Ga naar de inhoud
PodcastsTechnologieThe Elephant in AppSec

The Elephant in AppSec

The Elephant in AppSec
The Elephant in AppSec
Nieuwste aflevering

91 afleveringen

  • The Elephant in AppSec

    Don't just model the attack, model the recovery with Petra Vukmirovic

    06-09-2026 | 30 Min.
    My guest today is Petra Vukmirovic, Head of Information Security and IT at Numan, and she also works with DevArmor on automating threat modeling and security design reviews.
    Outside of that she started the OWASP Threat Model Library, an open collection of real threat models the community can learn from.

    What makes her path unusual is that she didn't come to AppSec through development, she came through emergency medicine, where she worked as a doctor.

    In this episode, we talked about what transfers from the ER to incident response, which is mostly the protocols: risk scores, runbooks, decision trees you can follow when things are on fire. She also thinks threat modeling stops too early. Most teams model protective controls and stop, when recovery deserves the same attention. 
    We also got into automating threat models with LLMs, catching drift between the model and the code, and where design reviews end and threat modeling begins.
    And much more!
    This podcast is brought to you by
    Escape: https://escape.tech  — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
  • The Elephant in AppSec

    The Docker mistakes everyone's still making and how to fix them with Advait Patel

    04-08-2026 | 36 Min.
    Today I'm joined by Advait Patel, Senior Site Reliability Engineer and the creator of DockSec, an open-source, AI-powered Docker security scanner that's now an official OWASP Incubator project.

    In this episode, we get into:
    Why dumping 200 container findings into a Jira ticket is the fastest way to get developers to fix nothing and how DockSec cuts that down to the 5 that actually matter

    The AI support agent that got hijacked by a single malicious ticket and emailed customer data straight to an attacker

    Why you should treat AI as an assistant on a leash, not an engineer with root access

    the Docker mistakes Advait sees everywhere (stale base images, root by default, and secrets baked right into the image)

    …and much more!
    Get ready, Advait doesn't hold back his opinions. Let's dive right in!
    Connect with Advait: https://www.linkedin.com/in/advaitpatel93/
    Connect with Alexandra: https://www.linkedin.com/in/alexandra-charikova/
    This podcast is brought to you by
    Escape: https://escape.tech  — Offensive security for the teams that are 100x outnumbered, combining ASM business-logic-aware DAST, and AI-powered pentesting solutions.
    Mentioned
    DockSec on GitHub (now the OWASP org repo): https://github.com/OWASP/DockSec
    OWASP project page: https://owasp.org/www-project-docksec/
    Open Policy Agent (his "open policy" reference): https://www.openpolicyagent.org/
    OWASP Top 10 for LLM Applications: https://genai.owasp.org/
  • The Elephant in AppSec

    Why Security Loses Influence in High-Growth Companies (And What to Do About It) with Kavia Venkatesh

    20-05-2026 | 31 Min.
    Today, I'm joined by Kavia Venkatesh, Director of Product Security at a large healthcare organization. She didn't take the traditional path into cybersecurity — she came from biotech. But that outsider lens turned out to be her edge.

    With over 10 years of experience leading cybersecurity strategy for hyper-scale ecosystems, she's built many security programs from the ground up, navigating 9 acquisitions in 18 months at a large tech org, and along the way developed a rare ability to translate risk into language that executives actually act on.
    Kavia is also a frequent speaker at premier global conferences, including DEF CON, BSides San Francisco, and Nullcon.

    In this episode, we talked about what most security teams get completely wrong during integrations, what she'd change about how security teams show up in organizations and the "breachability mindset" that changes how you approach risk.
    And much more!

    Get ready, Kavia doesn't hold back her opinions. Let's dive right in!

    This podcast is brought to you by Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.

    Connect with Kavia: https://www.linkedin.com/in/kaviavenkatesh/
  • The Elephant in AppSec

    The Lethal Trifecta or why your AI agent knows too much - Jason Fernandes

    11-05-2026 | 33 Min.
    Today, I’m joined by Jason Fernandes, VP of security and privacy at Mercari, the Japanese-born global marketplace now spanning e-commerce, FinTech, and crypto. It is this rare combination that puts him at the intersection of some of the strictest regulatory environments in tech.
    He oversees everything from product and platform security to threat detection, privacy, and, since last year,  AI security and AI governance.
    In this episode, we also talked about the challenges of AI governance, the lethal trifecta for AI agents, the confused deputy problem, and how to justify AI security investments to the leadership and working with FinOps teams. And much more!
    Dive right in!
    This podcast is brought to you by
    Escape: https://escape.tech  — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
    Mentioned
    FACADE (Google's internal fraud detection model) https://arxiv.org/abs/2412.06700
    Meta Practical AI Agent Security (Rule of Two) https://ai.meta.com/blog/practical-ai-agent-security/
    Simon Willison The Lethal Trifecta https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
    Hiroki's AI Security blog (Mercari) https://hi120ki.github.io/blog/posts/20260103/
    Anthropic  Project Vend https://www.anthropic.com/research/project-vend-2
  • The Elephant in AppSec

    25 years of the same problem in Application Security - Sam Stepanyan

    22-04-2026 | 37 Min.
    Today, I’m joined by Sam Stepanyan,  an OWASP Global Board member and an OWASP London Chapter Leader. Sam is an Independent Application Security Consultant and Security Architect with over 20 years of experience in the IT industry.
    Sam has worked for various financial services institutions in the City of London specialising in Application Security consulting, Secure Software Development Lifecycle (SDLC), developer training, source code reviews and vulnerability management. 
    He is also a Subject Matter Expert in Web Application Firewalls (WAF) and SIEM systems.
    In this episode, we explore why, despite OWASP being around for over 25 years, many developers are still unaware of it—and why shifting focus toward developer conferences might be key to spreading security knowledge more effectively.
    We also discuss the impact of AI on modern security practices, the growing role of automated penetration testing tools, and how even small changes—like adding the word “secure” to a vibe coding prompt—can help nudge developers toward more security-conscious decisions.
    Dive right in! 
    This podcast is brought to you by
    Escape: https://escape.tech  — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
Meer Technologie podcasts
Over The Elephant in AppSec
Time to discuss AppSec issues no one talks about.
Podcast website

Luister naar The Elephant in AppSec, AI Report en vele andere podcasts van over de hele wereld met de radio.net-app

Ontvang de gratis radio.net app

  • Zenders en podcasts om te bookmarken
  • Streamen via Wi-Fi of Bluetooth
  • Ondersteunt Carplay & Android Auto
  • Veel andere app-functies