Skip to content
PodcastsNewsApplication Security Weekly (Audio)

Application Security Weekly (Audio)

Mike Shema
Application Security Weekly (Audio)
Latest episode

413 episodes

  • Application Security Weekly (Audio)

    Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Ido Geffen, Sean Murphy, Idan Plotnik - ASW #399

    2026/09/08 | 1h 9 mins.
    We showcase recordings from this year's Black Hat.
    The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island
    Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of the trust and security controls applied to traditional software. Michael Leland discusses Island's research uncovering thousands of malicious repositories, widespread security flaws across MCP servers, and a new attack technique called "AgentBaiting," in which attackers manipulate agents into finding and recommending malware to users. The conversation explains how enterprises can govern AI capabilities without slowing adoption.
    Segment Resources:
    https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware
    For more information about Island's research, please visit https://securityweekly.com/islandbh
    After Mythos: Securing Frontier AI as Attack and Defense Accelerate - Black Hat interview with Sean Murphy, Field CISO - North America of F5
    Frontier AI is compressing the time between discovering and exploiting vulnerabilities, forcing enterprises to rethink how they secure modern applications and AI systems. Sean Murphy shares how security teams can prepare for the next generation of AI-powered threats, why known vulnerabilities may become a bigger risk than zero-days, and what it takes to secure AI at scale from shadow AI and governance to agent and API protection.
    This segment is sponsored by F5. Visit https://securityweekly.com/f5bh to learn more about them!
    The Perfect Storm: When AI Writes the Code and Sharpens the Attacks - Black Hat interview with Idan Plotnik, Co-Founder and CEO of Apiiro
    Two storms are converging on how software gets built. The first: AI coding assistants are generating far more code than any security team can review, and with it, far more risk. The second: AI is sharpening the tools attackers use to find and exploit weaknesses faster than ever. Idan Plotnik explains why this convergence has moved the security perimeter to the coding agent itself, and makes the case for a prevention-first model where an AI AppSec agent guards coding agents in real time, governed by the principle that the agent writing the code cannot be the one to secure it.
    This segment is sponsored by Apiiro. Visit https://securityweekly.com/apiirobh to learn more about them!
    Model, Harness, Gym: Why Novee Owns the Full AI Pentesting Stack - Black Hat interview with Ido Geffen, Founder & CEO of Novee Security
    Most AI security tools are thin wrappers around a general-purpose frontier LLM — reasoning capability rented from someone else, applied to a generic scanning workflow. In this interview, Ido Geffen breaks down what it means to own the full AI pentesting stack — the proprietary offensive reasoning model, the harness that coordinates specialized agents, and the training gym where those agents are continuously benchmarked, post-trained on real attacker tradecraft, and promoted into production.
    Ido explains why owning each layer matters: it's how Novee's model consistently outperforms frontier LLMs at live browser exploitation, how the platform improves at a rate the customer feels every cycle, how Novee keeps security testing cost-efficient rather than relying on tokenized pricing models, and how new attacker techniques get injected into agent memory the moment Novee's research team observes them in the wild. He then makes the case that owning the model is only half the story. The other half is the Asset Intelligence Model — a living understanding of each customer's environment, workflows, permissions, APIs, and business logic. That's what turns a generalist AI hacker into a bespoke one: not just an attacker that reasons well, but one that reasons well about your specific business. He closes with how this advantage leads to findings that get more targeted every cycle, remediation tailored to an organization's tech stack, and a platform whose ceiling rises as attackers get faster.
    This segment is sponsored by Novee Security. Visit https://securityweekly.com/noveebh to learn more about them!
    Visit https://www.securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-399
  • Application Security Weekly (Audio)

    Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398

    2026/09/01 | 1h 8 mins.
    AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable.
    Segment Resources
    https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt
    Vulnerability discovery and remediation gap in the AI era
    AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice.
    Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security
    AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation.
    Segment Resources:
    https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/
    https://orca.security/platform/ai-appgen-security/
    This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them!
    Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd
    Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch.
    Segment Resources:
    https://www.bugcrowd.com/products/pathseeker/
    https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/
    https://www.bugcrowd.com/products/platform
    https://www.bugcrowd.com/products/ai-powered-security-intelligence/
    Apply for early access at https://securityweekly.com/bugcrowdbh
    Visit https://www.securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-398
  • Application Security Weekly (Audio)

    Applying Zero Trust Principles to Agents - Kieran Human - ASW #397

    2026/08/25 | 1h 6 mins.
    Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of the properties that a good sandbox should have and how monitoring creates a feedback loop to refine allow lists and access controls. In practice, the potential unpredictable behavior of an agent isn't much different from malware. We talk through some of the ways orgs can securely deploy agents without unnecessarily increasing their attack surface.
    Resources
    https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents
    https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools
    https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats
    This interview is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!
    Visit https://www.securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-397
  • Application Security Weekly (Audio)

    Augmenting Threat Intel Analysis with Agents - Chris Wallis, Sai Kiran Uppu, Ramin Farassat - ASW #396

    2026/08/18 | 1h 9 mins.
    All sorts of cybersecurity disciplines are adopting agents to help humans save time and automate routine activities. Sai Kiran Uppu describes his work on creating a platform for agents to analyze external threat intel, examine internal systems, and present triage decisions to operators. This type of work is especially useful to orgs that deal with petabytes of data and thousands of systems. And, as Kiran notes, it's important to keep that scale from blowing up your budget or turning triage into a procession of false positives.
    Ideally, this kind of threat intel that's paying attention to attack trends and searching internal systems for evidence of compromise also turns into proactive defenses. We talk about some of the ways to engage developers to improve security visibility into their services and harden their designs against common attacks.
    After that discussion we're running two sponsored interviews from Black Hat.
    AI Pentesting and the Future of Cybersecurity: Black Hat interview with Chris Wallis, Founder and CEO of Intruder
    This segment discusses how AI addresses the long-standing gap between traditional pentesting and automated vulnerability scanning. Intruder CEO and founder Chris Wallis dives into the nuances of AI-enabled security and how these offerings will impact mid-market security teams.
    Segment Resources:
    https://www.intruder.io/platform/ai-pentesting
    https://www.intruder.io/blog/ai-pentesting-the-depth-of-a-pentest-on-demand
    https://www.intruder.io/blog/ai-web-app-pentesting-test-on-every-major-release
    Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. For more information about Intruder's products and services, please visit https://securityweekly.com/intruderbh.
    How Menlo Security Is Securing AI Agents from Prompt Injection: Black Hat Interview with Ramin Farassat, Chief Product Officer of Menlo
    Enterprises are deploying AI agents like Microsoft Copilot, Google Gemini, and Claude Code faster than they can secure them, and attackers are exploiting that gap through prompt injection. Hidden instructions get buried in web pages, files, and even images that a human would never notice but an AI agent reads and acts on. Menlo Security is building Menlo Agent Runtime Security (MARS) to close that gap, running every agent session in an isolated cloud that sanitizes content before an agent can act on it. Ramin Farassat, Menlo Security's Chief Product Officer, will discuss why the exposure lives in the connectors and integrations around the model rather than the model itself, and how security teams can put controls on the agent attack surface without blocking agentic AI outright.
    Segment Resources:
    https://www.menlosecurity.com/product/ai-agent-security
    MARS is now available today, please visit https://securityweekly.com/menlobh
    Visit https://www.securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-396
  • Application Security Weekly (Audio)

    Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

    2026/08/11 | 1h 9 mins.
    Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task.
    And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts.
    Episode Resources:
    https://projectdiscovery.io/research/ai-coding-impact-report
    https://projectdiscovery.io/blog/oh-my-rogue-agent
    Visit https://www.securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-395
More News podcasts
About Application Security Weekly (Audio)
About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.
Podcast website

Listen to Application Security Weekly (Audio), Black Box: The Chatbots and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Application Security Weekly (Audio): Podcasts in Family