OWASP Candidate Debate - 2025 Edition
What should OWASP become, and which leaders have a credible plan to get it there? In this special 2025 Board of Directors candidate debate, nine candidates…
Listen to the episodeTopic
The tools and standards that come out of OWASP — ZAP, ASVS, SAMM, Juice Shop, the Cheat Sheets, and the people who build them.
What should OWASP become, and which leaders have a credible plan to get it there? In this special 2025 Board of Directors candidate debate, nine candidates…
Listen to the episodeSteve Springett, an expert in secure software development and a key figure in several OWASP projects is back. Steve unpacks CycloneDX and the value proposition of various BOMs.
Listen to the episodeZAP supports an enormous share of the application security ecosystem, but who pays for the people keeping it reliable?
Listen to the episodeBjorn Kimminich, the driving force behind the OWASP Juice Shop project, joins Chris and Robert to discuss all things Juice Shop.
Listen to the episodeSix candidates for the 2023 OWASP Board of Directors debate the choices that shape the foundation and its community.
Listen to the episodeDevelopment, operations, and security teams generate oceans of data yet still struggle to answer basic questions about what code is running, who owns it, and which findings matter.
Listen to the episodeKevin Johnson is the CEO of Secure Ideas. He began his career as a developer but turned toward security when he discovered that the interface for an intrusion detection system, Snort, was out of date.
Listen to the episodeMark Curphey is one of the creators of OWASP from the very early days. Mark worked in the background over the few decades of OWASP but has recently taken more to the spotlight.
Listen to the episodeTiago Mendo is a co-founder and CTO of Probely. He has extensive experience in pentesting applications, training, and providing all-around security consultancy.
Listen to the episodeDominique Righetto is an AppSec enthusiast and OWASP projects contributor. Dominique joins us to discuss the OWASP Secure Headers project.
Listen to the episodePatrick is a Senior Product Security Engineer in the Application Security team at ServiceNow. He is also Co-Leader of the OWASP CycloneDX project.
Listen to the episodeSimon Bennetts is the OWASP Zed Attack Proxy (ZAP) Project Leader and a Distinguished Engineer at StackHawk, a company that uses ZAP to help users fix…
Listen to the episodeTimo Pagel has been in the IT industry for over fifteen years. After a system administrator and web developer career, he advises customers as a DevSecOps consultant and trainer.
Listen to the episodeVandana Verma is the President of Infosec girls and Infosec Kids, a board of directors member for OWASP, and a leader for BSides Dehli. She joins us to introduce the OWASP Spotlight Series.
Listen to the episodeSoftware bills of materials promise visibility into dependencies, but visibility alone does not create assurance.
Listen to the episodeElie Saad is an application security engineer, leading three different OWASP projects.
Listen to the episodeJannik Hollenbach is a Security Automation Engineer at iteratec GmbH, working on and with open source security testing tools to continuously detect security…
Listen to the episodeHow does an organization improve software security without reducing maturity to a checklist?
Listen to the episodeHow do you discover vulnerable libraries when the names developers use do not match the names in vulnerability databases?
Listen to the episodeSeason 5 covered application security from tools and threat models to mentoring, self-care, coaching, dependency risk, and program design.
Listen to the episodeAn SCA tool can find vulnerable libraries and still leave important software supply-chain questions unanswered.
Listen to the episodeWhat does OWASP Dependency-Track add beyond a conventional software composition analysis scanner?
Listen to the episodeHow do you keep an intentionally vulnerable application useful while its underlying frameworks keep fixing bugs?
Listen to the episodeWhat makes OWASP Juice Shop useful to developers when many intentionally vulnerable applications feel dated?
Listen to the episodeHow does an intentionally vulnerable application become a community learning movement?
Listen to the episodeHow do you make a powerful security testing tool approachable to the developers who need it?
Listen to the episodeDevelopers need useful findings in their workflow, not another collection of security tools to operate by hand.
Listen to the episodeOWASP became a reference point for software security, but it began with people sharing knowledge and trying to solve problems together.
Listen to the episodeCan an intentionally broken online shop help change an organization’s security culture?
Listen to the episodeMobile apps can hide credentials, expose powerful backend access, and repeat familiar web security mistakes.
Listen to the episodeA JavaScript library can keep working long after its security problems become public.
Listen to the episodeHow can a small AppSec team make sense of thousands of applications and a growing pile of security work?
Listen to the episodeWhat developers need from a threat model is often a clear set of requirements they can implement.
Listen to the episodeHow can one open-source rule set protect applications across competing products and very different architectures?
Listen to the episodeWhich practices belong in a complete application security program? The Season 3 finale answers by assembling clips that move from early development…
Listen to the episodeOWASP is widely recognized, but do people understand the community behind its famous Top 10?
Listen to the episodeYour application knows when a user does something that should be impossible, but does that knowledge help stop an attack?
Listen to the episodeFinding a vulnerable library in one build is only the beginning: how do you find every affected application across an organization?
Listen to the episodeDevelopers need concrete security answers, but finding trustworthy guidance can take longer than writing the code.
Listen to the episodeA web application firewall can buy time during a vulnerability crisis, but only if somebody understands and maintains its rules.
Listen to the episodeWhere should the OWASP Proactive Controls go after giving developers a concise defensive counterpart to the Top 10?
Listen to the episodeHow should the OWASP Top 10 balance data, expert judgment, community feedback, and a format people can actually use?
Listen to the episodeAPIs may lack a visible interface, but that does not make them hidden or safe. Tanya Janca and Nicole Becher use OWASP DevSlop and its Pixi application to…
Listen to the episodeDevelopers hear plenty about vulnerabilities, but what should they actually build into their applications to prevent them?
Listen to the episodeHow can developers turn OWASP’s many projects into practical help with the code they write?
Listen to the episodeThreat modeling is easier to adopt when its tools fit the way developers already work.
Listen to the episode