Josh Grossman--AI & SAST: Is it a match?
AI coding tools are accelerating development fast, but they’re also exposing the limits of traditional AppSec tooling.
Listen to the episodeTopic
SAST, DAST, IAST, fuzzing and penetration testing, and the false-positive problem that decides whether any of them get used.
AI coding tools are accelerating development fast, but they’re also exposing the limits of traditional AppSec tooling.
Listen to the episodeSimon and Devika Gibbs, the innovative minds behind Cybersec Games, join us on the episode today.
Listen to the episodeAndra Lezza and Javan Rasokat discuss the complexities of securing AI and LLM applications.
Listen to the episodeSecurity expert Tanya Janca discusses her new book "Alice and Bob Learn Secure Coding" and shares insights on making security accessible to developers.
Listen to the episodeSteve Wilson, the author of 'The Developer's Playbook for Large Language Model Security’ is back to dive into topics from his book like AI hallucinations, trust, and the future of AI.
Listen to the episodeJeff Williams, a renowned pioneer in the field of application security is with us to discuss Application Detection and Response (ADR), detailing its…
Listen to the episodePhilip Wiley shares his unique journey from professional wrestling to being a renowned pen tester. We define pen testing and the role of social engineering in ethical hacking.
Listen to the episodeTanya Janka, also known as SheHacksPurple, discusses secure guardrails, the difference between guardrails and paved roads, and how to implement both in application security.
Listen to the episodeJahanzeb Farooq discusses his journey in cybersecurity and the challenges of building AppSec programs from scratch.
Listen to the episodeMatt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec.
Listen to the episodeJames Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security.
Listen to the episodeMark Curphey and Simon Bennetts, join Chris on the podcast to discuss the challenges of funding and sustaining major open source security projects like ZAP.
Listen to the episodeDevon Rudnicki, the Chief Information Security Officer at Fitch Group, shares her journey of developing an application security program from scratch and advancing to the CISO role.
Listen to the episodeFrancesco Cipollone, CEO of Phoenix Security, joins Chris and Robert to discuss security and explain Application Security Posture Management (ASPM).
Listen to the episodeJason Nelson, an accomplished expert in information security management, joins Chris to share insights on establishing successful threat modeling programs…
Listen to the episodeErik Cabetas joins Robert and Chris for a thought-provoking discussion about modern software security.
Listen to the episodeJay Bobo and Darylynn Ross from CoverMyMeds join Chris to explain their assertion that 'AppSec is Dead.' They discuss the differences between product and…
Listen to the episodeChris John Riley joins Chris and Robert to discuss the Minimum Viable Secure Product. MVSP is a minimalistic security checklist for B2B software and business process outsourcing suppliers.
Listen to the episodeVarun Badhwar is a three-time founder, a luminary in the cyber security industry, and a clear communicator.
Listen to the episodeJeff Willams of Contrast Security joins Chris and Robert on the Application Security Podcast to discuss runtime security, emphasizing the significance of…
Listen to the episodeMark Curphey and John Viega join Chris and Robert to explain the details of Chalk, Crash Override's new tool.
Listen to the episodeMaril Vernon is passionate about Purple teaming and joins Robert and Chris to discuss the intricacies of purple teaming in cybersecurity.
Listen to the episodeDan Küykendall visits The Application Security Podcast to discuss his series "Why All AppSec Products Suck" and explain why software companies should…
Listen to the episodeKevin Johnson is the CEO of Secure Ideas. He began his career as a developer but turned toward security when he discovered that the interface for an intrusion detection system, Snort, was out of date.
Listen to the episodeCloud security is on an evolutionary path, with newer platforms embracing secure-by-default settings.
Listen to the episodeZohar Shachar joins us to discuss the bug bounty process from both sides. Zohar has spent time as a bug bounty hunter and shares wisdom on avoiding bug bounty-causing issues for your AppSec posture.
Listen to the episodeDerek is the author of “The Application Security Handbook.” He is a university instructor at Temple University, where he teaches software development security to undergraduate and graduate students.
Listen to the episodeRobyn Lundin started working in tech after a coding boot camp as a developer for a small startup.
Listen to the episodeAlex leads the Cyber Security Consulting Group, part of Rakuten's Cyber Security Defense Department.
Listen to the episodeMark Curphey is one of the creators of OWASP from the very early days. Mark worked in the background over the few decades of OWASP but has recently taken more to the spotlight.
Listen to the episodeTiago Mendo is a co-founder and CTO of Probely. He has extensive experience in pentesting applications, training, and providing all-around security consultancy.
Listen to the episodeSam Stepanyan is an OWASP London Chapter Leader and an Independent Application Security Consultant with over 20 years of IT experience and a background in…
Listen to the episodeChen Gour-Arie is the Chief Architect and Co-Founder of Enso Security. With over 15 years of hands-on experience in cybersecurity and software development,…
Listen to the episodeJosh Grossman has over 15 years of experience in IT Risk and Application Security consulting, and he has also worked as a software developer.
Listen to the episodeAlex Mor is a passionate cybersecurity defender or breaker depending on the time of day, providing expert technical guidance to product teams and building security in their platforms.
Listen to the episodeWill Ratner is a software security professional with extensive experience building and implementing security solutions across a myriad of industries…
Listen to the episodeKen Toler is a principal consultant at Kudelski Security and is passionate about building and optimizing application security programs that stick through strong adoption and ease of use.
Listen to the episodeOchaun Marshall is an Application Security Consultant. In his roles of secure ideas, he works on on-going development projects utilizing Amazon web services and breaks other people's web applications.
Listen to the episodeSimon Bennetts is the OWASP Zed Attack Proxy (ZAP) Project Leader and a Distinguished Engineer at StackHawk, a company that uses ZAP to help users fix…
Listen to the episodeMazin Ahmed is a security engineer that specializes in AppSec and offensive security.
Listen to the episodeDr. James Ransome is the Chief Scientist for CyberPhos, an early-stage cybersecurity startup.
Listen to the episodeEran Kinsbruner is the Chief Evangelist and Senior Director at Perforce Software. His published books include the 2016 Amazon bestseller, “The Digital…
Listen to the episodeJeroen Willemsen is a Principal Security Architect at Xebia. Jeroen is more or less a jack of all trades with an interest in infrastructure security, risk management, and application security.
Listen to the episodeBefore taking the plunge into information security leadership, Dustin Lehr spent over a decade as a software engineer and architect in a variety of…
Listen to the episodeAaron Rinehart is expanding the possibilities of chaos engineering to cybersecurity.
Listen to the episodeBrian Reed is Chief Mobility Officer at NowSecure. Brian has over 30 years in tech and 15 years in mobile, security, and apps dating back to the birth of…
Listen to the episodeThis is our final episode of Season 7, and we thought we'd share some of our favorite clips with you.
Listen to the episodeFrank Rietta is the CEO of Rietta.com, a Security Focused Web Application Firm. He is a web application security architect, expert witness, author, and speaker.
Listen to the episodeCaroline Wong is the Chief Strategy Officer at Cobalt.io. Wong's close and practical information security knowledge stems from broad experience as a Cigital…
Listen to the episodeElie Saad is an application security engineer, leading three different OWASP projects.
Listen to the episodeDrew Dennison is the CTO & co-founder of r2c, a startup working to profoundly improve software security and reliability to safeguard human progress.
Listen to the episodeAaron Guzman specializes in IoT, embedded, and automotive security. Aaron is the Co-Author of “IoT Penetration Testing Cookbook”.
Listen to the episodeCindy Blake is the Senior Security Evangelist at GitLab. Cindy collaborates around best practices for integrated DevSecOps application security solutions with major enterprises.
Listen to the episodeZsolt is the founder and CTO of GUARDARA with more than 15 years of experience in cybersecurity, both on the offensive and defensive side. Zsolt explains fuzz testing, who does it, and why.
Listen to the episodeAlyssa is a hacker, security evangelist, cybersecurity professional and international public speaker with almost 15 years of experience in the security industry.
Listen to the episodeSteve Lipner is a pioneer in cybersecurity, approaching 50 years’ experience. He retired in 2015 from Microsoft where he was the creator and long-time…
Listen to the episodeDavid Kosorok is a code security expert, software tester, father of 9, and a self-described major nerd.
Listen to the episodeAs the hosts of the Application Security Podcast, we get the opportunity from time to time to mix it up.
Listen to the episodeRonnie Flathers is a security guy, a pentester, and a researcher. In this conversation, we explore his experiences in building application security programs.
Listen to the episodeBrook Schoenfield is a Master Security Architect @IOActive and author of Securing Systems, as well as an industry leader in security architecture and threat modeling, and a friend.
Listen to the episodeElissa Shevinsky is CEO at Faster Than Light. She's had a storied career as an entrepreneur with Brave, Everyday Health, and Geekcorps.
Listen to the episodeNancy Gariché and Tanya Janca are two of the project leaders for the OWASP DevSlop Project. As we learn more about DevSlop, we realize that it is much more than a project: it's a movement.
Listen to the episodeSimon Bennetts is the project leader for OWASP ZAP. Simon joined Robert at CodeMash to talk about the origin of ZAP, the new heads up display, and ZAP API.
Listen to the episodeGeorgia Weidman (@georgiaweidman) met with Robert at CodeMash to discuss her origin story, mobile, IoT, penetration testing, and details about her various companies.
Listen to the episodeBill Wilder joins Chris and Robert to talk about Running Azure Securely. You can find Bill on Twitter @codingoutloud
Listen to the episodeJosh Grossman, Avi Douglen, and Ofer Maor at AppSec USA join Chris. They discuss the AppSec group in Israel and a few critical talks you should watch from AppSec USA this year.
Listen to the episodeJim Manico joins again to talk about how AppSec has changed over the years and gives us an in-depth look at the history of SQL Injection and XSS.
Listen to the episodeChris is at AppSec USA and is joined by Swaroop to talk about iGoat. They discuss how iGoat relates to WebGoat and how they can be used for pen testing.
Listen to the episodeChris talks with Erlend Oftedal about the Norway Chapter of OWASP and continues on to what retire.js is and how it works.
Listen to the episodeAbhay Bhargav joins Robert to talk about threat modeling as code. He dives into how this can help you in your threat models.
Listen to the episodeChris is joined by Ofer Maor to talk about his journey of transitioning into the world of #AppSec from the world of Pen Testing.
Listen to the episodeJulien Vehent joins us to discuss all things DevOps + Security. We talk through Julien's new book, Securing DevOps, and go in-depth about his journey to building security into DevOps at his job.
Listen to the episodeThe conclusion of Season 3, all the best highlights, and some great advice from our guests on what you need to build an #AppSec Program.
Listen to the episodeDevin McMasters joins Chris to talk about bug bounties and how to make them successful. You can find Devin on Twitter @DevinMcmasters
Listen to the episodeNeil Smithline joins this week to discuss one of the new items on the OWASP Top 10 List, Insufficient Logging and Monitoring.
Listen to the episodeJim Routh joins the podcast to discuss selling #AppSec up the chain. Jim has built five successful software security programs in his career and serves as a CISO now.
Listen to the episodeKaty Anton joins this week to discuss number four on the OWASP Top 10. She dives into what XXE is, how to deal with it, and other new items on the OWASP Top 10 2017.
Listen to the episodePete Chestna is an advocate for SAST, DAST, and IAST tools and a passionate #AppSec enthusiast.
Listen to the episodeRobert and Chris interview Kevin Greene from Mitre. We discuss an article Kevin wrote about shifting left and exploring codifying intuitions and new…
Listen to the episodeAditya Gupta joins Robert and Chris. They speak with him about the many facets of IoT and some of its effects on pen testing, training, and mobile application security.
Listen to the episodeTanya and Nicole join Chris and Robert. They talk about what APIs are, how they are used, and some of the threats involved with them.
Listen to the episodeRobert and I try a new format for discussing a few topics per episode. We discuss changes with the Proactive Controls, AppSecUSA, and the Gartner Magic Quadrant for Application Security Testing.
Listen to the episodeWe’re back with another episode of The Application Security Podcast. This time, we talked to Mark Willis about the many facets of static analysis and how it affects the DevOps world.
Listen to the episodeWelcome back to season two of the Application Security Podcast. In this week's episode, we talk to Eric Johnson about static analysis, pen testing, continuous integration, etc. Thanks for listening!
Listen to the episodeMike Landeck joins Robert and me. Mike is a Cyber security evangelist, AppSec junky & Docker Security geek, and can be found on Twitter @MikeLandeck.
Listen to the episodeOn this two-part episode of the Application Security PodCast, Robert and I speak with Daniel Ramsbrock about Web App Penetration testing.
Listen to the episodeOn this two-part episode of the Application Security PodCast, Robert and I speak with Daniel Ramsbrock about Web App Penetration testing.
Listen to the episodeOn this episode of the Application Security PodCast, we continue our journey through the foundations of application security. We explore the activities of the secure development life cycle.
Listen to the episode