books
The Web Application Hacker's Handbook
For over a decade, The Web Application Hacker's Handbook (WAHH) has been the de facto standard reference book for people who are learning about web ... It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 508Books
Thinking Fast and Slow
*Major New York Times Bestseller*More than 2. 6 million copies sold*One of The New York Times Book Review's ten best books of the year*Selected by The Wall St...
1 episodeVisit ↗ - 509Standards
thomasrbsa/BSA-Framework-for-Secure-Software
The BSA Framework for Secure Software is a new tool to describe and assess security outcomes for software products and services, built on established best practices and the experiences of some of the world's leading software developers. The Framework is a living document that will be updated based on feedback from the Github community and other stakeholders.
1 episodeVisit ↗ - 510Projects
Threat Dragon source code
An open source threat modeling tool from OWASP. Contribute to OWASP/threat-dragon development by creating an account on GitHub.
1 episodeVisit ↗ - 511Books
Threat Modeling (Adam Shostack)
Updated techniques for predicting and preventing security problems before a single line of code is written by you (or by an agent). Get proven, jargon-free threat modeling frameworks for an AI world from Adam Shostack.
1 episodeVisit ↗ - 512Articles
Threat Modeling Gameplay with EoP
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 513Articles
Threat Modeling of Threat Modeling
How can we make threat modeling a success? Read the analysis!
1 episodeVisit ↗ - 514Books
Threat Modeling: A Practical Guide for Development Teams
Threat Modeling: A Practical Guide for Development Teams is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 515Articles
Threat Modeling: Designing for Security
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 516Articles
Threat Modeling: Designing for Security — first edition
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 517Books
Threat Playbook
A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration - we45/ThreatPlaybook. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 518Articles
Tim Newsham's "Format String Attacks"
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 519Articles
TippingPoint (Trend Micro)
More than an Intrusion Prevention System (IPS), Trend Micro's TippingPoint™ Protection System integrates with Trend Vision One. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 520Standards
tj-actions/changed-files advisory (CVE-2025-30066)
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
1 episodeVisit ↗ - 521Articles
Toastmasters International
Thrive with new confidence by developing essential communication and leadership skills. Join our global community of 270,000+ professionals and unlock your full potential.
1 episodeVisit ↗ - 522Communities
Tommy Ross at RSA Conference
Tommy Ross at RSA Conference is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 523Standards
Top 10 CI/CD Security Risks
Contribute to cider-security-research/top-10-cicd-security-risks development by creating an account on GitHub. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 524Books
Understanding Complexity
Audiobook by Scott E. Page, The Great Courses, narrated by Scott E.
1 episodeVisit ↗ - 525Articles
UNESCO Recommendation on the Ethics of Artificial Intelligence
UNESCO is committed to a future where AI and emerging technologies work for the people. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 526Projects
uutils/coreutils
Cross-platform Rust rewrite of the GNU coreutils. Contribute to uutils/coreutils development by creating an account on GitHub.
1 episodeVisit ↗ - 527Standards
Veilid Application Framework
Veilid is an open-source, distributed application framework. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 528Projects
Venom (OVH)
🐍 Manage and run your integration tests with efficiency - Venom run executors (script, HTTP Request, web, imap, etc... ) and assertions - ovh/venom.
1 episodeVisit ↗ - 529Articles
Venture in Security: solving the circle sticker problem
Cybersecurity's circle stickers in a square box problem, how it's shaping the industry, and where we can go from here. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 530Projects
Visualizing the Software Supply Chain (GitHub)
A project to visualize the software supply chain. Contribute to SecureStackCo/visualizing-software-supply-chain development by creating an account on GitHub.
1 episodeVisit ↗ - 531Communities
Volatility
The Volatility Framework has become the world’s most widely used memory forensics tool. The Volatility Foundation helps keep Volatility going so that it may be used in perpetuity, free and open to all.
1 episodeVisit ↗ - 532Articles
Walter Isaacson
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 533Articles
Ward Cunningham
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 534Books
Watkins
Named one of 100 Leadership & Success Books to Read in a Lifetime by Amazon Editors The world's most trusted guide for leaders in transition. Transit….
1 episodeVisit ↗ - 535Articles
Web Application Penetration Testing — Part 2
Part two follows Daniel Ramsbrock into the practical workflow of a web application penetration test. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 536Articles
Werner Dietl
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 537Articles
What is Art by Leo Tolstoy
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 538Articles
Wiring the Winning Organization
Drawing on decades of meticulous research of high-performing organizations and cross-population surveys of tens of thousands of employees, award-winning authors Gene Kim and Dr. Steven J.
1 episodeVisit ↗ - 539Books
With the Old Breed by E.B. Sledge
NEW YORK TIMES BESTSELLER • “Of all the books about the ground war in the Pacific, [this] is the closest to a masterpiece.” —The...
1 episodeVisit ↗ - 540Articles
Women4Cyber Mentorship Programme
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 541Projects
WrongSecrets on GitHub
Vulnerable app with examples showing how to not use secrets - commjoen/wrongsecrets. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 542Projects
WrongSecrets on GitHub
Vulnerable app with examples showing how to not use secrets - OWASP/wrongsecrets. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 543Projects
Yoann Padioleau
I like to code and do research on stuff to make it easier to code stuff - aryx. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 544Tools
ZAP API documentation
ZAP API documentation is a security tool or technical reference discussed on the podcast and available from zaproxy. org.
1 episodeVisit ↗ - 545Articles
Zen of Python (PEP 20)
Long time Pythoneer Tim Peters succinctly channels the BDFL’s guiding principles for Python’s design into 20 aphorisms, only 19 of which have been written down. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗