Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.... more
FAQs about Absolute AppSec:How many episodes does Absolute AppSec have?The podcast currently has 327 episodes available.
March 19, 2024Episode 238 - AppSec vs. Enterprise Sec, Supply Chain Tool AnalysisKen and Seth are back to talk about the difference and competing priorities of Application and Enterprise Security. In short, recent news contends that Enterprise or Infrastructure security is lacking, whereas Application or Product Security is in a good state. This is followed by a discussion on supply chain security tools due to a recent analysis conducted by DoyenSec comparing false positives and negatives from the leading tools....more1h 9minPlay
March 12, 2024Episode 237 - Security 101, Nation State Hackers, Malicious CodeKen and Seth return for another episode, starting out with pointers on getting into security and finding a niche, all based on a recently released Microsoft project to introduce anyone to security. This is followed by a discussion on Chinese hacking groups and recent breaches among those groups. Finally, a discussion protecting the software supply chain due to recent forking and upload of malicious repositories on GitHub....more59minPlay
March 05, 2024Episode 236 - Memory Safe Languages, LLM Supply Chain SecuritySeth and Ken review the recent Whitehouse report on going back to the basics for software security and vulnerabilities. Specifically, how is the use of memory unsafe languages like C and C++ affecting the overall security of the internet landscape. This include a discussion on formal verification and crocs and socks of software testing. Finally, thoughts are shared on the recent use of Hugging Face and Github to host malicious code/packages and how this is a natural progression for popular package repositories....more1h 8minPlay
February 20, 2024Episode 235 - 2023 Top 10 Web Hacking Techniques, LLM Agent HackingPodcast viewers will be familiar with Portswigger's annual list of Web Hacking Techniques. Ken and Seth take some time to digest the list and recommend reviewing not only the top 10, but also the nominations. A discussion on the use of LLM Agents as a dynamic scanning engine for identifying vulnerabilities. If you aren't already using an LLM to help speed up your AppSec, why not? Finally, a discussion on security statistics and how bad they are....more1h 4minPlay
February 13, 2024Episode 234 - Password Analysis, GitHub CopilotKen and Seth comment on their recent use of the same passwords across multiple organizations. Errr, or wait. That's administrators in some instances, according to recently published analysis from Lares. Will we ever get over passwords or are we doomed to repeat the past? In other news, GitHub Copilot may be (one of) the culprit(s) for the enshitification of code, based on a published paper from GitClear. Or it might just be that organizations and developers should have coding standards. Or maybe it's not that deep. Come join us and chat about it....more1h 1minPlay
February 06, 2024Episode 233 - Scammers, Deep Fakes, Data ExposureSeth and Ken return to the podcast to talk about fraud scammers based on a recent article from Cory Doctorow and what AppSec can do to protect their apps and themselves. Crocs and Socks. The use of deep fakes to scam corporations to transfer money. Finally, a discussion on sensitive data and why it happens in APIs due to the recent news that Spoutible exposed all sorts of tokens as reported by Troy Hunt....more1h 8minPlay
January 30, 2024Episode 232 - Security Jobs, Surveillance, Prompt InjectionKen and Seth start out with a lengthy discussion about application security jobs, training, and getting into the security space due to an article based on someone's experience moving from IT to pentesting. This is followed by possible needs for the NSA to collect commercially available browsing data. Finally, a quick hit on prompt injection and how things are moving quickly in the AI/LLM space....more1h 5minPlay
January 23, 2024Episode 231 - FlowMate, State of Software Supply Chain SecuritySeth and Ken are back after a weeks hiatus and start by demonstrating FlowMate, a newly released Burp Extension for building context of the parameters used by an application. This is followed by in-depth analysis of Reversing Lab's State of Software Supply Chain Security Report....more1h 7minPlay
January 09, 2024Episode 230 - False Positives vs. Negatives, Scaling Vuln ManagementKen and Seth return to settle the age old question of whether false positives or false negatives are better when dealing with security tools. Tears are shed as stories of wasted efforts ring through on the podcasting airwaves. Maybe. Discussions on AI generated recommendations and how it _can_ be useful, but also turn out poorly. Finally, introductions on large scale vulnerability management at GitHub and how organizations struggle to fix issues identified through multiple streams....more1hPlay
January 02, 2024Episode 229 - Software Supply Chain Security, 2024 PredictionsSeth and Ken kick off a new year talking about recent news, including improvements in security process for software supply chains. This is followed by security predictions for 2024, including LLMs, dynamic scanning, process, and other possibilities in the near future....more1h 5minPlay
FAQs about Absolute AppSec:How many episodes does Absolute AppSec have?The podcast currently has 327 episodes available.