Ga naar de inhoud
PodcastsNieuwsThe Application Security Podcast

The Application Security Podcast

Chris Romeo and Robert Hurlbut
The Application Security Podcast
Nieuwste aflevering

312 afleveringen

  • The Application Security Podcast

    Your Opinion on AI Doesn't Matter. Learned Fragility Does

    05-10-2026 | 53 Min.
    What happens when a tsunami of AI-written code meets a security industry that has spent decades chasing vulnerabilities? Brook S.E. Schoenfield, CTO of Rezliant and author of Securing Systems, returns to warn about "the illusion of omniscient perfection," the cheerful confidence that makes AI output feel finished, and the "learned fragility" that sets in when nobody understands the code anymore. He, Chris, and Robert debate whether an AI threat model that gets 90% of the way there is a win, how Brook now uses AI for reachability analysis, and why prompt injection traces back to a 1975 design principle we ignored. They ask what architecture even means in the age of AI, where the next generation of architects will come from if nobody writes code, and why the collapsing cost of fixes means it's time to stop chasing vulnerabilities.
    This episode is sponsored by Security Compass. Make modern software development secure, consistent, and provable.
    About Security Compass
    AI writes code faster than anyone reviews the design. Threats do not wait for an annual assessment. Security Compass models threats continuously and turns them into requirements developers act on, not a report read after ship.
    → Learn more about securing the AI-DLC with Security Compass
    This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
    About Corgea
    Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
    → Learn more about Corgea
    Connect with Brook S.E. Schoenfield:
    → Brook S.E. Schoenfield on LinkedIn
    → brookschoenfield.com
    Mentioned in this episode:
    → Rezliant
    → Securing Systems: Applied Security Architecture and Threat Models by Brook S.E. Schoenfield
    → Saltzer and Schroeder: "The Protection of Information in Computer Systems" (1975)
    → Izar Tarandach on LinkedIn
    → Dwarkesh Patel: "The Rise and Fall of Agent Civilizations" (essay on the OpenAI–Hugging Face incident)
    → Kadrey v. Meta (2025 fair use ruling on AI training)
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
    Chapters:
    00:00:00 - Cold open — The illusion of omniscient perfection
    00:00:48 - Welcome back, Brook S.E. Schoenfield
    00:01:51 - AI is writing code and filling the security skills gap
    00:06:18 - Can AI threat model as well as the experts?
    00:08:46 - Is 90% of the way there good enough?
    00:13:47 - Closing one weakness beats chasing perfection
    00:16:33 - When AI threat modeling is enough, and when it isn't
    00:17:54 - Learned fragility
    00:19:26 - Embrace securing AI or be left in the dust
    00:23:41 - Against set and forget: agent drift and AI ethics
    00:29:30 - What does architecture mean in the age of AI?
    00:30:29 - Mixing control and data planes: the root of prompt injection
    00:32:49 - Reachability: how Brook threat models with AI today
    00:35:08 - Diagram drift and inclusive threat modeling
    00:38:46 - Will developers disappear and architects emerge?
    00:41:00 - The cost of code has collapsed
    00:44:33 - Where will the next architects come from?
    00:49:15 - Final thoughts: stop chasing vulnerabilities
  • The Application Security Podcast

    Why AI Code Review Will Replace Human Review Faster Than You Think

    29-09-2026 | 49 Min.
    Jim Manico thinks the era of human code review is ending, and that clinging to it will hurt your company. The founder of Manicode Security returns to explain why AI didn't kill AppSec education but supercharged it, why vague prompting on frontier models turns companies into "token furnaces," and why prompt injection is the one genuinely new vulnerability class of the AI era. He walks Chris and Robert through his full AI coding workflow, from reverse engineering an architecture file to security rules and planning-mode build plans that make AI output deterministic. The three debate whether AI will finally eliminate SQL injection, whether AppSec vendors can survive without integrating cyber models, and when humans still need to step in: the moment an agent tries something its policy doesn't allow. Plus: the one habit every security leader should teach developers now.
    This episode is sponsored by Security Compass. Make modern software development secure, consistent, and provable.
    About Security Compass
    AI writes code faster than anyone reviews the design. Threats do not wait for an annual assessment. Security Compass models threats continuously and turns them into requirements developers act on, not a report read after ship.
    → Learn more about securing the AI-DLC with Security Compass
    This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
    About Corgea
    Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
    → Learn more about Corgea
    Connect with Jim Manico:
    → Jim Manico on LinkedIn
    Mentioned in this episode:
    → Manicode Security
    → Manicode Forge
    → OWASP Artificial Intelligence Security Verification Standard (AISVS)
    → OWASP AISVS on GitHub
    → Claude Code
    → Ollama
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
    Chapters:
    00:00:00 - Cold open: the era of code review is ending
    00:00:47 - Meet Jim Manico
    00:01:03 - Welcome and what gets Jim away from screens
    00:05:29 - How AI changed developer security education
    00:07:03 - Teaching developers to use AI well
    00:09:26 - Where AI and AppSec stand: the token furnace
    00:12:08 - Separating signal from hype
    00:14:24 - Integrate with cyber models or die: the future of AppSec tools
    00:18:34 - Are AI coding assistants creating new vulnerabilities?
    00:20:02 - Prompt injection: the one truly new class
    00:21:15 - Will AI eliminate the OWASP Top 10?
    00:24:18 - Local models and Apple's hardware edge
    00:28:32 - Jim's AI coding workflow, step by step
    00:33:57 - The end of human code review
    00:38:31 - Can we trust AI code review, and when do humans step in?
    00:44:56 - Where companies really are with AI
    00:47:02 - One change for security leaders: planning mode
    00:48:19 - Wrap up
  • The Application Security Podcast

    Vulnerability Jail and the AI-Era AppSec Engineer

    22-09-2026 | 44 Min.
    Three years ago, Jeevan Singh mapped out what an application security engineer needed to know. AI has rewritten the job since. Jeevan, Director of Security Engineering at Rippling, returns to unpack how his team polices thousands of engineers shipping 10x more code: a "vulnerability jail" that locks non-compliant teams out of the main branch, AI-reviewed extension requests, and homegrown agents that hunt for entire classes of vulnerabilities instead of one bug at a time. He and Chris debate whether AI has killed classic SAST and DAST, whether code review still needs a human in the loop, and whether bug bounty programs still make sense when the researchers on both sides are running the same models. Plus: one concrete move every AppSec leader can make this quarter.
    This episode is sponsored by Security Compass. Make modern software development secure, consistent, and provable.
    About Security Compass
    AI writes code faster than anyone reviews the design. Threats do not wait for an annual assessment. Security Compass models threats continuously and turns them into requirements developers act on, not a report read after ship.
    → Learn more about securing the AI-DLC with Security Compass
    This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
    About Corgea
    Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
    → Learn more about Corgea
    Connect with Jeevan Singh:
    → Jeevan Singh on LinkedIn
    Mentioned in this episode:
    → Rippling
    → Dwarkesh Patel: "The Rise and Fall of Agent Civilizations" (essay on the OpenAI–Hugging Face incident)
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
    Chapters:
    00:00:00 - Cold open: vulnerability jail
    00:00:55 - Meet Jeevan Singh
    00:01:11 - Welcome and Robert's AI lab
    00:02:37 - What gets Jeevan away from the machines
    00:04:51 - Hardware projects with his son
    00:06:20 - What's changed for the AppSec engineer since AI
    00:08:17 - Shipping production code and fixing whole vulnerability classes
    00:09:13 - Why AppSec has to become less collaborative
    00:10:02 - From democratized vuln management to vulnerability jail
    00:11:50 - How engineering reacted and the feature flag jail precedent
    00:14:05 - From manual jail to automated checks
    00:15:30 - An AI bot that reviews SLA extensions
    00:16:06 - Can AI wipe out an entire vulnerability class?
    00:17:36 - Building an anti-SSRF library and rolling it out
    00:19:40 - Which AppSec skills matter now
    00:22:28 - Validating all that AI-generated code
    00:22:57 - Agents that hunt for vulnerability classes
    00:24:38 - Is this the death of classic AppSec tools?
    00:26:51 - Code review and humans in, on, and out of the loop
    00:28:00 - Objective-based agents that find RCEs
    00:28:59 - Build vs. buy for AppSec teams
    00:31:29 - Advice for teams of one to five AppSec engineers
    00:32:58 - Cutting SLAs to 3, 5, 7, and 10 days
    00:34:31 - Parachuted in as the only AppSec engineer
    00:37:59 - One investment to make this quarter
    00:39:09 - The Hugging Face and OpenAI agent incident
    00:40:13 - Is bug bounty dead?
    00:42:19 - Key takeaways: be an engineer, run toward AI
    00:43:53 - Wrap-up
  • The Application Security Podcast

    How Agentic AI Fails—and Which Controls Actually Stop It

    15-09-2026 | 36 Min.
    Most fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents. Petra traded emergency medicine for application security and now heads information security at Numan — and she joins Chris Romeo and Robert Hurlbut to make the case for fault tree analysis (FTA), the deductive method that picks up exactly where threat modeling stops. Petra walks through a "wrong customer refund" AI agent scenario step by step, showing how AND/OR gates and minimal cut sets turn vague worry into ranked, data backed probabilities. They dig into where AI helps build a tree, and where garbage in, garbage out still applies, why "comprehensive test coverage" is a myth, and how attaching real dollar figures to failure paths makes it easier to sell security controls to leadership.
    This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
    About Corgea
    Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
    → Learn more about Corgea
    Connect with Petra Vukmirovic:
    → Petra Vukmirovic on LinkedIn
    → OWASP Threat Model Library
    Mentioned in this episode:
    → Adam Shostack: "Stop Trying to 'Manage Risk'" (keynote)
    → OWASP Global AppSec USA 2026 (San Francisco, Nov 5–6)
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
    Chapters:
    00:00 Cold open — the math behind where to put your controls
    01:09 Meet Petra Vukmirovic
    01:28 Petra's origin story: from ER doctor to AppSec
    02:50 Career path: engineer to Head of InfoSec at Numan
    04:18 What is fault tree analysis, and where threat modeling ends
    06:22 Can AI actually do fault tree analysis?
    08:12 Walking the "wrong customer refund" agent example
    12:33 Storing your trees: JSON vs. Markdown
    16:08 Why conjunctive failures trip up narrow thinking
    17:27 Top 3 failure modes when agents touch downstream systems
    19:29 Real story: an agent pushed code to main without approval
    21:27 Testing: why "comprehensive coverage" is a myth
    23:54 How rough is rough? Assigning probabilities
    28:08 Getting started without a six week science project
    31:35 Using FTA to sell controls and build credibility
    33:43 The epiphany: FTA is about controls, not faults
    34:48 The one thing every agentic team should add today
    35:48 Closing thoughts and OWASP Global AppSec USA preview
  • The Application Security Podcast

    Your AppSec Bottleneck Is a People Problem

    07-09-2026 | 48 Min.
    Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a champions community so the whole thing doesn't stall the week security goes on vacation. We also get into cutting security wait times, winning organizational support, what AI does and doesn't change here, and why she will tell you never to record the champions meeting.
    This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
    About Corgea
    Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
    → Learn more about Corgea
    Connect with Lisi Hocke:
    → Lisi Hocke on LinkedIn
    → A Tester's Journey — Lisi's blog
    Mentioned in this episode:
    → Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano)
    → OWASP Juice Shop
    Follow the Application Security Podcast:
    ➜ Home: appsecpodcast.com
    ➜ X: @AppSecPodcast
    ➜ LinkedIn: The Application Security Podcast
    ➜ YouTube: @ApplicationSecurityPodcast
    ➜ Instagram: @appsecpodcast
    ➜ Facebook: Application Security Podcast
    Chapters:
    00:00 Cold open — what psychological safety actually means
    00:56 Meet Lisi Hocke
    02:25 Lisi's security origin story
    05:42 "That place was taken" — becoming a champion anyway
    07:39 Moving into a full-time product security role
    08:39 Meeting Björn Kimminich, the Juice Shop project lead
    09:23 Why role play instead of a normal conference talk
    12:27 Security and development, disconnected
    14:19 The first full-time security role
    15:14 Making people wait is the real damage
    17:10 Cutting the backlog and the turnaround time
    19:31 What Lisi got dead wrong
    20:08 What testing and quality work taught her
    21:31 The four things that make champions programs work
    22:07 One: fostering psychological safety
    24:50 Champions without their manager's blessing
    28:45 Two: managing cognitive load
    29:46 Three kinds of load, and which one to cut
    31:21 Three: power sources when you have no formal authority
    33:03 Four: build a champions community
    34:38 Keeping security people from burning out
    36:37 How AI changes who you recruit and what you need
    39:32 Should AI change champions programs at all?
    40:33 Psychological safety when a bot joins the meeting
    42:25 Don't record the champions meetings
    43:26 Programs that outlive the person who started them
    45:59 Key takeaway and homework
    47:21 Closing thoughts
Meer Nieuws podcasts
Over The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
Podcast website

Luister naar The Application Security Podcast, Maarten van Rossem & Tom Jessen en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app

  • Zenders en podcasts om te bookmarken
  • Streamen via Wi-Fi of Bluetooth
  • Ondersteunt Carplay & Android Auto
  • Veel andere app-functies