Absolute AppSec Podcast Por Ken Johnson and Seth Law arte de portada

Absolute AppSec

Absolute AppSec

De: Ken Johnson and Seth Law
Escúchala gratis

Exclusivo para miembros Prime | $0.99/mes por 4 meses + $20 de crédito en Audible

$8.99 al mes después de 4 meses. Consulta términos y condiciones.
A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.
Episodios
  • Episode 335 - w/ Ron Perris - Secure Coding with AI
    Oct 6 2026
    In episode 335 of Absolute AppSec, Seth and Ken sit down with Ron Perris. Ron is Chief Technology Officer at Manicode Security, to discuss the integration of AI into secure software development and AppSec workflows. The conversation explores the rapid adoption of large language models (LLMs) and local agentic harnesses, examining how developers use them for code generation and how security teams manage the resulting system-level risks on developer workstations. Perris details his work with Manicode.ai, founded alongside Jim Manico, which addresses LLM code generation defects by embedding language- and framework-specific positive security guidance directly into the AI's context window. By leveraginglifecycle hooks within coding harnesses to inject tailored defensive rules (e.g., parameterized queries or framework-specific escaping), Manicode guides LLM token generation away from common vulnerabilities rather than relying solely on post-generation SAST checks. The hosts and Perris critique the industry's overreliance on dashboard-driven vulnerability counting, arguing that AppSec must move beyond managing repetitive bugs and focus on systematically eliminating flaw classes through secure framework defaults and context engineering. Finally, Perris reflects on his time at Reddit, the challenges of preventing recurring vulnerability classes at scale, and the potential for reviving practitioner-focused conferences like LocomocoSec to address modern AI-driven AppSec realities. Sponsored by Guardsquare (guardsquare.com).
    Más Menos
    Menos de 1 minuto
  • Episode 334 - w/ Ryan Lloyd - Mobile Application Security
    Sep 16 2026
    In episode 334 of Absolute AppSec, hosts Ken Johnson and Seth Law interview Ryan Lloyd, Chief Product Officer at GuardSquare, to explore mobile application security and product management strategy. Lloyd details GuardSquare's evolution from the open-source Java optimizer ProGuard—which introduced basic name obfuscation—into a commercial suite offering multi-layered code hardening, control flow flattening, encryption, and automated runtime application self-protection (RASP) to detect dynamic tampering, hooking tools like Frida, and rooted devices. The discussion examines the product strategy behind balancing customer feature requests against core security engineering, emphasizing evidence-based decision-making over opinion. Addressing the broader mobile threat landscape, Lloyd highlights how attack vectors have expanded beyond financial services into retail, delivery, and loyalty apps, where attackers manipulate business logic or exploit open platform APIs like Android accessibility services for account takeovers. To track emerging threats, GuardSquare's research arm monitors reverse-engineering forums, academic compiler research, and dark web channels. Finally, the conversation evaluates how automated AI tools accelerate the velocity of reverse engineering and vulnerability discovery, underscoring that mobile security defenses must continually evolve to increase the time and cost required for attackers to tamper with client-side applications. Episode sponsored by GuardSquare (guardsquare.com).
    Más Menos
    Menos de 1 minuto
  • Episode 333 - LLM Patching Flaws, AI Code Regressions, Bug Bounty Economy
    Sep 8 2026
    Sponsored by GuardSquare (guardsquare.com), the discussion of Episode 333 opens with an analysis of a 1Password academic paper evaluating how frontier LLMs perform at autonomous vulnerability patching. The research indicates that LLMs successfully generate functional, side-effect-free patches only 26% of the time, often introducing new security flaws, breaking application behavior, or hallucinating fixes due to a lack of environmental context and "correctness collapse". The hosts critique the industry push toward auto-remediation, arguing that automated patch generation fails to address root causes like noisy tooling or organizational culture issues, and they emphasize that human domain expertise remains necessary for reliable patching. Turning to real-world AI security risks, the episode examines a Snowflake vulnerability where an AI coding tool (GitHub Copilot Autofix) regressed a GitHub Actions workflow into an unauthenticated Remote Code Execution (RCE) flaw via command injection, which was subsequently discovered and validated within five days by Wiz's automated "Red Agent". Finally, the hosts cover Dark Reading reporting on how the AI-driven "vulnpocalypse" is repricing the bug bounty economy. As automated scanning harnesses double report volumes, companies face budget constraints that reduce payout amounts per finding, forcing organizations to narrow program scopes toward high-priority assets.
    Más Menos
    Menos de 1 minuto
adbl_web_anon_alc_button_suppression_t1
Todavía no hay opiniones