AI Pen Testing Killed Traditional DAST
Is traditional DAST finally dead? James Berthoty explains how AI pentesting is changing the dynamics of security testing through contextual payloads,…
Listen to the episodeTopic
Containers, Kubernetes, infrastructure as code and the misconfigurations that make cloud its own discipline.
Is traditional DAST finally dead? James Berthoty explains how AI pentesting is changing the dynamics of security testing through contextual payloads,…
Listen to the episodeMatin Mavaddat discusses his perspective on security as a systemic concern, developed from his background in requirements engineering and systems architecture.
Listen to the episodeFrançois Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain.
Listen to the episodeTanya Janka, also known as SheHacksPurple, discusses secure guardrails, the difference between guardrails and paved roads, and how to implement both in application security.
Listen to the episodeHasan Yasar believes that everyone shares the responsibility of creating a secure environment, and this can only be achieved by working collaboratively.
Listen to the episodeItzik Alvas, Co-founder and CEO of Entro, is an expert on secrets security. Itzik joins Chris and Robert to discuss the significance of understanding and…
Listen to the episodeMark Curphey and John Viega join Chris and Robert to explain the details of Chalk, Crash Override's new tool.
Listen to the episodeCloud security is on an evolutionary path, with newer platforms embracing secure-by-default settings.
Listen to the episodeChristian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built.
Listen to the episodeDaniel Krivelevich is a cybersecurity expert and problem solver, with 15+ years of enterprise security experience with a proven track record working with…
Listen to the episodeJosh Grossman has over 15 years of experience in IT Risk and Application Security consulting, and he has also worked as a software developer.
Listen to the episodeWill Ratner is a software security professional with extensive experience building and implementing security solutions across a myriad of industries…
Listen to the episodeJeroen Willemsen is a passionate, hands-on security architect with a knack for mobile security and security automation.
Listen to the episodeOchaun Marshall is an Application Security Consultant. In his roles of secure ideas, he works on on-going development projects utilizing Amazon web services and breaks other people's web applications.
Listen to the episodeMazin Ahmed is a security engineer that specializes in AppSec and offensive security.
Listen to the episodeJeroen Willemsen is a Principal Security Architect at Xebia. Jeroen is more or less a jack of all trades with an interest in infrastructure security, risk management, and application security.
Listen to the episodeAaron Rinehart is expanding the possibilities of chaos engineering to cybersecurity.
Listen to the episodeAlyssa Miller is a life-long hacker, security advocate, and cybersecurity leader. She is the BISO for S&P Global ratings and has over 15 years of experience in security roles.
Listen to the episodeLiran Tal is an application security activist and long-time proponent of open-source software.
Listen to the episodeAaron Davis is a founder, dev, and a lead security researcher at MetaMask, a popular Ethereum wallet.
Listen to the episodeOchaun Marshall is a developer and security consultant. In his roles at Secure Ideas, he works on ongoing development projects utilizing Amazon Web Services and breaks other people's web applications.
Listen to the episodeJannik Hollenbach is a Security Automation Engineer at iteratec GmbH, working on and with open source security testing tools to continuously detect security…
Listen to the episodeWe’ve reached the end of season six, and here are a few of our favorite clips. Season seven is around the corner.
Listen to the episodeDJ Schleen is a seasoned DevSecOps advocate at Sonatype and provides thought leadership to organizations looking to integrate security into their DevOps practices.
Listen to the episodeNiels Tanis has a background in .NET development, pen-testing, and security consultancy. He has experience breaking, defending and building secure applications.
Listen to the episodeMaya is a Product Manager in Security & Privacy at Google, focused on container security. She previously worked on encryption at rest and encryption key management.
Listen to the episodeLiran Tal is a Developer Advocate @snyksec and is the author of Essential Node.js Security. He takes #opensource and protecting the #web very seriously.
Listen to the episodeOmer Levi Hevroni has written extensively on the topic of Kubernetes and secrets, and he's a super dev. He's the author of a tool for secrets management called Kamus.
Listen to the episodeBill Wilder joins Chris and Robert to talk about Running Azure Securely. You can find Bill on Twitter @codingoutloud
Listen to the episodeChris is at AppSec USA and is joined by Swaroop to talk about iGoat. They discuss how iGoat relates to WebGoat and how they can be used for pen testing.
Listen to the episodeTony UV joins Robert to discuss all things threat libraries in the cloud. You can find Tony on Twitter @t0nyuv
Listen to the episodeMohammed Imran joins us to discuss the DevSecOps Studio and more about the beautiful world of DevOps. You can find him on Twitter @secfigo
Listen to the episodeChase Schultz joins to discuss the combination of AppSec and hardware. He also dives into how the Meltdown and Spectre attacks worked.
Listen to the episodeThis is the final interview from the #AppSecUSA Conference in Orlando, and Brian Andrzejewski joins Chris and Robert. He talks about containers, their usage within #AppSec, and orchestrations.
Listen to the episodeTanya and Nicole join Chris and Robert. They talk about what APIs are, how they are used, and some of the threats involved with them.
Listen to the episodeA listener asked for a recommendation for a PodCast or Blog post about Docker security. We looked but couldn’t find one, so we created one.
Listen to the episode