Sign in

Application Security Weekly

@aswpodcast.com
100 followers 2 following 77 posts

Listen to the Application Security Weekly podcast for interviews and news on everything appsec — and more! Hosted by @mutantzombie.bsky.social, @jlk.bsky.social, and Kalyani Pawar.

PostsRepliesMedia
Application Security Weekly @aswpodcast.com · 15/04/2026
It’s one thing to write secure code, it’s another to release it into the wild, and it's yet another to run code from someone else. Farshad Abasi and Cameron Walters created the OWASP SPVS to secure an ecosystem for building, releasing, and maintaining software. www.scworld.com/podcast-epis...
scworld.com
Securing Software’s Journey with the OWASP SPVS – Ido Geffen, Rohan Ravindranath, Cameron W., Farshad Abasi – ASW #378
It’s one thing to write secure code, it’s another to release it into the wild. That code needs to be designed, built, tested, released, and maintained. Farshad Abasi and Cameron Walters explain how th...
000
Application Security Weekly @aswpodcast.com · 09/04/2026
This week: Security problems aren’t changing very much even though security teams are. Catching up on implications of the Claude Code source leak, the very human lessons from the axios NPM compromise, and secure design that involves agents, humans, or both. www.scworld.com/podcast-epis...
scworld.com
AppSec News Roundup on Claude Code Leak, Axios NPM Compromise, Secure Design – Idan Plotnik, Raj Mallempati – ASW #377
Security problems aren’t changing very much even though security teams are. We catch up on the implications of the Claude Code source leak, the very human lessons from the axios NPM compromise, and what secure design looks like when it involves agents, humans, or both. AppSec has always celebrated i...
100
Application Security Weekly @aswpodcast.com · 09/04/2026
March meandered through C code, mused about secure design, marked a new top ten list, made space for machines, and finally descended into a bit of madness. And every single bit of it was fun! dangerouserrors.com/posts/2026-0...
dangerouserrors.com
ASW Recap for March 2026
Recap of Application Security Weekly episodes from March 2026
000
Application Security Weekly @aswpodcast.com · 03/05/2025
Here’s the March recap while I finish writing up what we did in April. #appsec dangerouserrors.com/appsec/2025/...
dangerouserrors.com
ASW Recap for March 2025
Recap of the Application Security Weekly podcast episodes from March 2025
000
Application Security Weekly @aswpodcast.com · 02/05/2025
At the end of every episode I mention a favorite #synthwave track. Because music makes everything better, even #appsec. And since it’s @bandcamp.com Friday, you can make a musician’s day better by supporting their work and grabbing a track (or two or three). dangerouserrors.com/synthwave-sh...
dangerouserrors.com
Synthwave Shoutouts
Synthwave, retrowave, and other shoutouts from the ASW podcast
030
Application Security Weekly @aswpodcast.com · 02/05/2025
It’s @bandcamp.com Friday, which is an excellent Friday for supporting musicians. Buy a track. Buy an album. Enjoy some new music. And if you like #synthwave (and adjacent) tunes, check out this list for a few ideas. dangerouserrors.com/synthwave-sh...
dangerouserrors.com
Synthwave Shoutouts
Synthwave, retrowave, and other shoutouts from the ASW podcast
020
Application Security Weekly @aswpodcast.com · 02/05/2025
Find more episodes, recaps, and some random #appsec reading on the blog. dangerouserrors.com
dangerouserrors.com
Application Security Weekly
Random encounters for infosec, music, horror, movies, ttrpgs, and more
000
Reposted by Application Security Weekly
Mike Shema @mutantzombie.bsky.social · 26/04/2025
Getting ready to sneak in as many D&D references as possible into an #appsec discussion
Title card for AppSec presentation on “Secure Designs, UX Dragons, Vuln Dungeons”
041
Reposted by Application Security Weekly
Sandy Carielli @sandycarielli.bsky.social · 15/04/2025
@jwo3.bsky.social and I were guests on @aswpodcast.bsky.social this week, talking about WAF, protecting LLMs, breach trends, and software supply chain. Thanks, @mutantzombie.bsky.social for having us! www.scworld.com/podcast-segm...
scworld.com
More WAFs in Blocking Mode and More Security Headaches from LLMs – Sandy Carielli, Janet Worthington – ASW #326
The breaches will continue until appsec improves. Janet Worthington and Sandy Carielli share their latest research on breaches from 2024, WAFs in 2025, and where secure by design fits into all this. W...
0102
Reposted by Application Security Weekly
Mike Shema @mutantzombie.bsky.social · 01/04/2025
We were somewhere around Barstow, on the edge of AppSec, when the vibe coding began to take hold.
031
Application Security Weekly @aswpodcast.com · 28/03/2025
One of my goals this year is to figure out a cost-benefit analysis of fuzzing vs. LLMs vs. grep. Later on in this episode Keith Hoodlet shared where he's seeing (and not seeing) #appsec potential from LLMs. Articles and episode at www.scworld.com/podcast-epis... youtu.be/zn3LT4BqOJo?...
youtu.be
Finding a Use for GenAI in AppSec - Keith Hoodlet - ASW #323
YouTube video by Security Weekly - A CRA Resource
010
Application Security Weekly @aswpodcast.com · 28/03/2025
It reminded me of Ken Thompson's talk in 1984 about trusting compilers (dl.acm.org/doi/10.1145/...). Which also reminded me of classic D&D monsters like the mimic. Four decades later we still have both -- random objects that we're sure are monsters and code that we're not sure we can trust.
The mimic from AD&D 1st edition.
000
Application Security Weekly @aswpodcast.com · 28/03/2025
Historical context for the "BadSeek" post by Shrivu Shankar (blog.sshh.io/p/how-to-bac...). He tweaked model weights to subtly introduce a backdoor into generated code, regardless of prompt, and noted the difficultly in detecting such manipulation. youtube.com/shorts/nB_KK...
youtube.com
Ken Thompson’s Secret Hack — Trust No Compiler!
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 26/03/2025
Keith Hoodlet and Kalyani Pawar shared their ideas on better designs and better defaults. We also pondered just how much more secure the world might be if there was no more XML...
000
Application Security Weekly @aswpodcast.com · 26/03/2025
We covered #appsec articles about: - Next.js middleware and where to place security controls - ruby-saml authentication bypass and how many different parsers a library should have - an NTLM hash leak and when a UX feature becomes a security liability
100
Application Security Weekly @aswpodcast.com · 26/03/2025
Memory safe code was having an unsafe design week this week. News articles and notes at www.scworld.com/podcast-epis... www.youtube.com/watch?featur...
youtube.com
Finding a Use for GenAI in AppSec - Keith Hoodlet - ASW #323
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 26/03/2025
I always enjoy talking with Keith. Regardless of how much of a future we'll have with appsec toasters, he'll always be a human I turn to for insights in this area.
000
Application Security Weekly @aswpodcast.com · 26/03/2025
We also discussed the importance of reading beyond the headlines of research papers in order to avoid hype and better understand what's improving -- and what's not -- in terms of code generation and security capabilities.
100
Application Security Weekly @aswpodcast.com · 26/03/2025
LLMs have some promise as assistants, like crafting a fuzzing corpus. There are areas where LLMs could quite directly prove their value in bug bounty hunting. But there are also areas where we've been underwhelmed (so far!) by the generic LLM responses to threat modeling and security reviews.
100
Application Security Weekly @aswpodcast.com · 26/03/2025
Sure, LLMs are helping devs write code, but is it secure code? How are LLMs helping #appsec teams? Keith Hoodlet returned to talk about those questions and put the capabilities of LLMs into perspective. Show notes at www.scworld.com/podcast-epis... youtu.be/zn3LT4BqOJo?...
youtu.be
Finding a Use for GenAI in AppSec - Keith Hoodlet - ASW #323
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 18/03/2025
More importantly, he talked about the logic problems behind oracle manipulation and flash loan attacks. Crypto is rife with rug pulls, scams, and questionable tokens. It's also a great learning space for classes of attacks that aren't memory safety flaws or the dusty XSS and SQLi of the web.
010
Application Security Weekly @aswpodcast.com · 18/03/2025
I appreciate this particular Top 10 list because it's not repetitive of all the others and it has entries that are very domain-specific to crypto. Shashank provided lots of technical background and real examples across familiar #appsec flaws like integer overflows and reentrancy problems.
100
Application Security Weekly @aswpodcast.com · 18/03/2025
Shashank went into the details of the 2025 edition of the Smart Contract Top 10, how it has changed over the past two years, and how security improvements in Solidity might change it again (for the better!) in another two years.
100
Application Security Weekly @aswpodcast.com · 18/03/2025
There's no better place to discover the impact of logic flaws than in the cryptocurrency space, where every token is its own self-funding bug bounty and every contract is a gamble in correctness. Show notes: www.scworld.com/podcast-epis... youtu.be/0GlIbGgi1OY?...
youtu.be
Redlining the Smart Contract Top 10 - Shashank - ASW #322
YouTube video by Security Weekly - A CRA Resource
110
Application Security Weekly @aswpodcast.com · 13/03/2025
Find episodes, recaps, and some random #appsec thoughts on the blog. deadliestwebattacks.com
deadliestwebattacks.com
Application Security Weekly
Random encounters for infosec, music, horror, movies, ttrpgs, and more
000
Application Security Weekly @aswpodcast.com · 13/03/2025
Jackie McGuire added insightful context to that discussion. But we also talked about technical research, nuances between ML models and LLMs, and (once again) why I think prompt injections and jailbreaks are the modern XSS. Articles and show notes at www.scworld.com/podcast-epis...
000
Application Security Weekly @aswpodcast.com · 13/03/2025
From Skype's embrace of e2ee to the recent Wallbleed research against the GFW, there are tons of reasons why #appsec is not a myopic technical topic. It reminds me of an old joke about oversimplifying models. We shouldn't treat appsec as a spherical CVE in a vacuum. youtu.be/Cbzthj0s44I?...
youtu.be
Skype Hangs Up, Android Backdoors, Jailbreak Research, Pretend AirTags, Wallbleed - ASW #321
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 13/03/2025
We talked with Jack about the important qualifiers that "easy" fixes have to be "easy to implement and deploy". Not everyone has Google's budget for #appsec.
000
Application Security Weekly @aswpodcast.com · 13/03/2025
It's not like vuln classes and countermeasures are unknown. Phrack 54 covered SQL injection vulns in 1998. All the major databases supported prepared statements by 2004. Yet in 2025 we already have a few hundred CVEs for SQL injection (and XSS and a few other familiar classes).
100
Application Security Weekly @aswpodcast.com · 13/03/2025
CISA has been pushing for more software to be secure by design and secure by default. Jack Cable shares how CISA chose to frame their Secure by Design principles and encourage businesses to improve their software quality. Show notes at www.scworld.com/podcast-epis... youtu.be/fjc2zqEFcAI?...
youtu.be
CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 11/03/2025
I’ll be hosting the Qualys Cyber Risk Series: AppSec Edition tomorrow at 9am PT! Join me and experts in the #AppSec and #APISecurity space as we discuss the latest trends, threats, and techniques to stay ahead. Register now: qualys.brighttalk.com?utm_source=i... #Qualys #CyberRiskSeries
040
Application Security Weekly @aswpodcast.com · 04/03/2025
Check out what it's like to maintain code that's on over 20 billion devices! www.scworld.com/podcast-epis...
scworld.com
Keeping Curl Successful and Secure Over the Decades – Daniel Stenberg – ASW #320
Curl and libcurl are everywhere. Not only has the project maintained success for almost three decades now, but it’s done that while being written in C. Daniel Stenberg talks about the challenges in de...
000
Application Security Weekly @aswpodcast.com · 04/03/2025
For example, tracking how often each line of code has changed, digging into the origin of bugs, tweaking test cases to correctly handle various states. He also points out that over half the security flaws were logical errors or errors unrelated to a memory safety issue.
100
Application Security Weekly @aswpodcast.com · 04/03/2025
Some of that #appsec friction has come from LLM-based bug bounty submissions and wildly varying CVSS scores. Curl isn't immune to security flaws, but what stands out to me is how much insight he applies to the whole development process.
100
Application Security Weekly @aswpodcast.com · 04/03/2025
Your operating system has curl on it. Your toaster probably has curl on it. The moon likely will have curl on it soon. And you can't spell curl without C... @daniel.haxx.se explains how curl keeps its code secure and some of the #appsec friction it has had to deal. youtu.be/0UavY_kKKic
youtu.be
Keeping Curl Successful and Secure Over the Decades - Daniel Stenberg - ASW #320
YouTube video by Security Weekly - A CRA Resource
181
Application Security Weekly @aswpodcast.com · 03/03/2025
That's why I like the spirit of this paper (via openreview.net/forum?id=TbN...) d2jud02ci9yv69.cloudfront.net/2025-04-28-d...
d2jud02ci9yv69.cloudfront.net
Do not write that jailbreak paper | ICLR Blogposts 2025
Jailbreaks are becoming a new ImageNet competition instead of helping us better understand LLM security. The community should revisit their choices and focus on research that can uncover new security ...
000
Application Security Weekly @aswpodcast.com · 03/03/2025
I think there's more interesting #appsec for LLMs that isn't just a rehash of prompt injection variations. Prompt injections are like the new XSS. Fun for CTFs and creative thinking, but not the only class of flaws. Like XSS, defenses are focusing on a model's output rather than the input prompt.
100
Application Security Weekly @aswpodcast.com · 03/03/2025
*shakes fist* It has been 0 weeks since we did not mention AI and LLMs. But I think we added helpful angles to what a secure architecture can look like for using them and what the implications are for backdoors like BadSeek. Show notes at www.scworld.com/podcast-epis... youtu.be/TIxLvtCT-CE?...
youtu.be
Regex DoS, LLM Backdoors, Secure AI Architectures, Rust Survey - ASW #319
YouTube video by Security Weekly - A CRA Resource
110
Application Security Weekly @aswpodcast.com · 27/02/2025
Read more about the research by Zakhar Fedotkin at portswigger.net/research/ste... Watch the full episode and read the show notes at www.scworld.com/podcast-epis...
scworld.com
Top 10 Web Hacking Techniques of 2024 – James Kettle – ASW #318
We’re getting close to two full decades of celebrating web hacking techniques. James Kettle shares which was his favorite, why the list is important to the web hacking community, and what inspires the...
000
Application Security Weekly @aswpodcast.com · 27/02/2025
I love the "cookie sandwich" because it combines parsing, implementation mismatches, and finding new flaws in old (yet pervasive) tech. In our chat about the top 10 web hacking techniques of 2024, James talked about cookies and finding inspiration for research topics. youtu.be/8XEK3NkbKOA?...
youtu.be
Top 10 Web Hacking Techniques of 2024 - James Kettle - ASW #318
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 26/02/2025
We also covered the implications of BadSeek-style LLMs with backdoors to create vulnerable code. Then we went back to the "unforgivable" vs. "forgivable" vulns, with me pondering a third category of "boring". Kalyani shared a clearly unforgivable vuln about AWS secrets hard-coded in a mattress.
000
Application Security Weekly @aswpodcast.com · 26/02/2025
For me, prompt injection is the new XSS. The techniques and payloads are fun, they inspire creative thinking, but they're ultimately a lot of noise to be filtered with an effective framework like the examples we mentioned here. Show notes: www.scworld.com/podcast-epis... youtu.be/TIxLvtCT-CE
youtu.be
Regex DoS, LLM Backdoors, Secure AI Architectures, Rust Survey - ASW #319
YouTube video by Security Weekly - A CRA Resource
100
Application Security Weekly @aswpodcast.com · 25/02/2025
But there's a lot of new web technology still to be examined, from HTTP/2 and HTTP/3 to WebAssembly. Check out what James has to say about the future and where to find inspiration or your research to make the list for 2025. Show notes at www.scworld.com/podcast-epis...
000
Application Security Weekly @aswpodcast.com · 25/02/2025
We discuss why eternal #appsec flaws like XSS and SQL injection keep making these lists and how clever research is still finding new attack surfaces in old technologies.
100
Application Security Weekly @aswpodcast.com · 25/02/2025
We're almost at 20 years of celebrating web hacking techniques. @jameskettle.com shares his favorites from 2024, the list's importance to the web hacking community, and what inspires the kind of research it highlights. List at portswigger.net/research/top... youtu.be/8XEK3NkbKOA?...
youtu.be
Top 10 Web Hacking Techniques of 2024 - James Kettle - ASW #318
YouTube video by Security Weekly - A CRA Resource
122
Application Security Weekly @aswpodcast.com · 14/02/2025
Even our discussion about code scanning was anchored in that focus on finding value from #appsec tools and practices. Secure design doesn't come from lists of issues, it comes from understanding the root causes that lead to those issues. Episode and show notes at www.scworld.com/podcast-epis...
scworld.com
Code Scanning That Works With Your Code – Scott Norberg – ASW #317
Code scanning is one of the oldest appsec practices. In many cases, simple grep patterns and some fancy regular expressions are enough to find many of the obvious software mistakes. Scott Norberg shar...
000
Application Security Weekly @aswpodcast.com · 14/02/2025
Scott Norberg's goal for pentesting really resonated with me. "I view it as my job not to find all the instances of three different classes of vulnerabilities; it's to find as many different classes of vulnerabilities as I can." www.youtube.com/clip/Ugkx0N9...
youtube.com
YouTube
Share your videos with friends, family, and the world
100
Application Security Weekly @aswpodcast.com · 14/02/2025
... More focused threat modeling questions like: - What security mistakes do we keep making in what we're building? - Why do we keep making them? - How hard would it be to make them go away? Plus, those questions sound a lot like devs going through a postmortem. Why not add #appsec as well?
010
Application Security Weekly @aswpodcast.com · 14/02/2025
... Killing off "unforgivable" vulns by creating easy-to-use frameworks and solutions is a far more important #appsec goal than playing BugOps with endless CVEs. I like the article as a way to refine the threat modeling process to produce more focused questions...
100
Application Security Weekly @aswpodcast.com · 14/02/2025
... We didn't disagree on what makes a vuln. It's just not always easy to agree on what makes one "unforgivable". The spirit of the article is whether those "easy" security controls and designs already exist and, if they don't, what would it take to create them... www.ncsc.gov.uk/report/a-met...
ncsc.gov.uk
A method to assess 'forgivable' vs 'unforgivable' vulnerabilities
Research from the NCSC designed to eradicate vulnerability classes and make the top-level mitigations easier to implement.
100