Topics
16 subjects the show keeps returning to, drawn from what was actually said across 305 episodes rather than from tags nobody wrote.
SAST, DAST, IAST, fuzzing and penetration testing, and the false-positive problem that decides whether any of them get used.
Finding what can go wrong before it does — STRIDE, LINDDUN, data flow diagrams, and the practice of doing it at scale.
Dependencies, SBOMs, provenance and the long tail of open source that ships inside everything.
Injection, XSS, deserialization and the rest of the catalogue — plus bug bounty, disclosure, and what happens after a report lands.
The tools and standards that come out of OWASP — ZAP, ASVS, SAMM, Juice Shop, the Cheat Sheets, and the people who build them.
Security inside the pipeline — CI/CD, automation, shift left, and the difference between a gate and a guardrail.
Getting into application security and going further — origin stories, hiring, mentoring, certifications, and teaching the next generation.
GDPR, PCI, SOC 2 and the Cyber Resilience Act, and where regulation and engineering actually meet.
The list that most organisations meet first, how each revision was assembled, and what it is and is not good for.
Standing up and growing an application security function — maturity models, champions, metrics, and getting the budget.
Containers, Kubernetes, infrastructure as code and the misconfigurations that make cloud its own discipline.
Writing software that resists attack: secure defaults, guardrails, paved roads, code review, and training that developers will sit through.
Why developers do or do not adopt security — empathy, blamelessness and influence rather than mandates — and looking after the people doing the work, from burnout to neurodiversity.
REST and GraphQL, authentication and authorization, and the object-level access control failures that dominate real breaches.
Securing systems built on large language models, and what changes when the attacker writes the input and the model writes the code.
DEF CON villages, BSides, OWASP chapters and the volunteer effort that holds the field together.
Topics are derived from the transcripts, so an episode appears under a subject when it genuinely spends time there — never from a passing mention. Most carry two or three. The full archive is at all episodes.