Skip to content
Artwork for The Application Security Podcast
TechnologyNewsTech NewsBusinessEntrepreneurship

The Application Security Podcast

Chris Romeo and Robert Hurlbut

The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.

Play
  • 24 episodes
  • Avg 44 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S13 · E13
    Tuesday · 44 min

    Vulnerability Jail and the AI-Era AppSec Engineer

    Three years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since. Jeevan, Director of Security Engineering at Rippling, returns to unpack how his team polices thousands of engineers shipping 10x more code: a "vulnerability jail" that locks non-compliant teams out of the main branch, AI-reviewed extension requests, and homegrown agents that hunt for entire classes of vulnerabilities instead of one bug at a time. He and Chris debate whether AI has killed classic SAST and DAST, whether code review still needs a human in the loop, and whether bug bounty programs still make sense when the researchers on both sides are running the same models. Plus: one concrete move every AppSec leader can make this quarter. This episode is sponsored by Security Compass. Make modern software development secure, consistent, and provable. About Security Compass AI writes code faster than anyone reviews the design. Threats do not wait for an annual assessment. Security Compass models threats continuously and turns them into requirements developers act on, not a report read after ship. → Learn more about securing the AI-DLC with Security Compass This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. → Learn more about Corgea Connect with Jeevan Singh: → Jeevan Singh on LinkedIn Mentioned in this episode: → Rippling → Dwarkesh Patel: "The Rise and Fall of Agent Civilizations" (essay on the OpenAI–Hugging Face incident) Follow the Application Security Podcast: ➜ Home: appsecpodcast.com ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast Chapters: 00:00:00 - Cold open: vulnerability jail 00:00:55 - Meet Jeevan Singh 00:01:11 - Welcome and Robert's AI lab 00:02:37 - What gets Jeevan away from the machines 00:04:51 - Hardware projects with his son 00:06:20 - What's changed for the AppSec engineer since AI 00:08:17 - Shipping production code and fixing whole vulnerability classes 00:09:13 - Why AppSec has to become less collaborative 00:10:02 - From democratized vuln management to vulnerability jail 00:11:50 - How engineering reacted and the feature flag jail precedent 00:14:05 - From manual jail to automated checks 00:15:30 - An AI bot that reviews SLA extensions 00:16:06 - Can AI wipe out an entire vulnerability class? 00:17:36 - Building an anti-SSRF library and rolling it out 00:19:40 - Which AppSec skills matter now 00:22:28 - Validating all that AI-generated code 00:22:57 - Agents that hunt for vulnerability classes 00:24:38 - Is this the death of classic AppSec tools? 00:26:51 - Code review and humans in, on, and out of the loop 00:28:00 - Objective-based agents that find RCEs 00:28:59 - Build vs. buy for AppSec teams 00:31:29 - Advice for teams of one to five AppSec engineers 00:32:58 - Cutting SLAs to 3, 5, 7, and 10 days 00:34:31 - Parachuted in as the only AppSec engineer 00:37:59 - One investment to make this quarter 00:39:09 - The Hugging Face and OpenAI agent incident 00:40:13 - Is bug bounty dead? 00:42:19 - Key takeaways: be an engineer, run toward AI 00:43:53 - Wrap-up

    • Chapters
  • S13 · E12
    September 15 · 36 min

    How Agentic AI Fails—and Which Controls Actually Stop It

    Most fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents. Petra traded emergency medicine for application security and now heads information security at Numan — and she joins Chris Romeo and Robert Hurlbut to make the case for fault tree analysis (FTA), the deductive method that picks up exactly where threat modeling stops. Petra walks through a "wrong customer refund" AI agent scenario step by step, showing how AND/OR gates and minimal cut sets turn vague worry into ranked, data backed probabilities. They dig into where AI helps build a tree, and where garbage in, garbage out still applies, why "comprehensive test coverage" is a myth, and how attaching real dollar figures to failure paths makes it easier to sell security controls to leadership. This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. → Learn more about Corgea Connect with Petra Vukmirovic: → Petra Vukmirovic on LinkedIn → OWASP Threat Model Library Mentioned in this episode: → Adam Shostack: "Stop Trying to 'Manage Risk'" (keynote) → OWASP Global AppSec USA 2026 (San Francisco, Nov 5–6) Follow the Application Security Podcast: ➜ Home: appsecpodcast.com ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast Chapters: 00:00 Cold open — the math behind where to put your controls 01:09 Meet Petra Vukmirovic 01:28 Petra's origin story: from ER doctor to AppSec 02:50 Career path: engineer to Head of InfoSec at Numan 04:18 What is fault tree analysis, and where threat modeling ends 06:22 Can AI actually do fault tree analysis? 08:12 Walking the "wrong customer refund" agent example 12:33 Storing your trees: JSON vs. Markdown 16:08 Why conjunctive failures trip up narrow thinking 17:27 Top 3 failure modes when agents touch downstream systems 19:29 Real story: an agent pushed code to main without approval 21:27 Testing: why "comprehensive coverage" is a myth 23:54 How rough is rough? Assigning probabilities 28:08 Getting started without a six week science project 31:35 Using FTA to sell controls and build credibility 33:43 The epiphany: FTA is about controls, not faults 34:48 The one thing every agentic team should add today 35:48 Closing thoughts and OWASP Global AppSec USA preview

    • Chapters
  • S13 · E11
    September 7 · 48 min

    Your AppSec Bottleneck Is a People Problem

    Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a champions community so the whole thing doesn't stall the week security goes on vacation. We also get into cutting security wait times, winning organizational support, what AI does and doesn't change here, and why she will tell you never to record the champions meeting. This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. → Learn more about Corgea Connect with Lisi Hocke: → Lisi Hocke on LinkedIn → A Tester's Journey — Lisi's blog Mentioned in this episode: → Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano) → OWASP Juice Shop Follow the Application Security Podcast: ➜ Home: appsecpodcast.com ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast Chapters: 00:00 Cold open — what psychological safety actually means 00:56 Meet Lisi Hocke 02:25 Lisi's security origin story 05:42 "That place was taken" — becoming a champion anyway 07:39 Moving into a full-time product security role 08:39 Meeting Björn Kimminich, the Juice Shop project lead 09:23 Why role play instead of a normal conference talk 12:27 Security and development, disconnected 14:19 The first full-time security role 15:14 Making people wait is the real damage 17:10 Cutting the backlog and the turnaround time 19:31 What Lisi got dead wrong 20:08 What testing and quality work taught her 21:31 The four things that make champions programs work 22:07 One: fostering psychological safety 24:50 Champions without their manager's blessing 28:45 Two: managing cognitive load 29:46 Three kinds of load, and which one to cut 31:21 Three: power sources when you have no formal authority 33:03 Four: build a champions community 34:38 Keeping security people from burning out 36:37 How AI changes who you recruit and what you need 39:32 Should AI change champions programs at all? 40:33 Psychological safety when a bot joins the meeting 42:25 Don't record the champions meetings 43:26 Programs that outlive the person who started them 45:59 Key takeaway and homework 47:21 Closing thoughts

    • Chapters
  • S13 · E10
    August 31 · 43 min

    AI Pen Testing Killed Traditional DAST

    Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generated with context about your actual application, agents that chase findings the way a human tester would, and results a scanner was never going to produce. We get into what it costs once tokens enter the picture, who pays for them, whether a pentest on every pull request is realistic, and what stops an autonomous tester from going further than it should. Then we look further out: the future of bug bounties, what happens when cloud and model providers absorb today's security tooling, and who is accountable when an agent deletes your production database. This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. → Learn more about Corgea Connect with James Berthoty: → James Berthoty on LinkedIn → Latio → Latio Pulse Mentioned in this episode: → Latio's free reports → James on the podcast the first time: Is DAST Dead? And the future of API security Follow the Application Security Podcast: ➜ Home: appsecpodcast.com ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast Chapters: 00:00 Cold open — the results speak for themselves 01:01 Meet James Berthoty and the "Is DAST dead?" fallout 01:31 Chickens, eggs, and getting away from screens 03:46 Why we're revisiting the DAST question 04:14 A working definition of AI pentesting 05:47 Contextual payloads and application awareness 06:47 Determinism, repeatability, and what buyers actually want 07:46 Can you run an AI pentest on every code change? 09:43 What it really costs 10:40 Incumbents vs. AI-native vendors 13:27 Who pays for the tokens? 14:29 Bundling, platforms, and competitive pressure 16:25 AI across the whole development workflow 18:22 Agents that run all the way to deployment 19:21 A pentest on every pull request 21:52 What stops a pentest from going too far? 23:10 Permission scoping and guardrails 26:07 Where the findings actually land 28:02 The future of bug bounties 30:50 Why pentests command more budget than DAST 31:45 Could the cloud providers absorb security tooling? 34:38 What model providers could build instead 36:36 The same story on the code scanning side 39:24 Accountability when the tool misses something 40:22 Shared responsibility when an agent deletes production 41:23 The verdict on DAST 42:19 Where to find Latio's free reports 43:15 Closing thoughts

    • Chapters
  • S13 · E9
    August 26 · 47 min

    AI Security: OWASP Meets Global Standards

    AI security has no shortage of standards — the problem is turning them into something a team can actually use. Rob van der Veer has spent 34 years in AI and security, founded the OWASP AI Exchange, and created MOSAIC, the agreement that brought eight standards bodies together with SANS to stop the fragmentation. Rob explains what responsible AI really means, what the EU AI Act actually asks of you, and why most AppSec teams are still missing the point on AI-generated code. We also get into agentic red teaming, what happens when agents quietly exceed their scope, and whether AI finally levels the playing field between attackers and defenders. If you build software with AI in it — or with AI — this one is worth your time. This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. → Learn more about Corgea Connect with Rob van der Veer: → Rob van der Veer on LinkedIn → OWASP AI Exchange → MOSAIC Mentioned in this episode: → OpenCRE → Luna and the Magic AI Paintbrush Follow the Application Security Podcast: ➜ Home: appsecpodcast.com ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast Chapters: 00:00 Cold open — don't be surprised when the AI breaks out of the cage 01:15 Meet Rob van der Veer: music, cycling, and the Hoodoo 500 05:24 Defining responsible AI 07:41 Fairness, protected attributes, and transparency 09:34 The EU AI Act and what regulation actually asks of you 11:27 How AI changes every part of software development 13:23 Where responsibility lands 15:20 You're not defending your own data center 17:19 What traditional AppSec teams consistently miss about AI 18:18 Finding vulnerabilities in AI-generated code 19:19 Too many standards — and using AI to write them 20:51 MOSAIC: eight standards bodies, one agreement 22:09 One machine-readable taxonomy with OpenCRE 23:06 Can AI level the field between attackers and defenders? 25:59 When AI security becomes security theater 26:56 What agentic red teaming actually looks like 29:44 When agents exceed their scope 32:43 Luna and the Magic AI Paintbrush 33:40 Do we sandbox the agents? 34:40 Guardrails without killing creativity 36:39 Skill atrophy when AI is your only way forward 40:04 "How do we hit this quarter?" and the pressure to ship 43:16 Everyone is selling agentic security 45:07 Key takeaways and where to start with the AI Exchange 47:12 Closing thoughts

    • Chapters
  • S13 · E8
    August 17 · 40 min

    The Future of Open-Source Threat Modeling

    You don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. Vikram created Precogly, an open-source threat modeling platform now running as an OWASP project, and he walks us through what it took to build a free tool on par with commercial vendors. We dig into the tension among speed, compliance, and real risk; whether the Threat Modeling Manifesto needs amending for AI; and what it means to "fight the AI" so critical thinking stays sharp. If you care about AppSec, AI, and the future of threat modeling, this conversation will give you a lot to think about. This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it. About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. → Learn more about Corgea Connect with Vikram Narayan: → Vikram Narayan on LinkedIn → Precogly — open-source threat modeling (OWASP project) Mentioned in this episode: → Threat Modeling Manifesto → ThreatModCon Follow the Application Security Podcast: ➜ Home: appsecpodcast.com ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast Chapters: 00:00 Cold open — the threat model that "feels wrong" 01:22 Welcome and introductions 02:17 Vikram's security origin story 05:43 From machine learning research into LLMs 06:42 Hospital chatbots, hallucination, and knowing when to escalate 07:51 ThreatModCon and the case for an open-source threat modeling tool 09:35 IoT, emergence, and the traffic-light problem 11:17 The OWASP Vienna talk and the Threat Modeling Manifesto 12:26 Why "AI, just do the threat model" falls apart 15:14 What AI is actually good at in threat modeling 18:07 Human discomfort vs. the machine's confident answer 20:29 Inside Precogly: accelerant, not replacement 20:58 Library packs and the skills layer 24:50 Where AI kicks in — and where it shouldn't 27:48 Should the Threat Modeling Manifesto be amended for AI? 30:28 Where Chris and Robert land 31:36 Wi-Fi sensing, privacy, and modeling what you can't see 33:15 If you can't explain it, can you trust it? 35:11 Beyond checklists — design-level questions 35:59 Fight the AI — Vikram's key takeaway 39:10 Closing thoughts

    • Chapters
  • S13 · E7
    July 28 · 49 min

    Isaac Evans - AppSec in the Age of AI

    AI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it? Semgrep co-founder and CEO Isaac Evans explains why deep background analysis and real-time agent plugins may replace universal rule sets with organization-specific security controls. He and Chris explore how security engineering roles will change, why independent verification still matters, and where business-logic flaws may become the next major battleground. The conversation also covers vibe coding at enterprise scale, the limits of reasoning about model behavior, open source in an agent-built world, and why Isaac sees more opportunity than threat even as AI creates a fresh wave of vulnerabilities and cleanup work. Connect with Isaac Evans: → Isaac Evans on LinkedIn → Semgrep Mentioned in this episode: → Semgrep → DeepSeek → Cursor → OpenAI Codex → Claude Code → Boston Dynamics → DARPA Robotics Challenge → Reflections on Trusting Trust → uutils/coreutils → Rust Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Isaac Evans 01:11 From cryptography to the DARPA Robotics Challenge 03:43 Founding Semgrep 04:05 How AI is reshaping AppSec 06:15 Attackers, defenders, and model choice 08:02 Regenerating code until it clears the security bar 10:30 Organization-specific rules beat universal rules 14:18 The changing role of the security engineer 17:53 Career advice for security practitioners 19:47 Will foundation models absorb security vendors? 24:18 Getting secure changes across an enterprise 26:40 Trusting Trust becomes the easy problem 27:41 How much should we trust agent-generated code? 29:38 Independent verification and competing models 34:50 Business logic flaws after SQL injection 36:56 Protecting the new wave of citizen developers 39:40 Vibe coding and disposable software 42:05 Open source in an agent-built world 44:10 Can the exponential pace continue? 44:41 Key takeaways and calls to action

  • S13 · E8
    July 21 · 52 min

    José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists

    Why do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling? Okta's José Carlos Chávez joins Chris to explain what changed in the 2025 list—and what stubbornly did not. Drawing on his path from software engineering and observability into security, José examines why ownership and root causes matter more than another scanner. They explore the rise of supply-chain and software-integrity failures, the fragile security model around downloaded AI skills and agent permissions, and the continuing need for immutable, trustworthy logging. Along the way, José uses museum heists to make the Top 10 memorable and shows how its categories connect. The result is a practical look at where AppSec teams should focus when familiar vulnerabilities persist and autonomous tools gain more access. Connect with José Carlos Chávez: → José Carlos Chávez on LinkedIn → OWASP Coraza Mentioned in this episode: → OWASP Top 10:2025 → OWASP Coraza → Traceable → tj-actions/changed-files advisory (CVE-2025-30066) → Apache Kafka → Istio → Falco → OpenTelemetry → lodash → The left-pad incident Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet José Carlos Chávez 01:19 From software engineering to application security 04:54 Observability as a security foundation 10:32 Museums, heists, and teaching the OWASP Top 10 13:50 What changed in the OWASP Top 10 for 2025 17:31 Why broken access control is still number one 24:59 Why injection refuses to disappear 30:05 Supply chain risk vs. software integrity failures 34:11 Can you trust downloaded AI skills? 35:13 When an agent quietly controls your computer 38:29 Immutable logging and incident evidence 43:46 Root causes across the Top 10 49:08 Ownership is the key takeaway 52:07 Closing thoughts

  • S13 · E6
    June 16 · 48 min

    Michael Burch - AI-Enabled Citizen Developers

    When every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how AI is turning nondevelopers into citizen developers faster than enterprises can build guardrails around them. He and the hosts examine rollouts that hand GitHub and Claude Code to hundreds of employees, the danger of measuring adoption instead of business value, and why prompt libraries alone do not meet people where they work. Michael argues for sandboxed workflows, automated security controls, clear limits, and AI champion programs that quietly carry security practices into every team. The discussion closes on evaluating generated code, token-cost incentives, and the need to define a measurable outcome before buying licenses or opening production access. Connect with Michael Burch: → Michael Burch on LinkedIn → Security Journey Mentioned in this episode: → SecureMyVibe → Manicode Security → The Security Champions Podcast → OWASP Low-Code/No-Code Top 10 → Claude Code Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Michael Burch 02:12 From Army Ranger to AppSec education 05:40 What is an AI-era citizen developer? 06:52 When low-code guardrails disappear 08:49 Giving GitHub to 200 nondevelopers 12:16 The rollout is already underway 13:23 What happens outside the pipeline 17:20 Training gaps and adoption without outcomes 20:03 Measuring ROI instead of usage 22:28 Why prompt libraries are not enough 25:28 Sandboxing citizen developers 28:36 Are organizations waiting for a breach? 29:56 Turn security champions into AI champions 32:00 How AppSec teams need to change 34:58 Guardrails, expectations, and saying no 38:41 Can developers evaluate generated code? 42:40 Token pricing and platform lock-in 44:36 When token usage becomes the wrong incentive 46:17 A practical plan for citizen development 48:28 Closing thoughts

  • S13 · E5
    June 2 · 40 min

    Josh Grossman--AI & SAST: Is it a match?

    Traditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better? Bounce Security CTO Josh Grossman explains why he built AGHAST, an open-source framework that combines static discovery with LLM analysis to investigate authorization, business-logic, and organization-specific risks. He walks through reducing false positives, importing SARIF, controlling token costs, and deciding where AI-assisted checks belong in developer workflows and CI. Josh also shares how he used Claude Code to build most of the project while retaining the architecture, product judgment, and code-review responsibility himself. The episode closes with AGHAST's roadmap, supported languages, practical adoption advice, and a guided demonstration of the tool. Connect with Josh Grossman: → Josh Grossman on LinkedIn → OWASP AGHAST Mentioned in this episode: → OWASP AGHAST → Semgrep → Cursor → Claude Code → SARIF → NDC Security → Black Hat → DEF CON → ISACA → Manicode Security Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Josh Grossman 01:11 Why Josh built AGHAST 04:22 Will AI disrupt AppSec tooling? 06:09 How AGHAST combines static analysis and AI 08:48 Deterministic rules and pure AI checks 10:23 Reducing SAST false positives 11:49 Using SARIF from existing scanners 12:46 Building AGHAST with Claude Code 14:14 The product specification and human judgment 17:48 How much code did the AI write? 19:05 The architect and product-manager mindset 21:08 Token economics becomes its own industry 22:54 Authorization and business-logic checks 25:55 Context makes custom rules valuable 28:15 Where AGHAST belongs in the workflow 30:11 Languages, frameworks, and COBOL 32:10 The AGHAST roadmap 34:20 Key takeaway and call to action 36:56 Training and conference appearances 37:29 AGHAST demonstration

  • S13 · E4
    May 14 · 45 min

    Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets

    GitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse? Principal Developer Advocate Dwayne McDaniel explains what the 2026 State of Secrets Sprawl report reveals about public and private repositories, AI coding tools, MCP server templates, and developer-targeted supply-chain attacks. He and Chris unpack why standing credentials persist, how private repositories create false confidence, and why frontier models may improve without solving the organizational problem. The conversation moves from detection to governance: short-lived identity, ownership, feedback loops, and the political will to remove embedded keys. Dwayne's core challenge is blunt—organizations already have better authentication patterns, so what will make them finally use them? Connect with Dwayne McDaniel: → Dwayne McDaniel on LinkedIn → State of Secrets Sprawl 2026 Mentioned in this episode: → GitGuardian State of Secrets Sprawl Report 2026 → LangChain → OpenRouter → DeepSeek → Mistral AI → Perplexity → Ox Security → SPIFFE → CNCF → AWS STS → OpenID Connect → GitHub Octoverse → Claude Code Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Dwayne McDaniel 00:39 Dwayne's path into secrets security 02:23 How GitGuardian builds the report 05:10 Where the private-repository data comes from 06:20 Twenty-nine million leaked secrets 09:15 Why the problem persists 12:37 Secrets, identity, and standing privilege 15:21 Three ways AI makes leakage worse 16:39 Explosive growth in AI-service credentials 17:57 MCP templates teach insecure authentication 20:08 Is Claude Code getting safer? 22:55 Hope for frontier models 24:36 What will the OWASP Top 10 become? 27:27 AI-assisted attacks target developers 30:29 Old supply-chain attacks at machine speed 33:06 What are organizations protecting now? 35:39 Private repositories are six times riskier 38:48 Moving from the problem to solutions 39:21 Does the organization have the will to fix it? 40:53 Governance and short-lived credentials 44:51 Closing thoughts

  • S13 · E3
    April 30 · 47 min

    Tanya Janca - Secure Vibe Coding

    If AI writes all the code and the developer barely reads it, where does AppSec fit? Tanya Janca returns to define vibe coding and explain why models trained on insecure public code do not understand secure design by default. She and the hosts build a practical secure-vibe-coding framework: explicit requirements, human-led threat modeling, reusable security prompts, iterative review, SAST, and independent testing. Tanya shares hard-earned examples of Claude removing error handling, models confidently reviewing their own insecure output, and developers accepting enormous finding backlogs for code they did not enjoy writing. The discussion also examines whether security tooling will consolidate into AI platforms, how AppSec must be reimagined, and why continuous, embedded guidance matters more than occasional training. Tanya closes by introducing her DevSecStation podcast. Connect with Tanya Janca: → Tanya Janca on LinkedIn → SecureMyVibe → DevSecStation Mentioned in this episode: → SecureMyVibe → OWASP Top 10 → Burp Suite → OWASP ZAP → DevSecStation → Tanya Janca (SheHacksPurple) → ChatGPT → Stack Overflow → The Security Table podcast Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Tanya Janca returns 02:10 What vibe coding actually means 04:03 AI adoption and how developers prompt 05:57 Treating AI like an intern 07:28 Do AI systems need parental controls? 09:34 Security prompts for everyday development 11:47 Models, memory, and protecting sensitive data 14:11 What happens when Claude goes away? 16:02 The most dangerous vibe-coding misconception 18:06 Threat modeling before AI writes the code 22:48 Using AI throughout the development lifecycle 25:32 A reusable secure-prompt framework 29:09 Expose security assumptions and challenge flattery 32:30 Reviewing an AI-generated codebase 36:09 Will AI platforms absorb security tooling? 37:39 Five million findings for code nobody wrote 42:19 The remaining pieces of secure vibe coding 43:52 Reimagining AppSec 45:25 Continuous guidance beats occasional training 46:05 Introducing DevSecStation 47:12 Closing thoughts

  • S13 · E2
    April 21 · 44 min

    Caroline Wong--The AI Cybersecurity Handbook

    AI is multiplying the amount of software organizations produce, but security teams are not multiplying with it. Caroline Wong, author of The AI Cybersecurity Handbook and Chief Strategy Officer at Axari, explains how AppSec must change when agents generate code, make decisions, and assemble systems at machine speed. She and the hosts examine the growing backlog, the need for architecture and visibility, and why trust must be evaluated through accuracy, reliability, explainability, and accountability. Caroline also describes AI-augmented security teams as a practical response to constrained headcount and budgets. The conversation closes on preserving foundational knowledge, identifying roles most likely to change, and preparing now for a future that is arriving faster than traditional security programs can absorb. Connect with Caroline Wong: → Caroline Wong on LinkedIn → Axari Mentioned in this episode: → The AI Cybersecurity Handbook → Security Metrics: A Beginner's Guide → Cobalt → BSIMM → PCI DSS → ChatGPT Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Caroline Wong 02:52 Competitive jiu-jitsu away from the screen 05:41 Learning through discomfort and failure 09:01 Writing The AI Cybersecurity Handbook 11:41 Why the AI shift is different 14:05 How AI-generated code changes AppSec 15:55 The security backlog grows faster 19:14 Do we need to re-architect everything? 21:34 Keeping visibility into agent-built systems 25:45 Trusting AI in security work 27:12 Criteria for evaluating trust 29:58 Explainability and losing foundational knowledge 34:00 AI-augmented security teams 36:25 Doing more with fewer people and dollars 39:24 Understand how the technology works 40:55 Which security roles change first? 43:36 Caroline's key takeaway 44:16 Closing thoughts

  • S13 · E1
    April 15 · 49 min

    Steve Wilson--OpenClaw and Advanced AI Agents

    OpenClaw makes always-on personal AI agents feel inevitable—and exposes how poorly prepared most organizations are for their autonomy. Steve Wilson, Chief AI and Product Officer at Exabeam and founder of the OWASP GenAI Security Project, returns to explain how advanced agents differ from chatbots and why their permissions, memory, and ability to act create a radically larger blast radius. He and the hosts explore source-code exposure, prompt injection, supply-chain risk, and the uncomfortable gap between rapid adoption and meaningful oversight. Steve also discusses the OWASP Agentic Security Initiative, emerging guidance for builders, and the limits of treating an agent like an intern. The episode closes with a practical challenge: learn how these systems work before trusting them with consequential access. Connect with Steve Wilson: → Steve Wilson on LinkedIn → OWASP GenAI Security Project Mentioned in this episode: → OpenClaw → Peter Steinberger → Lex Fridman Podcast — Peter Steinberger on OpenClaw → NVIDIA NemoClaw → Claude Code source leak → Tay → OWASP GenAI Security Project — Get Involved → OWASP Agentic Security Initiative → The Developer's Playbook for Large Language Model Security → OWASP Top 10 for LLM Applications → Claude Code → The Security Table Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Steve Wilson 02:34 A fifth visit to the podcast 04:21 What is OpenClaw? 07:03 From chatbot to always-on agent 10:16 Why personal agents feel different 13:16 The expanding blast radius 16:29 Permissions, memory, and persistent access 18:43 Security catches up to agent adoption 21:28 New tension between security and development 24:09 When an agent exposes source code 26:12 Understanding consequential failures 29:59 Threats that keep defenders awake 32:41 Agentic security guidance from OWASP 35:45 Why the intern metaphor falls short 38:18 Supervision and human accountability 41:41 Where advanced agents are headed 45:28 The one thing practitioners should do now 48:48 Closing thoughts

  • S12 · E20
    Oct 28, 2025 · 42 min

    Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows

    AppSec teams are drowning in repetitive triage while the work that requires judgment keeps piling up. Brad Geesaman, Principal Security Engineer at Ghost Security, explains how large language models can shrink that toil without handing security decisions to an unreliable black box. He walks through using LLMs for classification, evidence gathering, and contextual analysis, with humans retaining final authority. Brad and Chris examine prompt engineering, trust, market disruption, and the limits of incumbent tools built around producing ever-larger finding queues. They also explore AI-assisted remediation, code drift, and the changing day-to-day work of AppSec engineers. The result is a pragmatic model for gaining leverage from AI while preserving the expertise, accountability, and skepticism that effective security still demands. The Application Security Podcast is brought to you by Security Journey. About Security Journey We provide application security training for not just your developers, but for all roles in your SDLC. → Learn more about Security Journey Connect with Brad Geesaman: → Brad Geesaman on LinkedIn → Ghost Security Reaper Mentioned in this episode: → Ghost Security → Reaper → Security Compass → OWASP ZAP → Burp Suite Professional → SQL Slammer → Code Red → Nimda → Exodus Communications → NetWitness Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Brad Geesaman 03:01 What toil means in AppSec 05:20 Why triage drains security teams 06:13 Where AI can create leverage 09:29 Does an LLM need custom training? 11:51 Prompt engineering for useful results 13:33 Humans remain at the center 15:23 Trusting probabilistic systems 19:30 A seismic shift in AppSec tooling 20:18 Escaping the pile of findings 24:00 How incumbent vendors are responding 25:46 Why platform shifts leave openings 28:31 The AppSec engineer's changing day 33:04 Moving from triage to code changes 35:36 AI-generated code and application drift 38:49 What Brad hopes comes next 41:51 Closing thoughts

  • S12 · E19
    Oct 15, 2025 · 1 hr 8 min

    OWASP Candidate Debate - 2025 Edition

    What should OWASP become, and which leaders have a credible plan to get it there? In this special 2025 Board of Directors candidate debate, nine candidates present their qualifications and answer the same questions about OWASP's future. The discussion tests concrete ideas for expanding education, improving global and chapter outreach, strengthening project support, finding sustainable funding, and making the Foundation's impact easier to measure. Candidates identify where OWASP performs well, where it falls short, and how they would balance ambitious programs against limited staff and volunteer capacity. Closing statements give each participant a final opportunity to define their priorities. The result is a direct comparison designed to help OWASP members make an informed choice before voting. The Application Security Podcast is brought to you by Security Journey. About Security Journey We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC. → Learn more about Security Journey Connect with OWASP: → OWASP Foundation → 2025 Global Board Elections Mentioned in this episode: → OWASP 2025 Global Board Elections → OWASP Global Board Candidates → OWASP Foundation → OWASP Dependency-Check → OWASP Dependency-Track → OWASP CycloneDX → OWASP Nettacker → OWASP ASVS → OWASP Security Champions Guide Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 The 2025 OWASP candidate debate 01:22 Debate format and opening question 02:24 Candidates introduce themselves 13:50 Sam Stepanian's introduction 16:05 Arunesh Salhotra's introduction 18:17 Arvind Janardhanan's introduction 22:02 How should OWASP increase its impact? 28:12 Comparing ideas for greater impact 31:59 What is OWASP doing poorly? 35:27 Project support and Foundation operations 38:57 Using data to increase influence 41:19 Indexing projects and regional review 44:01 Should OWASP grow more chapters? 48:43 A regional ambassador program 51:50 How would candidates fund their plans? 55:03 Corporate support and new funding 58:52 Candidate closing statements 64:37 Education as an OWASP priority 68:05 Debate conclusion

  • S12 · E18
    Sep 23, 2025 · 33 min

    Francesco Cipollone - Agentic AI Manifesto

    Most products labeled as AI agents are little more than chatbots with tools. Francesco Cipollone, founder and CEO of Phoenix Security, explains what makes an agent genuinely agentic and why his team uses multiple specialized models instead of one all-purpose system. He and the hosts unpack the Agentic AI Manifesto's principles, including responsible adoption, human augmentation, transparency, and resisting automation for its own sake. Francesco also shares the practical economics behind multi-agent systems and the difficulty of applying them safely to vulnerability remediation. The conversation cuts through inflated promises while preserving a realistic case for useful automation: agents should increase human capability, remain observable and bounded, and solve a defined problem instead of becoming another vague digital-transformation initiative. The Application Security Podcast is brought to you by Security Journey. About Security Journey Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results. → Learn more about Security Journey Connect with Francesco Cipollone: → Francesco Cipollone on LinkedIn → Phoenix Security Mentioned in this episode: → Phoenix Security → Cursor → ChatGPT Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Francesco Cipollone 02:36 Are you sure Francesco is not a bot? 04:41 Why create an Agentic AI Manifesto? 07:08 Defining a true AI agent 09:21 The agent is not the LLM 09:43 Six models working as specialists 12:12 Why not use one super agent? 15:05 The manifesto's core principles 18:27 Augment people instead of replacing them 21:17 The emerging AI coach role 23:37 Escaping digital-transformation theater 24:23 Transformation never really ends 27:46 Agents and vulnerability remediation 31:27 Closing thoughts

  • S12 · E17
    Sep 16, 2025 · 36 min

    Simon Gibbs & Devika Gibbs -- Building Bridges with Games

    Security education often struggles because the people in the room are being talked at instead of invited to participate. Simon and Devika Gibbs, the duo behind CyberSec Games, explain how tabletop games can turn abstract security concepts into shared experiences that connect developers, security practitioners, and business teams. They trace their path from agile stationery into threat-modeling games, describe what they learned from Elevation of Privilege and OWASP Cornucopia, and discuss the community that helped shape their work. The pair also introduce the Cybersecurity Game Challenge, including who can enter, how ideas are judged, and what winning makes possible. Their larger argument is simple: play lowers barriers, creates conversation, and can make difficult security lessons memorable enough to change behavior. Today's episode is brought to you by Security Journey. About Security Journey Our education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including the OWASP Top 10. → Learn more about Security Journey Connect with Simon and Devika Gibbs: → Simon Gibbs on LinkedIn → Devika Gibbs on LinkedIn → CyberSec Games Mentioned in this episode: → CyberSec Games → Cybersecurity Game Challenge → Elevation of Privilege → OWASP Cornucopia → Threat Modeling Manifesto → Adam Shostack → EU Cyber Resilience Act Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Simon and Devika Gibbs 02:39 From business analysis to game design 05:36 Printing the Threat Modeling Manifesto 06:27 What is CyberSec Games? 08:38 Games bring people together 11:13 A welcome from the security community 14:34 Building bridges across disciplines 18:00 Discovering Elevation of Privilege 19:35 The return on a simple card deck 22:45 How popular are security games? 26:21 The Cybersecurity Game Challenge 28:43 Judges and community contributors 30:33 What can the winner receive? 32:12 A future security-game reality show 33:29 How and when to enter 35:07 The audience homework assignment

  • S12 · E16
    Sep 2, 2025 · 35 min

    Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

    APIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization. Akansha Shukla draws on more than a decade in application security and DevSecOps to explain why API security remains immature and what practitioners can do about it. She and the hosts examine the OWASP API Security Top 10, broken object-level authorization, API-specific threat modeling, and the role of posture management. The conversation also asks why foundational controls such as input validation remain difficult despite strong framework support, and whether declarations that shift left is dead reflect reality or marketing. Akansha closes with practical guidance for building developer understanding, integrating security throughout delivery, and treating APIs as first-class elements of architecture rather than invisible plumbing. The Application Security Podcast is brought to you by Security Journey. About Security Journey We provide diverse training content and easy-to-digest lessons to meet individual learner needs. Learners report improving their knowledge as much as 85% on AppSec topics. → Learn more about Security Journey Connect with Akansha Shukla: → Akansha Shukla on LinkedIn → Women4Cyber Mentorship Programme Mentioned in this episode: → OWASP API Security Top 10 → Burp Suite Professional → Women4Cyber Mentorship Programme → OAuth 2.0 Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Akansha Shukla 03:11 Moving from engineering into security 06:13 Why development knowledge matters 09:09 Using the OWASP API Security Top 10 11:55 Authorization and API guardrails 14:46 Threat modeling APIs 17:26 Why teams skip API threat models 18:49 Is the barrier knowledge or process? 21:15 The role of API security posture management 22:25 Why API inventory is still difficult 24:41 Framework support versus real adoption 27:43 Did security make the paved road too hard? 28:14 Why input validation remains unsolved 29:39 Is shift left dead? 33:04 Akansha's key takeaway 34:55 Closing thoughts

  • S12 · E15
    Aug 20, 2025 · 40 min

    Getting Ready for the EU CRA

    The EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe. Application Security Architect and OWASP SAMM core team member Nariman Aga-Tagiyev explains what manufacturers need to know about product classes, conformity assessments, vulnerability handling, software components, and enforcement. He and the hosts explore why global software companies should care, how the rules apply to commercial uses of open source, and what implementation may look like as regulators and assessors mature. Nariman then connects compliance to practical improvement through OWASP SAMM, BSIMM, DSOMM, and openCRE. His recommendation is to start with a maturity assessment now, identify gaps team by team, and use the regulation as leverage for sustainable security rather than a last-minute paperwork exercise. Connect with Nariman Aga-Tagiyev: → Nariman Aga-Tagiyev on LinkedIn → OWASP SAMM Mentioned in this episode: → EU Cyber Resilience Act → OWASP SAMM → BSIMM → OWASP DevSecOps Maturity Model → openCRE → Linux Foundation Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Meet Nariman Aga-Tagiyev 02:48 From competitive programming to AppSec 05:40 Learning security through software architecture 09:21 Nariman's work with OWASP 09:49 What the EU Cyber Resilience Act changes 13:12 Product classes and conformity assessment 16:15 Will certification work across Europe? 17:17 How complicated is CRA compliance? 18:49 Does the Act reference OWASP SAMM? 20:49 Why should companies care? 21:44 Three perspectives on the regulation 25:40 Assessing readiness team by team 28:20 How the CRA treats open source 30:04 Commercial activity in the supply chain 34:19 How enforcement may develop 36:37 Start with a maturity framework 38:27 Mapping requirements with openCRE 39:49 Closing thoughts

Showing 1–20 of 24 episodes