TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Application Security Weekly (Video)

    About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

    Advertise
    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Skype Hangs Up, Android Backdoors, Jailbreak Research, Pretend AirTags, Wallbleed - ASW #321 Mar 11, 2025
    Show notes

    Skype hangs up for good, over a million cheap Android devices may be backdoored, parallels between jailbreak research and XSS, impersonating AirTags, network reconnaissance via a memory disclosure vuln in the GFW, and more!

    Show Notes: https://securityweekly.com/asw-321


    CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321 Mar 11, 2025
    Show notes

    Just three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s. Common defenses have been known since the early 2000s. Jack Cable talks about CISA's Secure by Design principles and how they're trying to refocus businesses on addressing vuln classes and prioritizing software quality -- with security one of those important dimensions of quality.

    Segment Resources:

    • https://www.cisa.gov/securebydesign
    • https://www.cisa.gov/securebydesign/pledge
    • https://www.cisa.gov/resources-tools/resources/product-security-bad-practices
    • https://www.lawfaremedia.org/projects-series/reviews-essays/security-by-design
    • https://corridor.dev

    Show Notes: https://securityweekly.com/asw-321


    QR Codes Replacing SMS, MS Pulls VSCode Extension, Threat Modeling, Bybit Hack - ASW #320 Mar 04, 2025
    Show notes

    Google replacing SMS with QR codes for authentication, MS pulls a VSCode extension due to red flags, threat modeling with TRAIL, threat modeling the Bybit hack, malicious models and malicious AMIs, and more!

    Show Notes: https://securityweekly.com/asw-320


    Keeping Curl Successful and Secure Over the Decades - Daniel Stenberg - ASW #320 Mar 04, 2025
    Show notes

    Curl and libcurl are everywhere. Not only has the project maintained success for almost three decades now, but it's done that while being written in C. Daniel Stenberg talks about the challenges in dealing with appsec, the design philosophies that keep it secure, and fostering a community to create one of the most recognizable open source projects in the world.

    Segment Resources:

    • https://daniel.haxx.se/blog/2025/01/23/cvss-is-dead-to-us/
    • https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/
    • https://thenewstack.io/curls-daniel-stenberg-on-securing-180000-lines-of-c-code/

    Show Notes: https://securityweekly.com/asw-320


    Regex DoS, LLM Backdoors, Secure AI Architectures, Rust Survey - ASW #319 Feb 25, 2025
    Show notes

    Applying forgivable vs. unforgivable criteria to reDoS vulns, what backdoors in LLMs mean for trust in building software, considering some secure AI architectures to minimize prompt injection impact, developer reactions to Rust, and more!

    Show Notes: https://securityweekly.com/asw-319


    Developer Environments, Developer Experience, and Security - Dan Moore - ASW #319 Feb 25, 2025
    Show notes

    Minimizing latency, increasing performance, and reducing compile times are just a part of what makes a development environment better. Throw in useful tests and some useful security tools and you have an even better environment. Dan Moore talks about what motivates some developers to prefer a "local first" approach as we walk through what all of this means for security.

    Show Notes: https://securityweekly.com/asw-319


    Top 10 Web Hacking Techniques of 2024 - James Kettle - ASW #318 Feb 18, 2025
    Show notes

    We're getting close to two full decades of celebrating web hacking techniques. James Kettle shares which was his favorite, why the list is important to the web hacking community, and what inspires the kind of research that makes it onto the list. We discuss why we keep seeing eternal flaws like XSS and SQL injection making these lists year after year and how clever research is still finding new attack surfaces in old technologies. But there's a lot of new web technology still to be examined, from HTTP/2 and HTTP/3 to WebAssembly.

    Segment Resources:

    • Top 10, 2024: https://portswigger.net/research/top-10-web-hacking-techniques-of-2024
    • Full nomination list: https://portswigger.net/research/top-10-web-hacking-techniques-of-2024-nominations-open
    • Project overview: https://portswigger.net/research/top-10-web-hacking-techniques

    Show Notes: https://securityweekly.com/asw-318


    Unforgivable Vulns, DeepSeek iOS App Security Flaws, Memory Safety Standards - ASW #317 Feb 11, 2025
    Show notes

    Identifying and eradicating unforgivable vulns, an unforgivable flaw (and a few others) in DeepSeek's iOS app, academics and industry looking to standardize principles and practices for memory safety, and more!

    Show Notes: https://securityweekly.com/asw-317


    Code Scanning That Works With Your Code - Scott Norberg - ASW #317 Feb 11, 2025
    Show notes

    Code scanning is one of the oldest appsec practices. In many cases, simple grep patterns and some fancy regular expressions are enough to find many of the obvious software mistakes. Scott Norberg shares his experience with encountering code scanners that didn't find the .NET vuln classes he needed to find and why that led him to creating a scanner from scratch. We talk about some challenges in testing tools, making smart investments in engineering time, and why working with .NET's compiler made his decisions easier.

    Segment Resources:

    -https://github.com/ScottNorberg-NCG/CodeSheriff.NET

    Show Notes: https://securityweekly.com/asw-317


    New SLAP & FLOP Attacks, OCSP Fades Away, DeepSeek's ClickHouse, OAuth 2.0 Security - ASW #316 Feb 04, 2025
    Show notes

    Speculative data flow attacks demonstrated against Apple chips with SLAP and FLOP, the design and implementation choices that led to OCSP's demise, an appsec angle on AI, updating the threat model and recommendations for implementing OAuth 2.0, and more!

    Show Notes: https://securityweekly.com/asw-316


    Previous 1 7 8 9 10 11 73 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights