The Future of Open-Source Threat Modeling
You don’t have to let AI do the thinking for you. In this episode, Vikram shares why the smartest teams use AI as an accelerant — not a replacement — and…
Listen to the episodeTopic
Finding what can go wrong before it does — STRIDE, LINDDUN, data flow diagrams, and the practice of doing it at scale.
You don’t have to let AI do the thinking for you. In this episode, Vikram shares why the smartest teams use AI as an accelerant — not a replacement — and…
Listen to the episodeAI adoption is accelerating faster than most organizations know how to handle it, and the gap between curiosity and confident use is where things go wrong.
Listen to the episodeAI isn’t just helping developers anymore; it’s writing the code, and that changes everything.
Listen to the episodeSimon and Devika Gibbs, the innovative minds behind Cybersec Games, join us on the episode today.
Listen to the episodeOur guest today is Akansha Shukla, an information security professional with over 10 years of experience in application security, DevSecOps, and API security.
Listen to the episodeThe European Union's Cyber Resilience Act is set to revolutionize how we approach product security worldwide.
Listen to the episodeAram Hovsepyan joins the podcast today to chat about the misconceptions behind common security metrics.
Listen to the episodeAndra Lezza and Javan Rasokat discuss the complexities of securing AI and LLM applications.
Listen to the episodeSecurity expert Tanya Janca discusses her new book "Alice and Bob Learn Secure Coding" and shares insights on making security accessible to developers.
Listen to the episodeBrett Crawley discusses the Elevation of Privilege (EoP) card game, a powerful tool for threat modeling in software development.
Listen to the episodeMatin Mavaddat discusses his perspective on security as a systemic concern, developed from his background in requirements engineering and systems architecture.
Listen to the episodeFrançois Proulx shares his discovery of security vulnerabilities in build pipelines. Francois has found that attackers can exploit this often overlooked side of the software supply chain.
Listen to the episodeJeff Williams, a renowned pioneer in the field of application security is with us to discuss Application Detection and Response (ADR), detailing its…
Listen to the episodeSteve Springett, an expert in secure software development and a key figure in several OWASP projects is back. Steve unpacks CycloneDX and the value proposition of various BOMs.
Listen to the episodeJahanzeb Farooq discusses his journey in cybersecurity and the challenges of building AppSec programs from scratch.
Listen to the episodeMatt Rose, an experienced technical AppSec testing leader discusses his career journey and significant contributions in AppSec.
Listen to the episodeRobert and Chris talk with Hendrik Ewerlin, a threat modeling advocate and trainer.
Listen to the episodeJason Nelson, an accomplished expert in information security management, joins Chris to share insights on establishing successful threat modeling programs…
Listen to the episodeChris Hughes, co-founder of Aquia, joins Chris and Robert on the Application Security Podcast to discuss points from his recent book Software Transparency:…
Listen to the episodeJay Bobo and Darylynn Ross from CoverMyMeds join Chris to explain their assertion that 'AppSec is Dead.' They discuss the differences between product and…
Listen to the episodeArshan Dabirsiaghi of Pixee joins Robert and Chris to discuss startups, AI in appsec, and Pixee's Codemodder.io.
Listen to the episodeSteve Wilson and Gavin Klondike are part of the core team for the OWASP Top 10 for Large Language Model Applications project.
Listen to the episodeTanya Janca, also known as SheHacksPurple, joins the Application Security Podcast again to discuss secure coding, threat modeling, education, and other topics in the AppSec world.
Listen to the episodeJeff Willams of Contrast Security joins Chris and Robert on the Application Security Podcast to discuss runtime security, emphasizing the significance of…
Listen to the episodeMaril Vernon is passionate about Purple teaming and joins Robert and Chris to discuss the intricacies of purple teaming in cybersecurity.
Listen to the episodeKim Wuyts discusses her work in privacy threat modeling with LINDDUN, a framework inspired by Microsoft's STRIDE for security threat modeling.
Listen to the episodeSoftware supply chain -- how deep does the problem go? François is here to help us realize how deep the rabbit hole of the supply chain is and enlighten us with strategies to get out of the hole.
Listen to the episodeJeevan Singh, the director of product security at Twilio, discusses the future of application security engineers.
Listen to the episodeHave you ever considered using an SBOM to inform your threat modeling? Tony Turner has. Tony joins us to discuss SBOMs, threat modeling, and the importance of Cyber Informed Engineering.
Listen to the episodeChristian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built.
Listen to the episodeSarah-Jane Madden is the Chief Information Security Officer of Sensing Technology Group. - part of Fortive.
Listen to the episodeRobyn Lundin started working in tech after a coding boot camp as a developer for a small startup.
Listen to the episodeAlex leads the Cyber Security Consulting Group, part of Rakuten's Cyber Security Defense Department.
Listen to the episodeJ. Wolfgang Goerlich is an Advisory CISO for Cisco Secure. He has been responsible for IT and IT security in the healthcare and financial services verticals.
Listen to the episodeIn this episode of the Application Security Podcast, Chris Romeo walks through the origin story of Security Journey and shares some experiences taking a security startup from bootstrap to acquisition.
Listen to the episodeIn this episode of the Application Security Podcast, we talk to Kristen Tan and Vaibhav Garg from Comcast.
Listen to the episodeAlex Mor is a passionate cybersecurity defender or breaker depending on the time of day, providing expert technical guidance to product teams and building security in their platforms.
Listen to the episodeJoern Freydank is a Lead Cyber Security Engineer with more than 20 years of experience. He is currently establishing the Threat Modeling Program at a major insurance company.
Listen to the episodeAdam is a leading expert on threat modeling, and a consultant, expert witness, author and game designer. He has decades of experience delivering security.
Listen to the episodeLoren Kohnfelder has over 20 years of experience in the security industry. At Microsoft, he was a key contributor to STRIDE, the industry’s first formalized…
Listen to the episodeDr. James Ransome is the Chief Scientist for CyberPhos, an early-stage cybersecurity startup.
Listen to the episodeRobert and I break down the OWASP Top 10 2021 Peer Review Edition. We walk through and give you our insights and highlights of the things that stand out to us and our questions.
Listen to the episodeMark Loveless - aka Simple Nomad - is a security researcher and hacker. He's spoken at numerous security and hacker conferences worldwide, including Blackhat, DEF CON, ShmooCon, and RSA.
Listen to the episodeKevin Greene is the Director of Security Solutions at Parasoft and has extensive experience and expertise in software security, cyber research and development, and DevOps.
Listen to the episodeJeevan Singh is a Security Engineer Manager at Segment, where he is embedding security into all aspects of the software development process.
Listen to the episodeIn this episode of the Application Security Podcast, we're joined by friends Izar and Matt, authors of the book "Threat Modeling: A Practical Guide for…
Listen to the episodeVandana Verma is the President of Infosec girls and Infosec Kids, a board of directors member for OWASP, and a leader for BSides Dehli. She joins us to introduce the OWASP Spotlight Series.
Listen to the episodeAlyssa Miller is a life-long hacker, security advocate, and cybersecurity leader. She is the BISO for S&P Global ratings and has over 15 years of experience in security roles.
Listen to the episodeFor this episode, Robert and I decided to talk about an article I wrote called "DevOps security culture: 12 fails your team can learn from". We hope you enjoy this walkthrough of the 12 fails.
Listen to the episodeThis is part two of the story of a diverse group of security and privacy people that love threat modeling and gathered to define threat modeling, encourage…
Listen to the episodeThis is part one of the story of a diverse group of security and privacy people that love threat modeling and gathered to define threat modeling, encourage…
Listen to the episodeAnastasiia Voitova is a software engineer who works on data security solutions at @cossacklabs, making complex crypto easy-to-use in modern software. She joins us to explore the idea of boring crypto.
Listen to the episodeApplication security applies to everyone, network architects included. Chris had an opportunity to join a friend's Podcast called "The Hedge." Chris talks…
Listen to the episodeGrant Ongers is co-founder of the bearded trio called Secure Delivery, with a philosophy and purpose for optimal delivery and security in one dynamic package.
Listen to the episodeAdam Shostack is a leading expert on threat modeling, and consultant, entrepreneur, technologist, author, and game designer.
Listen to the episodeAdam joins us to discuss remote threat modeling, and we do a live threat modeling exercise to figure out how remote threat modeling actually works.
Listen to the episodeKim Wuyts is a postdoctoral researcher at the Department of Computer Science at KU Leuven (Belgium). She has more than 10 years of experience in security and privacy in software engineering.
Listen to the episodeJohn Martin has owned responsibilities ranging from Software Supply Chain to DevSecOps Security Champions to Cloud Security Monitoring.
Listen to the episodeAlyssa is a hacker, security evangelist, cybersecurity professional and international public speaker with almost 15 years of experience in the security industry.
Listen to the episodeSteve Lipner is a pioneer in cybersecurity, approaching 50 years’ experience. He retired in 2015 from Microsoft where he was the creator and long-time…
Listen to the episodeAs the hosts of the Application Security Podcast, we get the opportunity from time to time to mix it up.
Listen to the episodeBill Dougherty is the vice president of IT and security at Omada Health, where he leads a team responsible for all aspects of internal IT including SaaS…
Listen to the episodeThreat modeling, secrets, mentoring, self-care, program building, and much more. Clips from Georgia Weidman, Simon Bennetts, Izar Tarandach, Omer Levi…
Listen to the episodeBrook Schoenfield is a Master Security Architect @IOActive and author of Securing Systems, as well as an industry leader in security architecture and threat modeling, and a friend.
Listen to the episodeAdam Shostack is a leading expert on threat modeling, and a consultant, entrepreneur, technologist, author and game designer.
Listen to the episodeIf you've done anything with threat modeling, you've heard of Adam Shostack. We asked him the question, "why would anyone threat model?".
Listen to the episodeMatt Clapham is a product security person, as a developer, security engineer, advisor, and manager.
Listen to the episodeIzar Tarandach is a threat modeling pioneer, seen as one of the movers and shakers in the threat modeling world.
Listen to the episodeGeoff Hill joins Chris and Robert to talk about Rapid Threat Model Prototyping Process. You can find Geoff on Twitter @Tutamantic_Sec
Listen to the episodeJosh Grossman, Avi Douglen, and Ofer Maor at AppSec USA join Chris. They discuss the AppSec group in Israel and a few critical talks you should watch from AppSec USA this year.
Listen to the episodeAbhay Bhargav joins Robert to talk about threat modeling as code. He dives into how this can help you in your threat models.
Listen to the episodeTony UV joins Robert to discuss all things threat libraries in the cloud. You can find Tony on Twitter @t0nyuv
Listen to the episodeStephen de Vries joins to discuss Threat Modeling and the unique approach that he takes by using tooling. We also discuss application security and startups.
Listen to the episodeSteven Wierckx joins Robert and Chris this week to talk about the #OWASP Threat Modeling project that he’s involved in.
Listen to the episodeChris and Robert go over a plethora of recommendations they have accumulated over their years of experience in the industry. Chris’s recommendations 1.
Listen to the episodeIrene Michlin operates at the intersection of security and agility. She teaches about incremental threat modeling and how to make threat modeling when living in an Agile or DevOps world.
Listen to the episodeSecurity champions are the hands and feet of any well-equipped product security team.
Listen to the episodeRobert and Chris interview Kevin Greene from Mitre. We discuss an article Kevin wrote about shifting left and exploring codifying intuitions and new…
Listen to the episodeThis is the conclusion of Season 02 for the AppSec PodCast. This episode focuses on all the OWASP goodness we’ve experienced this year.
Listen to the episodeOn this week's episode of the #AppSec Podcast, Chris and Robert are at #AppSecUSA. We hear a conference talk done by Robert on the topic of Threat Modeling.
Listen to the episodeIn this episode, we speak with Mike Goodwin, the founder of the OWASP Threat Dragon.
Listen to the episodeThis episode is an interview Robert and I did with Brook Schoenfield (@BrkSchoenfield) during the RSA Conference 2017. Brook S.E. Schoenfield is a Distinguished Engineer at Intel Security Group.
Listen to the episodeGood day, friends. The Application Security PodCast has concluded our first season. With many friends' help, we could record 18 episodes.
Listen to the episodeOn this episode, Robert and I are joined by Adam Shostack (@adamshostack). Adam is a well-known speaker and thought leader in application security.
Listen to the episodeThis is our third interview from ISC2 Security Congress. We are joined by Tony UcedaVelez, or TonyUV, founder and CEO of VerSprite – a global security consulting firm based in Atlanta, GA.
Listen to the episodeRobert and I are joined today by Matt Clapham. Matt “makes products more secure” I mean, hey, his Twitter handle is @ProdSec.
Listen to the episodeIn this episode, we talk about product development methodologies and the impact of security. We explore how to apply security activities to waterfall and Agile and discuss the pros and cons.
Listen to the episodeOn this episode of the Application Security PodCast, we continue our journey through the foundations of application security. We explore the activities of the secure development life cycle.
Listen to the episode