José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists
Why do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling?
Listen to the episodeTopic
The list that most organisations meet first, how each revision was assembled, and what it is and is not good for.
Why do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling?
Listen to the episodeGitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse?
Listen to the episodeOpenClaw makes always-on personal AI agents feel inevitable—and exposes how poorly prepared most organizations are for their autonomy.
Listen to the episodeAPIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization.
Listen to the episodeWe’re discussing the intersections of application security (AppSec) and sales strategy with our guest, Sean Varga.
Listen to the episodeHenrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies.
Listen to the episodeAndrew Van Der Stok, a leading web application security specialist and executive director at OWASP joins us for this episode.
Listen to the episodeZAP supports an enormous share of the application security ecosystem, but who pays for the people keeping it reliable?
Listen to the episodeThe first OWASP Top 10 for Large Language Model Applications gave developers and security teams a shared threat model for a rapidly changing technology.
Listen to the episodeHow do we do security in the world of AI and LLMs? A great place to start is with an OWASP project tasked with creating a standardized guideline for…
Listen to the episodeJet Anderson's passion is teaching today's software developers to write secure code as part of modern DevOps pipelines, at speed and scale, without missing a beat.
Listen to the episodeMichael Bargury is the Co-Founder and CTO of Zenity, where he helps companies secure their low-code/no-code apps.
Listen to the episodeMark Curphey is one of the creators of OWASP from the very early days. Mark worked in the background over the few decades of OWASP but has recently taken more to the spotlight.
Listen to the episodeCI/CD systems hold code, credentials, and production access, yet many organizations still treat them as internal plumbing rather than a critical attack surface.
Listen to the episodeSimon Bennetts is the OWASP Zed Attack Proxy (ZAP) Project Leader and a Distinguished Engineer at StackHawk, a company that uses ZAP to help users fix…
Listen to the episodeChris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams.
Listen to the episodeSoftware security has spent decades alternating between prevention, detection, and response. Kevin Greene joins Chris and Robert to ask what a balanced approach should look like now.
Listen to the episodeRuby on Rails can provide strong security defaults, but a framework cannot make every design decision for its developers.
Listen to the episodeMichael Furman is the Lead Security Architect at Tufin, and is responsible for the security and Security Development Lifecycle (SDL) of Tufin software products.
Listen to the episodeWhy did APIs need a security Top 10 of their own? Erez Yalon joins Chris and Robert to explain the gaps that led to the OWASP API Security project and walk through its original 2019 list.
Listen to the episodeHow do you make a powerful security testing tool approachable to the developers who need it?
Listen to the episodeAn IoT product’s attack surface extends well beyond the device in the box. Daniel Miessler explains that broader view while walking Chris and Robert through the 2018 OWASP IoT Top 10.
Listen to the episodeChanging security culture requires more than distributing policies or buying another training platform.
Listen to the episodeOWASP became a reference point for software security, but it began with people sharing knowledge and trying to solve problems together.
Listen to the episodeHow can application security become a field where more women enter, contribute, and advance?
Listen to the episodeOWASP is widely recognized, but do people understand the community behind its famous Top 10?
Listen to the episodeHow do you turn a security requirement into something a development team can build and test?
Listen to the episodeAn application can inherit serious vulnerabilities from code its developers never wrote.
Listen to the episodeA log file does little good if nobody can use it to detect or investigate an attack.
Listen to the episodeA feature built into XML processing can become a path to file disclosure, internal requests, or denial of service.
Listen to the episodeWhat happens when data arriving at an application is allowed to recreate objects and trigger unexpected behavior?
Listen to the episodeWhy does OWASP matter beyond its famous Top 10 list? The Season 2 finale revisits guests who demonstrate the breadth of the foundation’s work.
Listen to the episodeA web application firewall can buy time during a vulnerability crisis, but only if somebody understands and maintains its rules.
Listen to the episodeWhere should the OWASP Proactive Controls go after giving developers a concise defensive counterpart to the Top 10?
Listen to the episodeHow should the OWASP Top 10 balance data, expert judgment, community feedback, and a format people can actually use?
Listen to the episodeAgile delivery promises fast feedback, but where does application security fit when teams are already moving continuously?
Listen to the episodeWhat can practitioners learn from a new OWASP document, an upcoming conference, and an industry analyst report in one conversation?
Listen to the episodeDevelopers hear plenty about vulnerabilities, but what should they actually build into their applications to prevent them?
Listen to the episodeHow can developers turn OWASP’s many projects into practical help with the code they write?
Listen to the episodeWhy did the 2017 OWASP Top 10 release candidate provoke such a strong reaction? Chris and Robert walk through the proposed categories, compare them with…
Listen to the episodeIn the inaugural episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut introduce themselves, trace the experiences that brought them…
Listen to the episode