José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists
In this episode, we sit down with Jose Carlos Chavez from Okta to break down the OWASP Top 10 for 2025 and what actually changed since 2021.
Listen to the episodeTopic
The list that most organisations meet first, how each revision was assembled, and what it is and is not good for.
In this episode, we sit down with Jose Carlos Chavez from Okta to break down the OWASP Top 10 for 2025 and what actually changed since 2021.
Listen to the episodeGitGuardian found 29 million hard-coded secrets leaked in public GitHub commits in a single year, a 34% jump and the biggest spike they've ever recorded.
Listen to the episodeIn this episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut welcome back Steve Wilson, a global leader in AI security and Chief AI…
Listen to the episodeOur guest today is Akansha Shukla, an information security professional with over 10 years of experience in application security, DevSecOps, and API security.
Listen to the episodeWe’re discussing the intersections of application security (AppSec) and sales strategy with our guest, Sean Varga.
Listen to the episodeHenrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies.
Listen to the episodeAndrew Van Der Stok, a leading web application security specialist and executive director at OWASP joins us for this episode.
Listen to the episodeMark Curphey and Simon Bennetts, join Chris on the podcast to discuss the challenges of funding and sustaining major open source security projects like ZAP.
Listen to the episodeSteve Wilson and Gavin Klondike are part of the core team for the OWASP Top 10 for Large Language Model Applications project.
Listen to the episodeHow do we do security in the world of AI and LLMs? A great place to start is with an OWASP project tasked with creating a standardized guideline for…
Listen to the episodeJet Anderson's passion is teaching today's software developers to write secure code as part of modern DevOps pipelines, at speed and scale, without missing a beat.
Listen to the episodeMichael Bargury is the Co-Founder and CTO of Zenity, where he helps companies secure their low-code/no-code apps.
Listen to the episodeMark Curphey is one of the creators of OWASP from the very early days. Mark worked in the background over the few decades of OWASP but has recently taken more to the spotlight.
Listen to the episodeDaniel Krivelevich is a cybersecurity expert and problem solver, with 15+ years of enterprise security experience with a proven track record working with…
Listen to the episodeSimon Bennetts is the OWASP Zed Attack Proxy (ZAP) Project Leader and a Distinguished Engineer at StackHawk, a company that uses ZAP to help users fix…
Listen to the episodeRobert and I break down the OWASP Top 10 2021 Peer Review Edition. We walk through and give you our insights and highlights of the things that stand out to us and our questions.
Listen to the episodeKevin Greene is the Director of Security Solutions at Parasoft and has extensive experience and expertise in software security, cyber research and development, and DevOps.
Listen to the episodeFrank Rietta is the CEO of Rietta.com, a Security Focused Web Application Firm. He is a web application security architect, expert witness, author, and speaker.
Listen to the episodeMichael Furman is the Lead Security Architect at Tufin, and is responsible for the security and Security Development Lifecycle (SDL) of Tufin software products.
Listen to the episodeErez Yalon heads the security research group at Checkmarx. With vast defender and attacker experience and as an independent security researcher, he brings invaluable knowledge and skills to the table.
Listen to the episodeSimon Bennetts is the project leader for OWASP ZAP. Simon joined Robert at CodeMash to talk about the origin of ZAP, the new heads up display, and ZAP API.
Listen to the episodeDaniel Miessler joins Chris and Robert to talk about the upcoming Top 10 list for IoT. You can find Daniel on Twitter @DanielMiessler IoT Project
Listen to the episodeWe listen in on the #AppSecUSA talk by Chris about Security Culture Hacking. You can find Chris on Twitter @edgeroute
Listen to the episodeChris talks with Jeff Williams about the History of OWASP and where it came from. You can find Jeff on Twitter @planetlevel
Listen to the episodeJessie and Vandana join Chris from Women in #AppSec to discuss the project! They dive into what the project is and how the numerous OWASP Chapters around the world can participate!
Listen to the episodeIn this episode, Robert speaks about Malicious User Stories and DevOps with Apollo Clark. He discusses how to properly handle user stories in a world being taken over by DevOps.
Listen to the episodeDavid Habusha joins to discuss the OWASP Top 10 A9: Using components with known vulnerabilities. He also dives into the Software Composition Analysis (SCA) market.
Listen to the episodeNeil Smithline joins this week to discuss one of the new items on the OWASP Top 10 List, Insufficient Logging and Monitoring.
Listen to the episodeKaty Anton joins this week to discuss number four on the OWASP Top 10. She dives into what XXE is, how to deal with it, and other new items on the OWASP Top 10 2017.
Listen to the episodeBill Sempf joins to talk about insecure deserialization. We do a deep dive and contextual review of the generalities of deserialization and the specifics of…
Listen to the episodeThis is the conclusion of Season 02 for the AppSec PodCast. This episode focuses on all the OWASP goodness we’ve experienced this year.
Listen to the episodeTin Zaw, an advocate for ModSecurity, joins Robert and Chris. He dives into its background, the use of rules, and the many advantages.
Listen to the episodeChris and Robert talk to Jim Manico and Katy Anton about the OWASP Proactive Controls project. We have discussed this before, and they are looking for feedback on the upcoming update.
Listen to the episodeWe talk about the future of the OWASP Top 10. We do this by meeting the new project leadership team, understanding the process for how they do governance…
Listen to the episodeRobert and Chris speak with Jon Mccoy and Jonathan Marcil about using Agile #AppSec in the Secure Development Lifecycle.
Listen to the episodeRobert and I try a new format for discussing a few topics per episode. We discuss changes with the Proactive Controls, AppSecUSA, and the Gartner Magic Quadrant for Application Security Testing.
Listen to the episodeDave Ferguson discusses the OWASP Top 10 Proactive Controls in this episode with Chris.
Listen to the episodeWe’re here today with Jim Manico, a project lead with OWASP. We dive deep into some of the projects on his plate.
Listen to the episodeOn this episode of the application security podcast, Robert and I jump over a wall. Just kidding. This isn’t Top Gear. This is our second episode of season two of the #AppSec PodCast.
Listen to the episodeIn the inaugural episode of the Application Security PodCast, Robert and I introduce ourselves to the audience, explain our journeys into the security…
Listen to the episode