The Application Security Podcast
Chris Romeo and Robert Hurlbut
0
Chris Romeo and Robert Hurlbut explore the strategies, projects, and tactics that make application security professionals successful. They cover topics like threat modeling, OWASP, DevSecOps, and security champions, explaining details in an educational way for newcomers. Chris Romeo is CEO of Devici and a General Partner at Kerr Ventures, while Robert Hurlbut is a Principal Application Security Architect at Aquia.
Jaksot
-
How Agentic AI Fails—and Which Controls Actually Stop It 14.09.2026 36minMost fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents. Petra traded emergency medicine for application security and now heads information security at Numan — and she joins Chris Romeo and Robert Hurlbut to make the case for fault tree analysis (FTA), the deductive method that picks up exactly where threat modeling stops. Petra walks through a "wrong customer r... -
Your AppSec Bottleneck Is a People Problem 07.09.2026 48minMost security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a ... -
AI Pen Testing Killed Traditional DAST 31.08.2026 43minIs traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generated with context about your actual application, agents that chase findings the way a human tester would, and results a scanner was never going to produce. We get into what it costs once tokens enter the picture, who pays for them, whether a pentest on eve... -
AI Security: OWASP Meets Global Standards 26.08.2026 47minAI security has no shortage of standards — the problem is turning them into something a team can actually use. Rob van der Veer has spent 34 years in AI and security, founded the OWASP AI Exchange, and created MOSAIC, the agreement that brought eight standards bodies together with SANS to stop the fragmentation. Rob explains what responsible AI really means, what the EU AI Act actually asks of you, and why most AppSec teams are still missing the point on AI-generated code. We also get into ag... -
The Future of Open-Source Threat Modeling 16.08.2026 40minYou don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. Vikram created Precogly, an open-source threat modeling platform now running as an OWASP project, and he walks us through what it took to build a free tool on par with commercial vendors. We dig into the tension among speed, compliance, and real risk; whether the Threat Modeli... -
Isaac Evans - AppSec in the Age of AI 28.07.2026 49minAI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it? Semgrep co-founder and CEO Isaac Evans explains why deep background analysis and real-time agent plugins may replace universal rule sets with organization-specific security controls. He and Chris explore how security engineering roles will change, why independent verification still matters, and where business-logic flaws may become th... -
José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists 21.07.2026 52minWhy do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling? Okta's José Carlos Chávez joins Chris to explain what changed in the 2025 list—and what stubbornly did not. Drawing on his path from software engineering and observability into security, José examines why ownership and root causes matter more than another scanner. They explore the rise of supply-chain and software-integrity failures, the fragile security model around downloaded AI skill... -
Michael Burch - AI-Enabled Citizen Developers 16.06.2026 48minWhen every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how AI is turning nondevelopers into citizen developers faster than enterprises can build guardrails around them. He and the hosts examine rollouts that hand GitHub and Claude Code to hundreds of employees, the danger of measuring adoption instead of business value, and why prompt libraries alone do not meet people where they work. Michael arg... -
Josh Grossman--AI & SAST: Is it a match? 02.06.2026 40minTraditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better? Bounce Security CTO Josh Grossman explains why he built AGHAST, an open-source framework that combines static discovery with LLM analysis to investigate authorization, business-logic, and organization-specific risks. He walks through reducing false positives, importing SARIF, controlling token costs, and deciding where AI-assisted che... -
Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets 14.05.2026 45minGitGuardian found 29 million hard-coded secrets in public GitHub commits in one year—a 34% increase and its largest jump yet. Why is a supposedly simple problem getting worse? Principal Developer Advocate Dwayne McDaniel explains what the 2026 State of Secrets Sprawl report reveals about public and private repositories, AI coding tools, MCP server templates, and developer-targeted supply-chain attacks. He and Chris unpack why standing credentials persist, how private repositories create false... -
Tanya Janca - Secure Vibe Coding 30.04.2026 47minIf AI writes all the code and the developer barely reads it, where does AppSec fit? Tanya Janca returns to define vibe coding and explain why models trained on insecure public code do not understand secure design by default. She and the hosts build a practical secure-vibe-coding framework: explicit requirements, human-led threat modeling, reusable security prompts, iterative review, SAST, and independent testing. Tanya shares hard-earned examples of Claude removing error handling, models conf... -
Caroline Wong--The AI Cybersecurity Handbook 21.04.2026 44minAI is multiplying the amount of software organizations produce, but security teams are not multiplying with it. Caroline Wong, author of The AI Cybersecurity Handbook and Chief Strategy Officer at Axari, explains how AppSec must change when agents generate code, make decisions, and assemble systems at machine speed. She and the hosts examine the growing backlog, the need for architecture and visibility, and why trust must be evaluated through accuracy, reliability, explainability, and account... -
Steve Wilson--OpenClaw and Advanced AI Agents 15.04.2026 49minOpenClaw makes always-on personal AI agents feel inevitable—and exposes how poorly prepared most organizations are for their autonomy. Steve Wilson, Chief AI and Product Officer at Exabeam and founder of the OWASP GenAI Security Project, returns to explain how advanced agents differ from chatbots and why their permissions, memory, and ability to act create a radically larger blast radius. He and the hosts explore source-code exposure, prompt injection, supply-chain risk, and the uncomfortable... -
Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows 28.10.2025 42minAppSec teams are drowning in repetitive triage while the work that requires judgment keeps piling up. Brad Geesaman, Principal Security Engineer at Ghost Security, explains how large language models can shrink that toil without handing security decisions to an unreliable black box. He walks through using LLMs for classification, evidence gathering, and contextual analysis, with humans retaining final authority. Brad and Chris examine prompt engineering, trust, market disruption, and the limit... -
OWASP Candidate Debate - 2025 Edition 15.10.2025 1t 8minWhat should OWASP become, and which leaders have a credible plan to get it there? In this special 2025 Board of Directors candidate debate, nine candidates present their qualifications and answer the same questions about OWASP's future. The discussion tests concrete ideas for expanding education, improving global and chapter outreach, strengthening project support, finding sustainable funding, and making the Foundation's impact easier to measure. Candidates identify where OWASP performs well,... -
Francesco Cipollone - Agentic AI Manifesto 23.09.2025 33minMost products labeled as AI agents are little more than chatbots with tools. Francesco Cipollone, founder and CEO of Phoenix Security, explains what makes an agent genuinely agentic and why his team uses multiple specialized models instead of one all-purpose system. He and the hosts unpack the Agentic AI Manifesto's principles, including responsible adoption, human augmentation, transparency, and resisting automation for its own sake. Francesco also shares the practical economics behind multi... -
Simon Gibbs & Devika Gibbs -- Building Bridges with Games 16.09.2025 36minSecurity education often struggles because the people in the room are being talked at instead of invited to participate. Simon and Devika Gibbs, the duo behind CyberSec Games, explain how tabletop games can turn abstract security concepts into shared experiences that connect developers, security practitioners, and business teams. They trace their path from agile stationery into threat-modeling games, describe what they learned from Elevation of Privilege and OWASP Cornucopia, and discuss the ... -
Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps 02.09.2025 35minAPIs power modern applications, yet many AppSec programs still cannot reliably inventory them, model their threats, or enforce authorization. Akansha Shukla draws on more than a decade in application security and DevSecOps to explain why API security remains immature and what practitioners can do about it. She and the hosts examine the OWASP API Security Top 10, broken object-level authorization, API-specific threat modeling, and the role of posture management. The conversation also asks why ... -
Getting Ready for the EU CRA 20.08.2025 40minThe EU Cyber Resilience Act turns product security from a best practice into a market-access requirement, and its effects extend well beyond Europe. Application Security Architect and OWASP SAMM core team member Nariman Aga-Tagiyev explains what manufacturers need to know about product classes, conformity assessments, vulnerability handling, software components, and enforcement. He and the hosts explore why global software companies should care, how the rules apply to commercial uses of open ... -
Marisa Fagan - Measuring Security Culture 05.08.2025 50minSecurity champions programs rarely fail because the idea is bad; they fail because organizations launch without management support, meaningful incentives, or a plan to prove value. Marisa Fagan, Head of Product at Katilyst and a veteran security-culture practitioner, shares a practical blueprint for piloting and scaling a program that lasts. She explains how to recruit and motivate champions using status, access, power, and stuff, why a pilot should produce both learning and a business case, ...
Suosittu maassa
Tämä podcast esiintyy myös näiden maiden podcast-listoilla.