Absolute AppSec Podcast Por Ken Johnson and Seth Law arte de portada

Absolute AppSec

Absolute AppSec

De: Ken Johnson and Seth Law
Escúchala gratis

Exclusivo para miembros Prime | $0.99/mes por 4 meses + $20 de crédito en Audible

$8.99 al mes después de 4 meses. Consulta términos y condiciones.
A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.
Episodios
  • Episode 334 - w/ Ryan Lloyd - Mobile Application Security
    Sep 16 2026
    In episode 334 of Absolute AppSec, hosts Ken Johnson and Seth Law interview Ryan Lloyd, Chief Product Officer at GuardSquare, to explore mobile application security and product management strategy. Lloyd details GuardSquare's evolution from the open-source Java optimizer ProGuard—which introduced basic name obfuscation—into a commercial suite offering multi-layered code hardening, control flow flattening, encryption, and automated runtime application self-protection (RASP) to detect dynamic tampering, hooking tools like Frida, and rooted devices. The discussion examines the product strategy behind balancing customer feature requests against core security engineering, emphasizing evidence-based decision-making over opinion. Addressing the broader mobile threat landscape, Lloyd highlights how attack vectors have expanded beyond financial services into retail, delivery, and loyalty apps, where attackers manipulate business logic or exploit open platform APIs like Android accessibility services for account takeovers. To track emerging threats, GuardSquare's research arm monitors reverse-engineering forums, academic compiler research, and dark web channels. Finally, the conversation evaluates how automated AI tools accelerate the velocity of reverse engineering and vulnerability discovery, underscoring that mobile security defenses must continually evolve to increase the time and cost required for attackers to tamper with client-side applications. Episode sponsored by GuardSquare (guardsquare.com).
    Más Menos
    Menos de 1 minuto
  • Episode 333 - LLM Patching Flaws, AI Code Regressions, Bug Bounty Economy
    Sep 8 2026
    Sponsored by GuardSquare (guardsquare.com), the discussion of Episode 333 opens with an analysis of a 1Password academic paper evaluating how frontier LLMs perform at autonomous vulnerability patching. The research indicates that LLMs successfully generate functional, side-effect-free patches only 26% of the time, often introducing new security flaws, breaking application behavior, or hallucinating fixes due to a lack of environmental context and "correctness collapse". The hosts critique the industry push toward auto-remediation, arguing that automated patch generation fails to address root causes like noisy tooling or organizational culture issues, and they emphasize that human domain expertise remains necessary for reliable patching. Turning to real-world AI security risks, the episode examines a Snowflake vulnerability where an AI coding tool (GitHub Copilot Autofix) regressed a GitHub Actions workflow into an unauthenticated Remote Code Execution (RCE) flaw via command injection, which was subsequently discovered and validated within five days by Wiz's automated "Red Agent". Finally, the hosts cover Dark Reading reporting on how the AI-driven "vulnpocalypse" is repricing the bug bounty economy. As automated scanning harnesses double report volumes, companies face budget constraints that reduce payout amounts per finding, forcing organizations to narrow program scopes toward high-priority assets.
    Más Menos
    Menos de 1 minuto
  • Episode 332 - AI SDLC, Call for Cyber Defense, Rumor as the Exploit
    Sep 1 2026
    In episode 332, the discussion focuses on how artificial intelligence is reshaping the Software Development Lifecycle (SDLC). The episode analyzes Anthropic's blog post regarding an "AI-native SDLC," evaluating its vision of replacing traditional development bottlenecks with AI workflows. The commentary critiques Anthropic's reliance on simple Markdown files for tracking development decisions, noting that replacing deterministic tools with probabilistic LLMs in core SDLC processes introduces significant reliability risks, context drift, and excessive token costs. The conversation turns to OpenAI's "Collective Call for Cyber Defense" initiative, examining its push for frontier AI model regulation and critiques of open-weight models, which are viewed as an effort to establish vendor lock-in. Exploring the concept of "Rumor as the Exploit," the discussion highlights how public mentions or minor disclosures of vulnerabilities now allow AI-driven testing harnesses to rapidly discover and generate working exploits across unmaintained software ecosystems. To counter this accelerated threat landscape, the episode evaluates defensive strategies, including runtime verification, reachability analysis, and cooling-off periods for new package releases, emphasizing that security defenders must move beyond thin wrapper solutions and build robust systems combining deterministic controls with model capabilities. Episode sponsored by Guardsquare (guardsquare.com).
    Más Menos
    Menos de 1 minuto
adbl_web_anon_alc_button_suppression_t1
Todavía no hay opiniones