AI Pen Testing Killed Traditional DAST
Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started.
Listen to the episodeTopic
Containers, Kubernetes, infrastructure as code and the misconfigurations that make cloud its own discipline.
Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started.
Listen to the episodeMatin Mavaddat discusses his perspective on security as a systemic concern, developed from his background in requirements engineering and systems architecture.
Listen to the episodeFrançois Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain.
Listen to the episodeTanya Janka, also known as SheHacksPurple, discusses secure guardrails, the difference between guardrails and paved roads, and how to implement both in application security.
Listen to the episodeHasan Yasar believes that everyone shares the responsibility of creating a secure environment, and this can only be achieved by working collaboratively.
Listen to the episodeItzik Alvas, Co-founder and CEO of Entro, is an expert on secrets security. Itzik joins Chris and Robert to discuss the significance of understanding and…
Listen to the episodeDevelopment, operations, and security teams generate oceans of data yet still struggle to answer basic questions about what code is running, who owns it, and which findings matter.
Listen to the episodeCloud security is on an evolutionary path, with newer platforms embracing secure-by-default settings.
Listen to the episodeChristian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built.
Listen to the episodeCI/CD systems hold code, credentials, and production access, yet many organizations still treat them as internal plumbing rather than a critical attack surface.
Listen to the episodeJosh Grossman has over 15 years of experience in IT Risk and Application Security consulting, and he has also worked as a software developer.
Listen to the episodeWill Ratner is a software security professional with extensive experience building and implementing security solutions across a myriad of industries…
Listen to the episodeSecrets management fails in surprisingly ordinary ways: credentials land in code, deployment files, containers, and cloud resources, then quietly become part of the system’s attack surface.
Listen to the episodeInfrastructure as code gives security teams something they have wanted for years: a readable description of the systems surrounding an application.
Listen to the episodeMazin Ahmed is a security engineer that specializes in AppSec and offensive security.
Listen to the episodeJeroen Willemsen is a Principal Security Architect at Xebia. Jeroen is more or less a jack of all trades with an interest in infrastructure security, risk management, and application security.
Listen to the episodeAaron Rinehart is expanding the possibilities of chaos engineering to cybersecurity.
Listen to the episodeAlyssa Miller is a life-long hacker, security advocate, and cybersecurity leader. She is the BISO for S&P Global ratings and has over 15 years of experience in security roles.
Listen to the episodeCloud-native development gives engineers control over more of the stack, but it also gives them more security decisions to get wrong.
Listen to the episodeAaron Davis is a founder, dev, and a lead security researcher at MetaMask, a popular Ethereum wallet.
Listen to the episodeOchaun Marshall is a developer and security consultant. In his roles at Secure Ideas, he works on ongoing development projects utilizing Amazon Web Services and breaks other people's web applications.
Listen to the episodeJannik Hollenbach is a Security Automation Engineer at iteratec GmbH, working on and with open source security testing tools to continuously detect security…
Listen to the episodeSeason six closes by revisiting five conversations that capture the breadth of application security.
Listen to the episodeWhat changes when security becomes part of delivering software instead of a separate gate?
Listen to the episodeHow much behavior do you inherit when you add one library to a .NET application? Niels Tanis joins Chris and Robert to examine third-party risk beyond checking a dependency for known vulnerabilities.
Listen to the episodeContainers can improve your security story, but not simply because they are called containers.
Listen to the episodeDevelopers may want to own security, but what helps them turn that intention into safer software? Liran Tal joins Chris and Robert to examine Snyk's 2019 State of Open Source Security research.
Listen to the episodePutting an application in Kubernetes does not solve the problem of getting secrets to it safely.
Listen to the episodeMoving an application to Azure changes which security controls you operate yourself and which ones the platform can provide.
Listen to the episodeMobile apps can hide credentials, expose powerful backend access, and repeat familiar web security mistakes.
Listen to the episodeA list of weaknesses is not the same thing as an understanding of the threats facing a business.
Listen to the episodeLearning DevSecOps is hard when setting up the lab becomes a project of its own. Mohammed Imran introduces DevSecOps Studio, an environment designed to help…
Listen to the episodeWhere does application security end when software controls bootloaders, firmware, processors, and connected devices?
Listen to the episodeContainers make deployment repeatable, but insecure images, excessive privileges, and unmanaged secrets can travel with them.
Listen to the episodeAPIs may lack a visible interface, but that does not make them hidden or safe. Tanya Janca and Nicole Becher use OWASP DevSlop and its Pixi application to…
Listen to the episodeDoes moving an application into Docker make it safer, or simply change the risks you need to manage?
Listen to the episode