Sign in

Application Security Weekly

@aswpodcast.com
100 followers 2 following 77 posts

Listen to the Application Security Weekly podcast for interviews and news on everything appsec — and more! Hosted by @mutantzombie.bsky.social, @jlk.bsky.social, and Kalyani Pawar.

PostsRepliesMedia
Application Security Weekly @aswpodcast.com · 09/04/2026
This week: Security problems aren’t changing very much even though security teams are. Catching up on implications of the Claude Code source leak, the very human lessons from the axios NPM compromise, and secure design that involves agents, humans, or both. www.scworld.com/podcast-epis...
scworld.com
AppSec News Roundup on Claude Code Leak, Axios NPM Compromise, Secure Design – Idan Plotnik, Raj Mallempati – ASW #377
Security problems aren’t changing very much even though security teams are. We catch up on the implications of the Claude Code source leak, the very human lessons from the axios NPM compromise, and what secure design looks like when it involves agents, humans, or both. AppSec has always celebrated i...
100
Application Security Weekly @aswpodcast.com · 09/04/2026
March meandered through C code, mused about secure design, marked a new top ten list, made space for machines, and finally descended into a bit of madness. And every single bit of it was fun! dangerouserrors.com/posts/2026-0...
dangerouserrors.com
ASW Recap for March 2026
Recap of Application Security Weekly episodes from March 2026
000
Application Security Weekly @aswpodcast.com · 03/05/2025
Here’s the March recap while I finish writing up what we did in April. #appsec dangerouserrors.com/appsec/2025/...
dangerouserrors.com
ASW Recap for March 2025
Recap of the Application Security Weekly podcast episodes from March 2025
000
Application Security Weekly @aswpodcast.com · 02/05/2025
At the end of every episode I mention a favorite #synthwave track. Because music makes everything better, even #appsec. And since it’s @bandcamp.com Friday, you can make a musician’s day better by supporting their work and grabbing a track (or two or three). dangerouserrors.com/synthwave-sh...
dangerouserrors.com
Synthwave Shoutouts
Synthwave, retrowave, and other shoutouts from the ASW podcast
030
Application Security Weekly @aswpodcast.com · 02/05/2025
It’s @bandcamp.com Friday, which is an excellent Friday for supporting musicians. Buy a track. Buy an album. Enjoy some new music. And if you like #synthwave (and adjacent) tunes, check out this list for a few ideas. dangerouserrors.com/synthwave-sh...
dangerouserrors.com
Synthwave Shoutouts
Synthwave, retrowave, and other shoutouts from the ASW podcast
020
Application Security Weekly @aswpodcast.com · 02/05/2025
Find more episodes, recaps, and some random #appsec reading on the blog. dangerouserrors.com
dangerouserrors.com
Application Security Weekly
Random encounters for infosec, music, horror, movies, ttrpgs, and more
000
Reposted by Application Security Weekly
Mike Shema @mutantzombie.bsky.social · 26/04/2025
Getting ready to sneak in as many D&D references as possible into an #appsec discussion
Title card for AppSec presentation on “Secure Designs, UX Dragons, Vuln Dungeons”
041
Reposted by Application Security Weekly
Sandy Carielli @sandycarielli.bsky.social · 15/04/2025
@jwo3.bsky.social and I were guests on @aswpodcast.bsky.social this week, talking about WAF, protecting LLMs, breach trends, and software supply chain. Thanks, @mutantzombie.bsky.social for having us! www.scworld.com/podcast-segm...
scworld.com
More WAFs in Blocking Mode and More Security Headaches from LLMs – Sandy Carielli, Janet Worthington – ASW #326
The breaches will continue until appsec improves. Janet Worthington and Sandy Carielli share their latest research on breaches from 2024, WAFs in 2025, and where secure by design fits into all this. W...
0102
Reposted by Application Security Weekly
Mike Shema @mutantzombie.bsky.social · 01/04/2025
We were somewhere around Barstow, on the edge of AppSec, when the vibe coding began to take hold.
031
Application Security Weekly @aswpodcast.com · 28/03/2025
One of my goals this year is to figure out a cost-benefit analysis of fuzzing vs. LLMs vs. grep. Later on in this episode Keith Hoodlet shared where he's seeing (and not seeing) #appsec potential from LLMs. Articles and episode at www.scworld.com/podcast-epis... youtu.be/zn3LT4BqOJo?...
youtu.be
Finding a Use for GenAI in AppSec - Keith Hoodlet - ASW #323
YouTube video by Security Weekly - A CRA Resource
010
Application Security Weekly @aswpodcast.com · 28/03/2025
Historical context for the "BadSeek" post by Shrivu Shankar (blog.sshh.io/p/how-to-bac...). He tweaked model weights to subtly introduce a backdoor into generated code, regardless of prompt, and noted the difficultly in detecting such manipulation. youtube.com/shorts/nB_KK...
youtube.com
Ken Thompson’s Secret Hack — Trust No Compiler!
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 26/03/2025
Memory safe code was having an unsafe design week this week. News articles and notes at www.scworld.com/podcast-epis... www.youtube.com/watch?featur...
youtube.com
Finding a Use for GenAI in AppSec - Keith Hoodlet - ASW #323
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 26/03/2025
Sure, LLMs are helping devs write code, but is it secure code? How are LLMs helping #appsec teams? Keith Hoodlet returned to talk about those questions and put the capabilities of LLMs into perspective. Show notes at www.scworld.com/podcast-epis... youtu.be/zn3LT4BqOJo?...
youtu.be
Finding a Use for GenAI in AppSec - Keith Hoodlet - ASW #323
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 18/03/2025
There's no better place to discover the impact of logic flaws than in the cryptocurrency space, where every token is its own self-funding bug bounty and every contract is a gamble in correctness. Show notes: www.scworld.com/podcast-epis... youtu.be/0GlIbGgi1OY?...
youtu.be
Redlining the Smart Contract Top 10 - Shashank - ASW #322
YouTube video by Security Weekly - A CRA Resource
110
Application Security Weekly @aswpodcast.com · 13/03/2025
Find episodes, recaps, and some random #appsec thoughts on the blog. deadliestwebattacks.com
deadliestwebattacks.com
Application Security Weekly
Random encounters for infosec, music, horror, movies, ttrpgs, and more
000
Application Security Weekly @aswpodcast.com · 13/03/2025
From Skype's embrace of e2ee to the recent Wallbleed research against the GFW, there are tons of reasons why #appsec is not a myopic technical topic. It reminds me of an old joke about oversimplifying models. We shouldn't treat appsec as a spherical CVE in a vacuum. youtu.be/Cbzthj0s44I?...
youtu.be
Skype Hangs Up, Android Backdoors, Jailbreak Research, Pretend AirTags, Wallbleed - ASW #321
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 13/03/2025
CISA has been pushing for more software to be secure by design and secure by default. Jack Cable shares how CISA chose to frame their Secure by Design principles and encourage businesses to improve their software quality. Show notes at www.scworld.com/podcast-epis... youtu.be/fjc2zqEFcAI?...
youtu.be
CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 11/03/2025
I’ll be hosting the Qualys Cyber Risk Series: AppSec Edition tomorrow at 9am PT! Join me and experts in the #AppSec and #APISecurity space as we discuss the latest trends, threats, and techniques to stay ahead. Register now: qualys.brighttalk.com?utm_source=i... #Qualys #CyberRiskSeries
040
Application Security Weekly @aswpodcast.com · 04/03/2025
Your operating system has curl on it. Your toaster probably has curl on it. The moon likely will have curl on it soon. And you can't spell curl without C... @daniel.haxx.se explains how curl keeps its code secure and some of the #appsec friction it has had to deal. youtu.be/0UavY_kKKic
youtu.be
Keeping Curl Successful and Secure Over the Decades - Daniel Stenberg - ASW #320
YouTube video by Security Weekly - A CRA Resource
181
Application Security Weekly @aswpodcast.com · 03/03/2025
*shakes fist* It has been 0 weeks since we did not mention AI and LLMs. But I think we added helpful angles to what a secure architecture can look like for using them and what the implications are for backdoors like BadSeek. Show notes at www.scworld.com/podcast-epis... youtu.be/TIxLvtCT-CE?...
youtu.be
Regex DoS, LLM Backdoors, Secure AI Architectures, Rust Survey - ASW #319
YouTube video by Security Weekly - A CRA Resource
110
Application Security Weekly @aswpodcast.com · 27/02/2025
I love the "cookie sandwich" because it combines parsing, implementation mismatches, and finding new flaws in old (yet pervasive) tech. In our chat about the top 10 web hacking techniques of 2024, James talked about cookies and finding inspiration for research topics. youtu.be/8XEK3NkbKOA?...
youtu.be
Top 10 Web Hacking Techniques of 2024 - James Kettle - ASW #318
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 26/02/2025
For me, prompt injection is the new XSS. The techniques and payloads are fun, they inspire creative thinking, but they're ultimately a lot of noise to be filtered with an effective framework like the examples we mentioned here. Show notes: www.scworld.com/podcast-epis... youtu.be/TIxLvtCT-CE
youtu.be
Regex DoS, LLM Backdoors, Secure AI Architectures, Rust Survey - ASW #319
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 25/02/2025
We're almost at 20 years of celebrating web hacking techniques. @jameskettle.com shares his favorites from 2024, the list's importance to the web hacking community, and what inspires the kind of research it highlights. List at portswigger.net/research/top... youtu.be/8XEK3NkbKOA?...
youtu.be
Top 10 Web Hacking Techniques of 2024 - James Kettle - ASW #318
YouTube video by Security Weekly - A CRA Resource
122
Application Security Weekly @aswpodcast.com · 14/02/2025
Scott Norberg's goal for pentesting really resonated with me. "I view it as my job not to find all the instances of three different classes of vulnerabilities; it's to find as many different classes of vulnerabilities as I can." www.youtube.com/clip/Ugkx0N9...
youtube.com
YouTube
Share your videos with friends, family, and the world
100
Application Security Weekly @aswpodcast.com · 14/02/2025
Kalyani and I reviewed the "unforgivable" criteria in the recent article from @ncsc.gov.uk. We applied it to vulns in the news, with some easy ones like DeepSeek disabling ATS on iOS. But then the categories get messier... Show notes: www.scworld.com/podcast-epis... youtu.be/AVkucIviAnI?...
youtu.be
Unforgivable Vulns, DeepSeek iOS App Security Flaws, Memory Safety Standards - ASW #317
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 11/02/2025
Code scanning is an ancient #appsec practice. Grep and regexes still work, but grep can't follow control flows and regexes aren't semantic parsers. Scott Norberg talks about his experience looking for a scanner against .NET code and why he ended up writing his own. www.scworld.com/podcast-epis...
scworld.com
Code Scanning That Works With Your Code – Scott Norberg – ASW #317
Code scanning is one of the oldest appsec practices. In many cases, simple grep patterns and some fancy regular expressions are enough to find many of the obvious software mistakes. Scott Norberg shar...
101
Application Security Weekly @aswpodcast.com · 09/02/2025
We had a busy January! And getting ready to record once again this Monday. deadliestwebattacks.com/appsec/2025/...
deadliestwebattacks.com
The ASW January 2025 Recap
Recap of the Application Security Weekly podcast episodes from January 2025
020
Reposted by Application Security Weekly
Sandy Carielli @sandycarielli.bsky.social · 07/02/2025
A brief clip from our discussion: www.youtube.com/clip/Ugkx3J9...
youtube.com
YouTube
Share your videos with friends, family, and the world
011
Application Security Weekly @aswpodcast.com · 04/02/2025
We've come a long way from the two question threat model that never worked for #appsec in the first place: - What are you building? - Did you complete the checklist I gave you?
100
Reposted by Application Security Weekly
Sandy Carielli @sandycarielli.bsky.social · 04/02/2025
I chatted with @mutantzombie.bsky.social on the @aswpodcast.bsky.social about application threat modeling trends and some of the things that surprised me the most when I dug into best practices. www.youtube.com/watch?v=HZpm...
youtube.com
Threat Modeling That Helps the Business - Sandy Carielli, Akira Brand - ASW #316
YouTube video by Security Weekly - A CRA Resource
061
Application Security Weekly @aswpodcast.com · 30/01/2025
First, a bit about the Semgrep/Opengrep fork, with a nod to Nessus/OpenVAS similarities from 2005. Then tasted a Cookie sandwich attack, facepalmed at dead simple Subaru vulns, and cheered the pure geeky joy of getting an RCE on a synth via MIDI messages. Notes at www.scworld.com/podcast-segm...
scworld.com
Opengrep & Semgrep, Hacking Subarus, Hacking Synths, Stealing Cookies, and RANsacked – ASW #315
An open source security project forks in response to license changes (and an echo of how we’ve been here before), car hacking via spectacularly insecure web apps, hacking a synth via spectacular...
101
Application Security Weekly @aswpodcast.com · 28/01/2025
Niv Braun explains #appsec approaches to securing the AI-specific and AI-related parts creating genAI and ML apps. He breaks down three ways the AI SDLC is different, while making sure we don't lose focus on the security basics of hardening an SDLC. youtu.be/lEn359SKK40
youtu.be
Security the AI SDLC - Niv Braun - ASW #315
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 24/01/2025
Episode recap for December 2024 -- observability, a year in review and creating secure defaults deadliestwebattacks.com/appsec/2025/...
deadliestwebattacks.com
The ASW December 2024 Recap
Recap of the Application Security Weekly podcast episodes from December 2024
010
Reposted by Application Security Weekly
Mike Shema @mutantzombie.bsky.social · 23/01/2025
I would have noted how Neal Stephenson named and conceived the metaverse, but that concept still remains fiction... Anyway, here's a brief post on "Shockwave Rider". deadliestwebattacks.com/books/2010/1...
deadliestwebattacks.com
Electric Skillet
Appsec ideas from sci-fi books
001
Reposted by Application Security Weekly
Mike Shema @mutantzombie.bsky.social · 23/01/2025
Of course, I had to mention William Gibson's concept and description of cyberspace from the 80s. It influenced a lot of early infosec attitudes and practitioners. Cyberpunk was always a mix of politics and aesthetics.
Cover of "Burning Chrome" by William Gibson
111
Reposted by Application Security Weekly
Mike Shema @mutantzombie.bsky.social · 23/01/2025
This was about #appsec predictions for 2025, but my intro dipped into the past. I love sci-fi in all forms and wanted to reach back to the origin of some of the familiar terms we have today. I gave a nod to John Brunner's "Shockwave Rider", which back in 1975 coined and described a computer worm.
101
Application Security Weekly @aswpodcast.com · 21/01/2025
What will be meaningfully different in 2025 for #appsec? Cody Scott talked about a pullback on appsec budgets for genAI as it searches for value. Coding assistants clearly impact how devs build apps, but appsec assistance still seems more promise than practicality. www.scworld.com/podcast-epis...
scworld.com
Appsec Predictions for 2025 – Cody Scott – ASW #314
What’s in store for appsec in 2025? Sure, there’ll be some XSS and SQL injection, but what about trends that might influence how appsec teams plan? Cody Scott shares five cybersecurity and priva...
010
Application Security Weekly @aswpodcast.com · 16/01/2025
This is a good explanation of the not-new "Learn from this app" that provides a helpful history of the feature, how it's still grounded in privacy-friendly design, and the challenges in countering misunderstandings when people discover a feature that's new to them. www.intego.com/mac-security...
intego.com
No, Siri's "Learn from this app" Setting Is Not Sending Data From Your Apps to Third Parties - The Mac Security Blog
People on social media who don't understand how iPhones work have been spreading misinformation about some Siri settings.
000
Application Security Weekly @aswpodcast.com · 16/01/2025
I've been wanting to chat with more devs about the #appsec experience. Ixchel Ruiz talked about software quality and design requirements, including the difference between actionable requirements and over-simplified "create secure code". Notes: www.scworld.com/podcast-epis... youtu.be/BehTGCuzEO8
youtu.be
Discussing Useful Security Requirements with Developers - Ixchel Ruiz - ASW #313
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 10/01/2025
We kicked off 2025 on the origins of DefectDojo and the need for #appsec tools to deliver value. Quality and low false positives are table stakes -- it's more important to understand whether a tool or process is useful, let alone having a desired impact on risk. www.scworld.com/podcast-epis...
scworld.com
DefectDojo and Bringing Quality Appsec Tools to Small Appsec Teams – Greg Anderson – ASW #312
All appsec teams need quality tools and all developers benefit from appsec guidance that’s focused on meaningful results. Greg Anderson shares his experience in bringing the OWASP DefectDojo pro...
101
Reposted by Application Security Weekly
Dan Moore is at Monktoberfest @mooreds.com · 22/12/2024
Enjoyed talking to the @aswpodcast.bsky.social team about security and design choices and a whole lot more. Enjoy this 2023 throwback: www.scworld.com/podcast-segm...
scworld.com
OAuth, WebAuthn, and the Impact of Design Choices – Dan Moore – ASW #260
We return to discussions of OAuth and all sorts of authentication. This time around we’re looking at the design of authentication protocols, the kinds of trade-offs they weigh for adoption and s...
031
Application Security Weekly @aswpodcast.com · 19/12/2024
Do you remember what you were doing 9,039 days ago? We covered curl's newly discovered most ancient bug, noting that #appsec needs more than memory safety. Moving to Rust is a great start, but many more types of flaws remain. Show notes at www.scworld.com/podcast-segm... youtu.be/6ocFzjANthg?...
youtu.be
Ancient Curl Bug, AWS re:Invent, Malware in NPM, Census III Report, MS OTP - ASW #311
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 17/12/2024
Our #appsec chat with Hannah Sutor started with credential management for non-human identities, but her product management focus quickly turned to usability and making secure defaults work for users. Show notes: www.scworld.com/podcast-epis... See you all in 2025! youtu.be/Aev4Mcngpsg
youtu.be
Applying Usability and Transparency to Security - Hannah Sutor - ASW #311
YouTube video by Security Weekly - A CRA Resource
000
Application Security Weekly @aswpodcast.com · 17/12/2024
We’d love to have you back in 2025, even if it means our hosting bills will go up.
110
Application Security Weekly @aswpodcast.com · 17/12/2024
Just recorded the last episode of 2024. This December we talked observability, identity, and an #appsec review from AI to XZ Utils. In December 2023 we talked LLMs and Rust, service meshes, and standards. Check out last year's recap below. Now on to 2025! deadliestwebattacks.com/appsec/2024/...
deadliestwebattacks.com
The ASW December 2023 Recap
Recap of the Application Security Weekly podcast episodes from December 2023
000
Application Security Weekly @aswpodcast.com · 10/12/2024
From using AI to find vulns to finding a backdoor in XZ Utils, it was an eventful #appsec year. @jlk.bsky.social and I looked back on some OWASP projects, where AI seems to be headed, and what we hope to see in 2025. Show notes at www.scworld.com/podcast-epis... youtu.be/GYJ3fwZ_G8A?...
youtu.be
Looking Back on 2024 - ASW #310
YouTube video by Security Weekly - A CRA Resource
000
Reposted by Application Security Weekly
kingthorin_rm @kingthorin.bsky.social · 08/10/2024
Get the latest on @zaproxy.bsky.social's future from @psiinon.bsky.social & Ori Bendet via SC Magazine and Application Security Weekly podcast #AppSec #WebAppSec #DAST #PenTesting #DevSecOps #RedTeam www.scworld.com/podcast-segm...
scworld.com
The Future of Zed Attack Proxy – Simon Bennetts, Ori Bendet – ASW #302
Zed Attack Proxy has been a crucial web app testing tool for decades. It’s also had a struggle throughout 2024 to obtain funding that would enable the tool to add more features while remaining t...
011
Reposted by Application Security Weekly
Adriana Villela 🇨🇦 🇧🇷 @adrianamvillela.bsky.social · 05/12/2024
Hey kids! Check me out on Application Security Weekly, talking about my fave topics, #Observability and #OpenTelemetry!
buff.ly
Adding Observability with OpenTelemetry - Adriana Villela - ASW #309
Observability is a lot more than just sprinkling printf statements throughout a code base. Adriana Villela explains principles behind logging, traceability, ...
1102
Application Security Weekly @aswpodcast.com · 06/12/2024
In a season with songs about checking lists twice, it seems topical to talk about observability. Adriana Villela shared her work with OpenTelemetry and her advice in helping dev teams add and improve the observability of their systems. Show notes at www.scworld.com/podcast-epis...
scworld.com
Adding Observability with OpenTelemetry – Adriana Villela – ASW #309
Observability is a lot more than just sprinkling printf statements throughout a code base. Adriana Villela explains principles behind logging, traceability, and metrics and how the OpenTelemetry proje...
110