The AppSec bookshelf and toolbox
Useful things from the show notes
A normalized catalogue of references from the complete archive, ranked by the number of distinct episodes that link to each one. Inclusion reflects discussion, not endorsement.
541 resources
1,222 episode links
Bookshelf and toolbox
541 shown- 01Standards
OWASP Top 10
The OWASP Top 10 is the reference standard for the most critical web application security risks. Adopting the OWASP Top 10 is perhaps the most effective first step towards changing your software….
32 episodesVisit ↗ - 02Tools
OWASP ZAP
Welcome to ZAP! It provides a technical capability or reference that security practitioners can evaluate directly.
28 episodesVisit ↗ - 03Communities
OWASP Foundation
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
22 episodesVisit ↗ - 04Communities
DEF CON
The largest hacking and security conference with presentations, workshops, contests, villages and the premier Capture The Flag Contest. It connects practitioners through a security community, event, or professional group.
18 episodesVisit ↗ - 05Tools
Docker
Docker is a platform designed to help developers build, share, and run container applications. We handle the tedious setup, so you can focus on the code.
18 episodesVisit ↗ - 06Projects
OWASP Juice Shop
The most modern and sophisticated insecure web application for security training, awareness demos, CTFs and security tool testing. Contains OWASP Top 10 vulnerabilities.
18 episodesVisit ↗ - 07Standards
OWASP Top 10 Proactive Controls
OWASP Top 10 Proactive Controls is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
18 episodesVisit ↗ - 08Projects
OWASP Proactive Controls
OWASP Top 10 Proactive Controls. It is maintained as an open or collaborative project.
17 episodesVisit ↗ - 09Projects
OWASP Dependency-Check
Dependency-Check is a Software Composition Analysis (SCA) tool suite that identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities. It is maintained as an open or collaborative project.
16 episodesVisit ↗ - 10Communities
Black Hat
Black Hat is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
15 episodesVisit ↗ - 11Standards
OWASP SAMM
Measure and improve your organization. It documents security requirements, practices, or guidance for practitioners and teams.
14 episodesVisit ↗ - 12Tools
Burp Suite
PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & identify the very latest vulnerabilities.
13 episodesVisit ↗ - 13Tools
Kubernetes
Kubernetes, also known as K8s, is an open source system for automating deployment, scaling, and management of containerized applications. It groups containers that make up an application into logical units for easy management and discovery.
13 episodesVisit ↗ - 14Tools
Semgrep
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions. It provides a technical capability or reference that security practitioners can evaluate directly.
12 episodesVisit ↗ - 15Standards
BSIMM
Benchmark your AppSec program with BSIMM assessment services from Black Duck. Get data-driven insights from 100+ organizations, identify security gaps, and build a customized Maturity Action Plan (MAP) to advance your software security posture.
11 episodesVisit ↗ - 16Standards
National Vulnerability Database (NVD)
National Vulnerability Database (NVD) is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
11 episodesVisit ↗ - 17Standards
OWASP Cheat Sheet Series
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
11 episodesVisit ↗ - 18Communities
OWASP Slack
Join the OWASP Foundation Slack workspace to connect with the global application security community. It connects practitioners through a security community, event, or professional group.
10 episodesVisit ↗ - 19Communities
RSA Conference
RSA Conference is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
9 episodesVisit ↗ - 20Tools
Brakeman
Brakeman is a static analysis security vulnerability scanner for Ruby on Rails applications. It provides a technical capability or reference that security practitioners can evaluate directly.
8 episodesVisit ↗ - 21Projects
OWASP Threat Dragon Project
OWASP Threat Dragon is a free, open-source, cross-platform threat modeling application used to draw threat modeling diagrams and to list threats for elements in the diagram. Threat Dragon is designed….
8 episodesVisit ↗ - 22Projects
OWASP Web Security Testing Guide (WSTG)
The Web Security Testing Guide (WSTG) Project produces the premier cybersecurity testing resource for web application developers and security professionals. It is maintained as an open or collaborative project.
8 episodesVisit ↗ - 23Articles
Terraform
Explore Terraform product documentation, tutorials, and examples. It presents analysis, research, or practical guidance on its subject.
8 episodesVisit ↗ - 24Articles
Attack Trees (Schneier)
Modeling security threats By Bruce Schneier Few people truly understand computer security, as illustrated by computer-security company marketing literature that touts “hacker proof software,” “triple-DES security,” and the like. In truth, unbreakable security is broken all the time, often in ways its designers never imagined.
7 episodesVisit ↗ - 25Articles
Content-Security-Policy (MDN)
The HTTP Content-Security-Policy response header allows website administrators to control resources the user agent is allowed to load for a given page. With a few exceptions, policies mostly involve specifying server origins and script endpoints.
7 episodesVisit ↗ - 26Articles
Log4j
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
7 episodesVisit ↗ - 27Tools
Microsoft Threat Modeling Tool
Overview of the Microsoft Threat Modeling Tool, containing information on getting started with the tool, including the Threat Modeling process. It provides a technical capability or reference that security practitioners can evaluate directly.
7 episodesVisit ↗ - 28Standards
MITRE ATT&CK Framework
MITRE ATT&CK Framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
7 episodesVisit ↗ - 29Tools
Node.js
Node. js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
7 episodesVisit ↗ - 30Projects
OWASP DevSlop Project
OWASP DevSlop - An OWASP incubator project. It is maintained as an open or collaborative project.
7 episodesVisit ↗ - 31Projects
WebGoat
OWASP WebGoat - An OWASP lab project. It is maintained as an open or collaborative project.
7 episodesVisit ↗ - 32Communities
BSides
BSides is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
6 episodesVisit ↗ - 33Articles
Corgea
Corgea finds, triages, and fixes vulnerabilities across code, packages, infrastructure, and containers. It presents analysis, research, or practical guidance on its subject.
6 episodesVisit ↗ - 34Projects
CycloneDX
Know what’s inside. See how it connects.
6 episodesVisit ↗ - 35Projects
GitHub Copilot
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
6 episodesVisit ↗ - 36Projects
GitHub Dependabot
You can use Dependabot to keep the packages you use updated to the latest versions. It is maintained as an open or collaborative project.
6 episodesVisit ↗ - 37Communities
Linux Foundation
Helping open technology projects build world class open source software, communities and companies. It connects practitioners through a security community, event, or professional group.
6 episodesVisit ↗ - 38Standards
OWASP Top Ten for LLM Applications project homepage
OWASP Top 10 for Large Language Model Applications - An OWASP lab project. It documents security requirements, practices, or guidance for practitioners and teams.
6 episodesVisit ↗ - 39Standards
PCI DSS
A global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments. It documents security requirements, practices, or guidance for practitioners and teams.
6 episodesVisit ↗ - 40Projects
The Phoenix Project
The bestselling novel that introduced the world to DevOps and the Three Ways — an IT manager with 90 days to save his company. By Gene Kim, Behr & Spafford.
6 episodesVisit ↗ - 41Projects
Bandit
Bandit is a tool designed to find common security issues in Python code. - PyCQA/bandit.
5 episodesVisit ↗ - 42Articles
Claude Code
Anthropic's agentic coding tool for developers. Claude Code understands your codebase, edits files, runs commands, and helps you ship faster.
5 episodesVisit ↗ - 43Articles
Fortify (OpenText)
OpenText Fortify SAST detects code vulnerabilities early with precise static code analysis, 45+ language support, and seamless CI/CD integration across the SDLC. It presents analysis, research, or practical guidance on its subject.
5 episodesVisit ↗ - 44Projects
ModSecurity
ModSecurity is the standard open-source web application firewall (WAF) engine. Originally designed as a module for the Apache HTTP Server, it has evolved to provide HTTP request and response….
5 episodesVisit ↗ - 45Projects
OWASP AppSensor
OWASP AppSensor - An OWASP incubator project. It is maintained as an open or collaborative project.
5 episodesVisit ↗ - 46Projects
OWASP Cornucopia
OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is maintained as an open or collaborative project.
5 episodesVisit ↗ - 47Projects
OWASP DefectDojo
The leading open source application vulnerability management tool built for DevOps and continuous security integration. It is maintained as an open or collaborative project.
5 episodesVisit ↗ - 48Standards
OWASP Password Storage Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
5 episodesVisit ↗ - 49Projects
OWASP pytm
pytm is a Pythonic framework for threat modeling. Define your system in Python using the elements and properties described in the pytm framework.
5 episodesVisit ↗ - 50Standards
OWASP SAMM
A Software Assurance Maturity Model (SAMM) that provides an effective and measurable way for all types of organizations to analyse and improve their software security posture. It documents security requirements, practices, or guidance for practitioners and teams.
5 episodesVisit ↗ - 51Articles
PASTA
PASTA threat modeling explained: the risk-centric, 7-stage methodology co-created by VerSprite's CEO to simulate real attacks and prioritize business risk. It presents analysis, research, or practical guidance on its subject.
5 episodesVisit ↗ - 52Projects
PyTM
A Pythonic framework for threat modeling. Contribute to OWASP/pytm development by creating an account on GitHub.
5 episodesVisit ↗ - 53Articles
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society by Chris Hughes, Tony Turner
Discover the new cybersecurity landscape of the interconnected software supply chain In Software Transparency: Supply Chain Security in an Era of a Software-Driven Society, a team of veteran information security professionals delivers an expert treatment of software supply chain security. In the book, you’ll explore real-world examples and guidance on how to defend your own organization against internal and ext.
5 episodesVisit ↗ - 54Books
Start With Why
This book is about how articulating your purpose can inspire you and those around you. Organizations and leaders that start with their purpose, or “why,” are….
5 episodesVisit ↗ - 55Books
The Application Security Program Handbook by Derek Fisher
Secure apps, fast. Your guide to a robust application security program.
5 episodesVisit ↗ - 56Standards
BSIMM
Benchmark your AppSec program with BSIMM assessment services from Black Duck. Get data-driven insights from 100+ organizations, identify security gaps, and build a customized Maturity Action Plan (MAP) to advance your software security posture.
4 episodesVisit ↗ - 57Courses
Cisco Security Ninja
Did you know that October is National Cyber Security Awareness Month? Here at Cisco, we understand how important cybersecurity is in today’s interconnected world.
4 episodesVisit ↗ - 58Communities
CodeMash conference
A volunteer-run developer conference at Kalahari Resort in Ohio and Virginia. Sessions, hands-on workshops, KidzMash, and the tech community you.
4 episodesVisit ↗ - 59Tools
Docker Hub
Welcome to the world's largest container registry built for developers and open source contributors to find, use, and share their container images. Build, push and pull.
4 episodesVisit ↗ - 60Articles
Executive Order 14028
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
4 episodesVisit ↗ - 61Projects
GitLab
The intelligent orchestration platform for DevSecOps, enabling teams and agents to ship trusted software at enterprise scale. It is maintained as an open or collaborative project.
4 episodesVisit ↗ - 62Articles
Mobile Testing Guide
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
4 episodesVisit ↗ - 63Projects
MultiJuicer
Host and manage multiple Juice Shop instances for security trainings and Capture The Flags - juice-shop/multi-juicer. It is maintained as an open or collaborative project.
4 episodesVisit ↗ - 64Projects
OWASP DevSecOps Maturity Model (DSOMM)
OWASP Devsecops Maturity Model - An OWASP lab project. It is maintained as an open or collaborative project.
4 episodesVisit ↗ - 65Standards
OWASP IoT Top 10
OWASP Internet of Things - An OWASP lab project. It documents security requirements, practices, or guidance for practitioners and teams.
4 episodesVisit ↗ - 66Projects
OWASP Women in AppSec (WIA)
Women in AppSec Respository. Contribute to OWASP/WIA development by creating an account on GitHub.
4 episodesVisit ↗ - 67Articles
PASTA (Process for Attack Simulation and Threat Analysis)
PASTA threat modeling explained: the risk-centric, 7-stage methodology co-created by VerSprite's CEO to simulate real attacks and prioritize business risk. It presents analysis, research, or practical guidance on its subject.
4 episodesVisit ↗ - 68Standards
PCI Security Standards Council
A global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments. It documents security requirements, practices, or guidance for practitioners and teams.
4 episodesVisit ↗ - 69Communities
Women in AppSec
This meetup is for anyone interested in supporting and mentoring women and minorities in cyber security. It is primarily the OWASP Foundation Women in Application Security (WIA), Diversity and Inclusion Committee & we also welcome all women and minorities in security.
4 episodesVisit ↗ - 70Articles
Aleph One's "Smashing The Stack for Fun and Profit"
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 71Books
Alice and Bob Learn Application Security
Learn application security from the very start, with this comprehensive and approachable guide! It offers longer-form guidance and context on its subject.
3 episodesVisit ↗ - 72Articles
Alice and Bob Learn Application Security
Learn application security from the very start, with this comprehensive and approachable guide! Alice and Bob Learn Application Security is an accessible and thorough resource for anyone seeking to incorporate, from the beginning of the System Development Life Cycle, best security practices in software development.
3 episodesVisit ↗ - 73Books
Applied Cryptography
Applied Cryptography Protocols, Algorithms, and Source Code in C A book by Bruce Schneier This second edition of the cryptography classic provides you with a comprehensive survey of modern cryptography. The book details how programmers and electronic communications professionals can use cryptography—the technique of enciphering and deciphering messages—to maintain the privacy of computer data.
3 episodesVisit ↗ - 74Articles
Artificial Intelligence
UNESCO is committed to a future where AI and emerging technologies work for the people. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 75Communities
B-Sides
B-Sides is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
3 episodesVisit ↗ - 76Tools
Burp Suite Professional
Burp Suite Professional is the world. It provides a technical capability or reference that security practitioners can evaluate directly.
3 episodesVisit ↗ - 77Projects
Chaos Monkey
Chaos Monkey is a resiliency tool that helps applications tolerate random instance failures. - Netflix/chaosmonkey.
3 episodesVisit ↗ - 78Articles
Cyber Kill Chain (Lockheed Martin)
Lockheed Martin's Cyber Kill Chain® strengthens cybersecurity. Prevent cyber intrusions with our Intelligence Driven Defense® model.
3 episodesVisit ↗ - 79Projects
DevSlop
DevSlop has 8 repositories available. Follow their code on GitHub.
3 episodesVisit ↗ - 80Articles
EU Cyber Resilience Act
The Cyber Resilience Act (CRA) aims to make sure all digital products are safe from cyber threats. This rulebook requires that devices and software are designed, updated, and maintained to protect users in our increasingly digital world.
3 episodesVisit ↗ - 81Articles
Maker's Schedule, Manager's Schedule
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 82Communities
Open Security Summit
Open Security Summit is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
3 episodesVisit ↗ - 83Projects
Open Threat Model (OTM)
The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system. - iriusrisk/OpenThreatModel.
3 episodesVisit ↗ - 84Articles
OpenID Connect
What is OpenID Connect OpenID Connect is an interoperable authentication protocol based on the OAuth 2. 0 framework of specifications (IETF RFC 6749 and 6750).
3 episodesVisit ↗ - 85Projects
OWASP Developer Guide
The OWASP Developer Guide provides an introduction to security concepts and an initial reference for application and system developers. The content of the Developer Guide aims to be accessible,….
3 episodesVisit ↗ - 86Communities
OWASP Triangle Chapter
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
3 episodesVisit ↗ - 87Projects
Pixi (DevSlop)
The Pixi module is a MEAN Stack web app with wildly insecure APIs! - DevSlop/Pixi.
3 episodesVisit ↗ - 88Articles
Sqreen (now Datadog AAP)
Monitor threats targeting production system, leveraging the execution context provided by distributed traces. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 89Articles
SSLlabs.com
A comprehensive free SSL test for your public web servers. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 90Articles
Tay (Microsoft chatbot)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 91Books
The DevOps Handbook
This award-winning and bestselling business handbook for digital transformation is now fully updated and expanded with the latest research and new case studies. It offers longer-form guidance and context on its subject.
3 episodesVisit ↗ - 92Articles
The Tangled Web
Browsers are doing a lot of strange things under the hood. Security expert Michal Zalewski explains what and why.
3 episodesVisit ↗ - 93Books
The Web Application Hacker's Handbook
The highly successful security book returns with a new edition, completely updated Web applications are the front door to most organizations, exposing them to attacks that may disclose personal information, execute fraudulent transactions, or compromise ordinary users. This practical book has been completely updated and revised to discuss the latest step-by-step techniques for attacking and defending the range of eve.
3 episodesVisit ↗ - 94Articles
Tim Ferriss
The Tim Ferriss Show The Tim Ferriss Show is one of the most popular podcasts in the world, with more than one billion downloads. It has been selected for “Best of Apple Podcasts” three times.
3 episodesVisit ↗ - 95Articles
VulnDB (Flashpoint)
Flashpoint Vulnerability Intelligence helps teams discover vulnerabilities, prioritize threats and protect critical assets. It presents analysis, research, or practical guidance on its subject.
3 episodesVisit ↗ - 96Projects
WebGoat
WebGoat is a deliberately insecure application. Contribute to WebGoat/WebGoat development by creating an account on GitHub.
3 episodesVisit ↗ - 97Tools
ZAP Heads Up Display (HUD)
The world’s most widely used web app scanner. Free and open source.
3 episodesVisit ↗ - 98Books
Agile Application Security
Agile Application Security is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 99Tools
Ansible Automation Platform
A platform for implementing enterprise-wide automation, no matter where you are in your automation journey. It provides a technical capability or reference that security practitioners can evaluate directly.
2 episodesVisit ↗ - 100Articles
AOL Search Data Leak
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 101Books
Application Security Program Handbook
Application Security Program Handbook is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 102Standards
AppScan Standard (HCL)
Protect applications with the HCL AppScan Application Security Testing Platform for SAST, DAST, IAST, API security, AI-powered remediation, and compliance. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 103Articles
ArcSight (OpenText)
SIEM security software to minimize MTTD and MTTR with industry-leading correlation, threat intelligence, native SOAR, and real-time threat detection. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 104Projects
Björn Kimminich on GitHub
IT Product Group Lead @kuehne-nagel, Project Leader @OWASP @juice-shop, Amateur MTG Player @mull2five - bkimminich. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 105Communities
Boston Application Security Conference
BASC 2027, the Boston Application Security Conference by OWASP Boston. One day of AppSec talks and workshops.
2 episodesVisit ↗ - 106Courses
Carnegie Mellon University Software Engineering Institute
Whether you work in the DoW, government, academia, or private industry, the SEI can partner with your organization to research and solve its hardest software challenges. It provides structured security learning or training material.
2 episodesVisit ↗ - 107Projects
ChaoSlingr
ChaoSlingr: Introducing Security into Chaos Testing - Optum/ChaoSlingr. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 108Articles
Chromium
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 109Articles
CISA Zero Trust Maturity Model
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 110Articles
CISSP
Gain the CISSP certification with ISC2 to demonstrate your expertise in cybersecurity leadership, implementation & management. Advance your career today!
2 episodesVisit ↗ - 111Articles
Code Red
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 112Communities
Converge Conference
Converge Conference brings together thinkers, builders and leaders for a day of keynotes, workshops and connection. Where ideas, people and industries converge.
2 episodesVisit ↗ - 113Articles
Core Software Security: Security at the Source
Core Software Security: Security at the Source [Ransome, James, Misra, Anmol] on Amazon. com.
2 episodesVisit ↗ - 114Articles
Crash Override
Software Observability for the AI era. The data plane for software, from prompt to production.
2 episodesVisit ↗ - 115Books
Crossing the Chasm
Amazon. com: Crossing the Chasm, 3rd Edition: The Updated Version of the Insightful Guide on Bringing Cutting-Edge Products to the Mainstream (Collins Business Essentials): 9780062292988: Moore, Geoffrey A.
2 episodesVisit ↗ - 116Articles
CSA IoT Working Group
CSA’s working groups develop best practices, research and tools for cloud security. Each group focuses on a unique topic or aspect of cloud security.
2 episodesVisit ↗ - 117Articles
CSSLP
Secure your cybersecurity career with ISC2’s CSSLP certification and gain expertise in software lifecycle security and secure coding practices. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 118Articles
Cyber For Builders
Helping security practitioners, entrepreneurs, investors and executives build the future of cybersecurity. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 119Projects
Damn Vulnerable Web App (DVWA)
Damn Vulnerable Web Application (DVWA). Contribute to digininja/DVWA development by creating an account on GitHub.
2 episodesVisit ↗ - 120Articles
DevSecOps Reference Architecture (Sonatype)
An interactive DevSecOps reference architecture illustrates manual and automated processes, plus interactions between systems, stakeholders, and security. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 121Articles
DoD STIG
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 122Articles
Elevation of Privilege
The Elevation of Privilege (EoP) threat modeling card game, created by Adam Shostack in 2010, is the easy way to get started threat modeling. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 123Articles
Exodus Communications
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 124Projects
Gauntlt
a ruggedization framework that embodies the principle "be mean to your code" - gauntlt/gauntlt. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 125Tools
Hacking Exposed Web Applications
Hacking exposed by Joel Scambray, 2011, McGraw-Hill edition, electronic resource : in English - 3rd ed. It provides a technical capability or reference that security practitioners can evaluate directly.
2 episodesVisit ↗ - 126Articles
IEEE Center for Secure Design
The world's leading society for computing and engineering. Access our research, certifications, and global community of tech innovators.
2 episodesVisit ↗ - 127Articles
INCLUDES NO DIRT paper
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 128Projects
IoTGoat
IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices. - OWASP/IoTGoat.
2 episodesVisit ↗ - 129Projects
James Wickett
wickett has 72 repositories available. Follow their code on GitHub.
2 episodesVisit ↗ - 130Projects
Jon McCoy on GitHub
theJonMccoy has 7 repositories available. Follow their code on GitHub.
2 episodesVisit ↗ - 131Projects
Kamus
An open source, git-ops, zero-trust secret encryption and decryption solution for Kubernetes applications - Soluto/kamus. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 132Tools
Kubernetes Admission Controllers
This page provides an overview of admission controllers. An admission controller is a piece of code that intercepts requests to the Kubernetes API server prior to persistence of the resource, but after the request is authenticated and authorized.
2 episodesVisit ↗ - 133Projects
LavaMoat
tools for sandboxing your dependency graph. Contribute to LavaMoat/LavaMoat development by creating an account on GitHub.
2 episodesVisit ↗ - 134Communities
Loco Moco Product Security Conference
Security Conference in Hawaiʻi. It connects practitioners through a security community, event, or professional group.
2 episodesVisit ↗ - 135Projects
multi-juicer GitHub
Host and manage multiple Juice Shop instances for security trainings and Capture The Flags - juice-shop/multi-juicer. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 136Books
Nassim Taleb books
Nassim Taleb books is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 137Communities
NDC Conferences
NDC Conferences has been delivering high-end events for software developers for more than 20 years. Our events range from large 5-day events with more than 2500 people to smaller niche events and workshops.
2 episodesVisit ↗ - 138Articles
Nessus
Find out more about Nessus - the trusted gold standard for vulnerability assessment, designed for modern attack surfaces - used by thousands of organizations. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 139Articles
Net.wars (Wendy Grossman)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 140Articles
Never Split The Difference Chris Vosstahl Raz
This international bestseller, with more than 5 million copies sold, offers a field-tested approach to high-stakes negotiations and conflict resolution—whet... It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 141Articles
New School Of Information Security 9780132800280
This is the eBook version of the printed book. "It is about time that a book like The New School came along.
2 episodesVisit ↗ - 142Standards
NIST AI Risk Management Framework
NIST AI Risk Management Framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 143Standards
NIST SP 800-53
This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. The controls are flexible and customiza.
2 episodesVisit ↗ - 144Standards
NIST SP 800-63
NIST SP 800-63 is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 145Standards
NIST SP 800-63B
NIST Special Publication 800-63B. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 146Projects
Node.js security working group
Node. js Ecosystem Security Working Group.
2 episodesVisit ↗ - 147Projects
nodejsscan
nodejsscan is a static security code scanner for Node. js applications.
2 episodesVisit ↗ - 148Articles
npm event-stream incident
npm Blog (Archive); updates from the npm team are now published on the GitHub Blog and the GitHub Changelog. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 149Articles
OAuth 2.0
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 150Articles
OWASP 2025 Global Board Elections
OWASP 2025 Global Board Elections on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
2 episodesVisit ↗ - 151Projects
OWASP AppSec Pipeline Project
OWASP Foundation Web Respository. Contribute to OWASP/www-project-appsec-pipeline development by creating an account on GitHub.
2 episodesVisit ↗ - 152Communities
OWASP Bangalore
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
2 episodesVisit ↗ - 153Projects
OWASP GenAI Security Project
Identifying and tackling the risks of Gen AI systems and applications OWASP GenAI Security Project A global community-driven and expert led initiative to create freely available open source guidance and resources for understanding and mitigating security and safety concerns for Generative AI applications and adoption. Join Now Members k+ Countries + AI Cybersecurity Publications + […].
2 episodesVisit ↗ - 154Articles
OWASP Global Board Candidates
OWASP Global Board Candidates on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
2 episodesVisit ↗ - 155Communities
OWASP Israel
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
2 episodesVisit ↗ - 156Standards
OWASP ISVS
OWASP IoT Security Verification Standard (ISVS). Contribute to OWASP/IoT-Security-Verification-Standard-ISVS development by creating an account on GitHub.
2 episodesVisit ↗ - 157Projects
OWASP Java Encoder Project
OWASP Java Encoder - An OWASP project. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 158Projects
OWASP Juice Shop
Probably the most modern and sophisticated insecure web application for security trainings, awareness demos and CTFs. Also great voluntary guinea pig for your security tools and DevSecOps pipelines!
2 episodesVisit ↗ - 159Articles
OWASP Juice Shop Jingle
Play OWASP Juice Shop Jingle by braimee on desktop and mobile. Play over 320 million tracks for free on SoundCloud.
2 episodesVisit ↗ - 160Standards
OWASP Low-Code/No-Code Top 10
The OWASP Low-Code/No-Code Top 10 is a documentation project aimed at helping organizations understand and manage security risks in Low-Code and No-Code applications. It highlights the main security challenges these types of applications face and provides guidance on how to tackle them.
2 episodesVisit ↗ - 161Communities
OWASP Montreal chapter
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
2 episodesVisit ↗ - 162Communities
OWASP Netherlands Chapter
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
2 episodesVisit ↗ - 163Projects
OWASP Nettacker
OWASP Nettacker is an automated penetration testing framework designed to help cyber security professionals and ethical hackers perform reconnaissance, vulnerability assessments, and network security…. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 164Projects
OWASP Project Spotlight Series
OWASP Foundation Web Respository. Contribute to OWASP/www-project-spotlight-series development by creating an account on GitHub.
2 episodesVisit ↗ - 165Standards
OWASP Security Knowledge Framework
Security Knowledge Framework (SKF) Python Flask / Angular project - blabla1337/skf-flask. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 166Standards
OWASP Security Knowledge Framework
OWASP Security Knowledge Framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 167Projects
OWASP SecurityRAT
OWASP SecurityRAT - An OWASP incubator project. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 168Standards
OWASP SQL Injection Prevention Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 169Standards
OWASP Top 10 project repository
Official OWASP Top 10 Document Repository. Contribute to OWASP/Top10 development by creating an account on GitHub.
2 episodesVisit ↗ - 170Articles
P200000007269
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 171Articles
PASTA Threat Modeling
PASTA threat modeling ties every step to business risk, not just technical findings. Here's why security leaders adopt it — and what it delivers.
2 episodesVisit ↗ - 172Articles
Patrick DeBois
Research notes, frameworks, and prototypes organized by stream — thoughts, tools, talks. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 173Projects
Puma Scan
Puma Scan is a software security Visual Studio extension that provides real time, continuous source code analysis as development teams write code. Vulnerabilities are immediately displayed in the development environment as spell check and compiler warnings, preventing security bugs from entering your applications.
2 episodesVisit ↗ - 174Tools
r2c / Semgrep Inc.
Semgrep is an industry leader that is profoundly improving software security and reliability, powering 75M+ source-code security scans. It provides a technical capability or reference that security practitioners can evaluate directly.
2 episodesVisit ↗ - 175Projects
RepoKid
AWS Least Privilege for Distributed, High-Velocity Deployment - Netflix/repokid. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 176Projects
retire.js
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
2 episodesVisit ↗ - 177Articles
Ron Rivest
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 178Projects
Roslyn (.NET Compiler Platform)
The Roslyn . NET compiler provides C# and Visual Basic languages with rich code analysis APIs.
2 episodesVisit ↗ - 179Courses
SANS SEC542
Build real-world web app offensive skills with a hands-on, repeatable process for finding, exploiting, and clearly proving the vulnerabilities that matter. It provides structured security learning or training material.
2 episodesVisit ↗ - 180Tools
SAST, DAST, IAST, and RASP: Pros, cons and how to choose
SAST, DAST, IAST, and RASP: Pros, cons and how to choose is a security tool or technical reference discussed on the podcast and available from learn. techbeacon.
2 episodesVisit ↗ - 181Books
Securing DevOps (Julien Vehent)
Integrate security into your DevOps pipeline and build safer cloud services. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 182Books
Security Chaos Engineering
Security Chaos Engineering is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 183Books
Security Metrics: A Beginner's Guide
Security Metrics, A Beginner. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 184Articles
Segment
Collect, unify, and enrich customer data across any app or device with the Twilio Segment CDP, now available on Twilio. com.
2 episodesVisit ↗ - 185Communities
Slack
Boost productivity and save time with Slack — the AI work platform for managing projects, automating workflows, and connecting teams securely. Start working smarter today.
2 episodesVisit ↗ - 186Articles
Slides on SpeakerDeck
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 187Articles
Software Security
This is the Mobipocket version of the print book. "When it comes to software security, the devil is in the details.
2 episodesVisit ↗ - 188Articles
Software Security: Building Security In
Software Security: Building Security In [McGraw, Gary] on Amazon. com.
2 episodesVisit ↗ - 189Books
Software Transparency
Amazon. com: Software Transparency: Supply Chain Security in an Era of a Software-Driven Society: 9781394158485: Hughes, Chris, Turner, Tony, Springett, Steve, Friedman, Allan: Books.
2 episodesVisit ↗ - 190Books
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
Amazon. com: Software Transparency: Supply Chain Security in an Era of a Software-Driven Society: 9781394158485: Hughes, Chris, Turner, Tony, Springett, Steve, Friedman, Allan: Books.
2 episodesVisit ↗ - 191Articles
SonarQube
Modernize your AI workflows with code verification for the agentic era. Fight AI slop & improve reliability through automated, explainable, and compliant code reviews.
2 episodesVisit ↗ - 192Communities
Source Conference
June 15-17, 2021, HOUSTON Tehas State University (USA, Tehas, Houston) holds the 4th International Scientific and Practical Conference “Web Programming and Internet Technologies (WebConf2021)” on June 15-17, 2021. The Chairman of the Organizing Committee is academician of the National Academy of Sciences Anton Vladimirovich Abramenko.
2 episodesVisit ↗ - 193Projects
Spring Security
Level up your Java code and explore what Spring can do for you. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 194Books
SRE Engineering
Explore the world of site reliability engineering with top-rated sre books. Find resources on SRE principles, best practices and the role of a reliability engineer.
2 episodesVisit ↗ - 195Projects
Steve Springett on GitHub
I build stuff, I break stuff, I develop stuff to protect stuff. Creator of @DependencyTrack.
2 episodesVisit ↗ - 196Articles
The Cuckoo's Egg
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 197Books
The Cuckoo's Egg by Cliff Stoll
The Cuckoo. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 198Books
The Developer's Playbook for Large Language Model Security
The Developer's Playbook for Large Language Model Security is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 199Articles
The Hard Thing About Hard Things by Ben Horowitz
Ben Horowitz, cofounder of the venture capital firm Andreessen Horowitz and one of Silicon Valley’s most respected and experienced entrepreneurs, offers ess... It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 200Tools
The left-pad incident
The left-pad incident is a security tool or technical reference discussed on the podcast and available from en. wikipedia.
2 episodesVisit ↗ - 201Articles
The Pentester Blueprint: Starting a Career as an Ethical Hacker
JUMPSTART YOUR NEW AND EXCITING CAREER AS A PENETRATION TESTER The Pentester BluePrint: Your Guide to Being a Pentester offers readers a chance to delve deeply into the world of the ethical, or "white-hat" hacker. Accomplished pentester and author Phillip L.
2 episodesVisit ↗ - 202Articles
The Pentester BluePrint: Starting A Career As An Ethical Hacker P 9781119684305
JUMPSTART YOUR NEW AND EXCITING CAREER AS A PENETRATION TESTER The Pentester BluePrint: Your Guide to Being a Pentester offers readers a chance to delve deeply into the world of the ethical, or "white-hat" hacker. Accomplished pentester and author Phillip L.
2 episodesVisit ↗ - 203Books
The Phoenix Project
The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win [Gene Kim, Kevin Behr, George Spafford] on Amazon. com.
2 episodesVisit ↗ - 204Projects
The Software Security Project
Persiapkan kecepatan respons Anda. MAXWIN88 menyediakan koleksi permainan aksi yang intens untuk menguji keterampilan strategis dan mekanis Anda.
2 episodesVisit ↗ - 205Books
The Unicorn Project
The Unicorn Project is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
2 episodesVisit ↗ - 206Projects
The Unicorn Project
The highly anticipated follow-up to the bestselling title The Phoenix Project, this book unveils the Five Ideals of Software Development. It is maintained as an open or collaborative project.
2 episodesVisit ↗ - 207Books
Threat Modeling: A Practical Guide for Development Teams
Amazon. com: Threat Modeling: A Practical Guide for Development Teams: 9781492056553: Tarandach, Izar, Coles, Matthew J.
2 episodesVisit ↗ - 208Articles
TLDR newsletter
TLDR delivers byte sized daily emails on Tech, AI, Web Development, Information Security, Startups, Product Management, DevOps, Marketing, Design and more! It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 209Articles
Trusted Computer System Evaluation Criteria
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 210Articles
Twilio
Build amazing customer experiences on the Twilio platform with APIs for SMS, RCS, voice, and email, plus conversational AI for smarter engagement, and identity verification for trust. It presents analysis, research, or practical guidance on its subject.
2 episodesVisit ↗ - 211Tools
VEX
VEX is a security tool or technical reference discussed on the podcast and available from cisa. gov.
2 episodesVisit ↗ - 212Standards
XSS Prevention Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
2 episodesVisit ↗ - 213Projects
0x Project
Developers’ one-stop shop to enable faster crypto trading, better prices, and superior UX. Get started now at 0x.
1 episodeVisit ↗ - 214Books
10 Steps Every CISO Should Take to Secure Next-Gen Software
10 Steps Every CISO Should Take to Secure Next-Gen Software is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 215Articles
2019 State of Open Source Security — developer ownership findings
A worrying 27% of respondents stated they do not have any proactive or automatic way to find out about newly discovered vulnerabilities in their applications. 37% of users of users don’t implement any sort of security testing during CI.
1 episodeVisit ↗ - 216Articles
7 Web Application Security Best Practices
This article contains a list of 7 web application security best practices that we believe should be considered in your web app security strategy. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 217Articles
9781260464009
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 218Articles
A Tester's Journey — Lisi's blog
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 219Projects
Aaron “kumavis” Davis on GitHub
kumavis has 514 repositories available. Follow their code on GitHub.
1 episodeVisit ↗ - 220Tools
Acunetix Web Scanner
Invicti Web + API is an end-to-end web security scanner that offers a 360 view of an organization’s security. Allowing you to take control of the security of all you web applications, web services, and APIs to ensure long-term protection.
1 episodeVisit ↗ - 221Articles
Aditya Gupta and Attify
Attify is a premium offensive security company founded by Aditya Gupta, author of The IoT Hacker's Handbook. Training, consulting, and research for IoT, mobile, and complex systems security.
1 episodeVisit ↗ - 222Articles
Adversarial Misuse of Generative AI (Javan's blog article)
We share our findings on government-backed and information operations threat actor use of the Gemini web application. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 223Articles
AICPA SOC for Service Organizations overview
This document provides an overview of SOC for Service Organizations Engagements. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 224Communities
Alpha-Omega
Alpha-Omega is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 225Articles
Amazon AWS outage caused by AI agent (Engadget)
A recent Amazon Web Services outage was reportedly caused by the company. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 226Tools
An Analysis of Open-source Automated Threat Modeling Tools and Their Extensibility from Security into Privacy
An Analysis of Open-source Automated Threat Modeling Tools and Their Extensibility from Security into Privacy is a security tool or technical reference discussed on the podcast and available from usenix. org.
1 episodeVisit ↗ - 227Articles
Anastasiia Voitova at Cossack Labs
Media coverage, press releases, company dates of Cossack Labs, data security solution company that builds software and custom solutions for innovative teams. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 228Articles
Andrew van der Stock at OWASP
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 229Books
Antifragile by Nassim Nicholas Taleb
NEW YORK TIMES BESTSELLER • Antifragile is a standalone book in Nassim Nicholas Taleb’s landmark Incerto series, an investigation of opacity,... It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 230Articles
Applied Cryptography
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 231Articles
Applied Cryptography
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 232Projects
AppSensor source code
A toolkit for building self-defending applications through real-time event detection and response - jtmelton/appsensor. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 233Articles
ArcSight ESM (OpenText)
ArcSight ESM analyzes and correlates every event that occurs across the organization--every login, logoff, file access, database query--to deliver accurate prioritization of security risks and compliance violations. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 234Articles
Atomic Habits
Packed with evidence-based strategies, Atomic Habits will teach you how to make small changes that will transform your habits and deliver amazing results. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 235Books
Austin Kleon books
Illustrated guides to creativity in the digital age by the New York Times bestselling author. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 236Projects
AWS Threat Composer
A simple threat modeling tool to help humans to reduce time-to-value when threat modeling - awslabs/threat-composer. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 237Tools
Azure Kubernetes Service
Discover Azure Kubernetes Service (AKS) for secure, scalable containerized app deployment and management with fast delivery on managed Kubernetes clusters. It provides a technical capability or reference that security practitioners can evaluate directly.
1 episodeVisit ↗ - 238Books
B09NRF399J
IDENTIFIED: A hacker thriller ripped from the headlines of today. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 239Communities
Becoming jaded with Security BSides’ Jack Daniel
Becoming jaded with Security BSides’ Jack Daniel is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 240Books
Being Henry Fonz And Beyond Henry Winkler
From Emmy-award winning actor, comedian, producer, and director Henry Winkler, a memoir of the effects of stardom and the struggle to become whole. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 241Articles
Bill Sempf’s developer profile
Stack Overflow. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 242Articles
Billion Laughs Attack
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 243Books
Black Hat GraphQL (book)
Written by hackers for hackers, this hands-on book shows how to identify vulnerabilities in apps that use GraphQL. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 244Articles
Blockchain Security A Need For Todays Businesses Complete Guide For Beginners
In this article we will know about Blockchain Security: A need for Today’s Businesses (Complete Guide for Beginners). It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 245Books
Books by Martin Fowler
Books by Martin Fowler is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 246Books
Books by Yuval Noah Harari
Prof. Yuval Noah Harari is a historian, philosopher and best-selling author of 'Sapiens' and 'Homo Deus'.
1 episodeVisit ↗ - 247Communities
Boston .NET Architecture Group
**Description****We are celebrating 22 years in December, 2025 / January, 2026! **We are a group of software developers and architects primarily in the Boston area that get together and discuss various topics about Patterns, .
1 episodeVisit ↗ - 248Communities
BSides Boulder
Official BSides Boulder Event Page. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 249Communities
BSides Las Vegas
BSides Las Vegas. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 250Communities
BSides San Antonio
General information about BSides SATX 2026. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 251Communities
BSides Singapore
Where Singapore. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 252Standards
BSIMM
BSIMM is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 253Books
Building In Security At Agile Speed
Building in Security at Agile Speed [Ransome, James, Schoenfield, Brook] on Amazon. com.
1 episodeVisit ↗ - 254Books
Building Secure and Reliable Systems
Building Secure and Reliable Systems is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 255Projects
Bundler Audit
Patch-level verification for Bundler. Contribute to rubysec/bundler-audit development by creating an account on GitHub.
1 episodeVisit ↗ - 256Articles
Can Kubernetes Keep a Secret? (blog)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 257Articles
CAWE
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 258Articles
Chalk
This is the main page for Chalk docs. Chalk is an open-source project created and maintained by Crash Override.
1 episodeVisit ↗ - 259Articles
Chrome 68 "Not Secure" HTTP Labeling
We're marking all sites that are not encrypted with HTTPS as “not secure”. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 260Projects
CI/CD Goat
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
1 episodeVisit ↗ - 261Tools
CIS Docker Benchmark
Download our step-by-step checklist to secure your platform: An objective, consensus-driven security guideline for Docker. It provides a technical capability or reference that security practitioners can evaluate directly.
1 episodeVisit ↗ - 262Articles
Cisco Secure
Defend users, apps, and data against today's threats. Enable your agentic enterprise at scale with an open, network-native platform.
1 episodeVisit ↗ - 263Books
CISO Desk Reference Guide
An easy to use guide written by experienced practitioners for recently-hired or promoted Chief Information Security Officers (CISOs), individuals aspiring to become a CISO, as well as business and technical professionals interested in the topic of cybersecurity, including Chief Technology Officers (CTOs), Chief Information Officers (CIOs), Boards of Directors, Chief Privacy Officers, and other executives responsible. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 264Articles
Claude Code source leak (VentureBeat)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 265Projects
CodeProject
An open or collaborative project discussed on the podcast and hosted at codeproject. com.
1 episodeVisit ↗ - 266Projects
Conflict Modeling (GitHub)
A place to gather and organize information about using threat modeling frameworks to deal with social conflict in online systems - adamshostack/conflictmodeling. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 267Articles
Conscious Business by Fred Kofman
Sitio Oficial de Fred Kofman, vicepresidente y asesor de desarrollo de liderazgo en Google, director del Centro de Liderazgo Consciente en Tecnológico de Monterrey, y fundador y presidente del Conscious Business Center International. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 268Articles
Consequence-driven Cyber-Informed Engineering (CCE)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 269Standards
Content Security Policy Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 270Books
Cooking for Geeks
Cooking for Geeks is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 271Articles
CORBA
CORBA is an open, vendor-independent architecture and infrastructure that computer applications use to work together over networks. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 272Books
Core Software Security
Core Software Security is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 273Projects
CrackQL
CrackQL is a GraphQL password brute-force and fuzzing utility. - nicholasaleks/CrackQL.
1 episodeVisit ↗ - 274Books
Critical System Thinking Book
Critical System Thinking Book is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 275Articles
Crossing The Chasm 3rd Edition Geoffrey A Moore
The bible for bringing cutting-edge products to larger markets is now revised and updated with new insights into the realities of high-tech marketing. With ...
1 episodeVisit ↗ - 276Articles
CSP is Dead, Long Live CSP (Google Research)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 277Standards
CVE-2017-5638
CVE-2017-5638 is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 278Standards
CWE-611
Common Weakness Enumeration (CWE) is a list of software weaknesses. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 279Articles
Cyber-Informed Engineering (INL)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 280Books
Cybersecurity First Principles: A Reboot of Strategy and Tactics
Cybersecurity First Principles: A Reboot of Strategy and Tactics [Howard, Rick] on Amazon. com.
1 episodeVisit ↗ - 281Articles
Cybersecurity Game Challenge
Build trust, shape a culture and kick start conversations. Physical games for in person threat modelling, training and fun.
1 episodeVisit ↗ - 282Projects
Damn Vulnerable GraphQL Application
Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security. - dolevf/Damn-Vulnerable-GraphQL-Application.
1 episodeVisit ↗ - 283Articles
DARPA Robotics Challenge
The DARPA Robotics Challenge (DRC) is a competition of robot systems and software teams vying to develop robots capable of assisting humans in responding to natural and man-made disasters. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 284Articles
Datadog State of Application Security report
We analyzed data from thousands of organizations to discover which vulnerabilities really matter, which threats present a risk, and other insights. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 285Articles
Dave Cheney: The Zen of Go
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 286Articles
Dave Kennedy
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 287Articles
David Habusha: Why did I join WhiteSource
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 288Articles
Designing Secure Software
An elegant, team-oriented guide for building security into the software design process. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 289Articles
Developers mentoring other developers: practices I've seen work well
How does mentoring work? I asked this question ten years into my software engineering career when I joined Uber.
1 episodeVisit ↗ - 290Books
DevSecOps Playbook (GitHub)
This is a step-by-step guide to implementing a DevSecOps program for any size organization - 6mile/DevSecOps-Playbook. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 291Projects
DevSecOps Studio
Virtual environment for learning DevSecOps. Contribute to secfigo/DevSecOps-Studio development by creating an account on GitHub.
1 episodeVisit ↗ - 292Articles
Difficult Conversations
Difficult Conversations, a New York Times best-seller by Douglas Stone & Sheila Heen, teaches effective communication skills & strategies for managing conflict. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 293Articles
Do Hard Things
A NATIONAL BESTSELLER \"In Do Hard Things, Steve Magness beautifully and persuasively reimagines our understanding of toughness. This is a must-read fo...
1 episodeVisit ↗ - 294Projects
DOMPurify
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks.
1 episodeVisit ↗ - 295Books
Drive
Drive is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 296Articles
DtSR Episode 204: On Changing Culture
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 297Articles
Dwarkesh Patel: "The Rise and Fall of Agent Civilizations"
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 298Articles
DZone: Introduction to DevSecOps
Learn key methods and techniques for implementing the DevSecOps methodology to ensure your cloud environments are secured effectively. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 299Articles
Effective Vulnerability Management by Chris Hughes
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 300Articles
Elastic (ELK) Stack
Reliably and securely take data from any source, in any format, then search, analyze, and visualize it in real time. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 301Articles
ENISA Securing Machine Learning Algorithms
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.
1 episodeVisit ↗ - 302Articles
Exploring container security
Exploring container security: This year, it’s all about security. Again.
1 episodeVisit ↗ - 303Books
Extreme Ownership
Looking for leadership courses? Online solutions help you learn key leadership principles on demand wherever you are.
1 episodeVisit ↗ - 304Projects
Faster Than Light (BugCatcher)
Faster Than Light has 14 repositories available. Follow their code on GitHub.
1 episodeVisit ↗ - 305Projects
Fennec.CLI
Fennec. NetCore - .
1 episodeVisit ↗ - 306Projects
Find the Document on the OWASP GitHub
OWASP API Security Project. Contribute to OWASP/API-Security development by creating an account on GitHub.
1 episodeVisit ↗ - 307Projects
FINOS Common Cloud Controls
View resources from FINOS Common Cloud Controls - an open standard project that describes consistent controls for compliant public cloud deployments in the financial services (FS) sector. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 308Projects
Flask
An open or collaborative project discussed on the podcast and hosted at flask. palletsprojects.
1 episodeVisit ↗ - 309Articles
FMCSA Hours of Service
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 310Books
Foundation by Isaac Asimov
Foundation [Asimov, Isaac] on Amazon. com.
1 episodeVisit ↗ - 311Standards
Framework
Align your product team and build products that people want to buy with Pragmatic's product management methodology. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 312Articles
Gene Hoffman
Gene Hoffman Chief Executive Officer and President Gene Hoffman has built and sold three companies to PGP, Inc. , Vivendi-Universal, and ...
1 episodeVisit ↗ - 313Articles
Gentoo GitHub Hack
News and information from Gentoo Linux. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 314Books
Georgia Weidman's book on penetration testing
Georgia Weidman wrote the book on pentesting. Literally.
1 episodeVisit ↗ - 315Articles
GIAC GWAPT
The GIAC Web Application Penetration Tester (GWAPT) certification validates a practitioner's ability to advance organization security through penetration testing and deep understanding of web application security issues. GWAPT certification holders are equipped with expertise in web application exploits and penetration testing methodology.
1 episodeVisit ↗ - 316Articles
GitGuardian State of Secrets Sprawl Report 2026
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 317Projects
GitHub
🧠 Socially Engineering LLMs 🤖 Hacking AI Agents 🦄 Node. js Secure Coding 🌟 @GitHub Star 🏅 @OpenJS Pathfinder award 4 Security 🥑 DevRel @snyksec - lirantal.
1 episodeVisit ↗ - 318Projects
GitHub
DJ is a DevOps pioneer and a security sommelier. djschleen has 34 repositories available.
1 episodeVisit ↗ - 319Articles
GitHub Octoverse
Insights into the state of open source on GitHub. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 320Projects
github/secure_headers
Manages application of security headers with many safe defaults - github/secure_headers. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 321Articles
Go html/template
Package template (html/template) implements data-driven templates for generating HTML output safe against code injection. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 322Standards
Goal Question Metric (GQM) framework
Goal Question Metric (GQM) framework is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 323Standards
Google Secure AI Framework (SAIF)
Building AI? Learn how to keep it secure with Google.
1 episodeVisit ↗ - 324Articles
Hackedu Acquires Security Journey
Combining content and experiments creates a platform that enhances learning for developers and product development professionals. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 325Books
Hacking Kubernetes (book)
Hacking Kubernetes (book) is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 326Articles
Hacking: The Art of Exploitation, Vol. 2
Hacking is creative problem solving: unconventional solutions, exploited weaknesses, and the technical foundation to pull it off. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 327Projects
hcltm (now threatcl) on GitHub
Documenting your Threat Models with HCL. Contribute to threatcl/threatcl development by creating an account on GitHub.
1 episodeVisit ↗ - 328Articles
Hi5
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 329Articles
Hi5signup
Read the Security Journey blog for expert insights on secure coding, application security trends, and developer-focused AppSec education. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 330Articles
How Leaders Create and Use Networks
Reprint: R0701C Most people acknowledge that networking—creating a fabric of personal contacts to provide support, feedback, insight, and resources—is an essential activity for an ambitious manager. Indeed, it’s a requirement even for those focused simply on doing their current jobs well.
1 episodeVisit ↗ - 331Articles
How to Measure Anything in Cybersecurity Risk, 2nd Edition
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 332Articles
HTTPS Everywhere (EFF)
You no longer need HTTPS Everywhere to set HTTPS by default! Major browsers now offer native support for an HTTPS only mode.
1 episodeVisit ↗ - 333Books
I Have No Mouth and I Must Scream
Amazon. com: I Have No Mouth & I Must Scream: 9781497643079: Ellison, Harlan: Books.
1 episodeVisit ↗ - 334Projects
iGoat Swift
OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS - OWASP/iGoat-Swift. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 335Articles
INCLUDES NO DIRT at Omada Health
INCLUDES NO DIRT: A Practical Threat Modeling Approach for Digital Healthcare and Beyond. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 336Articles
INCLUDES NO DIRT: A Practical Threat Modeling Approach for Digital Healthcare and Beyond
Omada - Resource Center Blog. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 337Communities
Information security needs community: 6 ways to build up your teams
Information security needs community: 6 ways to build up your teams is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 338Articles
InfoSec is Good People (Rob Graham)
For all that we complain about drama in our community, we are actually good people. At a small conference yesterday, I met "Kath".
1 episodeVisit ↗ - 339Articles
InfoSecSherpa
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 340Books
Intelligence Driven Incident Response
Intelligence Driven Incident Response is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 341Articles
Interest In Secure Design Practices Is Increasing Leading To Two Predictions
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 342Standards
Ipd
This NIST AI report develops a taxonomy of concepts and defines terminology in the field of adversarial machine learning (AML). The taxonomy is built on survey of the AML literature and is arranged in a conceptual hierarchy that includes key types of ML methods and lifecycle stage of attack, attacker goals and objectives, and attacker capabilities and knowledge of the learning process.
1 episodeVisit ↗ - 343Articles
iTextSharp
PLEASE NOTE: iTextSharp is EOL, and has been replaced by iText. Only security fixes will be added We HIGHLY recommend customers use iText for new projects, and to consider moving existing projects from...
1 episodeVisit ↗ - 344Projects
Java Observability Toolkit (JOT)
Java Observability Toolkit. Contribute to planetlevel/jot development by creating an account on GitHub.
1 episodeVisit ↗ - 345Articles
Jenga View of Threat Modeling whitepaper
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 346Projects
Jeremy Long on GitHub
Founder and project lead for dependency-check. jeremylong has 73 repositories available.
1 episodeVisit ↗ - 347Articles
Joe's Blog Post
HackEDU acquires Security Journey to create an industry-leading application security offering. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 348Projects
John Melton on GitHub
jtmelton has 15 repositories available. Follow their code on GitHub.
1 episodeVisit ↗ - 349Articles
John Willis
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 350Articles
Jon Callas
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 351Projects
Juice Shop source code
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application - juice-shop/juice-shop. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 352Books
Justin Rosenstein's original codemod on GitHub
Codemod is a tool/library to assist you with large-scale codebase refactors that can be partially automated but still require human oversight and occasional intervention. Codemod was developed at Facebook and released as open source.
1 episodeVisit ↗ - 353Articles
Kevin Greene on API security testing
Overcome software quality challenges & achieve continuous delivery at speed with Parasoft SOAtest, Virtualize, CTP, and DTP. Learn more!
1 episodeVisit ↗ - 354Articles
Kevin's article on Dark Reading
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 355Articles
KidzMash and the CodeMash experience
Part developer conference, part waterpark takeover. Deep technical sessions, hands-on workshops, the Makerspace, KidzMash, and 19 years of community.
1 episodeVisit ↗ - 356Articles
Latio's free reports
Compare 700+ cybersecurity tools and vendors with expert reviews, Latio scores, and AI-powered search. Find the right security tool for your stack.
1 episodeVisit ↗ - 357Projects
Lemur
Repository for the Lemur Certificate Manager. Contribute to Netflix/lemur development by creating an account on GitHub.
1 episodeVisit ↗ - 358Articles
Lex Fridman Podcast — Peter Steinberger on OpenClaw
Peter Steinberger is the creator of OpenClaw, an open-source AI agent framework that’s the fastest-growing project in GitHub history. Thank you for listening ❤ Check out our sponsors: https://lexfridman.
1 episodeVisit ↗ - 359Books
Life 3.0
Life 3. 0: Being Human in the Age of Artificial Intelligence [Tegmark, Max] on Amazon.
1 episodeVisit ↗ - 360Articles
LINDDUN research and publications
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 361Standards
LINQ to SQL
LINQ to SQL is a component of the . NET Framework that provides a runtime infrastructure for managing relational data as objects.
1 episodeVisit ↗ - 362Tools
lodash
lodash is a security tool or technical reference discussed on the podcast and available from npmjs. com.
1 episodeVisit ↗ - 363Books
Luna and the Magic AI Paintbrush
Amazon. com: Luna and the Magic AI Paintbrush: An AI Made Simple Book (Seriously Simple): 9789083414478: Schenk, Bessie, van der Veer, Rob, van Yperen, Mireille: Books.
1 episodeVisit ↗ - 364Books
Malware Analyst's Cookbook
Amazon. com: Malware Analyst.
1 episodeVisit ↗ - 365Articles
Mark Frost
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 366Communities
Mark Willis at RSA Conference
Mark Willis at RSA Conference is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 367Projects
Mark’s GitLab threat modeling article
As usual, we’re creating our own path in how we handle our threat modeling, approaching development both iteratively and collaboratively, and seriously shifting left with our framework and processes. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 368Books
Math Without Numbers
Buy Math Without Numbers on Amazon. com ✓ FREE SHIPPING on qualified orders.
1 episodeVisit ↗ - 369Articles
Matt Conover's "w00w00 on Heap Overflows"
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 370Articles
Maya's website
Maya Kaczorowski builds enterprise security tools that people actually want to use. Cofounder at Oblique, previously at Tailscale, GitHub, Google.
1 episodeVisit ↗ - 371Standards
Microsoft Responsible AI Standard, v2
Discover Microsoft AI tools, industry-specific governance solutions, and responsible AI practices to make smarter, more informed decisions about AI implementation. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 372Tools
Microsoft Safe C Library
An overview of secure CRT functions in the Microsoft C runtime. It provides a technical capability or reference that security practitioners can evaluate directly.
1 episodeVisit ↗ - 373Projects
Mike Goodwin on GitHub
mike-goodwin has 24 repositories available. Follow their code on GitHub.
1 episodeVisit ↗ - 374Projects
mike-goodwin/owasp-threat-dragon
An open source, online threat modelling tool from OWASP - mike-goodwin/owasp-threat-dragon. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 375Articles
Mitigating Risky Pull Requests With Monocle Risk Advisor Part 2 7013e1485bf2
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 376Projects
mitre-attack/attack-navigator
Web app that provides basic navigation and annotation of ATT&CK matrices - mitre-attack/attack-navigator. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 377Projects
Mono.Cecil
Cecil is a library to inspect, modify and create . NET programs and libraries.
1 episodeVisit ↗ - 378Articles
Monocle Part 1
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 379Standards
MOSAIC
MOSAIC is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 380Articles
Mozilla HTTP Observatory
Test your site’s HTTP headers, including CSP and HSTS, to find security problems and get actionable recommendations to make your website more secure. Test other websites to see how you compare.
1 episodeVisit ↗ - 381Articles
NASA Ingenuity Mars Helicopter
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 382Projects
Neil Smithline on GitHub
Appsec dude. OWASP Top-10 Co-Lead.
1 episodeVisit ↗ - 383Projects
Netflix Simian Army
Tools for keeping your cloud operating in top form. Chaos Monkey is a resiliency tool that helps applications tolerate random instance failures.
1 episodeVisit ↗ - 384Articles
NetWitness
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 385Books
Never Eat Alone
Keith Ferrazzi is an American entrepreneur and recognized global thought leader in the relational and collaborative sciences. As Chairman of Ferrazzi Greenlight and its Research Institute, he works to identify behaviors that block global organizations from reaching their goals and to transform them by coaching new behaviors that increase growth and shareholder value.
1 episodeVisit ↗ - 386Articles
Niels's blog
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 387Articles
Nimda
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 388Standards
NIST Digital Identity Guidelines
NIST Special Publication 800-63 Digital Identity Guidelines. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 389Standards
NIST OSCAL
NIST OSCAL is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 390Standards
NIST SP 800-190
Application container technologies, also known as containers, are a form of operating system virtualization combined with application software packaging. Containers provide a portable, reusable, and automatable way to package and run applications.
1 episodeVisit ↗ - 391Articles
NVIDIA NemoClaw
Agents are evolving from question-and-answer systems into long-running autonomous assistants that read files, call APIs, and drive multi-step workflows. However….
1 episodeVisit ↗ - 392Articles
NYDFS 23 NYCRR 500
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 393Articles
OECD AI Principles
OECD. AI helps countries and shape trustworthy AI with the OECD AI Principles.
1 episodeVisit ↗ - 394Projects
Omer Levi Hevroni on GitHub
Engineer @goledge , OSS maintainer and a proud father - omerlh. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 395Communities
Open Security Summit 2018 archive
Open Security Summit 2018 archive is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 396Articles
OpenAI Codex
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 397Projects
OpenClaw
The AI that really does things. Any OS.
1 episodeVisit ↗ - 398Projects
OpenVEX spec
OpenVEX Specification. Contribute to openvex/spec development by creating an account on GitHub.
1 episodeVisit ↗ - 399Articles
Operation ShadowHammer (Kaspersky)
Operation ShadowHammer is a newly discovered supply chain attack that leveraged ASUS Live Update software. While the investigation is still in progress and full results will be published during SAS 2019 conference, we would like to share some important details about the attack.
1 episodeVisit ↗ - 400Articles
OWASP Agentic Security Initiative
What’s New Resources Learning Videos Blog Download Now Download Now Download Now Download Now Download Now Download Now Project Audience – All Topics – Agentic Security More Events Audience – All Topics – Agentic Security More Training Audience – AI/Data Scientists, Developers, Practitioners Topics – Agentic Security More Events Audience – AI/Data Scientists, Architects, Developers, […]. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 401Tools
OWASP AppSec Pipeline Toolbox
OWASP AppSec Pipeline Toolbox is a security tool or technical reference discussed on the podcast and available from appsecpipeline. org.
1 episodeVisit ↗ - 402Communities
OWASP Bangalore
The OWASP Bangalore chapter is located in India and has been active since 2014, making it about 9 years old. It serves as a community for people interested in web security, offering public meetings that anyone can join without needing to be a member.
1 episodeVisit ↗ - 403Communities
OWASP Bay Area
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 404Communities
OWASP Bristol Chapter
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 405Communities
OWASP Chapters
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 406Projects
OWASP crAPI
completely ridiculous API (crAPI). Contribute to OWASP/crAPI development by creating an account on GitHub.
1 episodeVisit ↗ - 407Projects
OWASP Dependency-Check
Dependency-Check is a Software Composition Analysis (SCA) tool suite that identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 408Projects
OWASP Developer Guide
The Developer Guide provides an introduction to security concepts and an initial reference for application and system developers. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 409Articles
OWASP DevSecOps Guideline
OWASP Foundation Developer Guide project. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 410Projects
OWASP GenAI Security Project — Get Involved
T10 FOR GEN AI Project Contribute How to Contribute? The OWASP Top 10 for LLM Applications is an open source effort and we welcome all expert ideas, contributions, suggestions, and remarks.
1 episodeVisit ↗ - 411Communities
OWASP Global AppSec conferences
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 412Articles
OWASP Global AppSec USA 2026
Training Dates - November 2-4, 2026 / Conference Dates - November 5-6, 2026It's our 25th Anniversary year! Get ready for an unforgettable experience at the OWASP Global AppSec USA Conference!
1 episodeVisit ↗ - 413Articles
OWASP Global Board Candidates
OWASP Board of Directors election candidates. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 414Projects
OWASP Glue source code
Application Security Automation. Contribute to OWASP/glue development by creating an account on GitHub.
1 episodeVisit ↗ - 415Projects
OWASP iGoat
OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar - OWASP/igoat. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 416Communities
OWASP Israel
OWASP Israel is a large chapter that has been active for several years. It focuses on improving software security through various activities, including frequent meetings and organizing the AppSec Israel conference, with the next one scheduled for May 2025.
1 episodeVisit ↗ - 417Standards
OWASP Logging Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 418Communities
OWASP Maine
The Open Web Application Security Project® (OWASP) is a nonprofit foundation that works to improve the security of software through open-source tools, expert education, and collaborative innovation. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 419Communities
OWASP Montreal
The Montreal Chapter has been active for several years and is part of a larger non-profit organization focused on improving cybersecurity. This chapter is open to everyone, and you do not need to be a member to attend their meetings.
1 episodeVisit ↗ - 420Projects
OWASP Secure Headers Project
The OWASP Secure Headers Project (OSHP) describes HTTP response headers that your application can use to increase the security of your application. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 421Projects
OWASP Security Shepherd
OWASP Security Shepherd is a web and mobile application security training platform. Security Shepherd has been designed to foster and improve security awareness among a varied skill-set demographic.
1 episodeVisit ↗ - 422Projects
OWASP Threat Model Library
OWASP Threat Model Library - An OWASP incubator project. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 423Standards
OWASP Top 10:2021
OWASP Top 10:2021 is a security standard, framework, or guidance reference discussed on the podcast. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 424Standards
OWASP Top 10:2025
OWASP Top 10:2025. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 425Standards
OWASP Top 10:2025
OWASP Top 10:2025. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 426Communities
OWASP Triangle
The Triangle-North Carolina chapter of OWASP has been active for a while, fostering a community focused on web application security. It is led by Chris Romeo and Steve Pinkham, who keep members updated through platforms like Meetup and Twitter.
1 episodeVisit ↗ - 427Projects
OWASP WrongSecrets project
Examples with how to not use secrets. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 428Standards
OWASP XXE Prevention Cheat Sheet
Website with the collection of all the cheat sheets of the project. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 429Articles
PASTA threat modeling
PASTA threat modeling explained: the risk-centric, 7-stage methodology co-created by VerSprite's CEO to simulate real attacks and prioritize business risk. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 430Articles
PBKDF2 (RFC 2898)
This document provides recommendations for the implementation of password-based cryptography, covering key derivation functions, encryption schemes, message-authentication schemes, and ASN. 1 syntax identifying the techniques.
1 episodeVisit ↗ - 431Books
People-Centric Security
People-Centric Security: Transforming Your Enterprise Security Culture: 9780071846776: Computer Science Books @ Amazon. com.
1 episodeVisit ↗ - 432Articles
Peter Checkland
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 433Projects
Peter Steinberger
Came back from retirement to mess with AI. Clawdfather @OpenClaw Previously: Founder of @PSPDFKit.
1 episodeVisit ↗ - 434Articles
Phantoms in the Brain: Probing the Mysteries of the Human Mind
Neuroscientist V. S.
1 episodeVisit ↗ - 435Articles
Phantoms in the Brain: Probing the Mysteries of the Human Mind
Neuroscientist V. S.
1 episodeVisit ↗ - 436Projects
Poutine
poutine, a supply chain vulnerability scanner for build pipelines - boostsecurityio/poutine. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 437Courses
Press Release: HackEDU Acquires Security Journey
Press Release: HackEDU Acquires Security Journey is a course, workshop, or training resource mentioned in episode show notes. It provides structured security learning or training material.
1 episodeVisit ↗ - 438Standards
PSIRT Services Framework (FIRST.org)
PSIRT Services Framework (FIRST. org) is a security standard, framework, or guidance reference discussed on the podcast.
1 episodeVisit ↗ - 439Standards
Purple Team Exercise Framework
Purple Team Exercise Framework. Contribute to scythe-io/purple-team-exercise-framework development by creating an account on GitHub.
1 episodeVisit ↗ - 440Articles
Pwning OWASP Juice Shop
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 441Projects
pytm GitHub page
A Pythonic framework for threat modeling. Contribute to izar/pytm development by creating an account on GitHub.
1 episodeVisit ↗ - 442Articles
Qualys Web Application Scanning
Qualys Web App Scanning security software and tools deliver automated vulnerability detection and continuous monitoring to protect your web applications from emerging threats. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 443Books
Quiet Influence
Quiet Influence is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 444Articles
Rails security guide
This guide describes common security problems in web applications and how to avoid them with Rails. After reading this guide, you will know: How to use the built-in authentication generator.
1 episodeVisit ↗ - 445Articles
Rakuten: Democratizing AppSec
Three of Rakuten’s cyber security professionals contributed topics on the theme of AppSec democratization at the OWASP 2022 Global AppSec APAC Conference. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 446Projects
Rapid Threat Model Prototyping documentation
This repository stores content that can be used to design a Rapid Threat Model Prototyping process for a software development group. - geoffrey-hill-tutamantic/rapid-threat-model-prototyping-docs.
1 episodeVisit ↗ - 447Articles
Rapid Threat Model Prototyping slides
Threat Modelling can be a laborious and time-consuming exercise, and is not a happy marriage with CI/DevOps methodologies. Introducing my Rapid Thre….
1 episodeVisit ↗ - 448Projects
Reaper
Live validation proxy tool for testing web app vulnerabilities - ghostsecurity/reaper. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 449Articles
Redefining Threat Modeling (Segment blog)
Explore technical topics, solutions, and resources for building with Twilio – and beyond. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 450Books
Ref=Sr 1 1
Building in Security at Agile Speed [Ransome, James, Schoenfield, Brook] on Amazon. com.
1 episodeVisit ↗ - 451Articles
Reflections on Trusting Trust
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 452Articles
Rekor (Sigstore)
The Rekor overview. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 453Articles
Release It! (2nd ed.)
Design your application for maximum uptime, performance, and return on investment in the face of the harsh realities of the real world. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 454Books
Ringworld by Larry Niven
Ringworld by Larry Niven is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 455Articles
Robert’s threat modeling resources
What kind of security threats are lurking in your software or business? You need threat modeling!
1 episodeVisit ↗ - 456Articles
Ronnie's blog
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 457Articles
Royal Holloway Information Security
Find out about our leading MSc degree, the world's oldest degree in information and cyber security. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 458Articles
S&P Global Ratings
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 459Articles
SARIF
This document defines SARIF, a standard format for the output of static analysis tools. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 460Articles
Scott Hanselman: Overposting/Mass Assignment
This little post is just a reminder that while Model Binding in ASP. NET is very ...
1 episodeVisit ↗ - 461Articles
Sean Wright’s blog
Personal blog of application security advocate, blogging about application security related topics, focused primarily on web based applications. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 462Articles
Secrets management deployment guidance
In a previous blog we talked about secure deployment. Secrets management is an important part of that.
1 episodeVisit ↗ - 463Articles
Secure Decisions
What's In The Name? We create the technologies that help you make sense of your security data.
1 episodeVisit ↗ - 464Books
Secure, Resilient, and Agile Software Development
Secure, Resilient, and Agile Software Development [Merkow, Mark] on Amazon. com.
1 episodeVisit ↗ - 465Books
Securing Systems: Applied Security Architecture and Threat Models
Internet attack on computer systems is pervasive. It can take from less than a minute to as much as eight hours for an unprotected machine connected to the Inte.
1 episodeVisit ↗ - 466Articles
Securing Systems: Applied Security Architecture and Threat Models
Securing Systems: Applied Security Architecture and Threat Models [Schoenfield, Brook S. E.
1 episodeVisit ↗ - 467Books
Security Assurance Using the Common Criteria
Computer Security Assurance: 9781401862657: Computer Science Books @ Amazon. com.
1 episodeVisit ↗ - 468Articles
Security Coaches episode page
Security programs improve when developers have someone who can help them want to get better, not merely tell them what they did wrong. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 469Articles
Security Compass
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 470Articles
Security Engineering by Ross Anderson
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 471Articles
Security in Computing
Search. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 472Projects
Security Monkey
Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time. - Netflix/security_monkey.
1 episodeVisit ↗ - 473Courses
segmentio/threat-modeling-training
Segment's Threat Modeling training for our engineers - segmentio/threat-modeling-training. It provides structured security learning or training material.
1 episodeVisit ↗ - 474Books
Seveneves by Neal Stephenson
Seveneves: A Novel [Stephenson, Neal] on Amazon. com.
1 episodeVisit ↗ - 475Articles
Shifting Engineering Right: What security engineers can learn from DevSecOps
The security industry generally agrees on the value of enabling developers in an agile environment—although we don’t agree on what to call it… “Shifting Left,” “Creating a Paved Path,” “DevSecOps.” Regardless of the name, we tend to focus on teaching developers how to Sec, but there’s less focus on security engineers learning how to Dev.
1 episodeVisit ↗ - 476Articles
Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano)
slides - The slides for the talks I've presented at various conferences and events (see https://www. lisihocke.
1 episodeVisit ↗ - 477Articles
SOAP 1.2 (W3C)
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 478Books
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
Amazon. com: Software Transparency: Supply Chain Security in an Era of a Software-Driven Society: 9781394158485: Hughes, Chris, Turner, Tony, Springett, Steve, Friedman, Allan: Books.
1 episodeVisit ↗ - 479Articles
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 480Articles
Solve for Happy by Mo Gawdat
Discover the equation for happiness in this international bestseller. Solve for Happy is a startlingly original book about creating and maintaining happiness….
1 episodeVisit ↗ - 481Articles
SQL Slammer
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 482Projects
SSLyze
Fast and powerful SSL/TLS scanning library. Contribute to nabla-c0d3/sslyze development by creating an account on GitHub.
1 episodeVisit ↗ - 483Projects
Stackless Python
The Stackless Python programming language. Contribute to stackless-dev/stackless development by creating an account on GitHub.
1 episodeVisit ↗ - 484Articles
Stephen E Ambrose
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 485Articles
Systems Thinking for Curious Managers by Russell Ackoff
details of Triarchy. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 486Articles
TeamCity
TeamCity keeps your delivery reliable, repeatable, and under control for both the humans and AI agents on your team. Sign up now.
1 episodeVisit ↗ - 487Articles
Techstars London
Our London programs catalyse emerging startups from all over the world, across all verticals, leveraging the city's strengths in diversity, global outlook and talent. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 488Books
The AI Cybersecurity Handbook
The AI Cybersecurity Handbook [Wong, Caroline] on Amazon. com.
1 episodeVisit ↗ - 489Articles
The Alignment Problem
The Alignment Problem: Machine Learning and Human Values. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 490Books
The Black Swan by Nassim Nicholas Taleb
NEW YORK TIMES BESTSELLER • The most influential book of the past seventy-five years: a groundbreaking exploration of everything we know about what... It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 491Books
The Body Keeps the Score
#1 New York Times bestseller “Essential reading for anyone interested in understanding and treating traumatic stress and the scope of its impact... It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 492Articles
The Checklist Manifesto: How to Get Things Right
The Checklist Manifesto: How to Get Things Right [Gawande, Atul] on Amazon. com.
1 episodeVisit ↗ - 493Books
The Crown Road by Iain Banks
The Crow Road [Iain Banks] on Amazon. com.
1 episodeVisit ↗ - 494Books
The Cuckoo’s Egg by Clifford Stoll
The Cuckoo’s Egg by Clifford Stoll is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 495Articles
The Ethical Algorithm 9780190948207
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 496Books
The Fifth Discipline
The Fifth Discipline: The Art & Practice of The Learning Organization [Senge, Peter M. ] on Amazon.
1 episodeVisit ↗ - 497Articles
The Hard Thing About Hard Things Ben Horowitz
Ben Horowitz, cofounder of the venture capital firm Andreessen Horowitz and one of Silicon Valley’s most respected and experienced entrepreneurs, offers ess... It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 498Articles
The Hedge episode 048
Chris Romeo is a famous application security expert who has spent the last several years building a consulting and training company called Security Journey. Chris joins Tom and Russ to talk about the state of security and what network engineers need to know about security from an application perspective.
1 episodeVisit ↗ - 499Articles
The Metrics Manifesto by Richard Seiersen
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 500Articles
The Power of Habit by Charles Duhigg
Discover 'The Power of Habit' by Charles Duhigg and learn how to transform your habits to improve your personal and professional life. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 501Articles
The Register (Security)
Latest news and insight on information security and IT defenses. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 502Books
The Rust Programming Language
The Rust Programming Language is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 503Books
The Web Application Hacker's Handbook
For over a decade, The Web Application Hacker's Handbook (WAHH) has been the de facto standard reference book for people who are learning about web ... It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 504Books
Thinking Fast and Slow
*Major New York Times Bestseller*More than 2. 6 million copies sold*One of The New York Times Book Review's ten best books of the year*Selected by The Wall St...
1 episodeVisit ↗ - 505Standards
thomasrbsa/BSA-Framework-for-Secure-Software
The BSA Framework for Secure Software is a new tool to describe and assess security outcomes for software products and services, built on established best practices and the experiences of some of the world's leading software developers. The Framework is a living document that will be updated based on feedback from the Github community and other stakeholders.
1 episodeVisit ↗ - 506Projects
Threat Dragon source code
An open source threat modeling tool from OWASP. Contribute to OWASP/threat-dragon development by creating an account on GitHub.
1 episodeVisit ↗ - 507Books
Threat Modeling (Adam Shostack)
Updated techniques for predicting and preventing security problems before a single line of code is written by you (or by an agent). Get proven, jargon-free threat modeling frameworks for an AI world from Adam Shostack.
1 episodeVisit ↗ - 508Articles
Threat Modeling Gameplay with EoP
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 509Articles
Threat Modeling of Threat Modeling
How can we make threat modeling a success? Read the analysis!
1 episodeVisit ↗ - 510Books
Threat Modeling: A Practical Guide for Development Teams
Threat Modeling: A Practical Guide for Development Teams is a book or longer-form guide mentioned in episode show notes. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 511Articles
Threat Modeling: Designing for Security
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 512Articles
Threat Modeling: Designing for Security — first edition
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 513Books
Threat Playbook
A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration - we45/ThreatPlaybook. It offers longer-form guidance and context on its subject.
1 episodeVisit ↗ - 514Articles
Tim Newsham's "Format String Attacks"
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 515Articles
TippingPoint (Trend Micro)
More than an Intrusion Prevention System (IPS), Trend Micro's TippingPoint™ Protection System integrates with Trend Vision One. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 516Standards
tj-actions/changed-files advisory (CVE-2025-30066)
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
1 episodeVisit ↗ - 517Articles
Toastmasters International
Thrive with new confidence by developing essential communication and leadership skills. Join our global community of 270,000+ professionals and unlock your full potential.
1 episodeVisit ↗ - 518Communities
Tommy Ross at RSA Conference
Tommy Ross at RSA Conference is a security community, event, or professional group mentioned in episode show notes. It connects practitioners through a security community, event, or professional group.
1 episodeVisit ↗ - 519Standards
Top 10 CI/CD Security Risks
Contribute to cider-security-research/top-10-cicd-security-risks development by creating an account on GitHub. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 520Books
Understanding Complexity
Audiobook by Scott E. Page, The Great Courses, narrated by Scott E.
1 episodeVisit ↗ - 521Articles
UNESCO Recommendation on the Ethics of Artificial Intelligence
UNESCO is committed to a future where AI and emerging technologies work for the people. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 522Projects
uutils/coreutils
Cross-platform Rust rewrite of the GNU coreutils. Contribute to uutils/coreutils development by creating an account on GitHub.
1 episodeVisit ↗ - 523Standards
Veilid Application Framework
Veilid is an open-source, distributed application framework. It documents security requirements, practices, or guidance for practitioners and teams.
1 episodeVisit ↗ - 524Projects
Venom (OVH)
🐍 Manage and run your integration tests with efficiency - Venom run executors (script, HTTP Request, web, imap, etc... ) and assertions - ovh/venom.
1 episodeVisit ↗ - 525Articles
Venture in Security: solving the circle sticker problem
Cybersecurity's circle stickers in a square box problem, how it's shaping the industry, and where we can go from here. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 526Projects
Visualizing the Software Supply Chain (GitHub)
A project to visualize the software supply chain. Contribute to SecureStackCo/visualizing-software-supply-chain development by creating an account on GitHub.
1 episodeVisit ↗ - 527Communities
Volatility
The Volatility Framework has become the world’s most widely used memory forensics tool. The Volatility Foundation helps keep Volatility going so that it may be used in perpetuity, free and open to all.
1 episodeVisit ↗ - 528Articles
Walter Isaacson
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 529Articles
Ward Cunningham
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 530Books
Watkins
Named one of 100 Leadership & Success Books to Read in a Lifetime by Amazon Editors The world's most trusted guide for leaders in transition. Transit….
1 episodeVisit ↗ - 531Articles
Web Application Penetration Testing — Part 2
Part two follows Daniel Ramsbrock into the practical workflow of a web application penetration test. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 532Articles
Werner Dietl
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 533Articles
What is Art by Leo Tolstoy
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 534Articles
Wiring the Winning Organization
Drawing on decades of meticulous research of high-performing organizations and cross-population surveys of tens of thousands of employees, award-winning authors Gene Kim and Dr. Steven J.
1 episodeVisit ↗ - 535Books
With the Old Breed by E.B. Sledge
NEW YORK TIMES BESTSELLER • “Of all the books about the ground war in the Pacific, [this] is the closest to a masterpiece.” —The...
1 episodeVisit ↗ - 536Articles
Women4Cyber Mentorship Programme
An article, report, or research reference discussed on the podcast. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗ - 537Projects
WrongSecrets on GitHub
Vulnerable app with examples showing how to not use secrets - commjoen/wrongsecrets. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 538Projects
WrongSecrets on GitHub
Vulnerable app with examples showing how to not use secrets - OWASP/wrongsecrets. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 539Projects
Yoann Padioleau
I like to code and do research on stuff to make it easier to code stuff - aryx. It is maintained as an open or collaborative project.
1 episodeVisit ↗ - 540Tools
ZAP API documentation
ZAP API documentation is a security tool or technical reference discussed on the podcast and available from zaproxy. org.
1 episodeVisit ↗ - 541Articles
Zen of Python (PEP 20)
Long time Pythoneer Tim Peters succinctly channels the BDFL’s guiding principles for Python’s design into 20 aphorisms, only 19 of which have been written down. It presents analysis, research, or practical guidance on its subject.
1 episodeVisit ↗