Skip to content
PodcastsNewsApplication Security Weekly (Audio)

Application Security Weekly (Audio)

Mike Shema
Application Security Weekly (Audio)
Latest episode

417 episodes

  • Application Security Weekly (Audio)

    Getting Granular with Access, Attributes, and Intent - Alex Olivier - ASW #403

    2026/10/06 | 1h 10 mins.
    The principle of least privilege access is ubiquitous in recommendations, but perhaps too uncommon in practice. Alex Olivier explains how the AuthZen Working Group has been approaching new standards, guidelines, and practical deployment patterns to make it easier for orgs to establish more refined and correct access policies. It's a problem that predates LLMs, but also one that agents and MCPs made all the more acute. We talk about what intent means when trying to constrain agents' activities, what role LLMs have in policy decisions, and how LLMs can help create a much-needed inventory of access controls.
    Segment Resources:
    https://www.cerbos.dev/blog/dimmer-switch-not-a-kill-switch-rethinking-ai-agent-governance
    https://www.cerbos.dev/blog/multi-hop-delegation-ai-agents
    https://openid.net/wg/authzen/
    Visit https://www.securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-403
  • Application Security Weekly (Audio)

    Going From Bug Bounty Bugs to More Secure Systems - Shlomie Liberow - ASW #402

    2026/09/29 | 1h 2 mins.
    Finding flaws with LLMs and agents is changing bug bounty programs. But it's not necessarily changing how orgs fix those flaws. Shlomie Liberow shares his experience across a decade of bounty programs and how they have changed for researchers and orgs. He explains why fixing the bug reported through a bug bounty is more about understanding interconnected systems than fixing a single piece of software. We discuss how orgs can be more effective at securing their environment and what role LLMs might have in evaluating controls. Plus, we look to the future of bug bounty programs and how researchers can still excel through curiosity and expertise on a topic rather than relying on scanners, prompts, and luck.
    Visit https://www.securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-402
  • Application Security Weekly (Audio)

    Understanding Prompt Injection In Order to Contain It - Julie Brunias - ASW #401

    2026/09/22 | 1h
    Prompt injection demonstrates one of the major challenges in securing LLMs and agents -- how do you ensure an agent ignores attackers and only does what you instructed it to do. The flaw highlights how LLMs mix inputs, context, and outputs without any strict boundaries between them. Julie Brunias joins us to talk through examples of injections, why their consequences can go beyond information leaks, and why trying to mitigate them with other LLMs is insufficient.
    Segment resources:
    https://llmgateway.io/open-source
    https://www.wiz.io/blog/off-guard-breaking-litellm-from-authentication-bypass-to-cloud-compromise
    Visit https://www.securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-401
  • Application Security Weekly (Audio)

    The AI Threat Multiplier: Securing Mobile Apps in the Automated Era - Ryan Lloyd, Jason Cortlund - ASW #400

    2026/09/15 | 52 mins.
    While agents and LLMs haven't fundamentally changed core mobile vulnerability types, they have supercharged speed, scale, and accessibility—democratizing threats like automated phishing, synthetic identity fraud, and easier identification of hard-coded secrets. Ryan Lloyd and Jason Cortlund break down how threat actors leverage LLMs as a force multiplier to accelerate mobile app attacks. Then we discuss actionable defense strategies, from viewing agents as an active adversary to leveraging server-side threat telemetry, attestation, and layered defense strategies combined with polymorphic code releases.
    This segment is sponsored by Guardsquare. Visit https://securityweekly.com/guardsquare to learn more about them!
    Visit https://www.securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-400
  • Application Security Weekly (Audio)

    Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Ido Geffen, Sean Murphy, Idan Plotnik - ASW #399

    2026/09/08 | 1h 9 mins.
    We showcase recordings from this year's Black Hat.
    The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island
    Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of the trust and security controls applied to traditional software. Michael Leland discusses Island's research uncovering thousands of malicious repositories, widespread security flaws across MCP servers, and a new attack technique called "AgentBaiting," in which attackers manipulate agents into finding and recommending malware to users. The conversation explains how enterprises can govern AI capabilities without slowing adoption.
    Segment Resources:
    https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware
    For more information about Island's research, please visit https://securityweekly.com/islandbh
    After Mythos: Securing Frontier AI as Attack and Defense Accelerate - Black Hat interview with Sean Murphy, Field CISO - North America of F5
    Frontier AI is compressing the time between discovering and exploiting vulnerabilities, forcing enterprises to rethink how they secure modern applications and AI systems. Sean Murphy shares how security teams can prepare for the next generation of AI-powered threats, why known vulnerabilities may become a bigger risk than zero-days, and what it takes to secure AI at scale from shadow AI and governance to agent and API protection.
    This segment is sponsored by F5. Visit https://securityweekly.com/f5bh to learn more about them!
    The Perfect Storm: When AI Writes the Code and Sharpens the Attacks - Black Hat interview with Idan Plotnik, Co-Founder and CEO of Apiiro
    Two storms are converging on how software gets built. The first: AI coding assistants are generating far more code than any security team can review, and with it, far more risk. The second: AI is sharpening the tools attackers use to find and exploit weaknesses faster than ever. Idan Plotnik explains why this convergence has moved the security perimeter to the coding agent itself, and makes the case for a prevention-first model where an AI AppSec agent guards coding agents in real time, governed by the principle that the agent writing the code cannot be the one to secure it.
    This segment is sponsored by Apiiro. Visit https://securityweekly.com/apiirobh to learn more about them!
    Model, Harness, Gym: Why Novee Owns the Full AI Pentesting Stack - Black Hat interview with Ido Geffen, Founder & CEO of Novee Security
    Most AI security tools are thin wrappers around a general-purpose frontier LLM — reasoning capability rented from someone else, applied to a generic scanning workflow. In this interview, Ido Geffen breaks down what it means to own the full AI pentesting stack — the proprietary offensive reasoning model, the harness that coordinates specialized agents, and the training gym where those agents are continuously benchmarked, post-trained on real attacker tradecraft, and promoted into production.
    Ido explains why owning each layer matters: it's how Novee's model consistently outperforms frontier LLMs at live browser exploitation, how the platform improves at a rate the customer feels every cycle, how Novee keeps security testing cost-efficient rather than relying on tokenized pricing models, and how new attacker techniques get injected into agent memory the moment Novee's research team observes them in the wild. He then makes the case that owning the model is only half the story. The other half is the Asset Intelligence Model — a living understanding of each customer's environment, workflows, permissions, APIs, and business logic. That's what turns a generalist AI hacker into a bespoke one: not just an attacker that reasons well, but one that reasons well about your specific business. He closes with how this advantage leads to findings that get more targeted every cycle, remediation tailored to an organization's tech stack, and a platform whose ceiling rises as attackers get faster.
    This segment is sponsored by Novee Security. Visit https://securityweekly.com/noveebh to learn more about them!
    Visit https://www.securityweekly.com/asw for all the latest episodes!
    Show Notes: https://securityweekly.com/asw-399
More News podcasts
About Application Security Weekly (Audio)
About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.
Podcast website

Listen to Application Security Weekly (Audio), Newshour and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Application Security Weekly (Audio): Podcasts in Family