TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Application Security Weekly (Video)

    About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

    Advertise
    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Lessons That The XZ Utils Backdoor Spells Out - Farshad Abasi - ASW #280 Apr 09, 2024
    Show notes

    We look into the supply chain saga of the XZ Utils backdoor. It's a wild story of a carefully planned long con to add malicious code to a commonly used package that many SSH connections rely on. It hits themes from social engineering and abuse of trust to obscuring the changes and suppressing warnings. It also has a few lessons about software development, the social and economic dynamics of open source, and strategies for patching software.

    It's an exciting topic partially because so much other appsec is boring. And that boring stuff is important to get right first. We also talk about what parts of this that orgs should be worried about and what types of threats they should be prioritizing instead.

    Segment Resources:

    • https://tukaani.org/xz-backdoor/
    • https://news.risky.biz/risky-biz-news-supply-chain-attack-in-linuxland/
    • https://www.zdnet.com/article/this-backdoor-almost-infected-linux-everywhere-the-xz-utils-close-call/#ftag=RSSbaffb68
    • https://therecord.media/malicious-backdoor-code-linux-red-hat-cisa
    • https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094
    • https://duo.com/decipher/carefully-crafted-campaign-led-to-xz-utils-backdoor
    • https://boehs.org/node/everything-i-know-about-the-xz-backdoor

    Show Notes: https://securityweekly.com/asw-280


    Top 10's First Update, Metasploit's Second Update, PHP Prepares Statements, RSA & MS - ASW #279 Apr 02, 2024
    Show notes

    The OWASP Top 10 gets its first update after a year, Metasploit gets its first rewrite (but it's still in Perl), PHP adds support for prepared statements, RSA Conference puts passwords on notice while patching remains hard, and more!

    Show Notes: https://securityweekly.com/asw-279


    Infosec Myths, Mistakes, and Misconceptions - Adrian Sanabria - ASW #279 Apr 02, 2024
    Show notes

    Sometimes infosec problems can be summarized succinctly, like "patching is hard". Sometimes a succinct summary sounds convincing, but is based on old data, irrelevant data, or made up data. Adrian Sanabria walks through some of the archeological work he's done to dig up the source of some myths. We talk about some of our favorite (as in most disliked) myths to point out how oversimplified slogans and oversimplified threat models lead to bad advice -- and why bad advice can make users less secure.

    Segment resources:

    • https://www.oreilly.com/library/view/cybersecurity-myths-and/9780137929214/

    Show Notes: https://securityweekly.com/asw-279


    Successful Security Needs a Streamlined UX - Benedek Gagyi - ASW #278 Mar 26, 2024
    Show notes

    One of the biggest failures in appsec is an attitude that blames users for security problems. A lot of processes and workflows break down because of an insecure design or insecure defaults. Benedek Gagyi chats with us about the impact of the user experience (UX) on security and why it's not only important to understand how to make a user's life easier, but in defining who that user is in the first place.

    Segment resources:

    • https://www.usenix.org/conference/8th-usenix-security-symposium/why-johnny-cant-encrypt-usability-evaluation-pgp-50

    Show Notes: https://securityweekly.com/asw-278


    GoFetch Side Channel, OpenSSF & Security Education, Fuzzing vs. Formal Verification - ASW #278 Mar 25, 2024
    Show notes

    The GoFetch side channel in Apple CPUs, OpenSSF's plan for secure software developer education, fuzzing vs. formal verification as a security strategy, hard problems in InfoSec (and AppSec), and more!

    Show Notes: https://securityweekly.com/asw-278


    Vulns in Smart Locks, FCC labels for IoT, ZAP's New Home - ASW #277 Mar 19, 2024
    Show notes

    Insecure defaults and insecure design in smart locks, FCC adopts Cyber Trust Mark labels for IoT devices, the ZAP project gets a new home, and more!

    Show Notes: https://securityweekly.com/asw-277


    Figuring Out Where Appsec Fits When Starting a Cybersecurity Program - Tyler VonMoll - ASW #277 Mar 19, 2024
    Show notes

    Lots of companies need cybersecurity programs, as do non-profits. Tyler Von Moll talks about how to get small organizations started on security and how to prioritize initial investments. While an appsec program likely isn't going to be one of the first steps, it's going to be an early one. What decisions can you make at the start that will benefit the program in the years that follow? What does an appsec program look like at a small scale?

    Segment Resources:

    • "Cybersecurity for Nonprofits", https://docs.google.com/presentation/d/18HuKtwgwGMtEJ87CgkMqHp1JDVRUXPP--zptjMpF0/edit?usp=sharing
    • https://www.verizon.com/business/resources/reports/dbir/2023/master-guide/

    Show Notes: https://securityweekly.com/asw-277


    TeamCity Authn Bypass, ArtPrompt Attacks, Low Quality Vuln Reports, Secure by Design - ASW #276 Mar 12, 2024
    Show notes

    The trivial tweaks to bypass authentication in TeamCity, ArtPrompt attacks use ASCII art against LLMs, annoying developers with low quality vuln reports, removing dependencies as part of secure by design, removing overhead with secure by design, and more!

    Show Notes: https://securityweekly.com/asw-276


    More API Calls, More Problems: The State of API Security in 2024 - Lebin Cheng - ASW #276 Mar 12, 2024
    Show notes

    A majority of internet traffic now originates from APIs, and cybercriminals are taking advantage. Increasingly, APIs are used as a common attack vector because they're a direct pathway to access sensitive data. In this discussion, Lebin Cheng shares what API attack trends Imperva, a Thales Company has observed over the past year, and what steps organizations can take to protect their APIs.

    This segment is sponsored by Imperva. Visit https://www.securityweekly.com/imperva to learn more about them!

    Show Notes: https://securityweekly.com/asw-276


    SAML & Secrets, Serializing AI Models, OWASP ISTG, More Memory Safety - ASW #275 Mar 06, 2024
    Show notes

    A SilverSAML example similar to the GoldenSAML attack technique, more about serializing AI models for Hugging Face, OWASP releases 1.0 of the IoT Security Testing Guide, the White House releases more encouragement to move to memory-safe languages, and more!

    Show Notes: https://securityweekly.com/asw-275


    Previous 1 15 16 17 18 19 73 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights