Josh Grossman--AI & SAST: Is it a match?
AI coding tools are accelerating development fast, but they’re also exposing the limits of traditional AppSec tooling.
Listen to the episodeTopic
REST and GraphQL, authentication and authorization, and the object-level access control failures that dominate real breaches.
AI coding tools are accelerating development fast, but they’re also exposing the limits of traditional AppSec tooling.
Listen to the episodeGitGuardian found 29 million hard-coded secrets leaked in public GitHub commits in a single year, a 34% jump and the biggest spike they've ever recorded.
Listen to the episodeOur guest today is Akansha Shukla, an information security professional with over 10 years of experience in application security, DevSecOps, and API security.
Listen to the episodeMatin Mavaddat discusses his perspective on security as a systemic concern, developed from his background in requirements engineering and systems architecture.
Listen to the episodeJeff Williams, a renowned pioneer in the field of application security is with us to discuss Application Detection and Response (ADR), detailing its…
Listen to the episodeAndrew Van Der Stok, a leading web application security specialist and executive director at OWASP joins us for this episode.
Listen to the episodeJames Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security.
Listen to the episodeMukund Sarma, the Senior Director for Product Security at Chime, talks with Chris about his career path from being a software engineer to becoming a leader in application security.
Listen to the episodeWhat is zero trust, and how does it impact the world of applications and application security?
Listen to the episodeDolev Farhi is a security engineer and author with extensive experience leading security engineering teams in complex environments and scales in the Fintech and cyber security industries.
Listen to the episodeBrett Smith is a Software Architect/Engineer/Developer with 20+ years of experience.
Listen to the episodeNeil Matatall is an engineer with a background in security. He has previously worked at GitHub and Twitter and is a co-founder of Loco Moco Product Security Conference.
Listen to the episodeRobert and I break down the OWASP Top 10 2021 Peer Review Edition. We walk through and give you our insights and highlights of the things that stand out to us and our questions.
Listen to the episodeLiran Tal is an application security activist and long-time proponent of open-source software.
Listen to the episodeDmitry Sotnikov serves as Chief Product Officer at 42Crunch – an enterprise API security company.
Listen to the episodeGrant Ongers is co-founder of the bearded trio called Secure Delivery, with a philosophy and purpose for optimal delivery and security in one dynamic package.
Listen to the episodeZsolt is the founder and CTO of GUARDARA with more than 15 years of experience in cybersecurity, both on the offensive and defensive side. Zsolt explains fuzz testing, who does it, and why.
Listen to the episodeErez Yalon heads the security research group at Checkmarx. With vast defender and attacker experience and as an independent security researcher, he brings invaluable knowledge and skills to the table.
Listen to the episodeGeoff Hill joins Chris and Robert to talk about Rapid Threat Model Prototyping Process. You can find Geoff on Twitter @Tutamantic_Sec
Listen to the episodeTony UV joins Robert to discuss all things threat libraries in the cloud. You can find Tony on Twitter @t0nyuv
Listen to the episodeJim Manico joins us to discuss some of the changes with the OWASP Cheat Sheets and their plans for that project's future.
Listen to the episodeOn this week's episode of the #AppSec Podcast, Chris and Robert are at #AppSecUSA. We hear a conference talk done by Robert on the topic of Threat Modeling.
Listen to the episodeRobert and Chris speak with Jon Mccoy and Jonathan Marcil about using Agile #AppSec in the Secure Development Lifecycle.
Listen to the episodeDave Ferguson discusses the OWASP Top 10 Proactive Controls in this episode with Chris.
Listen to the episodeOn this episode of the application security podcast, Robert and I jump over a wall. Just kidding. This isn’t Top Gear. This is our second episode of season two of the #AppSec PodCast.
Listen to the episode