Skip to content
AppSec PodcastThe Application Security Podcast — home

The AppSec bookshelf and toolbox

Useful things from the show notes

A normalized catalogue of references from the complete archive, ranked by the number of distinct episodes that link to each one. Inclusion reflects discussion, not endorsement.

541 resources
1,222 episode links

Bookshelf and toolbox

541 shown
  1. 01Standards

    OWASP Top 10

    The OWASP Top 10 is the reference standard for the most critical web application security risks. Adopting the OWASP Top 10 is perhaps the most effective first step towards changing your software….

    32 episodesVisit ↗
  2. 02Tools

    OWASP ZAP

    Welcome to ZAP! It provides a technical capability or reference that security practitioners can evaluate directly.

    28 episodesVisit ↗
  3. 03Communities

    OWASP Foundation

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.

    22 episodesVisit ↗
  4. 04Communities

    DEF CON

    The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest. It connects practitioners through a security community, event, or professional group.

    18 episodesVisit ↗
  5. 05Tools

    Docker

    Docker is a platform designed to help developers build, share, and run container applications. We handle the tedious setup, so you can focus on the code.

    18 episodesVisit ↗
  6. 06Projects

    OWASP Juice Shop

    The most modern and sophisticated insecure web application for security training, awareness demos, CTFs and security tool testing. Contains OWASP Top 10 vulnerabilities.

    18 episodesVisit ↗
  7. 07Standards

    OWASP Top 10 Proactive Controls

    OWASP Top 10 Proactive Controls is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    18 episodesVisit ↗
  8. 08Projects

    OWASP Proactive Controls

    OWASP Top 10 Proactive Controls. It is maintained as an open or collaborative project.

    17 episodesVisit ↗
  9. 09Projects

    OWASP Dependency-Check

    Dependency-Check is a Software Composition Analysis (SCA) tool suite that identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities. It is maintained as an open or collaborative project.

    16 episodesVisit ↗
  10. 10Communities

    Black Hat

    Black Hat is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.

    15 episodesVisit ↗
  11. 11Standards

    OWASP SAMM

    Measure and improve your organization. It documents security requirements, practices, or guidance for practitioners and teams.

    14 episodesVisit ↗
  12. 12Tools

    Burp Suite

    PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & identify the very latest vulnerabilities.

    13 episodesVisit ↗
  13. 13Tools

    Kubernetes

    Kubernetes, also known as K8s, is an open source system for automating deployment, scaling, and management of containerized applications. It groups containers that make up an application into logical units for easy management and discovery.

    13 episodesVisit ↗
  14. 14Tools

    Semgrep

    An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions. It provides a technical capability or reference that security practitioners can evaluate directly.

    12 episodesVisit ↗
  15. 15Standards

    BSIMM

    Benchmark your AppSec program with BSIMM assessment services from Black Duck. Get data-driven insights from 100+ organizations, identify security gaps, and build a customized Maturity Action Plan (MAP) to advance your software security posture.

    11 episodesVisit ↗
  16. 16Standards

    National Vulnerability Database (NVD)

    National Vulnerability Database (NVD) is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    11 episodesVisit ↗
  17. 17Standards

    OWASP Cheat Sheet Series

    Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.

    11 episodesVisit ↗
  18. 18Communities

    OWASP Slack

    Join the OWASP Foundation Slack workspace to connect with the global application security community. It connects practitioners through a security community, event, or professional group.

    10 episodesVisit ↗
  19. 19Communities

    RSA Conference

    RSA Conference is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.

    9 episodesVisit ↗
  20. 20Tools

    Brakeman

    Brakeman is a static analysis security vulnerability scanner for Ruby on Rails applications. It provides a technical capability or reference that security practitioners can evaluate directly.

    8 episodesVisit ↗
  21. 21Projects

    OWASP Threat Dragon Project

    OWASP Threat Dragon is a free, open-source, cross-platform threat modeling application used to draw threat modeling diagrams and to list threats for elements in the diagram. Threat Dragon is designed….

    8 episodesVisit ↗
  22. 22Projects

    OWASP Web Security Testing Guide (WSTG)

    The Web Security Testing Guide (WSTG) Project produces the premier cybersecurity testing resource for web application developers and security professionals. It is maintained as an open or collaborative project.

    8 episodesVisit ↗
  23. 23Articles

    Terraform

    Explore Terraform product documentation, tutorials, and examples. It presents analysis, research, or practical guidance on its subject.

    8 episodesVisit ↗
  24. 24Articles

    Attack Trees (Schneier)

    Modeling security threats By Bruce Schneier Few people truly understand computer security, as illustrated by computer-security company marketing literature that touts “hacker proof software,” “triple-DES security,” and the like. In truth, unbreakable security is broken all the time, often in ways its designers never imagined.

    7 episodesVisit ↗
  25. 25Articles

    Content-Security-Policy (MDN)

    The HTTP Content-Security-Policy response header allows website administrators to control resources the user agent is allowed to load for a given page. With a few exceptions, policies mostly involve specifying server origins and script endpoints.

    7 episodesVisit ↗
  26. 26Articles

    Log4j

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    7 episodesVisit ↗
  27. 27Tools

    Microsoft Threat Modeling Tool

    Overview of the Microsoft Threat Modeling Tool, containing information on getting started with the tool, including the Threat Modeling process. It provides a technical capability or reference that security practitioners can evaluate directly.

    7 episodesVisit ↗
  28. 28Standards

    MITRE ATT&CK Framework

    MITRE ATT&CK Framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    7 episodesVisit ↗
  29. 29Tools

    Node.js

    Node. js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

    7 episodesVisit ↗
  30. 30Projects

    OWASP DevSlop Project

    OWASP DevSlop - An OWASP incubator project. It is maintained as an open or collaborative project.

    7 episodesVisit ↗
  31. 31Projects

    WebGoat

    OWASP WebGoat - An OWASP lab project. It is maintained as an open or collaborative project.

    7 episodesVisit ↗
  32. 32Communities

    BSides

    BSides is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.

    6 episodesVisit ↗
  33. 33Articles

    Corgea

    Corgea finds, triages, and fixes vulnerabilities across code, packages, infrastructure, and containers. It presents analysis, research, or practical guidance on its subject.

    6 episodesVisit ↗
  34. 34Projects

    CycloneDX

    Know what’s inside. See how it connects.

    6 episodesVisit ↗
  35. 35Projects

    GitHub Copilot

    GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

    6 episodesVisit ↗
  36. 36Projects

    GitHub Dependabot

    You can use Dependabot to keep the packages you use updated to the latest versions. It is maintained as an open or collaborative project.

    6 episodesVisit ↗
  37. 37Communities

    Linux Foundation

    Helping open technology projects build world class open source software, communities and companies. It connects practitioners through a security community, event, or professional group.

    6 episodesVisit ↗
  38. 38Standards

    OWASP Top Ten for LLM Applications project homepage

    OWASP Top 10 for Large Language Model Applications - An OWASP lab project. It documents security requirements, practices, or guidance for practitioners and teams.

    6 episodesVisit ↗
  39. 39Standards

    PCI DSS

    A global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments. It documents security requirements, practices, or guidance for practitioners and teams.

    6 episodesVisit ↗
  40. 40Projects

    The Phoenix Project

    The bestselling novel that introduced the world to DevOps and the Three Ways — an IT manager with 90 days to save his company. By Gene Kim, Behr & Spafford.

    6 episodesVisit ↗
  41. 41Projects

    Bandit

    Bandit is a tool designed to find common security issues in Python code. - PyCQA/bandit.

    5 episodesVisit ↗
  42. 42Articles

    Claude Code

    Anthropic's agentic coding tool for developers. Claude Code understands your codebase, edits files, runs commands, and helps you ship faster.

    5 episodesVisit ↗
  43. 43Articles

    Fortify (OpenText)

    OpenText Fortify SAST detects code vulnerabilities early with precise static code analysis, 45+ language support, and seamless CI/CD integration across the SDLC. It presents analysis, research, or practical guidance on its subject.

    5 episodesVisit ↗
  44. 44Projects

    ModSecurity

    ModSecurity is the standard open-source web application firewall (WAF) engine. Originally designed as a module for the Apache HTTP Server, it has evolved to provide HTTP request and response….

    5 episodesVisit ↗
  45. 45Projects

    OWASP AppSensor

    OWASP AppSensor - An OWASP incubator project. It is maintained as an open or collaborative project.

    5 episodesVisit ↗
  46. 46Projects

    OWASP Cornucopia

    OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is maintained as an open or collaborative project.

    5 episodesVisit ↗
  47. 47Projects

    OWASP DefectDojo

    The leading open source application vulnerability management tool built for DevOps and continuous security integration. It is maintained as an open or collaborative project.

    5 episodesVisit ↗
  48. 48Standards

    OWASP Password Storage Cheat Sheet

    Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.

    5 episodesVisit ↗
  49. 49Projects

    OWASP pytm

    pytm is a Pythonic framework for threat modeling. Define your system in Python using the elements and properties described in the pytm framework.

    5 episodesVisit ↗
  50. 50Standards

    OWASP SAMM

    A Software Assurance Maturity Model (SAMM) that provides an effective and measurable way for all types of organizations to analyse and improve their software security posture. It documents security requirements, practices, or guidance for practitioners and teams.

    5 episodesVisit ↗
  51. 51Articles

    PASTA

    PASTA threat modeling explained: the risk-centric, 7-stage methodology co-created by VerSprite's CEO to simulate real attacks and prioritize business risk. It presents analysis, research, or practical guidance on its subject.

    5 episodesVisit ↗
  52. 52Projects

    PyTM

    A Pythonic framework for threat modeling. Contribute to OWASP/pytm development by creating an account on GitHub.

    5 episodesVisit ↗
  53. 53Articles

    Software Transparency: Supply Chain Security in an Era of a Software-Driven Society by Chris Hughes, Tony Turner

    Discover the new cybersecurity landscape of the interconnected software supply chain In Software Transparency: Supply Chain Security in an Era of a Software-Driven Society, a team of veteran information security professionals delivers an expert treatment of software supply chain security. In the book, you’ll explore real-world examples and guidance on how to defend your own organization against internal and ext.

    5 episodesVisit ↗
  54. 54Books

    Start With Why

    This book is about how articulating your purpose can inspire you and those around you. Organizations and leaders that start with their purpose, or “why,” are….

    5 episodesVisit ↗
  55. 55Books

    The Application Security Program Handbook by Derek Fisher

    Secure apps, fast. Your guide to a robust application security program.

    5 episodesVisit ↗
  56. 56Standards

    BSIMM

    Benchmark your AppSec program with BSIMM assessment services from Black Duck. Get data-driven insights from 100+ organizations, identify security gaps, and build a customized Maturity Action Plan (MAP) to advance your software security posture.

    4 episodesVisit ↗
  57. 57Courses

    Cisco Security Ninja

    Did you know that October is National Cyber Security Awareness Month? Here at Cisco, we understand how important cybersecurity is in today’s interconnected world.

    4 episodesVisit ↗
  58. 58Communities

    CodeMash conference

    A volunteer-run developer conference at Kalahari Resort in Ohio and Virginia. Sessions, hands-on workshops, KidzMash, and the tech community you.

    4 episodesVisit ↗
  59. 59Tools

    Docker Hub

    Welcome to the world's largest container registry built for developers and open source contributors to find, use, and share their container images. Build, push and pull.

    4 episodesVisit ↗
  60. 60Articles

    Executive Order 14028

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    4 episodesVisit ↗
  61. 61Projects

    GitLab

    The intelligent orchestration platform for DevSecOps, enabling teams and agents to ship trusted software at enterprise scale. It is maintained as an open or collaborative project.

    4 episodesVisit ↗
  62. 62Articles

    Mobile Testing Guide

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    4 episodesVisit ↗
  63. 63Projects

    MultiJuicer

    Host and manage multiple Juice Shop instances for security trainings and Capture The Flags - juice-shop/multi-juicer. It is maintained as an open or collaborative project.

    4 episodesVisit ↗
  64. 64Projects

    OWASP DevSecOps Maturity Model (DSOMM)

    OWASP Devsecops Maturity Model - An OWASP lab project. It is maintained as an open or collaborative project.

    4 episodesVisit ↗
  65. 65Standards

    OWASP IoT Top 10

    OWASP Internet of Things - An OWASP lab project. It documents security requirements, practices, or guidance for practitioners and teams.

    4 episodesVisit ↗
  66. 66Projects

    OWASP Women in AppSec (WIA)

    Women in AppSec Respository. Contribute to OWASP/WIA development by creating an account on GitHub.

    4 episodesVisit ↗
  67. 67Articles

    PASTA (Process for Attack Simulation and Threat Analysis)

    PASTA threat modeling explained: the risk-centric, 7-stage methodology co-created by VerSprite's CEO to simulate real attacks and prioritize business risk. It presents analysis, research, or practical guidance on its subject.

    4 episodesVisit ↗
  68. 68Standards

    PCI Security Standards Council

    A global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments. It documents security requirements, practices, or guidance for practitioners and teams.

    4 episodesVisit ↗
  69. 69Communities

    Women in AppSec

    This meetup is for anyone interested in supporting and mentoring women and minorities in cyber security. It is primarily the OWASP Foundation Women in Application Security (WIA), Diversity and Inclusion Committee & we also welcome all women and minorities in security.

    4 episodesVisit ↗
  70. 70Articles

    Aleph One's "Smashing The Stack for Fun and Profit"

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    3 episodesVisit ↗
  71. 71Books

    Alice and Bob Learn Application Security

    Learn application security from the very start, with this comprehensive and approachable guide! It offers longer-form guidance and context on its subject.

    3 episodesVisit ↗
  72. 72Articles

    Alice and Bob Learn Application Security

    Learn application security from the very start, with this comprehensive and approachable guide! Alice and Bob Learn Application Security is an accessible and thorough resource for anyone seeking to incorporate, from the beginning of the System Development Life Cycle, best security practices in software development.

    3 episodesVisit ↗
  73. 73Books

    Applied Cryptography

    Applied Cryptography Protocols, Algorithms, and Source Code in C A book by Bruce Schneier This second edition of the cryptography classic provides you with a comprehensive survey of modern cryptography. The book details how programmers and electronic communications professionals can use cryptography—the technique of enciphering and deciphering messages—to maintain the privacy of computer data.

    3 episodesVisit ↗
  74. 74Articles

    Artificial Intelligence

    UNESCO is committed to a future where AI and emerging technologies work for the people. It presents analysis, research, or practical guidance on its subject.

    3 episodesVisit ↗
  75. 75Communities

    B-Sides

    B-Sides is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.

    3 episodesVisit ↗
  76. 76Tools

    Burp Suite Professional

    Burp Suite Professional is the world. It provides a technical capability or reference that security practitioners can evaluate directly.

    3 episodesVisit ↗
  77. 77Projects

    Chaos Monkey

    Chaos Monkey is a resiliency tool that helps applications tolerate random instance failures. - Netflix/chaosmonkey.

    3 episodesVisit ↗
  78. 78Articles

    Cyber Kill Chain (Lockheed Martin)

    Lockheed Martin's Cyber Kill Chain® strengthens cybersecurity. Prevent cyber intrusions with our Intelligence Driven Defense® model.

    3 episodesVisit ↗
  79. 79Projects

    DevSlop

    DevSlop has 8 repositories available. Follow their code on GitHub.

    3 episodesVisit ↗
  80. 80Articles

    EU Cyber Resilience Act

    The Cyber Resilience Act (CRA) aims to make sure all digital products are safe from cyber threats. This rulebook requires that devices and software are designed, updated, and maintained to protect users in our increasingly digital world.

    3 episodesVisit ↗
  81. 81Articles

    Maker's Schedule, Manager's Schedule

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    3 episodesVisit ↗
  82. 82Communities

    Open Security Summit

    Open Security Summit is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.

    3 episodesVisit ↗
  83. 83Projects

    Open Threat Model (OTM)

    The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system. - iriusrisk/OpenThreatModel.

    3 episodesVisit ↗
  84. 84Articles

    OpenID Connect

    What is OpenID Connect OpenID Connect is an interoperable authentication protocol based on the OAuth 2. 0 framework of specifications (IETF RFC 6749 and 6750).

    3 episodesVisit ↗
  85. 85Projects

    OWASP Developer Guide

    The OWASP Developer Guide provides an introduction to security concepts and an initial reference for application and system developers. The content of the Developer Guide aims to be accessible,….

    3 episodesVisit ↗
  86. 86Communities

    OWASP Triangle Chapter

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.

    3 episodesVisit ↗
  87. 87Projects

    Pixi (DevSlop)

    The Pixi module is a MEAN Stack web app with wildly insecure APIs! - DevSlop/Pixi.

    3 episodesVisit ↗
  88. 88Articles

    Sqreen (now Datadog AAP)

    Monitor threats targeting production system, leveraging the execution context provided by distributed traces. It presents analysis, research, or practical guidance on its subject.

    3 episodesVisit ↗
  89. 89Articles

    SSLlabs.com

    A comprehensive free SSL test for your public web servers. It presents analysis, research, or practical guidance on its subject.

    3 episodesVisit ↗
  90. 90Articles

    Tay (Microsoft chatbot)

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    3 episodesVisit ↗
  91. 91Books

    The DevOps Handbook

    This award-winning and bestselling business handbook for digital transformation is now fully updated and expanded with the latest research and new case studies. It offers longer-form guidance and context on its subject.

    3 episodesVisit ↗
  92. 92Articles

    The Tangled Web

    Browsers are doing a lot of strange things under the hood. Security expert Michal Zalewski explains what and why.

    3 episodesVisit ↗
  93. 93Books

    The Web Application Hacker's Handbook

    The highly successful security book returns with a new edition, completely updated Web applications are the front door to most organizations, exposing them to attacks that may disclose personal information, execute fraudulent transactions, or compromise ordinary users. This practical book has been completely updated and revised to discuss the latest step-by-step techniques for attacking and defending the range of eve.

    3 episodesVisit ↗
  94. 94Articles

    Tim Ferriss

    The Tim Ferriss Show The Tim Ferriss Show is one of the most popular podcasts in the world, with more than one billion downloads. It has been selected for “Best of Apple Podcasts” three times.

    3 episodesVisit ↗
  95. 95Articles

    VulnDB (Flashpoint)

    Flashpoint Vulnerability Intelligence helps teams discover vulnerabilities, prioritize threats and protect critical assets. It presents analysis, research, or practical guidance on its subject.

    3 episodesVisit ↗
  96. 96Projects

    WebGoat

    WebGoat is a deliberately insecure application. Contribute to WebGoat/WebGoat development by creating an account on GitHub.

    3 episodesVisit ↗
  97. 97Tools

    ZAP Heads Up Display (HUD)

    The world’s most widely used web app scanner. Free and open source.

    3 episodesVisit ↗
  98. 98Books

    Agile Application Security

    Agile Application Security is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    2 episodesVisit ↗
  99. 99Tools

    Ansible Automation Platform

    A platform for implementing enterprise-wide automation, no matter where you are in your automation journey. It provides a technical capability or reference that security practitioners can evaluate directly.

    2 episodesVisit ↗
  100. 100Articles

    AOL Search Data Leak

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  101. 101Books

    Application Security Program Handbook

    Application Security Program Handbook is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    2 episodesVisit ↗
  102. 102Standards

    AppScan Standard (HCL)

    Protect applications with the HCL AppScan Application Security Testing Platform for SAST, DAST, IAST, API security, AI-powered remediation, and compliance. It documents security requirements, practices, or guidance for practitioners and teams.

    2 episodesVisit ↗
  103. 103Articles

    ArcSight (OpenText)

    SIEM security software to minimize MTTD and MTTR with industry-leading correlation, threat intelligence, native SOAR, and real-time threat detection. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  104. 104Projects

    Björn Kimminich on GitHub

    IT Product Group Lead @kuehne-nagel, Project Leader @OWASP @juice-shop, Amateur MTG Player @mull2five - bkimminich. It is maintained as an open or collaborative project.

    2 episodesVisit ↗
  105. 105Communities

    Boston Application Security Conference

    BASC 2027, the Boston Application Security Conference by OWASP Boston. One day of AppSec talks and workshops.

    2 episodesVisit ↗
  106. 106Courses

    Carnegie Mellon University Software Engineering Institute

    Whether you work in the DoW, government, academia, or private industry, the SEI can partner with your organization to research and solve its hardest software challenges. It provides structured security learning or training material.

    2 episodesVisit ↗
  107. 107Projects

    ChaoSlingr

    ChaoSlingr: Introducing Security into Chaos Testing - Optum/ChaoSlingr. It is maintained as an open or collaborative project.

    2 episodesVisit ↗
  108. 108Articles

    Chromium

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  109. 109Articles

    CISA Zero Trust Maturity Model

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  110. 110Articles

    CISSP

    Gain the CISSP certification with ISC2 to demonstrate your expertise in cybersecurity leadership, implementation & management. Advance your career today!

    2 episodesVisit ↗
  111. 111Articles

    Code Red

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  112. 112Communities

    Converge Conference

    Converge Conference brings together thinkers, builders and leaders for a day of keynotes, workshops and connection. Where ideas, people and industries converge.

    2 episodesVisit ↗
  113. 113Articles

    Core Software Security: Security at the Source

    Core Software Security: Security at the Source [Ransome, James, Misra, Anmol] on Amazon. com.

    2 episodesVisit ↗
  114. 114Articles

    Crash Override

    Software Observability for the AI era. The data plane for software, from prompt to production.

    2 episodesVisit ↗
  115. 115Books

    Crossing the Chasm

    Amazon. com: Crossing the Chasm, 3rd Edition: The Updated Version of the Insightful Guide on Bringing Cutting-Edge Products to the Mainstream (Collins Business Essentials): 9780062292988: Moore, Geoffrey A.

    2 episodesVisit ↗
  116. 116Articles

    CSA IoT Working Group

    CSA’s working groups develop best practices, research and tools for cloud security. Each group focuses on a unique topic or aspect of cloud security.

    2 episodesVisit ↗
  117. 117Articles

    CSSLP

    Secure your cybersecurity career with ISC2’s CSSLP certification and gain expertise in software lifecycle security and secure coding practices. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  118. 118Articles

    Cyber For Builders

    Helping security practitioners, entrepreneurs, investors and executives build the future of cybersecurity. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  119. 119Projects

    Damn Vulnerable Web App (DVWA)

    Damn Vulnerable Web Application (DVWA). Contribute to digininja/DVWA development by creating an account on GitHub.

    2 episodesVisit ↗
  120. 120Articles

    DevSecOps Reference Architecture (Sonatype)

    An interactive DevSecOps reference architecture illustrates manual and automated processes, plus interactions between systems, stakeholders, and security. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  121. 121Articles

    DoD STIG

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  122. 122Articles

    Elevation of Privilege

    The Elevation of Privilege (EoP) threat modeling card game, created by Adam Shostack in 2010, is the easy way to get started threat modeling. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  123. 123Articles

    Exodus Communications

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  124. 124Projects

    Gauntlt

    a ruggedization framework that embodies the principle "be mean to your code" - gauntlt/gauntlt. It is maintained as an open or collaborative project.

    2 episodesVisit ↗
  125. 125Tools

    Hacking Exposed Web Applications

    Hacking exposed by Joel Scambray, 2011, McGraw-Hill edition, electronic resource : in English - 3rd ed. It provides a technical capability or reference that security practitioners can evaluate directly.

    2 episodesVisit ↗
  126. 126Articles

    IEEE Center for Secure Design

    The world's leading society for computing and engineering. Access our research, certifications, and global community of tech innovators.

    2 episodesVisit ↗
  127. 127Articles

    INCLUDES NO DIRT paper

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  128. 128Projects

    IoTGoat

    IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices. - OWASP/IoTGoat.

    2 episodesVisit ↗
  129. 129Projects

    James Wickett

    wickett has 72 repositories available. Follow their code on GitHub.

    2 episodesVisit ↗
  130. 130Projects

    Jon McCoy on GitHub

    theJonMccoy has 7 repositories available. Follow their code on GitHub.

    2 episodesVisit ↗
  131. 131Projects

    Kamus

    An open source, git-ops, zero-trust secret encryption and decryption solution for Kubernetes applications - Soluto/kamus. It is maintained as an open or collaborative project.

    2 episodesVisit ↗
  132. 132Tools

    Kubernetes Admission Controllers

    This page provides an overview of admission controllers. An admission controller is a piece of code that intercepts requests to the Kubernetes API server prior to persistence of the resource, but after the request is authenticated and authorized.

    2 episodesVisit ↗
  133. 133Projects

    LavaMoat

    tools for sandboxing your dependency graph. Contribute to LavaMoat/LavaMoat development by creating an account on GitHub.

    2 episodesVisit ↗
  134. 134Communities

    Loco Moco Product Security Conference

    Security Conference in Hawaiʻi. It connects practitioners through a security community, event, or professional group.

    2 episodesVisit ↗
  135. 135Projects

    multi-juicer GitHub

    Host and manage multiple Juice Shop instances for security trainings and Capture The Flags - juice-shop/multi-juicer. It is maintained as an open or collaborative project.

    2 episodesVisit ↗
  136. 136Books

    Nassim Taleb books

    Nassim Taleb books is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    2 episodesVisit ↗
  137. 137Communities

    NDC Conferences

    NDC Conferences has been delivering high-end events for software developers for more than 20 years. Our events range from large 5-day events with more than 2500 people to smaller niche events and workshops.

    2 episodesVisit ↗
  138. 138Articles

    Nessus

    Find out more about Nessus - the trusted gold standard for vulnerability assessment, designed for modern attack surfaces - used by thousands of organizations. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  139. 139Articles

    Net.wars (Wendy Grossman)

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  140. 140Articles

    Never Split The Difference Chris Vosstahl Raz

    This international bestseller, with more than 5 million copies sold, offers a field-tested approach to high-stakes negotiations and conflict resolution—whet... It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  141. 141Articles

    New School Of Information Security 9780132800280

    This is the eBook version of the printed book. "It is about time that a book like The New School came along.

    2 episodesVisit ↗
  142. 142Standards

    NIST AI Risk Management Framework

    NIST AI Risk Management Framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    2 episodesVisit ↗
  143. 143Standards

    NIST SP 800-53

    This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. The controls are flexible and customiza.

    2 episodesVisit ↗
  144. 144Standards

    NIST SP 800-63

    NIST SP 800-63 is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    2 episodesVisit ↗
  145. 145Standards

    NIST SP 800-63B

    NIST Special Publication 800-63B. It documents security requirements, practices, or guidance for practitioners and teams.

    2 episodesVisit ↗
  146. 146Projects

    Node.js security working group

    Node. js Ecosystem Security Working Group.

    2 episodesVisit ↗
  147. 147Projects

    nodejsscan

    nodejsscan is a static security code scanner for Node. js applications.

    2 episodesVisit ↗
  148. 148Articles

    npm event-stream incident

    npm Blog (Archive); updates from the npm team are now published on the GitHub Blog and the GitHub Changelog. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  149. 149Articles

    OAuth 2.0

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  150. 150Articles

    OWASP 2025 Global Board Elections

    OWASP 2025 Global Board Elections on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.

    2 episodesVisit ↗
  151. 151Projects

    OWASP AppSec Pipeline Project

    OWASP Foundation Web Respository. Contribute to OWASP/www-project-appsec-pipeline development by creating an account on GitHub.

    2 episodesVisit ↗
  152. 152Communities

    OWASP Bangalore

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.

    2 episodesVisit ↗
  153. 153Projects

    OWASP GenAI Security Project

    Identifying and tackling the risks of Gen AI systems and applications OWASP GenAI Security Project A global community-driven and expert led initiative to create freely available open source guidance and resources for understanding and mitigating security and safety concerns for Generative AI applications and adoption. Join Now Members k+ Countries + AI Cybersecurity Publications + […].

    2 episodesVisit ↗
  154. 154Articles

    OWASP Global Board Candidates

    OWASP Global Board Candidates on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.

    2 episodesVisit ↗
  155. 155Communities

    OWASP Israel

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.

    2 episodesVisit ↗
  156. 156Standards

    OWASP ISVS

    OWASP IoT Security Verification Standard (ISVS). Contribute to OWASP/IoT-Security-Verification-Standard-ISVS development by creating an account on GitHub.

    2 episodesVisit ↗
  157. 157Projects

    OWASP Java Encoder Project

    OWASP Java Encoder - An OWASP project. It is maintained as an open or collaborative project.

    2 episodesVisit ↗
  158. 158Projects

    OWASP Juice Shop

    Probably the most modern and sophisticated insecure web application for security trainings, awareness demos and CTFs. Also great voluntary guinea pig for your security tools and DevSecOps pipelines!

    2 episodesVisit ↗
  159. 159Articles

    OWASP Juice Shop Jingle

    Play OWASP Juice Shop Jingle by braimee on desktop and mobile. Play over 320 million tracks for free on SoundCloud.

    2 episodesVisit ↗
  160. 160Standards

    OWASP Low-Code/No-Code Top 10

    The OWASP Low-Code/No-Code Top 10 is a documentation project aimed at helping organizations understand and manage security risks in Low-Code and No-Code applications. It highlights the main security challenges these types of applications face and provides guidance on how to tackle them.

    2 episodesVisit ↗
  161. 161Communities

    OWASP Montreal chapter

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.

    2 episodesVisit ↗
  162. 162Communities

    OWASP Netherlands Chapter

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.

    2 episodesVisit ↗
  163. 163Projects

    OWASP Nettacker

    OWASP Nettacker is an automated penetration testing framework designed to help cyber security professionals and ethical hackers perform reconnaissance, vulnerability assessments, and network security…. It is maintained as an open or collaborative project.

    2 episodesVisit ↗
  164. 164Projects

    OWASP Project Spotlight Series

    OWASP Foundation Web Respository. Contribute to OWASP/www-project-spotlight-series development by creating an account on GitHub.

    2 episodesVisit ↗
  165. 165Standards

    OWASP Security Knowledge Framework

    Security Knowledge Framework (SKF) Python Flask / Angular project - blabla1337/skf-flask. It documents security requirements, practices, or guidance for practitioners and teams.

    2 episodesVisit ↗
  166. 166Standards

    OWASP Security Knowledge Framework

    OWASP Security Knowledge Framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    2 episodesVisit ↗
  167. 167Projects

    OWASP SecurityRAT

    OWASP SecurityRAT - An OWASP incubator project. It is maintained as an open or collaborative project.

    2 episodesVisit ↗
  168. 168Standards

    OWASP SQL Injection Prevention Cheat Sheet

    Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.

    2 episodesVisit ↗
  169. 169Standards

    OWASP Top 10 project repository

    Official OWASP Top 10 Document Repository. Contribute to OWASP/Top10 development by creating an account on GitHub.

    2 episodesVisit ↗
  170. 170Articles

    P200000007269

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  171. 171Articles

    PASTA Threat Modeling

    PASTA threat modeling ties every step to business risk, not just technical findings. Here's why security leaders adopt it — and what it delivers.

    2 episodesVisit ↗
  172. 172Articles

    Patrick DeBois

    Research notes, frameworks, and prototypes organized by stream — thoughts, tools, talks. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  173. 173Projects

    Puma Scan

    Puma Scan is a software security Visual Studio extension that provides real time, continuous source code analysis as development teams write code. Vulnerabilities are immediately displayed in the development environment as spell check and compiler warnings, preventing security bugs from entering your applications.

    2 episodesVisit ↗
  174. 174Tools

    r2c / Semgrep Inc.

    Semgrep is an industry leader that is profoundly improving software security and reliability, powering 75M+ source-code security scans. It provides a technical capability or reference that security practitioners can evaluate directly.

    2 episodesVisit ↗
  175. 175Projects

    RepoKid

    AWS Least Privilege for Distributed, High-Velocity Deployment - Netflix/repokid. It is maintained as an open or collaborative project.

    2 episodesVisit ↗
  176. 176Projects

    retire.js

    scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

    2 episodesVisit ↗
  177. 177Articles

    Ron Rivest

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  178. 178Projects

    Roslyn (.NET Compiler Platform)

    The Roslyn . NET compiler provides C# and Visual Basic languages with rich code analysis APIs.

    2 episodesVisit ↗
  179. 179Courses

    SANS SEC542

    Build real-world web app offensive skills with a hands-on, repeatable process for finding, exploiting, and clearly proving the vulnerabilities that matter. It provides structured security learning or training material.

    2 episodesVisit ↗
  180. 180Tools

    SAST, DAST, IAST, and RASP: Pros, cons and how to choose

    SAST, DAST, IAST, and RASP: Pros, cons and how to choose is a security tool or technical reference discussed on the podcast and available from learn. techbeacon.

    2 episodesVisit ↗
  181. 181Books

    Securing DevOps (Julien Vehent)

    Integrate security into your DevOps pipeline and build safer cloud services. It offers longer-form guidance and context on its subject.

    2 episodesVisit ↗
  182. 182Books

    Security Chaos Engineering

    Security Chaos Engineering is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    2 episodesVisit ↗
  183. 183Books

    Security Metrics: A Beginner's Guide

    Security Metrics, A Beginner. It offers longer-form guidance and context on its subject.

    2 episodesVisit ↗
  184. 184Articles

    Segment

    Collect, unify, and enrich customer data across any app or device with the Twilio Segment CDP, now available on Twilio. com.

    2 episodesVisit ↗
  185. 185Communities

    Slack

    Boost productivity and save time with Slack‌ — ‌the AI work platform for managing projects, automating workflows, and connecting teams securely. Start working smarter today.

    2 episodesVisit ↗
  186. 186Articles

    Slides on SpeakerDeck

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  187. 187Articles

    Software Security

    This is the Mobipocket version of the print book. "When it comes to software security, the devil is in the details.

    2 episodesVisit ↗
  188. 188Articles

    Software Security: Building Security In

    Software Security: Building Security In [McGraw, Gary] on Amazon. com.

    2 episodesVisit ↗
  189. 189Books

    Software Transparency

    Amazon. com: Software Transparency: Supply Chain Security in an Era of a Software-Driven Society: 9781394158485: Hughes, Chris, Turner, Tony, Springett, Steve, Friedman, Allan: Books.

    2 episodesVisit ↗
  190. 190Books

    Software Transparency: Supply Chain Security in an Era of a Software-Driven Society

    Amazon. com: Software Transparency: Supply Chain Security in an Era of a Software-Driven Society: 9781394158485: Hughes, Chris, Turner, Tony, Springett, Steve, Friedman, Allan: Books.

    2 episodesVisit ↗
  191. 191Articles

    SonarQube

    Modernize your AI workflows with code verification for the agentic era. Fight AI slop & improve reliability through automated, explainable, and compliant code reviews.

    2 episodesVisit ↗
  192. 192Communities

    Source Conference

    June 15-17, 2021, HOUSTON Tehas State University (USA, Tehas, Houston) holds the 4th International Scientific and Practical Conference “Web Programming and Internet Technologies (WebConf2021)” on June 15-17, 2021. The Chairman of the Organizing Committee is academician of the National Academy of Sciences Anton Vladimirovich Abramenko.

    2 episodesVisit ↗
  193. 193Projects

    Spring Security

    Level up your Java code and explore what Spring can do for you. It is maintained as an open or collaborative project.

    2 episodesVisit ↗
  194. 194Books

    SRE Engineering

    Explore the world of site reliability engineering with top-rated sre books. Find resources on SRE principles, best practices and the role of a reliability engineer.

    2 episodesVisit ↗
  195. 195Projects

    Steve Springett on GitHub

    I build stuff, I break stuff, I develop stuff to protect stuff. Creator of @DependencyTrack.

    2 episodesVisit ↗
  196. 196Articles

    The Cuckoo's Egg

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  197. 197Books

    The Cuckoo's Egg by Cliff Stoll

    The Cuckoo. It offers longer-form guidance and context on its subject.

    2 episodesVisit ↗
  198. 198Books

    The Developer's Playbook for Large Language Model Security

    The Developer's Playbook for Large Language Model Security is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    2 episodesVisit ↗
  199. 199Articles

    The Hard Thing About Hard Things by Ben Horowitz

    Ben Horowitz, cofounder of the venture capital firm Andreessen Horowitz and one of Silicon Valley’s most respected and experienced entrepreneurs, offers ess... It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  200. 200Tools

    The left-pad incident

    The left-pad incident is a security tool or technical reference discussed on the podcast and available from en. wikipedia.

    2 episodesVisit ↗
  201. 201Articles

    The Pentester Blueprint: Starting a Career as an Ethical Hacker

    JUMPSTART YOUR NEW AND EXCITING CAREER AS A PENETRATION TESTER The Pentester BluePrint: Your Guide to Being a Pentester  offers readers a chance to delve deeply into the world of the ethical, or "white-hat" hacker. Accomplished pentester and author Phillip L.

    2 episodesVisit ↗
  202. 202Articles

    The Pentester BluePrint: Starting A Career As An Ethical Hacker P 9781119684305

    JUMPSTART YOUR NEW AND EXCITING CAREER AS A PENETRATION TESTER The Pentester BluePrint: Your Guide to Being a Pentester  offers readers a chance to delve deeply into the world of the ethical, or "white-hat" hacker. Accomplished pentester and author Phillip L.

    2 episodesVisit ↗
  203. 203Books

    The Phoenix Project

    The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win [Gene Kim, Kevin Behr, George Spafford] on Amazon. com.

    2 episodesVisit ↗
  204. 204Projects

    The Software Security Project

    Persiapkan kecepatan respons Anda. MAXWIN88 menyediakan koleksi permainan aksi yang intens untuk menguji keterampilan strategis dan mekanis Anda.

    2 episodesVisit ↗
  205. 205Books

    The Unicorn Project

    The Unicorn Project is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    2 episodesVisit ↗
  206. 206Projects

    The Unicorn Project

    The highly anticipated follow-up to the bestselling title The Phoenix Project, this book unveils the Five Ideals of Software Development. It is maintained as an open or collaborative project.

    2 episodesVisit ↗
  207. 207Books

    Threat Modeling: A Practical Guide for Development Teams

    Amazon. com: Threat Modeling: A Practical Guide for Development Teams: 9781492056553: Tarandach, Izar, Coles, Matthew J.

    2 episodesVisit ↗
  208. 208Articles

    TLDR newsletter

    TLDR delivers byte sized daily emails on Tech, AI, Web Development, Information Security, Startups, Product Management, DevOps, Marketing, Design and more! It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  209. 209Articles

    Trusted Computer System Evaluation Criteria

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  210. 210Articles

    Twilio

    Build amazing customer experiences on the Twilio platform with APIs for SMS, RCS, voice, and email, plus conversational AI for smarter engagement, and identity verification for trust. It presents analysis, research, or practical guidance on its subject.

    2 episodesVisit ↗
  211. 211Tools

    VEX

    VEX is a security tool or technical reference discussed on the podcast and available from cisa. gov.

    2 episodesVisit ↗
  212. 212Standards

    XSS Prevention Cheat Sheet

    Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.

    2 episodesVisit ↗
  213. 213Projects

    0x Project

    Developers’ one-stop shop to enable faster crypto trading, better prices, and superior UX. Get started now at 0x.

    1 episodeVisit ↗
  214. 214Books

    10 Steps Every CISO Should Take to Secure Next-Gen Software

    10 Steps Every CISO Should Take to Secure Next-Gen Software is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  215. 215Articles

    2019 State of Open Source Security — developer ownership findings

    A worrying 27% of respondents stated they do not have any proactive or automatic way to find out about newly discovered vulnerabilities in their applications. 37% of users of users don’t implement any sort of security testing during CI.

    1 episodeVisit ↗
  216. 216Articles

    7 Web Application Security Best Practices

    This article contains a list of 7 web application security best practices that we believe should be considered in your web app security strategy. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  217. 217Articles

    9781260464009

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  218. 218Articles

    A Tester's Journey — Lisi's blog

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  219. 219Projects

    Aaron “kumavis” Davis on GitHub

    kumavis has 514 repositories available. Follow their code on GitHub.

    1 episodeVisit ↗
  220. 220Tools

    Acunetix Web Scanner

    Invicti Web + API is an end-to-end web security scanner that offers a 360 view of an organization’s security. Allowing you to take control of the security of all you web applications, web services, and APIs to ensure long-term protection.

    1 episodeVisit ↗
  221. 221Articles

    Aditya Gupta and Attify

    Attify is a premium offensive security company founded by Aditya Gupta, author of The IoT Hacker's Handbook. Training, consulting, and research for IoT, mobile, and complex systems security.

    1 episodeVisit ↗
  222. 222Articles

    Adversarial Misuse of Generative AI (Javan's blog article)

    We share our findings on government-backed and information operations threat actor use of the Gemini web application. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  223. 223Articles

    AICPA SOC for Service Organizations overview

    This document provides an overview of SOC for Service Organizations Engagements. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  224. 224Communities

    Alpha-Omega

    Alpha-Omega is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  225. 225Articles

    Amazon AWS outage caused by AI agent (Engadget)

    A recent Amazon Web Services outage was reportedly caused by the company. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  226. 226Tools

    An Analysis of Open-source Automated Threat Modeling Tools and Their Extensibility from Security into Privacy

    An Analysis of Open-source Automated Threat Modeling Tools and Their Extensibility from Security into Privacy is a security tool or technical reference discussed on the podcast and available from usenix. org.

    1 episodeVisit ↗
  227. 227Articles

    Anastasiia Voitova at Cossack Labs

    Media coverage, press releases, company dates of Cossack Labs, data security solution company that builds software and custom solutions for innovative teams. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  228. 228Articles

    Andrew van der Stock at OWASP

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  229. 229Books

    Antifragile by Nassim Nicholas Taleb

    NEW YORK TIMES BESTSELLER • Antifragile is a standalone book in Nassim Nicholas Taleb’s landmark Incerto series, an investigation of opacity,... It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  230. 230Articles

    Applied Cryptography

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  231. 231Articles

    Applied Cryptography

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  232. 232Projects

    AppSensor source code

    A toolkit for building self-defending applications through real-time event detection and response - jtmelton/appsensor. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  233. 233Articles

    ArcSight ESM (OpenText)

    ArcSight ESM analyzes and correlates every event that occurs across the organization--every login, logoff, file access, database query--to deliver accurate prioritization of security risks and compliance violations. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  234. 234Articles

    Atomic Habits

    Packed with evidence-based strategies, Atomic Habits will teach you how to make small changes that will transform your habits and deliver amazing results. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  235. 235Books

    Austin Kleon books

    Illustrated guides to creativity in the digital age by the New York Times bestselling author. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  236. 236Projects

    AWS Threat Composer

    A simple threat modeling tool to help humans to reduce time-to-value when threat modeling - awslabs/threat-composer. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  237. 237Tools

    Azure Kubernetes Service

    Discover Azure Kubernetes Service (AKS) for secure, scalable containerized app deployment and management with fast delivery on managed Kubernetes clusters. It provides a technical capability or reference that security practitioners can evaluate directly.

    1 episodeVisit ↗
  238. 238Books

    B09NRF399J

    IDENTIFIED: A hacker thriller ripped from the headlines of today. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  239. 239Communities

    Becoming jaded with Security BSides’ Jack Daniel

    Becoming jaded with Security BSides’ Jack Daniel is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  240. 240Books

    Being Henry Fonz And Beyond Henry Winkler

    From Emmy-award winning actor, comedian, producer, and director Henry Winkler, a memoir of the effects of stardom and the struggle to become whole. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  241. 241Articles

    Bill Sempf’s developer profile

    Stack Overflow. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  242. 242Articles

    Billion Laughs Attack

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  243. 243Books

    Black Hat GraphQL (book)

    Written by hackers for hackers, this hands-on book shows how to identify vulnerabilities in apps that use GraphQL. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  244. 244Articles

    Blockchain Security A Need For Todays Businesses Complete Guide For Beginners

    In this article we will know about Blockchain Security: A need for Today’s Businesses (Complete Guide for Beginners). It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  245. 245Books

    Books by Martin Fowler

    Books by Martin Fowler is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  246. 246Books

    Books by Yuval Noah Harari

    Prof. Yuval Noah Harari is a historian, philosopher and best-selling author of 'Sapiens' and 'Homo Deus'.

    1 episodeVisit ↗
  247. 247Communities

    Boston .NET Architecture Group

    **Description****We are celebrating 22 years in December, 2025 / January, 2026! **We are a group of software developers and architects primarily in the Boston area that get together and discuss various topics about Patterns, .

    1 episodeVisit ↗
  248. 248Communities

    BSides Boulder

    Official BSides Boulder Event Page. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  249. 249Communities

    BSides Las Vegas

    BSides Las Vegas. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  250. 250Communities

    BSides San Antonio

    General information about BSides SATX 2026. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  251. 251Communities

    BSides Singapore

    Where Singapore. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  252. 252Standards

    BSIMM

    BSIMM is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  253. 253Books

    Building In Security At Agile Speed

    Building in Security at Agile Speed [Ransome, James, Schoenfield, Brook] on Amazon. com.

    1 episodeVisit ↗
  254. 254Books

    Building Secure and Reliable Systems

    Building Secure and Reliable Systems is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  255. 255Projects

    Bundler Audit

    Patch-level verification for Bundler. Contribute to rubysec/bundler-audit development by creating an account on GitHub.

    1 episodeVisit ↗
  256. 256Articles

    Can Kubernetes Keep a Secret? (blog)

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  257. 257Articles

    CAWE

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  258. 258Articles

    Chalk

    This is the main page for Chalk docs. Chalk is an open-source project created and maintained by Crash Override.

    1 episodeVisit ↗
  259. 259Articles

    Chrome 68 "Not Secure" HTTP Labeling

    We're marking all sites that are not encrypted with HTTPS as “not secure”. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  260. 260Projects

    CI/CD Goat

    A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

    1 episodeVisit ↗
  261. 261Tools

    CIS Docker Benchmark

    Download our step-by-step checklist to secure your platform: An objective, consensus-driven security guideline for Docker. It provides a technical capability or reference that security practitioners can evaluate directly.

    1 episodeVisit ↗
  262. 262Articles

    Cisco Secure

    Defend users, apps, and data against today's threats. Enable your agentic enterprise at scale with an open, network-native platform.

    1 episodeVisit ↗
  263. 263Books

    CISO Desk Reference Guide

    An easy to use guide written by experienced practitioners for recently-hired or promoted Chief Information Security Officers (CISOs), individuals aspiring to become a CISO, as well as business and technical professionals interested in the topic of cybersecurity, including Chief Technology Officers (CTOs), Chief Information Officers (CIOs), Boards of Directors, Chief Privacy Officers, and other executives responsible. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  264. 264Articles

    Claude Code source leak (VentureBeat)

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  265. 265Projects

    CodeProject

    An open or collaborative project discussed on the podcast and hosted at codeproject. com.

    1 episodeVisit ↗
  266. 266Projects

    Conflict Modeling (GitHub)

    A place to gather and organize information about using threat modeling frameworks to deal with social conflict in online systems - adamshostack/conflictmodeling. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  267. 267Articles

    Conscious Business by Fred Kofman

    Sitio Oficial de Fred Kofman, vicepresidente y asesor de desarrollo de liderazgo en Google, director del Centro de Liderazgo Consciente en Tecnológico de Monterrey, y fundador y presidente del Conscious Business Center International. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  268. 268Articles

    Consequence-driven Cyber-Informed Engineering (CCE)

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  269. 269Standards

    Content Security Policy Cheat Sheet

    Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  270. 270Books

    Cooking for Geeks

    Cooking for Geeks is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  271. 271Articles

    CORBA

    CORBA is an open, vendor-independent architecture and infrastructure that computer applications use to work together over networks. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  272. 272Books

    Core Software Security

    Core Software Security is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  273. 273Projects

    CrackQL

    CrackQL is a GraphQL password brute-force and fuzzing utility. - nicholasaleks/CrackQL.

    1 episodeVisit ↗
  274. 274Books

    Critical System Thinking Book

    Critical System Thinking Book is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  275. 275Articles

    Crossing The Chasm 3rd Edition Geoffrey A Moore

    The bible for bringing cutting-edge products to larger markets is now revised and updated with new insights into the realities of high-tech marketing. With ...

    1 episodeVisit ↗
  276. 276Articles

    CSP is Dead, Long Live CSP (Google Research)

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  277. 277Standards

    CVE-2017-5638

    CVE-2017-5638 is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  278. 278Standards

    CWE-611

    Common Weakness Enumeration (CWE) is a list of software weaknesses. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  279. 279Articles

    Cyber-Informed Engineering (INL)

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  280. 280Books

    Cybersecurity First Principles: A Reboot of Strategy and Tactics

    Cybersecurity First Principles: A Reboot of Strategy and Tactics [Howard, Rick] on Amazon. com.

    1 episodeVisit ↗
  281. 281Articles

    Cybersecurity Game Challenge

    Build trust, shape a culture and kick start conversations. Physical games for in person threat modelling, training and fun.

    1 episodeVisit ↗
  282. 282Projects

    Damn Vulnerable GraphQL Application

    Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security. - dolevf/Damn-Vulnerable-GraphQL-Application.

    1 episodeVisit ↗
  283. 283Articles

    DARPA Robotics Challenge

    The DARPA Robotics Challenge (DRC) is a competition of robot systems and software teams vying to develop robots capable of assisting humans in responding to natural and man-made disasters. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  284. 284Articles

    Datadog State of Application Security report

    We analyzed data from thousands of organizations to discover which vulnerabilities really matter, which threats present a risk, and other insights. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  285. 285Articles

    Dave Cheney: The Zen of Go

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  286. 286Articles

    Dave Kennedy

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  287. 287Articles

    David Habusha: Why did I join WhiteSource

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  288. 288Articles

    Designing Secure Software

    An elegant, team-oriented guide for building security into the software design process. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  289. 289Articles

    Developers mentoring other developers: practices I've seen work well

    How does mentoring work? I asked this question ten years into my software engineering career when I joined Uber.

    1 episodeVisit ↗
  290. 290Books

    DevSecOps Playbook (GitHub)

    This is a step-by-step guide to implementing a DevSecOps program for any size organization - 6mile/DevSecOps-Playbook. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  291. 291Projects

    DevSecOps Studio

    Virtual environment for learning DevSecOps. Contribute to secfigo/DevSecOps-Studio development by creating an account on GitHub.

    1 episodeVisit ↗
  292. 292Articles

    Difficult Conversations

    Difficult Conversations, a New York Times best-seller by Douglas Stone & Sheila Heen, teaches effective communication skills & strategies for managing conflict. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  293. 293Articles

    Do Hard Things

    A NATIONAL BESTSELLER \"In Do Hard Things, Steve Magness beautifully and persuasively reimagines our understanding of toughness. This is a must-read fo...

    1 episodeVisit ↗
  294. 294Projects

    DOMPurify

    DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks.

    1 episodeVisit ↗
  295. 295Books

    Drive

    Drive is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  296. 296Articles

    DtSR Episode 204: On Changing Culture

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  297. 297Articles

    Dwarkesh Patel: "The Rise and Fall of Agent Civilizations"

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  298. 298Articles

    DZone: Introduction to DevSecOps

    Learn key methods and techniques for implementing the DevSecOps methodology to ensure your cloud environments are secured effectively. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  299. 299Articles

    Effective Vulnerability Management by Chris Hughes

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  300. 300Articles

    Elastic (ELK) Stack

    Reliably and securely take data from any source, in any format, then search, analyze, and visualize it in real time. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  301. 301Articles

    ENISA Securing Machine Learning Algorithms

    ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.

    1 episodeVisit ↗
  302. 302Articles

    Exploring container security

    Exploring container security: This year, it’s all about security. Again.

    1 episodeVisit ↗
  303. 303Books

    Extreme Ownership

    Looking for leadership courses? Online solutions help you learn key leadership principles on demand wherever you are.

    1 episodeVisit ↗
  304. 304Projects

    Faster Than Light (BugCatcher)

    Faster Than Light has 14 repositories available. Follow their code on GitHub.

    1 episodeVisit ↗
  305. 305Projects

    Fennec.CLI

    Fennec. NetCore - .

    1 episodeVisit ↗
  306. 306Projects

    Find the Document on the OWASP GitHub

    OWASP API Security Project. Contribute to OWASP/API-Security development by creating an account on GitHub.

    1 episodeVisit ↗
  307. 307Projects

    FINOS Common Cloud Controls

    View resources from FINOS Common Cloud Controls - an open standard project that describes consistent controls for compliant public cloud deployments in the financial services (FS) sector. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  308. 308Projects

    Flask

    An open or collaborative project discussed on the podcast and hosted at flask. palletsprojects.

    1 episodeVisit ↗
  309. 309Articles

    FMCSA Hours of Service

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  310. 310Books

    Foundation by Isaac Asimov

    Foundation [Asimov, Isaac] on Amazon. com.

    1 episodeVisit ↗
  311. 311Standards

    Framework

    Align your product team and build products that people want to buy with Pragmatic's product management methodology. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  312. 312Articles

    Gene Hoffman

    Gene Hoffman Chief Executive Officer and President Gene Hoffman has built and sold three companies to PGP, Inc. , Vivendi-Universal, and ...

    1 episodeVisit ↗
  313. 313Articles

    Gentoo GitHub Hack

    News and information from Gentoo Linux. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  314. 314Books

    Georgia Weidman's book on penetration testing

    Georgia Weidman wrote the book on pentesting. Literally.

    1 episodeVisit ↗
  315. 315Articles

    GIAC GWAPT

    The GIAC Web Application Penetration Tester (GWAPT) certification validates a practitioner's ability to advance organization security through penetration testing and deep understanding of web application security issues. GWAPT certification holders are equipped with expertise in web application exploits and penetration testing methodology.

    1 episodeVisit ↗
  316. 316Articles

    GitGuardian State of Secrets Sprawl Report 2026

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  317. 317Projects

    GitHub

    🧠 Socially Engineering LLMs 🤖 Hacking AI Agents 🦄 Node. js Secure Coding 🌟 @GitHub Star 🏅 @OpenJS Pathfinder award 4 Security 🥑 DevRel @snyksec - lirantal.

    1 episodeVisit ↗
  318. 318Projects

    GitHub

    DJ is a DevOps pioneer and a security sommelier. djschleen has 34 repositories available.

    1 episodeVisit ↗
  319. 319Articles

    GitHub Octoverse

    Insights into the state of open source on GitHub. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  320. 320Projects

    github/secure_headers

    Manages application of security headers with many safe defaults - github/secure_headers. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  321. 321Articles

    Go html/template

    Package template (html/template) implements data-driven templates for generating HTML output safe against code injection. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  322. 322Standards

    Goal Question Metric (GQM) framework

    Goal Question Metric (GQM) framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  323. 323Standards

    Google Secure AI Framework (SAIF)

    Building AI? Learn how to keep it secure with Google.

    1 episodeVisit ↗
  324. 324Articles

    Hackedu Acquires Security Journey

    Combining content and experiments creates a platform that enhances learning for developers and product development professionals. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  325. 325Books

    Hacking Kubernetes (book)

    Hacking Kubernetes (book) is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  326. 326Articles

    Hacking: The Art of Exploitation, Vol. 2

    Hacking is creative problem solving: unconventional solutions, exploited weaknesses, and the technical foundation to pull it off. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  327. 327Projects

    hcltm (now threatcl) on GitHub

    Documenting your Threat Models with HCL. Contribute to threatcl/threatcl development by creating an account on GitHub.

    1 episodeVisit ↗
  328. 328Articles

    Hi5

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  329. 329Articles

    Hi5signup

    Read the Security Journey blog for expert insights on secure coding, application security trends, and developer-focused AppSec education. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  330. 330Articles

    How Leaders Create and Use Networks

    Reprint: R0701C Most people acknowledge that networking—creating a fabric of personal contacts to provide support, feedback, insight, and resources—is an essential activity for an ambitious manager. Indeed, it’s a requirement even for those focused simply on doing their current jobs well.

    1 episodeVisit ↗
  331. 331Articles

    How to Measure Anything in Cybersecurity Risk, 2nd Edition

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  332. 332Articles

    HTTPS Everywhere (EFF)

    You no longer need HTTPS Everywhere to set HTTPS by default! Major browsers now offer native support for an HTTPS only mode.

    1 episodeVisit ↗
  333. 333Books

    I Have No Mouth and I Must Scream

    Amazon. com: I Have No Mouth & I Must Scream: 9781497643079: Ellison, Harlan: Books.

    1 episodeVisit ↗
  334. 334Projects

    iGoat Swift

    OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS - OWASP/iGoat-Swift. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  335. 335Articles

    INCLUDES NO DIRT at Omada Health

    INCLUDES NO DIRT: A Practical Threat Modeling Approach for Digital Healthcare and Beyond. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  336. 336Articles

    INCLUDES NO DIRT: A Practical Threat Modeling Approach for Digital Healthcare and Beyond

    Omada - Resource Center Blog. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  337. 337Communities

    Information security needs community: 6 ways to build up your teams

    Information security needs community: 6 ways to build up your teams is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  338. 338Articles

    InfoSec is Good People (Rob Graham)

    For all that we complain about drama in our community, we are actually good people. At a small conference yesterday, I met "Kath".

    1 episodeVisit ↗
  339. 339Articles

    InfoSecSherpa

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  340. 340Books

    Intelligence Driven Incident Response

    Intelligence Driven Incident Response is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  341. 341Articles

    Interest In Secure Design Practices Is Increasing Leading To Two Predictions

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  342. 342Standards

    Ipd

    This NIST AI report develops a taxonomy of concepts and defines terminology in the field of adversarial machine learning (AML). The taxonomy is built on survey of the AML literature and is arranged in a conceptual hierarchy that includes key types of ML methods and lifecycle stage of attack, attacker goals and objectives, and attacker capabilities and knowledge of the learning process.

    1 episodeVisit ↗
  343. 343Articles

    iTextSharp

    PLEASE NOTE: iTextSharp is EOL, and has been replaced by iText. Only security fixes will be added We HIGHLY recommend customers use iText for new projects, and to consider moving existing projects from...

    1 episodeVisit ↗
  344. 344Projects

    Java Observability Toolkit (JOT)

    Java Observability Toolkit. Contribute to planetlevel/jot development by creating an account on GitHub.

    1 episodeVisit ↗
  345. 345Articles

    Jenga View of Threat Modeling whitepaper

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  346. 346Projects

    Jeremy Long on GitHub

    Founder and project lead for dependency-check. jeremylong has 73 repositories available.

    1 episodeVisit ↗
  347. 347Articles

    Joe's Blog Post

    HackEDU acquires Security Journey to create an industry-leading application security offering. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  348. 348Projects

    John Melton on GitHub

    jtmelton has 15 repositories available. Follow their code on GitHub.

    1 episodeVisit ↗
  349. 349Articles

    John Willis

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  350. 350Articles

    Jon Callas

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  351. 351Projects

    Juice Shop source code

    OWASP Juice Shop: Probably the most modern and sophisticated insecure web application - juice-shop/juice-shop. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  352. 352Books

    Justin Rosenstein's original codemod on GitHub

    Codemod is a tool/library to assist you with large-scale codebase refactors that can be partially automated but still require human oversight and occasional intervention. Codemod was developed at Facebook and released as open source.

    1 episodeVisit ↗
  353. 353Articles

    Kevin Greene on API security testing

    Overcome software quality challenges & achieve continuous delivery at speed with Parasoft SOAtest, Virtualize, CTP, and DTP. Learn more!

    1 episodeVisit ↗
  354. 354Articles

    Kevin's article on Dark Reading

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  355. 355Articles

    KidzMash and the CodeMash experience

    Part developer conference, part waterpark takeover. Deep technical sessions, hands-on workshops, the Makerspace, KidzMash, and 19 years of community.

    1 episodeVisit ↗
  356. 356Articles

    Latio's free reports

    Compare 700+ cybersecurity tools and vendors with expert reviews, Latio scores, and AI-powered search. Find the right security tool for your stack.

    1 episodeVisit ↗
  357. 357Projects

    Lemur

    Repository for the Lemur Certificate Manager. Contribute to Netflix/lemur development by creating an account on GitHub.

    1 episodeVisit ↗
  358. 358Articles

    Lex Fridman Podcast — Peter Steinberger on OpenClaw

    Peter Steinberger is the creator of OpenClaw, an open-source AI agent framework that’s the fastest-growing project in GitHub history. Thank you for listening ❤ Check out our sponsors: https://lexfridman.

    1 episodeVisit ↗
  359. 359Books

    Life 3.0

    Life 3. 0: Being Human in the Age of Artificial Intelligence [Tegmark, Max] on Amazon.

    1 episodeVisit ↗
  360. 360Articles

    LINDDUN research and publications

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  361. 361Standards

    LINQ to SQL

    LINQ to SQL is a component of the . NET Framework that provides a runtime infrastructure for managing relational data as objects.

    1 episodeVisit ↗
  362. 362Tools

    lodash

    lodash is a security tool or technical reference discussed on the podcast and available from npmjs. com.

    1 episodeVisit ↗
  363. 363Books

    Luna and the Magic AI Paintbrush

    Amazon. com: Luna and the Magic AI Paintbrush: An AI Made Simple Book (Seriously Simple): 9789083414478: Schenk, Bessie, van der Veer, Rob, van Yperen, Mireille: Books.

    1 episodeVisit ↗
  364. 364Books

    Malware Analyst's Cookbook

    Amazon. com: Malware Analyst.

    1 episodeVisit ↗
  365. 365Articles

    Mark Frost

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  366. 366Communities

    Mark Willis at RSA Conference

    Mark Willis at RSA Conference is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  367. 367Projects

    Mark’s GitLab threat modeling article

    As usual, we’re creating our own path in how we handle our threat modeling, approaching development both iteratively and collaboratively, and seriously shifting left with our framework and processes. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  368. 368Books

    Math Without Numbers

    Buy Math Without Numbers on Amazon. com ✓ FREE SHIPPING on qualified orders.

    1 episodeVisit ↗
  369. 369Articles

    Matt Conover's "w00w00 on Heap Overflows"

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  370. 370Articles

    Maya's website

    Maya Kaczorowski builds enterprise security tools that people actually want to use. Cofounder at Oblique, previously at Tailscale, GitHub, Google.

    1 episodeVisit ↗
  371. 371Standards

    Microsoft Responsible AI Standard, v2

    Discover Microsoft AI tools, industry-specific governance solutions, and responsible AI practices to make smarter, more informed decisions about AI implementation. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  372. 372Tools

    Microsoft Safe C Library

    An overview of secure CRT functions in the Microsoft C runtime. It provides a technical capability or reference that security practitioners can evaluate directly.

    1 episodeVisit ↗
  373. 373Projects

    Mike Goodwin on GitHub

    mike-goodwin has 24 repositories available. Follow their code on GitHub.

    1 episodeVisit ↗
  374. 374Projects

    mike-goodwin/owasp-threat-dragon

    An open source, online threat modelling tool from OWASP - mike-goodwin/owasp-threat-dragon. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  375. 375Articles

    Mitigating Risky Pull Requests With Monocle Risk Advisor Part 2 7013e1485bf2

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  376. 376Projects

    mitre-attack/attack-navigator

    Web app that provides basic navigation and annotation of ATT&CK matrices - mitre-attack/attack-navigator. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  377. 377Projects

    Mono.Cecil

    Cecil is a library to inspect, modify and create . NET programs and libraries.

    1 episodeVisit ↗
  378. 378Articles

    Monocle Part 1

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  379. 379Standards

    MOSAIC

    MOSAIC is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  380. 380Articles

    Mozilla HTTP Observatory

    Test your site’s HTTP headers, including CSP and HSTS, to find security problems and get actionable recommendations to make your website more secure. Test other websites to see how you compare.

    1 episodeVisit ↗
  381. 381Articles

    NASA Ingenuity Mars Helicopter

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  382. 382Projects

    Neil Smithline on GitHub

    Appsec dude. OWASP Top-10 Co-Lead.

    1 episodeVisit ↗
  383. 383Projects

    Netflix Simian Army

    Tools for keeping your cloud operating in top form. Chaos Monkey is a resiliency tool that helps applications tolerate random instance failures.

    1 episodeVisit ↗
  384. 384Articles

    NetWitness

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  385. 385Books

    Never Eat Alone

    Keith Ferrazzi is an American entrepreneur and recognized global thought leader in the relational and collaborative sciences. As Chairman of Ferrazzi Greenlight and its Research Institute, he works to identify behaviors that block global organizations from reaching their goals and to transform them by coaching new behaviors that increase growth and shareholder value.

    1 episodeVisit ↗
  386. 386Articles

    Niels's blog

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  387. 387Articles

    Nimda

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  388. 388Standards

    NIST Digital Identity Guidelines

    NIST Special Publication 800-63 Digital Identity Guidelines. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  389. 389Standards

    NIST OSCAL

    NIST OSCAL is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  390. 390Standards

    NIST SP 800-190

    Application container technologies, also known as containers, are a form of operating system virtualization combined with application software packaging. Containers provide a portable, reusable, and automatable way to package and run applications.

    1 episodeVisit ↗
  391. 391Articles

    NVIDIA NemoClaw

    Agents are evolving from question-and-answer systems into long-running autonomous assistants that read files, call APIs, and drive multi-step workflows. However….

    1 episodeVisit ↗
  392. 392Articles

    NYDFS 23 NYCRR 500

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  393. 393Articles

    OECD AI Principles

    OECD. AI helps countries and shape trustworthy AI with the OECD AI Principles.

    1 episodeVisit ↗
  394. 394Projects

    Omer Levi Hevroni on GitHub

    Engineer @goledge , OSS maintainer and a proud father - omerlh. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  395. 395Communities

    Open Security Summit 2018 archive

    Open Security Summit 2018 archive is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  396. 396Articles

    OpenAI Codex

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  397. 397Projects

    OpenClaw

    The AI that really does things. Any OS.

    1 episodeVisit ↗
  398. 398Projects

    OpenVEX spec

    OpenVEX Specification. Contribute to openvex/spec development by creating an account on GitHub.

    1 episodeVisit ↗
  399. 399Articles

    Operation ShadowHammer (Kaspersky)

    Operation ShadowHammer is a newly discovered supply chain attack that leveraged ASUS Live Update software. While the investigation is still in progress and full results will be published during SAS 2019 conference, we would like to share some important details about the attack.

    1 episodeVisit ↗
  400. 400Articles

    OWASP Agentic Security Initiative

    What’s New Resources Learning Videos Blog Download Now Download Now Download Now Download Now Download Now Download Now Project Audience – All Topics – Agentic Security More Events Audience – All Topics – Agentic Security More Training Audience – AI/Data Scientists, Developers, Practitioners Topics – Agentic Security More Events Audience – AI/Data Scientists, Architects, Developers, […]. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  401. 401Tools

    OWASP AppSec Pipeline Toolbox

    OWASP AppSec Pipeline Toolbox is a security tool or technical reference discussed on the podcast and available from appsecpipeline. org.

    1 episodeVisit ↗
  402. 402Communities

    OWASP Bangalore

    The OWASP Bangalore chapter is located in India and has been active since 2014, making it about 9 years old. It serves as a community for people interested in web security, offering public meetings that anyone can join without needing to be a member.

    1 episodeVisit ↗
  403. 403Communities

    OWASP Bay Area

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  404. 404Communities

    OWASP Bristol Chapter

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  405. 405Communities

    OWASP Chapters

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  406. 406Projects

    OWASP crAPI

    completely ridiculous API (crAPI). Contribute to OWASP/crAPI development by creating an account on GitHub.

    1 episodeVisit ↗
  407. 407Projects

    OWASP Dependency-Check

    Dependency-Check is a Software Composition Analysis (SCA) tool suite that identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  408. 408Projects

    OWASP Developer Guide

    The Developer Guide provides an introduction to security concepts and an initial reference for application and system developers. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  409. 409Articles

    OWASP DevSecOps Guideline

    OWASP Foundation Developer Guide project. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  410. 410Projects

    OWASP GenAI Security Project — Get Involved

    T10 FOR GEN AI Project Contribute How to Contribute? The OWASP Top 10 for LLM Applications is an open source effort and we welcome all expert ideas, contributions, suggestions, and remarks.

    1 episodeVisit ↗
  411. 411Communities

    OWASP Global AppSec conferences

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  412. 412Articles

    OWASP Global AppSec USA 2026

    Training Dates - November 2-4, 2026 / Conference Dates - November 5-6, 2026It's our 25th Anniversary year! Get ready for an unforgettable experience at the OWASP Global AppSec USA Conference!

    1 episodeVisit ↗
  413. 413Articles

    OWASP Global Board Candidates

    OWASP Board of Directors election candidates. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  414. 414Projects

    OWASP Glue source code

    Application Security Automation. Contribute to OWASP/glue development by creating an account on GitHub.

    1 episodeVisit ↗
  415. 415Projects

    OWASP iGoat

    OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar - OWASP/igoat. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  416. 416Communities

    OWASP Israel

    OWASP Israel is a large chapter that has been active for several years. It focuses on improving software security through various activities, including frequent meetings and organizing the AppSec Israel conference, with the next one scheduled for May 2025.

    1 episodeVisit ↗
  417. 417Standards

    OWASP Logging Cheat Sheet

    Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  418. 418Communities

    OWASP Maine

    The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  419. 419Communities

    OWASP Montreal

    The Montreal Chapter has been active for several years and is part of a larger non-profit organization focused on improving cybersecurity. This chapter is open to everyone, and you do not need to be a member to attend their meetings.

    1 episodeVisit ↗
  420. 420Projects

    OWASP Secure Headers Project

    The OWASP Secure Headers Project (OSHP) describes HTTP response headers that your application can use to increase the security of your application. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  421. 421Projects

    OWASP Security Shepherd

    OWASP Security Shepherd is a web and mobile application security training platform. Security Shepherd has been designed to foster and improve security awareness among a varied skill-set demographic.

    1 episodeVisit ↗
  422. 422Projects

    OWASP Threat Model Library

    OWASP Threat Model Library - An OWASP incubator project. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  423. 423Standards

    OWASP Top 10:2021

    OWASP Top 10:2021 is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  424. 424Standards

    OWASP Top 10:2025

    OWASP Top 10:2025. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  425. 425Standards

    OWASP Top 10:2025

    OWASP Top 10:2025. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  426. 426Communities

    OWASP Triangle

    The Triangle-North Carolina chapter of OWASP has been active for a while, fostering a community focused on web application security. It is led by Chris Romeo and Steve Pinkham, who keep members updated through platforms like Meetup and Twitter.

    1 episodeVisit ↗
  427. 427Projects

    OWASP WrongSecrets project

    Examples with how to not use secrets. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  428. 428Standards

    OWASP XXE Prevention Cheat Sheet

    Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  429. 429Articles

    PASTA threat modeling

    PASTA threat modeling explained: the risk-centric, 7-stage methodology co-created by VerSprite's CEO to simulate real attacks and prioritize business risk. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  430. 430Articles

    PBKDF2 (RFC 2898)

    This document provides recommendations for the implementation of password-based cryptography, covering key derivation functions, encryption schemes, message-authentication schemes, and ASN. 1 syntax identifying the techniques.

    1 episodeVisit ↗
  431. 431Books

    People-Centric Security

    People-Centric Security: Transforming Your Enterprise Security Culture: 9780071846776: Computer Science Books @ Amazon. com.

    1 episodeVisit ↗
  432. 432Articles

    Peter Checkland

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  433. 433Projects

    Peter Steinberger

    Came back from retirement to mess with AI. Clawdfather @OpenClaw Previously: Founder of @PSPDFKit.

    1 episodeVisit ↗
  434. 434Articles

    Phantoms in the Brain: Probing the Mysteries of the Human Mind

    Neuroscientist V. S.

    1 episodeVisit ↗
  435. 435Articles

    Phantoms in the Brain: Probing the Mysteries of the Human Mind

    Neuroscientist V. S.

    1 episodeVisit ↗
  436. 436Projects

    Poutine

    poutine, a supply chain vulnerability scanner for build pipelines - boostsecurityio/poutine. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  437. 437Courses

    Press Release: HackEDU Acquires Security Journey

    Press Release: HackEDU Acquires Security Journey is a course, workshop, or training resource mentioned in episode show notes. It provides structured security learning or training material.

    1 episodeVisit ↗
  438. 438Standards

    PSIRT Services Framework (FIRST.org)

    PSIRT Services Framework (FIRST. org) is a security standard, framework, or guidance reference discussed on the podcast.

    1 episodeVisit ↗
  439. 439Standards

    Purple Team Exercise Framework

    Purple Team Exercise Framework. Contribute to scythe-io/purple-team-exercise-framework development by creating an account on GitHub.

    1 episodeVisit ↗
  440. 440Articles

    Pwning OWASP Juice Shop

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  441. 441Projects

    pytm GitHub page

    A Pythonic framework for threat modeling. Contribute to izar/pytm development by creating an account on GitHub.

    1 episodeVisit ↗
  442. 442Articles

    Qualys Web Application Scanning

    Qualys Web App Scanning security software and tools deliver automated vulnerability detection and continuous monitoring to protect your web applications from emerging threats. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  443. 443Books

    Quiet Influence

    Quiet Influence is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  444. 444Articles

    Rails security guide

    This guide describes common security problems in web applications and how to avoid them with Rails. After reading this guide, you will know: How to use the built-in authentication generator.

    1 episodeVisit ↗
  445. 445Articles

    Rakuten: Democratizing AppSec

    Three of Rakuten’s cyber security professionals contributed topics on the theme of AppSec democratization at the OWASP 2022 Global AppSec APAC Conference. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  446. 446Projects

    Rapid Threat Model Prototyping documentation

    This repository stores content that can be used to design a Rapid Threat Model Prototyping process for a software development group. - geoffrey-hill-tutamantic/rapid-threat-model-prototyping-docs.

    1 episodeVisit ↗
  447. 447Articles

    Rapid Threat Model Prototyping slides

    Threat Modelling can be a laborious and time-consuming exercise, and is not a happy marriage with CI/DevOps methodologies. Introducing my Rapid Thre….

    1 episodeVisit ↗
  448. 448Projects

    Reaper

    Live validation proxy tool for testing web app vulnerabilities - ghostsecurity/reaper. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  449. 449Articles

    Redefining Threat Modeling (Segment blog)

    Explore technical topics, solutions, and resources for building with Twilio – and beyond. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  450. 450Books

    Ref=Sr 1 1

    Building in Security at Agile Speed [Ransome, James, Schoenfield, Brook] on Amazon. com.

    1 episodeVisit ↗
  451. 451Articles

    Reflections on Trusting Trust

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  452. 452Articles

    Rekor (Sigstore)

    The Rekor overview. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  453. 453Articles

    Release It! (2nd ed.)

    Design your application for maximum uptime, performance, and return on investment in the face of the harsh realities of the real world. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  454. 454Books

    Ringworld by Larry Niven

    Ringworld by Larry Niven is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  455. 455Articles

    Robert’s threat modeling resources

    What kind of security threats are lurking in your software or business? You need threat modeling!

    1 episodeVisit ↗
  456. 456Articles

    Ronnie's blog

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  457. 457Articles

    Royal Holloway Information Security

    Find out about our leading MSc degree, the world's oldest degree in information and cyber security. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  458. 458Articles

    S&P Global Ratings

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  459. 459Articles

    SARIF

    This document defines SARIF, a standard format for the output of static analysis tools. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  460. 460Articles

    Scott Hanselman: Overposting/Mass Assignment

    This little post is just a reminder that while Model Binding in ASP. NET is very ...

    1 episodeVisit ↗
  461. 461Articles

    Sean Wright’s blog

    Personal blog of application security advocate, blogging about application security related topics, focused primarily on web based applications. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  462. 462Articles

    Secrets management deployment guidance

    In a previous blog we talked about secure deployment. Secrets management is an important part of that.

    1 episodeVisit ↗
  463. 463Articles

    Secure Decisions

    What's In The Name? We create the technologies that help you make sense of your security data.

    1 episodeVisit ↗
  464. 464Books

    Secure, Resilient, and Agile Software Development

    Secure, Resilient, and Agile Software Development [Merkow, Mark] on Amazon. com.

    1 episodeVisit ↗
  465. 465Books

    Securing Systems: Applied Security Architecture and Threat Models

    Internet attack on computer systems is pervasive. It can take from less than a minute to as much as eight hours for an unprotected machine connected to the Inte.

    1 episodeVisit ↗
  466. 466Articles

    Securing Systems: Applied Security Architecture and Threat Models

    Securing Systems: Applied Security Architecture and Threat Models [Schoenfield, Brook S. E.

    1 episodeVisit ↗
  467. 467Books

    Security Assurance Using the Common Criteria

    Computer Security Assurance: 9781401862657: Computer Science Books @ Amazon. com.

    1 episodeVisit ↗
  468. 468Articles

    Security Coaches episode page

    Security programs improve when developers have someone who can help them want to get better, not merely tell them what they did wrong. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  469. 469Articles

    Security Compass

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  470. 470Articles

    Security Engineering by Ross Anderson

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  471. 471Articles

    Security in Computing

    Search. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  472. 472Projects

    Security Monkey

    Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time. - Netflix/security_monkey.

    1 episodeVisit ↗
  473. 473Courses

    segmentio/threat-modeling-training

    Segment's Threat Modeling training for our engineers - segmentio/threat-modeling-training. It provides structured security learning or training material.

    1 episodeVisit ↗
  474. 474Books

    Seveneves by Neal Stephenson

    Seveneves: A Novel [Stephenson, Neal] on Amazon. com.

    1 episodeVisit ↗
  475. 475Articles

    Shifting Engineering Right: What security engineers can learn from DevSecOps

    The security industry generally agrees on the value of enabling developers in an agile environment—although we don’t agree on what to call it… “Shifting Left,” “Creating a Paved Path,” “DevSecOps.” Regardless of the name, we tend to focus on teaching developers how to Sec, but there’s less focus on security engineers learning how to Dev.

    1 episodeVisit ↗
  476. 476Articles

    Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano)

    slides - The slides for the talks I've presented at various conferences and events (see https://www. lisihocke.

    1 episodeVisit ↗
  477. 477Articles

    SOAP 1.2 (W3C)

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  478. 478Books

    Software Transparency: Supply Chain Security in an Era of a Software-Driven Society

    Amazon. com: Software Transparency: Supply Chain Security in an Era of a Software-Driven Society: 9781394158485: Hughes, Chris, Turner, Tony, Springett, Steve, Friedman, Allan: Books.

    1 episodeVisit ↗
  479. 479Articles

    Software Transparency: Supply Chain Security in an Era of a Software-Driven Society

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  480. 480Articles

    Solve for Happy by Mo Gawdat

    Discover the equation for happiness in this international bestseller. Solve for Happy is a startlingly original book about creating and maintaining happiness….

    1 episodeVisit ↗
  481. 481Articles

    SQL Slammer

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  482. 482Projects

    SSLyze

    Fast and powerful SSL/TLS scanning library. Contribute to nabla-c0d3/sslyze development by creating an account on GitHub.

    1 episodeVisit ↗
  483. 483Projects

    Stackless Python

    The Stackless Python programming language. Contribute to stackless-dev/stackless development by creating an account on GitHub.

    1 episodeVisit ↗
  484. 484Articles

    Stephen E Ambrose

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  485. 485Articles

    Systems Thinking for Curious Managers by Russell Ackoff

    details of Triarchy. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  486. 486Articles

    TeamCity

    TeamCity keeps your delivery reliable, repeatable, and under control for both the humans and AI agents on your team. Sign up now.

    1 episodeVisit ↗
  487. 487Articles

    Techstars London

    Our London programs catalyse emerging startups from all over the world, across all verticals, leveraging the city's strengths in diversity, global outlook and talent. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  488. 488Books

    The AI Cybersecurity Handbook

    The AI Cybersecurity Handbook [Wong, Caroline] on Amazon. com.

    1 episodeVisit ↗
  489. 489Articles

    The Alignment Problem

    The Alignment Problem: Machine Learning and Human Values. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  490. 490Books

    The Black Swan by Nassim Nicholas Taleb

    NEW YORK TIMES BESTSELLER • The most influential book of the past seventy-five years: a groundbreaking exploration of everything we know about what... It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  491. 491Books

    The Body Keeps the Score

    #1 New York Times bestseller “Essential reading for anyone interested in understanding and treating traumatic stress and the scope of its impact... It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  492. 492Articles

    The Checklist Manifesto: How to Get Things Right

    The Checklist Manifesto: How to Get Things Right [Gawande, Atul] on Amazon. com.

    1 episodeVisit ↗
  493. 493Books

    The Crown Road by Iain Banks

    The Crow Road [Iain Banks] on Amazon. com.

    1 episodeVisit ↗
  494. 494Books

    The Cuckoo’s Egg by Clifford Stoll

    The Cuckoo’s Egg by Clifford Stoll is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  495. 495Articles

    The Ethical Algorithm 9780190948207

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  496. 496Books

    The Fifth Discipline

    The Fifth Discipline: The Art & Practice of The Learning Organization [Senge, Peter M. ] on Amazon.

    1 episodeVisit ↗
  497. 497Articles

    The Hard Thing About Hard Things Ben Horowitz

    Ben Horowitz, cofounder of the venture capital firm Andreessen Horowitz and one of Silicon Valley’s most respected and experienced entrepreneurs, offers ess... It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  498. 498Articles

    The Hedge episode 048

    Chris Romeo is a famous application security expert who has spent the last several years building a consulting and training company called Security Journey. Chris joins Tom and Russ to talk about the state of security and what network engineers need to know about security from an application perspective.

    1 episodeVisit ↗
  499. 499Articles

    The Metrics Manifesto by Richard Seiersen

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  500. 500Articles

    The Power of Habit by Charles Duhigg

    Discover 'The Power of Habit' by Charles Duhigg and learn how to transform your habits to improve your personal and professional life. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  501. 501Articles

    The Register (Security)

    Latest news and insight on information security and IT defenses. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  502. 502Books

    The Rust Programming Language

    The Rust Programming Language is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  503. 503Books

    The Web Application Hacker's Handbook

    For over a decade, The Web Application Hacker's Handbook (WAHH) has been the de facto standard reference book for people who are learning about web ... It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  504. 504Books

    Thinking Fast and Slow

    *Major New York Times Bestseller*More than 2. 6 million copies sold*One of The New York Times Book Review's ten best books of the year*Selected by The Wall St...

    1 episodeVisit ↗
  505. 505Standards

    thomasrbsa/BSA-Framework-for-Secure-Software

    The BSA Framework for Secure Software is a new tool to describe and assess security outcomes for software products and services, built on established best practices and the experiences of some of the world's leading software developers. The Framework is a living document that will be updated based on feedback from the Github community and other stakeholders.

    1 episodeVisit ↗
  506. 506Projects

    Threat Dragon source code

    An open source threat modeling tool from OWASP. Contribute to OWASP/threat-dragon development by creating an account on GitHub.

    1 episodeVisit ↗
  507. 507Books

    Threat Modeling (Adam Shostack)

    Updated techniques for predicting and preventing security problems before a single line of code is written by you (or by an agent). Get proven, jargon-free threat modeling frameworks for an AI world from Adam Shostack.

    1 episodeVisit ↗
  508. 508Articles

    Threat Modeling Gameplay with EoP

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  509. 509Articles

    Threat Modeling of Threat Modeling

    How can we make threat modeling a success? Read the analysis!

    1 episodeVisit ↗
  510. 510Books

    Threat Modeling: A Practical Guide for Development Teams

    Threat Modeling: A Practical Guide for Development Teams is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  511. 511Articles

    Threat Modeling: Designing for Security

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  512. 512Articles

    Threat Modeling: Designing for Security — first edition

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  513. 513Books

    Threat Playbook

    A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration - we45/ThreatPlaybook. It offers longer-form guidance and context on its subject.

    1 episodeVisit ↗
  514. 514Articles

    Tim Newsham's "Format String Attacks"

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  515. 515Articles

    TippingPoint (Trend Micro)

    More than an Intrusion Prevention System (IPS), Trend Micro's TippingPoint™ Protection System integrates with Trend Vision One. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  516. 516Standards

    tj-actions/changed-files advisory (CVE-2025-30066)

    GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

    1 episodeVisit ↗
  517. 517Articles

    Toastmasters International

    Thrive with new confidence by developing essential communication and leadership skills. Join our global community of 270,000+ professionals and unlock your full potential.

    1 episodeVisit ↗
  518. 518Communities

    Tommy Ross at RSA Conference

    Tommy Ross at RSA Conference is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.

    1 episodeVisit ↗
  519. 519Standards

    Top 10 CI/CD Security Risks

    Contribute to cider-security-research/top-10-cicd-security-risks development by creating an account on GitHub. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  520. 520Books

    Understanding Complexity

    Audiobook by Scott E. Page, The Great Courses, narrated by Scott E.

    1 episodeVisit ↗
  521. 521Articles

    UNESCO Recommendation on the Ethics of Artificial Intelligence

    UNESCO is committed to a future where AI and emerging technologies work for the people. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  522. 522Projects

    uutils/coreutils

    Cross-platform Rust rewrite of the GNU coreutils. Contribute to uutils/coreutils development by creating an account on GitHub.

    1 episodeVisit ↗
  523. 523Standards

    Veilid Application Framework

    Veilid is an open-source, distributed application framework. It documents security requirements, practices, or guidance for practitioners and teams.

    1 episodeVisit ↗
  524. 524Projects

    Venom (OVH)

    🐍 Manage and run your integration tests with efficiency - Venom run executors (script, HTTP Request, web, imap, etc... ) and assertions - ovh/venom.

    1 episodeVisit ↗
  525. 525Articles

    Venture in Security: solving the circle sticker problem

    Cybersecurity's circle stickers in a square box problem, how it's shaping the industry, and where we can go from here. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  526. 526Projects

    Visualizing the Software Supply Chain (GitHub)

    A project to visualize the software supply chain. Contribute to SecureStackCo/visualizing-software-supply-chain development by creating an account on GitHub.

    1 episodeVisit ↗
  527. 527Communities

    Volatility

    The Volatility Framework has become the world’s most widely used memory forensics tool. The Volatility Foundation helps keep Volatility going so that it may be used in perpetuity, free and open to all.

    1 episodeVisit ↗
  528. 528Articles

    Walter Isaacson

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  529. 529Articles

    Ward Cunningham

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  530. 530Books

    Watkins

    Named one of 100 Leadership & Success Books to Read in a Lifetime by Amazon Editors The world's most trusted guide for leaders in transition. Transit….

    1 episodeVisit ↗
  531. 531Articles

    Web Application Penetration Testing — Part 2

    Part two follows Daniel Ramsbrock into the practical workflow of a web application penetration test. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  532. 532Articles

    Werner Dietl

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  533. 533Articles

    What is Art by Leo Tolstoy

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  534. 534Articles

    Wiring the Winning Organization

    Drawing on decades of meticulous research of high-performing organizations and cross-population surveys of tens of thousands of employees, award-winning authors Gene Kim and Dr. Steven J.

    1 episodeVisit ↗
  535. 535Books

    With the Old Breed by E.B. Sledge

    NEW YORK TIMES BESTSELLER • “Of all the books about the ground war in the Pacific, [this] is the closest to a masterpiece.” —The...

    1 episodeVisit ↗
  536. 536Articles

    Women4Cyber Mentorship Programme

    An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗
  537. 537Projects

    WrongSecrets on GitHub

    Vulnerable app with examples showing how to not use secrets - commjoen/wrongsecrets. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  538. 538Projects

    WrongSecrets on GitHub

    Vulnerable app with examples showing how to not use secrets - OWASP/wrongsecrets. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  539. 539Projects

    Yoann Padioleau

    I like to code and do research on stuff to make it easier to code stuff - aryx. It is maintained as an open or collaborative project.

    1 episodeVisit ↗
  540. 540Tools

    ZAP API documentation

    ZAP API documentation is a security tool or technical reference discussed on the podcast and available from zaproxy. org.

    1 episodeVisit ↗
  541. 541Articles

    Zen of Python (PEP 20)

    Long time Pythoneer Tim Peters succinctly channels the BDFL’s guiding principles for Python’s design into 20 aphorisms, only 19 of which have been written down. It presents analysis, research, or practical guidance on its subject.

    1 episodeVisit ↗