Isaac Evans - AppSec in the Age of AI
In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected.
Listen to the episodeTopic
Injection, XSS, deserialization and the rest of the catalogue — plus bug bounty, disclosure, and what happens after a report lands.
In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected.
Listen to the episodeIn this episode, we sit down with Jose Carlos Chavez from Okta to break down the OWASP Top 10 for 2025 and what actually changed since 2021.
Listen to the episodeBrad Geesaman, Principal Security Engineer at Ghost, joins the podcast today to explore how AI and large language models are transforming the world of application security.
Listen to the episodeAndra Lezza and Javan Rasokat discuss the complexities of securing AI and LLM applications.
Listen to the episodeMilan Williams discusses the importance of application security metrics and how to make them both meaningful and actionable.
Listen to the episodeJeff Williams, a renowned pioneer in the field of application security is with us to discuss Application Detection and Response (ADR), detailing its…
Listen to the episodePhilip Wiley shares his unique journey from professional wrestling to being a renowned pen tester. We define pen testing and the role of social engineering in ethical hacking.
Listen to the episodeAndrew Van Der Stok, a leading web application security specialist and executive director at OWASP joins us for this episode.
Listen to the episodeJames Berthoty, a cloud security engineer with a diverse IT background, discusses his journey into application and product security.
Listen to the episodeErik Cabetas joins Robert and Chris for a thought-provoking discussion about modern software security.
Listen to the episodeEitan Worcel joins the Application Security Podcast, to talk automated code fixes and the role of artificial intelligence in application security.
Listen to the episodeChris and Robert are thrilled to have an insightful conversation with Dr. Jared Demott, a seasoned expert in the field of cybersecurity.
Listen to the episodeVarun Badhwar is a three-time founder, a luminary in the cyber security industry, and a clear communicator.
Listen to the episodeJeff Willams of Contrast Security joins Chris and Robert on the Application Security Podcast to discuss runtime security, emphasizing the significance of…
Listen to the episodeWhat is the state of application security? JB Aviat answered that question, by creating the state of application security report based on data from Datadog…
Listen to the episodeZohar Shachar joins us to discuss the bug bounty process from both sides. Zohar has spent time as a bug bounty hunter and shares wisdom on avoiding bug bounty-causing issues for your AppSec posture.
Listen to the episodeJames Mckee is a developer (MCPDEA) and security advocate (CISSP) whose biggest responsibility is leading developer security practices.
Listen to the episodeMichael Bargury is the Co-Founder and CTO of Zenity, where he helps companies secure their low-code/no-code apps.
Listen to the episodeTiago Mendo is a co-founder and CTO of Probely. He has extensive experience in pentesting applications, training, and providing all-around security consultancy.
Listen to the episodeSam Stepanyan is an OWASP London Chapter Leader and an Independent Application Security Consultant with over 20 years of IT experience and a background in…
Listen to the episodeBrett Smith is a Software Architect/Engineer/Developer with 20+ years of experience.
Listen to the episodeMazin Ahmed is a security engineer that specializes in AppSec and offensive security.
Listen to the episodeRobert and I break down the OWASP Top 10 2021 Peer Review Edition. We walk through and give you our insights and highlights of the things that stand out to us and our questions.
Listen to the episodeJC Herz is the COO of Ion Channel, a software logistics and supply chain assurance platform for critical infrastructure.
Listen to the episodeJb Aviat is CTO and co-founder at Sqreen. Prior to this, Jb worked at Apple as a reverse engineer, pentester, and developer.
Listen to the episodeCaroline Wong is the Chief Strategy Officer at Cobalt.io. Wong's close and practical information security knowledge stems from broad experience as a Cigital…
Listen to the episodeMichael Furman is the Lead Security Architect at Tufin, and is responsible for the security and Security Development Lifecycle (SDL) of Tufin software products.
Listen to the episodeElie Saad is an application security engineer, leading three different OWASP projects.
Listen to the episodeZsolt is the founder and CTO of GUARDARA with more than 15 years of experience in cybersecurity, both on the offensive and defensive side. Zsolt explains fuzz testing, who does it, and why.
Listen to the episodeJeremy Long is a principal engineer specializing in securing the SDLC. Jeremy is the founder and project lead for the OWASP dependency-check project; a…
Listen to the episodeErez Yalon heads the security research group at Checkmarx. With vast defender and attacker experience and as an independent security researcher, he brings invaluable knowledge and skills to the table.
Listen to the episodeDavid Kosorok is a code security expert, software tester, father of 9, and a self-described major nerd.
Listen to the episodeBill Wilder joins Chris and Robert to talk about Running Azure Securely. You can find Bill on Twitter @codingoutloud
Listen to the episodeJim Manico joins again to talk about how AppSec has changed over the years and gives us an in-depth look at the history of SQL Injection and XSS.
Listen to the episodeChris talks with Jeff Williams about the History of OWASP and where it came from. You can find Jeff on Twitter @planetlevel
Listen to the episodeBjorn Kimminich joins to talk about JuiceShop. He dives into what JuiceShop is and some of its use cases. You can find Bjorn on Twitter @bkimminich
Listen to the episodeChris and Robert talk with Adam and John from HackerOne about Bug Bounty. They dive into bug bounty from the programming and security researcher sides to…
Listen to the episodeChris is joined by Ofer Maor to talk about his journey of transitioning into the world of #AppSec from the world of Pen Testing.
Listen to the episodeDevin McMasters joins Chris to talk about bug bounties and how to make them successful. You can find Devin on Twitter @DevinMcmasters
Listen to the episodeDavid Habusha joins to discuss the OWASP Top 10 A9: Using components with known vulnerabilities. He also dives into the Software Composition Analysis (SCA) market.
Listen to the episodeSteve Springett joins the show to talk about Dependency Check and Dependency Track. He also discusses how they can help prevent you from using components with known vulnerabilities.
Listen to the episodePete Chestna is an advocate for SAST, DAST, and IAST tools and a passionate #AppSec enthusiast.
Listen to the episodeBill Sempf joins to talk about insecure deserialization. We do a deep dive and contextual review of the generalities of deserialization and the specifics of…
Listen to the episodeThis is the final interview from the #AppSecUSA Conference in Orlando, and Brian Andrzejewski joins Chris and Robert. He talks about containers, their usage within #AppSec, and orchestrations.
Listen to the episodeAditya Gupta joins Robert and Chris. They speak with him about the many facets of IoT and some of its effects on pen testing, training, and mobile application security.
Listen to the episodeWe talk about the future of the OWASP Top 10. We do this by meeting the new project leadership team, understanding the process for how they do governance…
Listen to the episodeDave Ferguson discusses the OWASP Top 10 Proactive Controls in this episode with Chris.
Listen to the episodeOn this episode of the application security podcast, Robert and I jump over a wall. Just kidding. This isn’t Top Gear. This is our second episode of season two of the #AppSec PodCast.
Listen to the episodeThis is our third interview from ISC2 Security Congress. We are joined by Tony UcedaVelez, or TonyUV, founder and CEO of VerSprite – a global security consulting firm based in Atlanta, GA.
Listen to the episodeMike Landeck joins Robert and me. Mike is a Cyber security evangelist, AppSec junky & Docker Security geek, and can be found on Twitter @MikeLandeck.
Listen to the episodeOn this two-part episode of the Application Security PodCast, Robert and I speak with Daniel Ramsbrock about Web App Penetration testing.
Listen to the episode