Obtenez 3 mois à 0,99 $/mois

OFFRE D'UNE DURÉE LIMITÉE
Page de couverture de Application Security Weekly (Audio)

Application Security Weekly (Audio)

Application Security Weekly (Audio)

Auteur(s): Security Weekly Productions
Écouter gratuitement

À propos de cet audio

About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.© 2024 CyberRisk Alliance Politique
Épisodes
  • Making TN Critical Infrastructure the Most Secure in the Nation - T. Gwyddon 'Data' ("Gwee-thin") Owen, James Cotter - ASW #359
    Dec 2 2025

    For OT systems, uptime is paramount. That's a hard rule that makes maintaining, upgrading, and securing them a complex struggle. Tomas "Data" Owens and James Cotter discuss how Tennessee is tackling the organizational and technical challenges that come with hardening OT systems across the state. Those challenges range from old technology (like RS-232 over Wi-Fi!?) to limited budgets. They talk about the different domains where OT appears and provide some examples of how the next generation of builders and breakers can start learning about this space.

    Segment Resources:

    Free Cyber OT Training (INL): https://ics-training.inl.gov/

    Free Cyber Hygiene Training (CISA): https://www.cisa.gov/cyber-hygiene-services

    Recommendations for network hardening (CISA): https://www.cisa.gov/shields-up

    More OT and ICS resources: https://github.com/biero-el-corridor/OTICSressource_list

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-359

    Voir plus Voir moins
    59 min
  • Figuring Out Where to Start with Secure Code - ASW #358
    Nov 25 2025

    What are your favorite resources for secure code? Co-hosts John Kinsella and Kalyani Pawar talk about the reality of bringing security into a business. We talk about the role of the OWASP Top 10 and the OWASP ASVS in crafting security programs. And balance that with a discussion in what's the best use of everyone's time -- developers and appsec folks alike -- in crafting code that's secure by design rather than just secure from scanner results.

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-358

    Voir plus Voir moins
    46 min
  • Secure Coding as Critical Thinking Instead of Vulnspotting - Matias Madou - ASW #357
    Nov 18 2025

    Secure code should be grounded more in concepts like secure by default and secure by design than by "spot the vuln" thinking. Matias Madou shares his experience in secure coding training and the importance of teaching critical thinking. He also discusses why critical thinking is so closely related to threat modeling and how LLMs can be a tool for helping developers get beyond the superficial advice of, "Think like an attacker."

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-357

    Voir plus Voir moins
    1 h et 4 min
Pas encore de commentaire