Isaac Evans - AppSec in the Age of AI
AI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it?
Listen to the episodeTopic
Dependencies, SBOMs, provenance and the long tail of open source that ships inside everything.
AI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it?
Listen to the episodeWhy do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling?
Listen to the episodeWhat should OWASP become, and which leaders have a credible plan to get it there? In this special 2025 Board of Directors candidate debate, nine candidates…
Listen to the episodeThe EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe.
Listen to the episodeHenrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies.
Listen to the episodeFrançois Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain.
Listen to the episodeSteve Springett, an expert in secure software development and a key figure in several OWASP projects is back. Steve unpacks CycloneDX and the value proposition of various BOMs.
Listen to the episodeMatt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec.
Listen to the episodeJames Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security.
Listen to the episodeZAP supports an enormous share of the application security ecosystem, but who pays for the people keeping it reliable?
Listen to the episodeKyle Kelly joins Chris to explore the wild west of software supply chain security.
Listen to the episodeChris Hughes, co-founder of Aquia, joins Chris and Robert on the Application Security Podcast to discuss points from his recent book Software Transparency:…
Listen to the episodeChris John Riley joins Chris and Robert to discuss the Minimum Viable Secure Product. MVSP is a minimalistic security checklist for B2B software and business process outsourcing suppliers.
Listen to the episodeThe first OWASP Top 10 for Large Language Model Applications gave developers and security teams a shared threat model for a rapidly changing technology.
Listen to the episodeHasan Yasar believes that everyone shares the responsibility of creating a secure environment, and this can only be achieved by working collaboratively.
Listen to the episodeVarun Badhwar is a three-time founder, a luminary in the cyber security industry, and a clear communicator.
Listen to the episodeDevelopment, operations, and security teams generate oceans of data yet still struggle to answer basic questions about what code is running, who owns it, and which findings matter.
Listen to the episodeKevin Johnson is the CEO of Secure Ideas. He began his career as a developer but turned toward security when he discovered that the interface for an intrusion detection system, Snort, was out of date.
Listen to the episodeCloud security is on an evolutionary path, with newer platforms embracing secure-by-default settings.
Listen to the episode"Visualizing the Software Supply Chain" is a project which aims to kick off a discussion about the scope and breadth of the software supply chain.
Listen to the episodeSoftware supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole.
Listen to the episodeWhat is the state of application security? JB Aviat answered that question by creating the state of application security report based on data from Datadog…
Listen to the episodeHave you ever considered using an SBOM to inform your threat modeling? Tony Turner has. Tony joins us to discuss SBOMs, threat modeling, and the importance of Cyber Informed Engineering.
Listen to the episodeDerek is the author of “The Application Security Handbook. ” He is a university instructor at Temple University, where he teaches software development security to undergraduate and graduate students.
Listen to the episodeMark Curphey is one of the creators of OWASP from the very early days. Mark worked in the background over the few decades of OWASP but has recently taken more to the spotlight.
Listen to the episodeWith nearly 25 years of experience in the cyber-security industry, Guy held various positions in both corporates and startups.
Listen to the episodeBrett Smith is a Software Architect/Engineer/Developer with 20+ years of experience.
Listen to the episodePatrick is a Senior Product Security Engineer in the Application Security team at ServiceNow. He is also Co-Leader of the OWASP CycloneDX project.
Listen to the episodeCI/CD systems hold code, credentials, and production access, yet many organizations still treat them as internal plumbing rather than a critical attack surface.
Listen to the episodeAlex Mor is a passionate cybersecurity defender or breaker depending on the time of day, providing expert technical guidance to product teams and building security in their platforms.
Listen to the episodeWill Ratner is a software security professional with extensive experience building and implementing security solutions across a myriad of industries…
Listen to the episodeKen Toler is a principal consultant at Kudelski Security and is passionate about building and optimizing application security programs that stick through strong adoption and ease of use.
Listen to the episodeInfrastructure as code gives security teams something they have wanted for years: a readable description of the systems surrounding an application.
Listen to the episodeJeroen Willemsen is a Principal Security Architect at Xebia. Jeroen is more or less a jack of all trades with an interest in infrastructure security, risk management, and application security.
Listen to the episodeSoftware security has spent decades alternating between prevention, detection, and response. Kevin Greene joins Chris and Robert to ask what a balanced approach should look like now.
Listen to the episodeVandana Verma is the President of Infosec girls and Infosec Kids, a board of directors member for OWASP, and a leader for BSides Dehli. She joins us to introduce the OWASP Spotlight Series.
Listen to the episodeDr. Anita D’Amico is the CEO of Code Dx, which provides Application Security Orchestration and Correlation solutions to industry and government.
Listen to the episodeCloud-native development gives engineers control over more of the stack, but it also gives them more security decisions to get wrong.
Listen to the episodeSoftware bills of materials promise visibility into dependencies, but visibility alone does not create assurance.
Listen to the episodeRuby on Rails can provide strong security defaults, but a framework cannot make every design decision for its developers.
Listen to the episodeAaron Davis is a founder, dev, and a lead security researcher at MetaMask, a popular Ethereum wallet.
Listen to the episodeDrew Dennison is the CTO & co-founder of r2c, a startup working to profoundly improve software security and reliability to safeguard human progress.
Listen to the episodeHow do you discover vulnerable libraries when the names developers use do not match the names in vulnerability databases?
Listen to the episodeHow much behavior do you inherit when you add one library to a .NET application? Niels Tanis joins Chris and Robert to examine third-party risk beyond checking a dependency for known vulnerabilities.
Listen to the episodeContainers can improve your security story, but not simply because they are called containers.
Listen to the episodeSeason 5 covered application security from tools and threat models to mentoring, self-care, coaching, dependency risk, and program design.
Listen to the episodeDevelopers may want to own security, but what helps them turn that intention into safer software? Liran Tal joins Chris and Robert to examine Snyk's 2019 State of Open Source Security research.
Listen to the episodeWhy should developers care about open source security when they already have features, testing, accessibility, and performance to manage?
Listen to the episodeAn SCA tool can find vulnerable libraries and still leave important software supply-chain questions unanswered.
Listen to the episodeWhat does OWASP Dependency-Track add beyond a conventional software composition analysis scanner?
Listen to the episodeSoftware producers, customers, and policymakers need a common way to discuss security without pretending that one checklist fits every product.
Listen to the episodeOWASP became a reference point for software security, but it began with people sharing knowledge and trying to solve problems together.
Listen to the episodeA JavaScript library can keep working long after its security problems become public.
Listen to the episodeWhich practices belong in a complete application security program? The Season 3 finale answers by assembling clips that move from early development…
Listen to the episodeAn application can inherit serious vulnerabilities from code its developers never wrote.
Listen to the episodeFinding a vulnerable library in one build is only the beginning: how do you find every affected application across an organization?
Listen to the episodeContainers make deployment repeatable, but insecure images, excessive privileges, and unmanaged secrets can travel with them.
Listen to the episodeDoes moving an application into Docker make it safer, or simply change the risks you need to manage?
Listen to the episodeEvery software organization accumulates technical debt, but security debt raises the cost and risk of every future change.
Listen to the episode