The OWASP Podcast Series cover image

The OWASP Podcast Series

Latest episodes

undefined
Dec 23, 2024 • 1h

ep2024-12 Tanya Janca: Happy Holidays are Secure Code

In this engaging discussion, Tanya Janca, an AppSec expert and author of 'Alice and Bob Learn Secure Coding', dives into the essentials of secure coding practices. She shares insights on the lack of formal security education and advocates for improved AppSec curricula. Tanya emphasizes practical training and accessible resources for developers, while also reflecting on her personal journey in learning and teaching. Key topics include the importance of not trusting input and the principle of defense in depth, all presented with a relatable touch.
undefined
Oct 31, 2024 • 37min

ep2024-10 Don't be Scared, It's just a Pen Test with Brad Causey

There's no reason to be scared about a pen test - especially when it's run by a professional like Brad Causey. I catch up with Brad in this episode to discuss what's recently changed in pen testing in how you test and people's motivations for hiring a pen testing. Interesting and not spooky at all. Show Links: Brad on LinkedIn - https://www.linkedin.com/in/bradcausey/ SecurIT360 - https://www.securit360.com/ - https://www.linkedin.com/company/securit360/ OWASP Testing Guide - https://owasp.org/www-project-web-security-testing-guide/
undefined
Sep 25, 2024 • 36min

ep2024-09 Threat Modeling with Takaharu

What happens when you get interested in Threat Modeling and you want to share. For some, that means you do one work shop, then another, then another. What happens when you start down this path. Takaharu Ogasa tells us what it's been like to become a threat modeling evangelist in Japan, what he's learned and what he's got planned next. It's a great story on how sharing what you learned can make the world just that much better for you and those lucky enough to be involved. Threat Modeling Community (Japanese): - https://threatmodeling.connpass.com/ Takaharu on Twitter -https://x.com/TakaharuOgasa
undefined
Aug 30, 2024 • 36min

ep2024-08 OWASP Projects Roundup

The August episode is a review of projects from a recent OWASP project showcase. We talk to the leaders of the OWASP pytm, OWASP Developer Guide, OWASP State of AppSec Survey Project. Get up on the latest news and update on these OWASP projects. OWASP pytm: - https://owasp.org/www-project-pytm/ - https://github.com/izar/pytm OWASP Develper Guide: - https://owasp.org/www-project-developer-guide/ - https://github.com/OWASP/www-project-developer-guide OWASP AppSec Survey Project: - https://owasp.org/www-project-state-of-appsec-survey/
undefined
Jul 12, 2024 • 32min

ep2024-07 Safety belts for AppSec with Lisa Plaggemier

After a long and unplanned pause, the OWASP podast is back with a home run of an episode. We have Lisa Plaggemier as our guest who reprises her eloquent keynote topic from AppSec DC. All hope isn't lost, we are making progress - just look at safety in the auto industry to understand where we are and where we're going. Links: Lisa's keynote from AppSec DC https://www.youtube.com/watch?v=Rirxc1OXR4Q&list=PLpr-xdpM8wG_3eyVQxB0oXqVJwlNKs85x&index=38&ab_channel=OWASPFoundation Kubikle web series https://kubikleseries.com/ Convene Seattle 2024 event https://staysafeonline.org/programs/events/convene-seattle-2024/
undefined
Oct 2, 2023 • 33min

ep2023-09 Vulnerable Data Gathering for AI with Arturo Buanzo Busleiman

Arturo Buanzo Busleiman, a cybersecurity and government expert, discusses potential vulnerabilities in web crawlers used for AI systems. They explore the PGP signing of HTTP requests, vulnerability analysis in access logs, and the importance of implementation details. They also touch on space exploration, Python's capabilities, and their appreciation for the OWASP community.
undefined
Aug 31, 2023 • 33min

ep2023-08 Finding Next Gen Cybersecurity Professionals with Brad Causey

Brad Causey, an expert in finding next-gen cybersecurity professionals, discusses the shortage of cybersecurity professionals and his successful approach to address it. They cover building and training entry-level professionals, the evolution of cybersecurity testing, security vulnerabilities in outdated payment devices and Linux-powered IoT devices, avenues for finding cybersecurity professionals, and the need for cybersecurity professionals in the future.
undefined
Jul 31, 2023 • 34min

ep2023-07 What's Audit got to do with IT

In this episode we talk with Zain Haq and take a leap and bound over the first and second line to discover more about the third line - internal audit. We discover answers to a number of questions: What role does audit play in the overall cybersecurity of an organization? What does the CISO gain from having an audit function? What makes a good auditor? Learn how to get the most out of audit and what they bring to the table. Special thanks to Tina Turner for inspiring the show title. ;-) Show Links: - Zain Haq: https://www.linkedin.com/in/zainhaq25/
undefined
Jun 27, 2023 • 30min

SBOMS, CycloneDX and Dependency Track: Automation for Survival with Steve Springett

Software supply chain seems to be front and center for technologists, cybersecurity and many governments. One of the early pioneers in this space was Steve Springett with two highly successful projects: OWASP Dependency Track and CycloneDX. In this episode, we catch up with Steve to talk about how he got started in software supply chain management as well as the explosive growth for Dependency Track and ClycloneDX. We also touch on future developments for CycloneDX and places where Steve never expected to see his projects go. Enjoy! Show Links: - OWASP Dependency Track: https://dependencytrack.org/ - Dependency Track Github: https://github.com/DependencyTrack - CycloneDX: https://cyclonedx.org/ - CycloneDX Github: https://github.com/CycloneDX - Software Component Verification Standard: https://scvs.owasp.org/ Social Media links: - https://twitter.com/stevespringett - https://infosec.exchange/@stevespringett - https://www.linkedin.com/in/stevespringett/
undefined
May 22, 2023 • 44min

AppSec at 40,000 feet

In this episode I speak with Jerry Hoff who provides some very interesting perspective on application security especially at scale and from a high level view like that of a CISO. Even if you're not in a senior leadership position, you're likely to be reporting to one. Understanding that point of view can help you successfully frame your work and accomplish your goals. We touch on multiple topics and have some great back and forth that I'm sure will entertain and inform you. Enjoy!

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app