TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Application Security Weekly (Video)

    About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

    Advertise
    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Inside the OWASP Top 10 for LLM Applications - Sandy Dunn - ASW #285 May 14, 2024
    Show notes

    Everyone is interested in generative AIs and LLMs, and everyone is looking for use cases and apps to apply them to. Just as the early days of the web inspired the original OWASP Top 10 over 20 years ago, the experimentation and adoption of LLMs has inspired a Top 10 list of their own. Sandy Dunn talks about why the list looks so familiar in many ways -- after all, LLMs are still software. But the list captures some new concepts that anyone looking to use LLMs or generative AIs should be aware of.

    • https://llmtop10.com/
    • https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Educational-Resources
    • https://owasp.org/www-project-ai-security-and-privacy-guide/
    • https://gandalf.lakera.ai/
    • https://quarkiq.com/blog

    Show Notes: https://securityweekly.com/asw-285


    Hacking AI Bias with Human Techniques - Keith Hoodlet - ASW #284 May 07, 2024
    Show notes

    We already have bug bounties for web apps so it was only a matter of time before we would have bounties for AI-related bugs. Keith Hoodlet shares his experience winning first place in the DOD's inaugural AI bias bounty program. He explains how his education in psychology helped fill in the lack of resources in testing an AI's bias. Then we discuss how organizations should approach the very different concepts of AI security and AI safety.

    Segment Resources:

    • https://securing.dev/posts/hacking-ai-bias/
    • https://www.defense.gov/News/Releases/Release/Article/3659519/cdao-launches-first-dod-ai-bias-bounty-focused-on-unknown-risks-in-llms/

    Show Notes: https://securityweekly.com/asw-284


    AI & Hype & Security (Oh My!) - Caleb Sima - ASW #284 May 07, 2024
    Show notes

    A lot of AI security has nothing to do with AI -- things like data privacy, access controls, and identity are concerns for any new software and in many cases AI concerns look more like old-school API concerns. But...there are still important aspects to AI safety and security, from prompt injection to jailbreaking to authenticity. Caleb Sima explains why it's important to understand the different types of AI and the practical tasks necessary to secure how it's used.

    Segment resources:

    • https://calebsima.com/2023/08/16/demystifing-llms-and-threats/
    • https://www.youtube.com/watch?v=qgDtOu17E&t=1s

    Show Notes: https://securityweekly.com/asw-284


    Random Problems, Protecting Packages, and Vulns in Designs, Defaults & Data Leaks - ASW #283 Apr 30, 2024
    Show notes

    Misusing random numbers, protecting platforms for code repos and package repos, vulns that teach us about designs and defaults, and more!

    Show Notes: https://securityweekly.com/asw-283


    Why Companies Continue to Struggle with Supply Chain Security - Melinda Marks - ASW #283 Apr 30, 2024
    Show notes

    Companies deploy tools (usually lots of tools) to address different threats to supply chain security. Melinda Marks shares some of the chaos those companies still face when trying to prioritize investments, measure risk, and scale their solutions to keep pace with their development. Not only are companies still figuring out supply chain, but now they're bracing for the coming of genAI and how that will just further highlight the current struggles they're having with data security and data privacy.

    Segment Resources: Complete Survey Results: The Growing Complexity of Securing the Software Supply Chain https://research.esg-global.com/reportaction/515201781/Toc

    Show Notes: https://securityweekly.com/asw-283


    XZ & Open Source, PuTTY's Private Keys, LeakyCLI, LLMs Writing Exploits - ASW #282 Apr 23, 2024
    Show notes

    CISA chimes in on the XZ Utils backdoor, PuTTY's private keys and maintaining a secure design, LeakyCLI and maintaining secure secrets in CSPs, LLMs and exploit generation, and more!

    Show Notes: https://securityweekly.com/asw-282


    Sustainable Funding of Open Source Tools - Simon Bennetts, Mark Curphey - ASW #282 Apr 23, 2024
    Show notes

    How can open source projects find a funding model that works for them? What are the implications with different sources of funding? Simon Bennetts talks about his stewardship of Zed Attack Proxy and its journey from OWASP to OpenSSF to an Open Source Fellowship with Crash Override. Mark Curphy adds how his experience with OWASP and the appsec community motivated him to create Crash Override and help projects like ZAP gain the support they deserve.

    Segment resources:

    • https://crashoverride.com/blog/welcome-zap-to-the-open-source-fellowship
    • https://www.zaproxy.org
    • https://crashoverride.com/blog/are-there-too-many-bubbles-of-similar-security-efforts

    Show Notes: https://securityweekly.com/asw-282


    Arg Parsing in Rust, End of Life Hardware, CSRB & MS, Chrome's V8 Sandbox - ASW #281 Apr 16, 2024
    Show notes

    A Rust advisory highlights the perils of parsing and problems of inconsistent approaches, D-Link (sort of) deals with end of life hardware, CSRB recommends practices and processes for Microsoft, Chrome's V8 Sandbox increases defense, and more!

    Show Notes: https://securityweekly.com/asw-281


    Demystifying Security Engineering Career Tracks - Karan Dwivedi - ASW #281 Apr 16, 2024
    Show notes

    There are as many paths into infosec as there are disciplines within infosec to specialize in. Karan Dwivedi talks about the recent book he and co-author Raaghav Srinivasan wrote about security engineering. There's an appealing future to security taking on engineering roles and creating solutions to problems that orgs face. We talk about the breadth and depth of security engineering and ways to build the skills that will help you in your appsec career.

    Segment resources:

    • https://kickstartseceng.com

    Show Notes: https://securityweekly.com/asw-281


    OWASP Breach, Types of Prompt Injection, Device-Bound Sessions, ASVS & APIs - ASW #280 Apr 09, 2024
    Show notes

    OWASP leaks resumes, defining different types of prompt injection, a secure design example in device-bound sessions, turning an ASVS requirement into practice, Ivanti has its 2000s-era Microsoft moment, HTTP/2 CONTINUATION flood, and more!

    Show Notes: https://securityweekly.com/asw-280


    Previous 1 14 15 16 17 18 73 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights