Graham Holmes — Adversarial Machine Learning
Graham Holmes is the founder and owner of AoP CyberSecurity, LLC whose mission is to enable organizations to “create scalable and effective strategies for trustworthy outcomes.
Listen to the episode310 episodes, going back to 2016.
Graham Holmes is the founder and owner of AoP CyberSecurity, LLC whose mission is to enable organizations to “create scalable and effective strategies for trustworthy outcomes.
Listen to the episodeOchaun Marshall is a developer and security consultant. In his roles at Secure Ideas, he works on ongoing development projects utilizing Amazon Web Services and breaks other people's web applications.
Listen to the episodeDrew Dennison is the CTO & co-founder of r2c, a startup working to profoundly improve software security and reliability to safeguard human progress.
Listen to the episodeAaron Guzman specializes in IoT, embedded, and automotive security. Aaron is the Co-Author of “IoT Penetration Testing Cookbook”.
Listen to the episodeAdam Shostack is a leading expert on threat modeling, and consultant, entrepreneur, technologist, author and game designer.
Listen to the episodeCindy Blake is the Senior Security Evangelist at GitLab. Cindy collaborates around best practices for integrated DevSecOps application security solutions with major enterprises.
Listen to the episodeJannik Hollenbach is a Security Automation Engineer at iteratec GmbH, working on and with open source security testing tools to continuously detect security…
Listen to the episodeHow does an organization improve software security without reducing maturity to a checklist?
Listen to the episodeSeason six closes by revisiting five conversations that capture the breadth of application security.
Listen to the episodeMark Merkow works at WageWorks in Tempe, Arizona, leading application security architecture and engineering efforts in the office of the CISO.
Listen to the episodeFuzz testing can sound specialized and difficult, but Zsolt Imre argues that teams can start small and learn quickly.
Listen to the episodeAdam joins us to discuss remote threat modeling, and we do a live threat modeling exercise to figure out how remote threat modeling actually works.
Listen to the episodeA system can protect data from attackers and still violate the privacy of the people using it.
Listen to the episodeWhat happens when society’s dependence on software grows faster than its ability to make that software safe?
Listen to the episodeHow do you discover vulnerable libraries when the names developers use do not match the names in vulnerability databases?
Listen to the episodeAutomating security tests is useful, but it does not by itself make a development team secure.
Listen to the episodeBuilding a stronger security community means helping more kinds of people participate and succeed.
Listen to the episodeWhat changes when security becomes part of delivering software instead of a separate gate?
Listen to the episodeHow much behavior do you inherit when you add one library to a .NET application? Niels Tanis joins Chris and Robert to examine third-party risk beyond checking a dependency for known vulnerabilities.
Listen to the episodeContainers can improve your security story, but not simply because they are called containers.
Listen to the episodeWhy can a technically sound DevSecOps initiative fail before it changes how anyone works? Geoff Hill joins Chris and Robert to discuss the diplomacy behind application security transformation.
Listen to the episodeWhy did APIs need a security Top 10 of their own? Erez Yalon joins Chris and Robert to explain the gaps that led to the OWASP API Security project and walk through its original 2019 list.
Listen to the episodeHow did Microsoft's Security Development Lifecycle become a repeatable engineering practice rather than a one-time security push?
Listen to the episodeWhere should a small application security team begin when it cannot do everything? David Kosorok joins Chris and Robert with a practical framework: prevent, detect, and react.
Listen to the episode