Why AI Code Review Will Replace Human Review Faster Than You Think
Jim Manico thinks the era of human code review is ending, and that clinging to it will hurt your company.
Listen to the episodeTopic
Injection, XSS, deserialization and the rest of the catalogue — plus bug bounty, disclosure, and what happens after a report lands.
Jim Manico thinks the era of human code review is ending, and that clinging to it will hurt your company.
Listen to the episodeThree years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since.
Listen to the episodeIs traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started.
Listen to the episodeAI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it?
Listen to the episodeWhy do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling?
Listen to the episodeAppSec teams are drowning in repetitive triage while the work that requires judgment keeps piling up.
Listen to the episodeWhat happens when teams add large language models to real applications and discover that familiar AppSec controls are no longer enough?
Listen to the episodeMilan Williams discusses the importance of application security metrics and how to make them both meaningful and actionable.
Listen to the episodeJeff Williams, a renowned pioneer in the field of application security is with us to discuss Application Detection and Response (ADR), detailing its…
Listen to the episodePhilip Wiley shares his unique journey from professional wrestling to being a renowned pen tester. We define pen testing and the role of social engineering in ethical hacking.
Listen to the episodeAndrew Van Der Stok, a leading web application security specialist and executive director at OWASP joins us for this episode.
Listen to the episodeJames Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security.
Listen to the episodeErik Cabetas joins Robert and Chris for a thought-provoking discussion about modern software security.
Listen to the episodeEitan Worcel joins the Application Security Podcast, to talk automated code fixes and the role of artificial intelligence in application security.
Listen to the episodeChris and Robert are thrilled to have an insightful conversation with Dr. Jared Demott, a seasoned expert in the field of cybersecurity.
Listen to the episodeVarun Badhwar is a three-time founder, a luminary in the cyber security industry, and a clear communicator.
Listen to the episodeJeff Willams of Contrast Security joins Chris and Robert on the Application Security Podcast to discuss runtime security, emphasizing the significance of…
Listen to the episodeWhat is the state of application security? JB Aviat answered that question by creating the state of application security report based on data from Datadog…
Listen to the episodeZohar Shachar joins us to discuss the bug bounty process from both sides. Zohar has spent time as a bug bounty hunter and shares wisdom on avoiding bug bounty-causing issues for your AppSec posture.
Listen to the episodeJames Mckee is a developer (MCPDEA) and security advocate (CISSP) whose biggest responsibility is leading developer security practices.
Listen to the episodeMichael Bargury is the Co-Founder and CTO of Zenity, where he helps companies secure their low-code/no-code apps.
Listen to the episodeTiago Mendo is a co-founder and CTO of Probely. He has extensive experience in pentesting applications, training, and providing all-around security consultancy.
Listen to the episodeSam Stepanyan is an OWASP London Chapter Leader and an Independent Application Security Consultant with over 20 years of IT experience and a background in…
Listen to the episodeBrett Smith is a Software Architect/Engineer/Developer with 20+ years of experience.
Listen to the episodeMazin Ahmed is a security engineer that specializes in AppSec and offensive security.
Listen to the episodeChris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams.
Listen to the episodeSoftware bills of materials promise visibility into dependencies, but visibility alone does not create assurance.
Listen to the episodeJb Aviat is CTO and co-founder at Sqreen. Prior to this, Jb worked at Apple as a reverse engineer, pentester and developer.
Listen to the episodeCaroline Wong is the Chief Strategy Officer at Cobalt. io. You cannot hack yourself secure. The challenge is that developers get bored with hacking broken pieces of code after a while.
Listen to the episodeMichael Furman is the Lead Security Architect at Tufin, and is responsible for the security and Security Development Lifecycle (SDL) of Tufin software products.
Listen to the episodeElie Saad is an application security engineer, leading three different OWASP projects.
Listen to the episodeFuzz testing can sound specialized and difficult, but Zsolt Imre argues that teams can start small and learn quickly.
Listen to the episodeHow do you discover vulnerable libraries when the names developers use do not match the names in vulnerability databases?
Listen to the episodeWhy did APIs need a security Top 10 of their own? Erez Yalon joins Chris and Robert to explain the gaps that led to the OWASP API Security project and walk through its original 2019 list.
Listen to the episodeWhere should a small application security team begin when it cannot do everything? David Kosorok joins Chris and Robert with a practical framework: prevent, detect, and react.
Listen to the episodeMoving an application to Azure changes which security controls you operate yourself and which ones the platform can provide.
Listen to the episodeWhy are SQL injection and cross-site scripting still with us after years of knowing how to prevent them?
Listen to the episodeOWASP became a reference point for software security, but it began with people sharing knowledge and trying to solve problems together.
Listen to the episodeCan an intentionally broken online shop help change an organization’s security culture?
Listen to the episodeWhat does a bug bounty look like from both sides of the relationship? Adam Bacchus and Jon Bottarini of HackerOne compare the responsibilities of the…
Listen to the episodeFinding vulnerabilities is only part of improving software security; the harder work is changing how people build and operate applications.
Listen to the episodeA bug bounty can create a productive relationship with security researchers—or damage trust on both sides.
Listen to the episodeAn application can inherit serious vulnerabilities from code its developers never wrote.
Listen to the episodeFinding a vulnerable library in one build is only the beginning: how do you find every affected application across an organization?
Listen to the episodeBuying more scanners does not automatically create a better application security program.
Listen to the episodeWhat happens when data arriving at an application is allowed to recreate objects and trigger unexpected behavior?
Listen to the episodeContainers make deployment repeatable, but insecure images, excessive privileges, and unmanaged secrets can travel with them.
Listen to the episodeWhy can an IoT product look secure in one component and still fail as a complete system?
Listen to the episodeHow should the OWASP Top 10 balance data, expert judgment, community feedback, and a format people can actually use?
Listen to the episodeDevelopers hear plenty about vulnerabilities, but what should they actually build into their applications to prevent them?
Listen to the episodeWhy did the 2017 OWASP Top 10 release candidate provoke such a strong reaction? Chris and Robert walk through the proposed categories, compare them with…
Listen to the episodeA useful threat model should explain how an attacker could harm the business, not just complete a checklist.
Listen to the episodeSecurity advice only helps when it connects to the needs of the people building and running the business.
Listen to the episodePart two follows Daniel Ramsbrock into the practical workflow of a web application penetration test.
Listen to the episode