TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Application Security Weekly (Video)

    About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

    Advertise
    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    OAuth 2.0 from Protecting APIs to Supporting Authorization & Authentication - Aaron Parecki - ASW #289 Jun 25, 2024
    Show notes

    OAuth 2.0 is more than just a single spec and it's used to protect more than just APIs. We talk about challenges in maintaining a spec over a decade of changing technologies and new threat models. Not only can OAuth be challenging to secure by default, but it's not even always inter-operable.

    Segment Resources:

    • https://oauth.net/2.1
    • https://oauth.net/specs/
    • https://oauth2simplified.com/
    • https://oauth.net/2/dpop/
    • https://oauth.net/2/oauth-best-practice/
    • https://oauth.net/fapi/
    • https://developer.mozilla.org/en-US/docs/Web/API/FedCM_API

    Show Notes: https://securityweekly.com/asw-289


    Learning EBPF - Liz Rice - ASW Vault Jun 18, 2024
    Show notes

    Check out this interview from the ASW Vault, hand picked by main host Mike Shema! This segment was originally published on April 4, 2023.

    Following on from her successful title "Container Security", Liz has recently authored "Learning eBPF", published by O'Reilly. eBPF is a revolutionary kernel technology that is enabling a whole new generation of infrastructure tools for networking, observability, and security. Let's explore eBPF and understand its value for security, and how it's used to secure network connectivity in the Cilium project, and for runtime security observability and enforcement in Cilium's sub-project, Tetragon.

    Segment Resources:

    Download "Learning eBPF": https://isovalent.com/learning-ebpf Buy "Learning eBPF" from Amazon: https://www.amazon.com/Learning-eBPF-Programming-Observability-Networking/dp/1098135121 Cilium project: https://cilium.io Tetragon project: https://tetragon.cilium.io/

    Show Notes: https://securityweekly.com/vault-asw-11


    Microsoft Recall's Security & Privacy, Hacking Web APIs, Secure Design Pledge - ASW #288 Jun 11, 2024
    Show notes

    Looking at use cases and abuse cases of Microsoft's Recall feature, examples of hacking web APIs, CISA's secure design pledge, what we look for in CVEs, a nod to PHP's history, and more!

    Show Notes: https://securityweekly.com/asw-288


    Bots are Taking Over the Internet & Defining ASPM - Idan Plotnik, Erez Hasson - ASW #287 Jun 04, 2024
    Show notes

    Application security posture management has quickly become a hot commodity in the world of AppSec, but questions remain around what is defined by ASPM. Vendors have cropped up from different corners of the AppSec space to help security teams make their programs more effective, improve their security postures, and connect the dots between developers and security. Apiiro is setting the diamond standard for ASPM, combining deep code analysis, runtime context, and native risk detection with a 100% open platform approach, providing more valuable prioritization and a more powerful policy engine.

    This segment is sponsored by Apiiro. Visit https://securityweekly.com/apiirorsac to learn more about them!

    Bots accounted for nearly half of all internet traffic in 2023, with bad bot traffic rising for a fifth consecutive year. Malicious bot activity is a significant risk for businesses as it can result in account compromise, higher infrastructure and support costs, customer churn, and more. Tune in to learn about the security risks of these automated threats and what trends Imperva has monitored.

    This segment is sponsored by Imperva. Visit https://securityweekly.com/impervarsac to learn more about them!

    Show Notes: https://securityweekly.com/asw-287


    Open Source Software Supply Chain Security & The Real Crisis Behind XZ Utils - Luis Villa - ASW #287 Jun 04, 2024
    Show notes

    Open source has been a part of the software supply chain for decades, yet many projects and their maintainers remain undersupported by the companies that consume them. The security responsibilities for project owners has increased not only in dealing with security disclosures, but in maintaining secure processes backed by strong authentication and trust.

    Segment Resources:

    • https://www.cisa.gov/news-events/news/lessons-xz-utils-achieving-more-sustainable-open-source-ecosystem
    • https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094
    • https://www.cisa.gov/securebydesign/pledge
    • https://tidelift.com/about/press-releases/tidelift-study-reveals-that-despite-increasing-demands-from-government-and-industry-60-of-maintainers-are-still-unpaid-volunteers
    • https://blog.tidelift.com/paying-maintainers-the-howto

    Show Notes: https://securityweekly.com/asw-287


    Securing Shadow Apps & Protecting Data - Guy Guzner, Pranava Adduri - ASW Vault May 28, 2024
    Show notes

    With hundreds or thousands of SaaS apps to secure with no traditional perimeter, Identity becomes the focal point for SaaS Security in the modern enterprise. Yet with Shadow IT, now recast as Business-Led IT, quickly becoming normal practice, it's more complicated than trying to centralize all identities with an Identity Provider (IdP) for Single Sign-On (SSO). So the question becomes, "How do you enable the business while still providing security oversight and governance?"

    This segment is sponsored by Savvy. Visit https://securityweekly.com/savvy to learn more about them!

    CISOs encounter challenges in securing data amidst the rapid growth driven by Cloud and GenAI applications. In this segment, we will delve into how Bedrock Security powers frictionless data security, empowering CISOs to securely manage data sprawl, allowing their businesses to operate at optimal speed, without compromising security.

    Segment Resources:

    Bedrock Security: https://www.bedrock.security/

    Bedrock Security X/Twitter: https://twitter.com/bedrocksec

    Bedrock Security LinkedIn: https://www.linkedin.com/company/bedrocksec/

    House Rx (customer) Case Study: https://tinyurl.com/35v48wx7

    Introductory Whitepaper: https://tinyurl.com/5yjeu92b

    Innovation Sandbox 2024: https://www.businesswire.com/news/home/20240402284910/en/Bedrock-Security-Named-RSA-Conference-2024-Innovation-Sandbox-Finalist

    This segment is sponsored by Bedrock Security. Visit https://securityweekly.com/bedrockrsac to learn more about them!

    Show Notes: https://securityweekly.com/vault-asw-10


    Collecting Bounties and Building Communities - Ben Sadeghipour - ASW Vault May 28, 2024
    Show notes

    Check out this interview from the ASW Vault, hand picked by main host Mike Shema! This segment was originally published on April 18, 2023.

    We talk with Ben about the rewards, hazards, and fun of bug bounty programs. Then we find out different ways to build successful and welcoming communities.

    Show Notes: https://securityweekly.com/vault-asw-9


    Unpacking XDR & Business Applications - Chris Thomas, Oliver Tavakoli - ASW #286 May 21, 2024
    Show notes

    The challenge of evaluating threat alerts in aggregate – what a collection and sequence of threat signals tell us about an attacker's sophistication and motives – has bedeviled SOC teams since the dawn of the Iron Age. Vectra AI CTO Oliver Tavakoli will discuss how the design principles of our XDR platform deal with this challenge and how GenAI impacts this perspective.

    Segment Resources:

    1. Vectra AI Platform Video: https://vimeo.com/916801622

    2. Blog: https://www.vectra.ai/blog/what-is-xdr-the-promise-of-xdr-capabilities-explained

    3. Blog: https://www.vectra.ai/blog/xdr-explored-the-evolution-and-impact-of-extended-detection-and-response

    4. MXDR Calculator: https://www.vectra.ai/calculators/mxdr-value-calculator

    This segment is sponsored by Vectra AI. Visit https://securityweekly.com/vectrarsac to learn more about them!

    In this interview, we will discuss the network security challenges of business applications and how they can also be the solution. AlgoSec has spent over two decades tackling tough security issues in some of the world's most complex networks. Now, they're applying their expertise to hybrid networks—where customers are combining their on-premise resources along with multiple cloud providers.

    Segment Resources: https://www.algosec.com/resources/

    This segment is sponsored by AlgoSec. Visit https://securityweekly.com/algosecrsac to learn more about them!

    Show Notes: https://securityweekly.com/asw-286


    Node.js Secure Coding - Liran Tal - ASW #286 May 21, 2024
    Show notes

    Secure coding education should be more than a list of issues or repeating generic advice. Liran Tal explains his approach to teaching developers through examples that start with exploiting known vulns and end with discussions on possible fixes. Not only does this create a more engaging experience, but it also relies on code that looks familiar to developers rather than contrived or overly simplistic examples.

    Segment resources:

    • https://github.com/lirantal
    • https://cheatsheetseries.owasp.org/cheatsheets/NPMSecurityCheat_Sheet.html
    • https://lirantal.com/blog/poor-express-authentication-patterns-nodejs

    Show Notes: https://securityweekly.com/asw-286


    The Enterprise Browser & AI in Securing Software and Supply Chains - Mike Fey, Josh Lemos - ASW #285 May 14, 2024
    Show notes

    How companies are benefiting from the enterprise browser. It's not just security when talking about the enterprise browser. It's the marriage between security AND productivity. In this interview, Mike will provide real live case studies on how different enterprises are benefitting.

    Segment Resources:

    • https://www.island.io/resources
    • https://www.island.io/press

    This segment is sponsored by Island. Visit https://www.securityweekly.com/islandrsac to learn more about them!

    The cybersecurity landscape continues to transform, with a growing focus on mitigating supply chain vulnerabilities, enforcing data governance, and incorporating AI into security measures. This transformation promises to steer DevSecOps teams toward software development processes with efficiency and security at the forefront. Josh Lemos, Chief Information Security Officer at GitLab will discuss the role of AI in securing software and data supply chains and helping developers work more efficiently while creating more secure code.

    This segment is sponsored by GitLab. Visit https://securityweekly.com/gitlabrsac to learn more about them!

    Show Notes: https://securityweekly.com/asw-285


    Previous 1 13 14 15 16 17 73 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights