Security Weekly Podcast Network (Video)

Uniting software development and application security - Jonathan Schneider, Will Vandevanter - ASW #342


Listen Later

Maintaining code is a lot more than keeping dependencies up to date. It involved everything from keeping old code running to changing frameworks to even changing implementation languages. Jonathan Schneider talks about the engineering considerations of refactoring and rewriting code, why code maintenance is important to appsec, and how to build confidence that adding automation to a migration results in code that has the same workflows as before.

Resources

  • https://docs.openrewrite.org
  • https://github.com/openrewrite

Then, instead of our usual news segment, we do a deep dive on some recent vulns NVIDIA's Triton Inference Server disclosed by Trail of Bits' Will Vandevanter. Will talks about the thought process and tools that go into identify potential vulns, the analysis in determining whether they're exploitable, and the disclosure process with vendors. He makes the important point that even if something doesn't turn out to be a vuln, there's still benefit to the learning process and gaining experience in seeing the different ways that devs design software. Of course, it's also more fun when you find an exploitable vuln -- which Will did here!

Resources

  • https://nvidia.custhelp.com/app/answers/detail/a_id/5687
  • https://github.com/triton-inference-server/server
  • https://blog.trailofbits.com/2025/07/31/hijacking-multi-agent-systems-in-your-pajamas/
  • https://blog.trailofbits.com/2025/07/28/we-built-the-security-layer-mcp-always-needed/

Show Notes: https://securityweekly.com/asw-342

...more
View all episodesView all episodes
Download on the App Store

Security Weekly Podcast Network (Video)By Security Weekly

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

35 ratings


More shows like Security Weekly Podcast Network (Video)

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,998 Listeners

MacBreak Weekly (Audio) by TWiT

MacBreak Weekly (Audio)

2,013 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

638 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,018 Listeners

Security Weekly News (Audio) by Security Weekly Productions

Security Weekly News (Audio)

33 Listeners

The Daily by The New York Times

The Daily

112,500 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,961 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

965 Listeners

The Matt Walsh Show by The Daily Wire

The Matt Walsh Show

28,586 Listeners

Morning Wire by The Daily Wire

Morning Wire

26,657 Listeners

The Criminal Connection Podcast by The Criminal Connection Podcast

The Criminal Connection Podcast

40 Listeners