<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Application Security Weekly (Audio)</title><link>https://www.spreaker.com/show/application-security-weekly-audio</link><description><![CDATA[Application Security Weekly decrypts development for the Security Professional - exploring how to inject security into their organization’s Software Development Lifecycle (SDLC) in a fluid and transparent way; Learn the tools, techniques, and processes necessary to move at the speed of DevOps (even if you aren’t a DevOps shop yet). The target audience for Application Security Weekly spans the gamut of Security Engineers and Practitioners that need to level-up their skills in the Application Security space - as well as enabling “Cyber Curious” developers to get involved in the Application Security process at their organizations. To a lesser extent, we hope to arm Security Managers and Executives with the knowledge to be conversational in the realm of DevOps - and to provide the right questions to ask their colleagues in development, along with the metrics to think critically about the answers they receive.]]></description><atom:link href="https://www.spreaker.com/show/2902493/episodes/feed" rel="self" type="application/rss+xml"/><language>en</language><category>Society &amp; Culture</category><copyright>Copyright Security Weekly</copyright><image><url>https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/316e0491d24b9ffae8beff81f4aeefd2.jpg</url><title>Application Security Weekly (Audio)</title><link>https://www.spreaker.com/show/application-security-weekly-audio</link></image><lastBuildDate>Wed, 27 Jul 2022 15:30:39 +0000</lastBuildDate><itunes:author>Security Weekly</itunes:author><itunes:owner><itunes:name>Security Weekly</itunes:name><itunes:email>feeds@spreaker.com</itunes:email></itunes:owner><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/316e0491d24b9ffae8beff81f4aeefd2.jpg"/><itunes:subtitle>Application Security Weekly decrypts development for the Security Professional - exploring how to inject security into their organization’s Software Development Lifecycle (SDLC) in a fluid and transparent way; Learn the tools, techniques, and...</itunes:subtitle><itunes:summary><![CDATA[Application Security Weekly decrypts development for the Security Professional - exploring how to inject security into their organization’s Software Development Lifecycle (SDLC) in a fluid and transparent way; Learn the tools, techniques, and processes necessary to move at the speed of DevOps (even if you aren’t a DevOps shop yet). The target audience for Application Security Weekly spans the gamut of Security Engineers and Practitioners that need to level-up their skills in the Application Security space - as well as enabling “Cyber Curious” developers to get involved in the Application Security process at their organizations. To a lesser extent, we hope to arm Security Managers and Executives with the knowledge to be conversational in the realm of DevOps - and to provide the right questions to ask their colleagues in development, along with the metrics to think critically about the answers they receive.]]></itunes:summary><itunes:category text="Society &amp; Culture"/><itunes:explicit>clean</itunes:explicit><itunes:type>episodic</itunes:type><item><title>Goose Egg - ASW #140</title><link>https://www.spreaker.com/user/securityweekly/goose-egg-asw-140</link><description><![CDATA[This week, we welcome Brandon Edwards, Co-Founder and Chief Scientist at Capsule8, to discuss Targeting, Exploiting, & Defending Linux! Linux is all over the place (sometimes surprising), why is targeting it different? What types of attacks are used? How can we defend against attacks on Linux? We can incorporate recent attacks against Sudo as a timely reference. In the Application Security News, Dependency confusion for internal packages, Chrome pulls down the Great Suspender, Microsoft highlights web shells, some strategies on scaling AppSec, & more!   Show Notes: <a href="https://securityweekly.com/asw140" rel="noopener">https://securityweekly.com/asw140</a> Visit <a href="https://securityweekly.com/capsule8" rel="noopener">https://securityweekly.com/capsule8</a> to learn more about them! To register for Capsule8's upcoming webcast "Preparing Linux Hosts for Unexpected Threats" visit  <a href="https://attendee.gotowebinar.com/register/1056145103342240783?source=SW" rel="noopener">https://attendee.gotowebinar.com/register/1056145103342240783?source=SW</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">a280cf88-9288-4f1b-9149-1632b9e35555</guid><pubDate>Tue, 23 Feb 2021 18:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43670049/asw_140_0.mp3" length="97410880" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Brandon Edwards, Co-Founder and Chief Scientist at Capsule8, to discuss Targeting, Exploiting, &amp; Defending Linux! Linux is all over the place (sometimes surprising), why is targeting it different? What types of attacks are used?...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Brandon Edwards, Co-Founder and Chief Scientist at Capsule8, to discuss Targeting, Exploiting, & Defending Linux! Linux is all over the place (sometimes surprising), why is targeting it different? What types of attacks are used? How can we defend against attacks on Linux? We can incorporate recent attacks against Sudo as a timely reference. In the Application Security News, Dependency confusion for internal packages, Chrome pulls down the Great Suspender, Microsoft highlights web shells, some strategies on scaling AppSec, & more!   Show Notes: <a href="https://securityweekly.com/asw140" rel="noopener">https://securityweekly.com/asw140</a> Visit <a href="https://securityweekly.com/capsule8" rel="noopener">https://securityweekly.com/capsule8</a> to learn more about them! To register for Capsule8's upcoming webcast "Preparing Linux Hosts for Unexpected Threats" visit  <a href="https://attendee.gotowebinar.com/register/1056145103342240783?source=SW" rel="noopener">https://attendee.gotowebinar.com/register/1056145103342240783?source=SW</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4059</itunes:duration><itunes:keywords>apisecurity,applicationsecurity,compliance,containersecurity,dast,devops,devsecops,docker,governance,microsegmentation,openshift,policy,rasp,riskmanagement,software,sqlinjection,vendorrisk,vulnerabilities,xss,zerotrust</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a98e3ae66bc0df541af21a14240057ae.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Sound of Silence - ASW #138</title><link>https://www.spreaker.com/user/securityweekly/the-sound-of-silence-asw-138</link><description><![CDATA[This week, we welcome John Delaroderie, Security Solutions Architect at Qualys, to discuss Groundhog Day - It's Time to Reset the Script on Vulnerabilities! In honor of the movie Groundhog Day, John will take a look at the top 10 most routinely exploited vulnerabilities through a web app security lens. In the Application Security News, Sudo sure does, Libgcrypt flaw, iMessage demonstrates security by design, AWS Lambda shares a message on its design security, & more!   Show Notes: <a href="https://securityweekly.com/asw138" rel="noopener">https://securityweekly.com/asw138</a> Visit <a href="https://securityweekly.com/qualys" rel="noopener">https://securityweekly.com/qualys</a> to learn more about them!   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">fc8271f2-8c29-4d0c-a249-1dd493edf4a2</guid><pubDate>Tue, 02 Feb 2021 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43670051/asw138_0.mp3" length="97554304" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome John Delaroderie, Security Solutions Architect at Qualys, to discuss Groundhog Day - It's Time to Reset the Script on Vulnerabilities! In honor of the movie Groundhog Day, John will take a look at the top 10 most routinely...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome John Delaroderie, Security Solutions Architect at Qualys, to discuss Groundhog Day - It's Time to Reset the Script on Vulnerabilities! In honor of the movie Groundhog Day, John will take a look at the top 10 most routinely exploited vulnerabilities through a web app security lens. In the Application Security News, Sudo sure does, Libgcrypt flaw, iMessage demonstrates security by design, AWS Lambda shares a message on its design security, & more!   Show Notes: <a href="https://securityweekly.com/asw138" rel="noopener">https://securityweekly.com/asw138</a> Visit <a href="https://securityweekly.com/qualys" rel="noopener">https://securityweekly.com/qualys</a> to learn more about them!   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4065</itunes:duration><itunes:keywords>apisecurity,applicationsecurity,containersecurity,dast,devops,devsecops,docker,microsegmentation,mobileapplication,openshift,rasp,sast,sca,software,sqlinjection,swcompositionanalysis,vulnerabilities,waf,xss,zerotrust</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/3a661b6191d94ee000cd92d3dd3a706a.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>A Tree of Woe - ASW #137</title><link>https://www.spreaker.com/user/securityweekly/a-tree-of-woe-asw-137</link><description><![CDATA[This week, we welcome back Taylor McCaslin, Sr. Product Manager of Secure at GitLab, to discuss Reading Industry Analyst Tea Leaves To Predict The Future! It's analyst season with the new Forrester Wave on SAST recently published as well as Gartner's Application Security Testing Magic Quadrant publishing in April. We'll talk about what are analyst reports, how should you use them, and how should you interpret placement on them as as I like to call it, reading the analyst tea leaves.   In the AppSec News, an overflow and a flawed regex paint an RCE picture for Kindle, messaging apps miss the message on secure state machines, three pillars of a data security strategy for the cloud, where DoH might fit into AppSec, and all the things that can go wrong when you give up root in your Kubernetes pod!   Show Notes: <a href="https://securityweekly.com/asw137" rel="noopener">https://securityweekly.com/asw137</a> Visit <a href="https://securityweekly.com/GitLab" rel="noopener">https://securityweekly.com/GitLab</a> to learn more about them!   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">a9529585-8ab7-4f0d-b4ac-39b687c23a32</guid><pubDate>Tue, 26 Jan 2021 17:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/43670050/asw137_0.mp3" length="101532160" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome back Taylor McCaslin, Sr. Product Manager of Secure at GitLab, to discuss Reading Industry Analyst Tea Leaves To Predict The Future! It's analyst season with the new Forrester Wave on SAST recently published as well as Gartner's...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome back Taylor McCaslin, Sr. Product Manager of Secure at GitLab, to discuss Reading Industry Analyst Tea Leaves To Predict The Future! It's analyst season with the new Forrester Wave on SAST recently published as well as Gartner's Application Security Testing Magic Quadrant publishing in April. We'll talk about what are analyst reports, how should you use them, and how should you interpret placement on them as as I like to call it, reading the analyst tea leaves.   In the AppSec News, an overflow and a flawed regex paint an RCE picture for Kindle, messaging apps miss the message on secure state machines, three pillars of a data security strategy for the cloud, where DoH might fit into AppSec, and all the things that can go wrong when you give up root in your Kubernetes pod!   Show Notes: <a href="https://securityweekly.com/asw137" rel="noopener">https://securityweekly.com/asw137</a> Visit <a href="https://securityweekly.com/GitLab" rel="noopener">https://securityweekly.com/GitLab</a> to learn more about them!   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4231</itunes:duration><itunes:keywords>apisecurity,applicationsecurity,compliance,containersecurity,dast,devops,devsecops,docker,governance,openshift,policy,rasp,riskmanagement,sast,sca,software,sqlinjection,vendorrisk,vulnerabilities,xss</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a573326f5dcb8ea4bc0c2aae46a3f857.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Maximum Isolation - ASW #117</title><link>https://www.spreaker.com/user/securityweekly/maximum-isolation-asw-117</link><description><![CDATA[This week, it's Security Weekly Virtual Hacker Summer Camp 2020! In our first segment, we welcome Mike Rothman, President at DisruptOps, to discuss: How Does Sec Live In A DevOps World? In the Application Security News, Using Amazon GuardDuty to Protect Your S3, OkCupid Security Flaw Threatens Intimate Dater Details, Florida teen charged as mastermind in Twitter hack hitting Biden, Bezos, and others, Sandboxing and Workload Isolation, and Microsoft to remove all SHA-1 Windows downloads next week!   Show Notes: <a href="https://wiki.securityweekly.com/asw117" rel="noopener">https://wiki.securityweekly.com/asw117</a> Try it out free of charge and experience the future of security operations. Visit <a href="https://disruptops.com/free-evaluation/" rel="noopener">https://disruptops.com/free-evaluation/</a>   Join the Security Weekly Discord Server: <a href="https://discord.gg/pqSwWm4" rel="noopener">https://discord.gg/pqSwWm4</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></description><guid isPermaLink="false">b403ffdd-5a59-4570-8355-5ae77dc0b858</guid><pubDate>Tue, 04 Aug 2020 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/40365320/asw117_0.mp3" length="60944463" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, it's Security Weekly Virtual Hacker Summer Camp 2020! In our first segment, we welcome Mike Rothman, President at DisruptOps, to discuss: How Does Sec Live In A DevOps World? In the Application Security News, Using Amazon GuardDuty to...</itunes:subtitle><itunes:summary><![CDATA[This week, it's Security Weekly Virtual Hacker Summer Camp 2020! In our first segment, we welcome Mike Rothman, President at DisruptOps, to discuss: How Does Sec Live In A DevOps World? In the Application Security News, Using Amazon GuardDuty to Protect Your S3, OkCupid Security Flaw Threatens Intimate Dater Details, Florida teen charged as mastermind in Twitter hack hitting Biden, Bezos, and others, Sandboxing and Workload Isolation, and Microsoft to remove all SHA-1 Windows downloads next week!   Show Notes: <a href="https://wiki.securityweekly.com/asw117" rel="noopener">https://wiki.securityweekly.com/asw117</a> Try it out free of charge and experience the future of security operations. Visit <a href="https://disruptops.com/free-evaluation/" rel="noopener">https://disruptops.com/free-evaluation/</a>   Join the Security Weekly Discord Server: <a href="https://discord.gg/pqSwWm4" rel="noopener">https://discord.gg/pqSwWm4</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></itunes:summary><itunes:duration>3809</itunes:duration><itunes:keywords>apisecurity,applicationsecurity,containersecurity,dast,devops,devsecops,docker,microsegmentation,mobileapplication,openshift,rasp,sast,sca,software,sqlinjection,swcompositionanalysis,vulnerabilities,waf,xss,zerotrust</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c7890e61b33af965a4014a5f7bc17db7.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Absolutely Useless - ASW #114</title><link>https://www.spreaker.com/user/securityweekly/absolutely-useless-asw-114</link><description><![CDATA[This week, we welcome Judy Ngure, Cybersecurity Engineer at Africastalking, to talk about DevSecOps! In the Application Security News, Microsoft OneDrive client for Windows Qt QML module hijack, Zero-day flaw found in Zoom for Windows 7, Protecting your remote workforce from application-based attacks like consent phishing, Verizon Media, PayPal, Twitter Top Bug-Bounty Rankings, Mozilla suspends Firefox Send service while it addresses malware abuse, and Stop Talking About Technical Debt!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode114" rel="noopener">https://wiki.securityweekly.com/ASWEpisode114</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">4f1dc10d-bbd2-4eb2-b1c9-ba6de2f4e65f</guid><pubDate>Tue, 14 Jul 2020 20:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/40365324/asw114_0.mp3" length="63062680" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Judy Ngure, Cybersecurity Engineer at Africastalking, to talk about DevSecOps! In the Application Security News, Microsoft OneDrive client for Windows Qt QML module hijack, Zero-day flaw found in Zoom for Windows 7, Protecting...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Judy Ngure, Cybersecurity Engineer at Africastalking, to talk about DevSecOps! In the Application Security News, Microsoft OneDrive client for Windows Qt QML module hijack, Zero-day flaw found in Zoom for Windows 7, Protecting your remote workforce from application-based attacks like consent phishing, Verizon Media, PayPal, Twitter Top Bug-Bounty Rankings, Mozilla suspends Firefox Send service while it addresses malware abuse, and Stop Talking About Technical Debt!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode114" rel="noopener">https://wiki.securityweekly.com/ASWEpisode114</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3942</itunes:duration><itunes:keywords>apisecurity,applicationsecurity,compliance,containersecurity,dast,devops,devsecops,docker,governance,openshift,policy,rasp,riskmanagement,sast,sca,software,sqlinjection,vendorrisk,vulnerabilities,xss</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a26cc59e7c3d7bdb4d80cf28ea5eaacc.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Crunchy Crunchy! - ASW #113</title><link>https://www.spreaker.com/user/securityweekly/crunchy-crunchy-asw-113</link><description><![CDATA[This week, we welcome Catherine Chambers and Will Hickie from Irdeto, to discuss Protecting Mobile Applications! In the Application Security News, Would you like some RCE with your Guacamole?, Attackers Will Target Critical PAN-OS Flaw, Security Experts Warn, Microsoft releases emergency security update to fix two bugs in Windows codecs, The Current State of Kubernetes Threat Modelling, and How To Build a Culture of Resilience Through Good Habits!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode113" rel="noopener">https://wiki.securityweekly.com/ASWEpisode113</a> To download the white paper, visit: <a href="https://securityweekly.com/irdeto" rel="noopener">https://securityweekly.com/irdeto</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">5c2cfc75-a1a1-4672-acd0-fd8badac6d2e</guid><pubDate>Mon, 06 Jul 2020 22:30:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/40365321/asw113_0.mp3" length="67010305" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Catherine Chambers and Will Hickie from Irdeto, to discuss Protecting Mobile Applications! In the Application Security News, Would you like some RCE with your Guacamole?, Attackers Will Target Critical PAN-OS Flaw, Security...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Catherine Chambers and Will Hickie from Irdeto, to discuss Protecting Mobile Applications! In the Application Security News, Would you like some RCE with your Guacamole?, Attackers Will Target Critical PAN-OS Flaw, Security Experts Warn, Microsoft releases emergency security update to fix two bugs in Windows codecs, The Current State of Kubernetes Threat Modelling, and How To Build a Culture of Resilience Through Good Habits!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode113" rel="noopener">https://wiki.securityweekly.com/ASWEpisode113</a> To download the white paper, visit: <a href="https://securityweekly.com/irdeto" rel="noopener">https://securityweekly.com/irdeto</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4189</itunes:duration><itunes:keywords>apisecurity,applicationsecurity,containersecurity,dast,devops,devsecops,docker,microsegmentation,mobileapplication,openshift,rasp,sast,sca,software,sqlinjection,swcompositionanalysis,vulnerabilities,waf,xss,zerotrust</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/368fe4edb4c5a0c514b2528805975b37.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Carrot in the Cliff - ASW #91</title><link>https://www.spreaker.com/user/securityweekly/carrot-in-the-cliff-asw-91_1</link><description><![CDATA[This week, we welcome Hillel Solow, CTO at Check Point, to discuss The Evolution of DevSecOps and AppSec Trends in 2020! In the Application Security News, Policy and Disclosure: 2020 Edition, A look back & forward for bug bounties over the past decade, 4 Ring Employees Fired For Spying on Customers, Exploit Fully Breaks SHA-1, Lowers the Attack Bar, The Open Source Licence Debate: Comprehension Consternations & Stipulation Frustrations, Synopsys Buys Tinfoil, and Rotate Your Amazon RDS, Aurora, and Amazon DocumentDB (with MongoDB compatibility) Certificates!     Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode91" rel="noopener">https://wiki.securityweekly.com/ASWEpisode91</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>  ]]></description><guid isPermaLink="false">f9fb3554-fbaf-4867-a81e-9ad4eea18118</guid><pubDate>Tue, 14 Jan 2020 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/21670606/asw91_0.mp3" length="66377514" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Hillel Solow, CTO at Check Point, to discuss The Evolution of DevSecOps and AppSec Trends in 2020! In the Application Security News, Policy and Disclosure: 2020 Edition, A look back &amp; forward for bug bounties over the past...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Hillel Solow, CTO at Check Point, to discuss The Evolution of DevSecOps and AppSec Trends in 2020! In the Application Security News, Policy and Disclosure: 2020 Edition, A look back & forward for bug bounties over the past decade, 4 Ring Employees Fired For Spying on Customers, Exploit Fully Breaks SHA-1, Lowers the Attack Bar, The Open Source Licence Debate: Comprehension Consternations & Stipulation Frustrations, Synopsys Buys Tinfoil, and Rotate Your Amazon RDS, Aurora, and Amazon DocumentDB (with MongoDB compatibility) Certificates!     Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode91" rel="noopener">https://wiki.securityweekly.com/ASWEpisode91</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>  ]]></itunes:summary><itunes:duration>4149</itunes:duration><itunes:keywords>applicationsecurity,aws,azure,breaches,cloud,cloudsecurity,coding,containersecurity,devops,devsecops,digitaltransformation,docker,exploits,openshift,opensource,programmer,programming,software,threats,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/2f989d1c88de6af80cee4dc9b482bc30.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Learn &amp; Improve - ASW #90</title><link>https://www.spreaker.com/user/securityweekly/learn-improve-asw-90_1</link><description><![CDATA[This week on Application Security Weekly, Mike Shema and Matt Alderman discuss Privacy by Design - The 7 Foundational Principles! In the Application Security News, Featured Flaws and Big Breaches, Cloud, Code and Controls (Python is dead. Long live Python!), Learning and Tools (Breaking Down the OWASP API Security Top 10), and Food for Thought (Facebook will stop mining contacts with your 2FA number, 6 Security Team Goals for DevSecOps in 2020, 7 security incidents that cost CISOs their jobs)!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode90" rel="noopener">https://wiki.securityweekly.com/ASWEpisode90</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">adcbaa11-7668-41f7-8300-fa0011d0c342</guid><pubDate>Tue, 07 Jan 2020 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/21432727/asw90_0.mp3" length="55042043" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week on Application Security Weekly, Mike Shema and Matt Alderman discuss Privacy by Design - The 7 Foundational Principles! In the Application Security News, Featured Flaws and Big Breaches, Cloud, Code and Controls (Python is dead. Long live...</itunes:subtitle><itunes:summary><![CDATA[This week on Application Security Weekly, Mike Shema and Matt Alderman discuss Privacy by Design - The 7 Foundational Principles! In the Application Security News, Featured Flaws and Big Breaches, Cloud, Code and Controls (Python is dead. Long live Python!), Learning and Tools (Breaking Down the OWASP API Security Top 10), and Food for Thought (Facebook will stop mining contacts with your 2FA number, 6 Security Team Goals for DevSecOps in 2020, 7 security incidents that cost CISOs their jobs)!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode90" rel="noopener">https://wiki.securityweekly.com/ASWEpisode90</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3441</itunes:duration><itunes:keywords>accesscontrol,applicationsecurity,authorization,aws,azure,cloud,cloudsecurity,coding,compliance,devops,devsecops,gcp,iam,identity,mfa,password,policy,software,threats,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/614c0fa778831902ea751d90200cf6f8.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Backup &amp; Restore - ASW #89</title><link>https://www.spreaker.com/user/securityweekly/backup-restore-asw-89_1</link><description><![CDATA[This week, we welcome Dave Ferguson, Director of Product Management and WAS at Qualys! Dave will discuss the issue of latent vulnerabilities and how they may linger in your custom-coded web applications and APIs, presenting an enticing target for attackers. In the Application Security News, GitLab Doles Out Half a Million Bucks to White Hats, How can we integrate security into the DevOps pipelines?, Go passwordless to strengthen security and reduce costs - and design your app to support these types of workflows, including account recovery.   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode89" rel="noopener">https://wiki.securityweekly.com/ASWEpisode89</a> To learn more, visit: <a href="https://securityweekly.com/qualys" rel="noopener">https://securityweekly.com/qualys</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">f57f7635-8686-417b-9a33-0fd6c72b7c36</guid><pubDate>Tue, 17 Dec 2019 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/20819311/asw89_0.mp3" length="69427781" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Dave Ferguson, Director of Product Management and WAS at Qualys! Dave will discuss the issue of latent vulnerabilities and how they may linger in your custom-coded web applications and APIs, presenting an enticing target for...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Dave Ferguson, Director of Product Management and WAS at Qualys! Dave will discuss the issue of latent vulnerabilities and how they may linger in your custom-coded web applications and APIs, presenting an enticing target for attackers. In the Application Security News, GitLab Doles Out Half a Million Bucks to White Hats, How can we integrate security into the DevOps pipelines?, Go passwordless to strengthen security and reduce costs - and design your app to support these types of workflows, including account recovery.   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode89" rel="noopener">https://wiki.securityweekly.com/ASWEpisode89</a> To learn more, visit: <a href="https://securityweekly.com/qualys" rel="noopener">https://securityweekly.com/qualys</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4340</itunes:duration><itunes:keywords>accesscontrol,applicationsecurity,authorization,breaches,cloudsecurity,coding,devops,devsecops,digitaltransformation,exploits,iam,identity,password,protection,riskmanagement,software,threathunting,threatintelligence,threats,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9f4e90d2d91ccb2063532e51d95a6495.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Dad Jokes - ASW #88</title><link>https://www.spreaker.com/user/securityweekly/dad-jokes-asw-88_1</link><description><![CDATA[This week, we welcome Allan Friedman, Director of Cybersecurity Initiatives at the NTIA US Department of Commerce, to talk about the Software Bill of Materials! In the Application Security News, GitHub Seeks Security Dominance With Developers, IoT and Agile Framework Partners in Efficacy, WhiteSource acquires & open sources Renovate dependency update toolset, and Java vs. Python: Which should you choose?   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode88" rel="noopener">https://wiki.securityweekly.com/ASWEpisode88</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>  ]]></description><guid isPermaLink="false">6ff6d399-3155-4a56-9e77-8155bdd1d1e4</guid><pubDate>Tue, 10 Dec 2019 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/20621370/asw88_0.mp3" length="65426657" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Allan Friedman, Director of Cybersecurity Initiatives at the NTIA US Department of Commerce, to talk about the Software Bill of Materials! In the Application Security News, GitHub Seeks Security Dominance With Developers, IoT and...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Allan Friedman, Director of Cybersecurity Initiatives at the NTIA US Department of Commerce, to talk about the Software Bill of Materials! In the Application Security News, GitHub Seeks Security Dominance With Developers, IoT and Agile Framework Partners in Efficacy, WhiteSource acquires & open sources Renovate dependency update toolset, and Java vs. Python: Which should you choose?   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode88" rel="noopener">https://wiki.securityweekly.com/ASWEpisode88</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>  ]]></itunes:summary><itunes:duration>4090</itunes:duration><itunes:keywords>allanfriedman,compliance,iot,johnkinsella,paulasadoorian,policy,privacy,riskmanagement,threats,vendorrisk,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c6212fbaa82cc0ad9e6b5a1592f50f71.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Low Hanging Fruit - ASW #87</title><link>https://www.spreaker.com/user/securityweekly/low-hanging-fruit-asw-87_1</link><description><![CDATA[This week, we welcome Sandy Carielli, Principal Analyst at Forrester Research, to discuss the impact of good and bad bots on enterprises and how it is both a security and customer experience problem! In the Application Security News, Analysis of Jira Bug Stresses Impact of SSRF in Public Cloud, DevSecOps Adoption and the Web Security Myth, Facebook, Twitter profiles slurped by mobile apps using malicious SDKs, Firefox gets tough on tracking tricks that sneakily sap your privacy, and Decoding the Modern Enterprise Software Spaghetti!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode87" rel="noopener">https://wiki.securityweekly.com/ASWEpisode87</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">77d592e8-a24b-46a2-82f8-321577a40836</guid><pubDate>Tue, 03 Dec 2019 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/20448619/asw87_0.mp3" length="61530442" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Sandy Carielli, Principal Analyst at Forrester Research, to discuss the impact of good and bad bots on enterprises and how it is both a security and customer experience problem! In the Application Security News, Analysis of Jira...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Sandy Carielli, Principal Analyst at Forrester Research, to discuss the impact of good and bad bots on enterprises and how it is both a security and customer experience problem! In the Application Security News, Analysis of Jira Bug Stresses Impact of SSRF in Public Cloud, DevSecOps Adoption and the Web Security Myth, Facebook, Twitter profiles slurped by mobile apps using malicious SDKs, Firefox gets tough on tracking tricks that sneakily sap your privacy, and Decoding the Modern Enterprise Software Spaghetti!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode87" rel="noopener">https://wiki.securityweekly.com/ASWEpisode87</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3846</itunes:duration><itunes:keywords>applicationsecurity,beaubullock,cloudsecurity,coding,devops,devsecops,digitaltransformation,exploits,firewall,mattalderman,mikeshema,sandycarielli,software,sqlinjection,threats,vulnerabilities,waf,xss</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/98d7534a2e5497395160cc1534414d9a.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Snarky Ways - ASW #86</title><link>https://www.spreaker.com/user/securityweekly/snarky-ways-asw-86_1</link><description><![CDATA[This week, we welcome Tim Mackey, Principal Security Strategist at Synopsys! In the Application Security News, $1M Google Hacking Prize, 1.2B Records Exposed in Massive Server Leak, How Attackers Could Hijack Your Android Camera to Spy on You, XSS in GMail s AMP4Email via DOM Clobbering, and more!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode86" rel="noopener">https://wiki.securityweekly.com/ASWEpisode86</a> To learn more about Synopsys, visit: <a href="https://securityweekly.com/synopsys" rel="noopener">https://securityweekly.com/synopsys</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></description><guid isPermaLink="false">8e441c4b-7d29-4483-aaaf-51725d58c8ef</guid><pubDate>Tue, 26 Nov 2019 17:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/20290161/asw86_0.mp3" length="62883376" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Tim Mackey, Principal Security Strategist at Synopsys! In the Application Security News, $1M Google Hacking Prize, 1.2B Records Exposed in Massive Server Leak, How Attackers Could Hijack Your Android Camera to Spy on You, XSS in...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Tim Mackey, Principal Security Strategist at Synopsys! In the Application Security News, $1M Google Hacking Prize, 1.2B Records Exposed in Massive Server Leak, How Attackers Could Hijack Your Android Camera to Spy on You, XSS in GMail s AMP4Email via DOM Clobbering, and more!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode86" rel="noopener">https://wiki.securityweekly.com/ASWEpisode86</a> To learn more about Synopsys, visit: <a href="https://securityweekly.com/synopsys" rel="noopener">https://securityweekly.com/synopsys</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></itunes:summary><itunes:duration>3931</itunes:duration><itunes:keywords>applicationsecurity,cloudsecurity,coding,devops,devsecops,digitaltransformation,johnkinsella,mattalderman,mikeshema,software,timmackey</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/fc17a0fa33295d2b3da3ea2695f7d0a0.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Notoriously Targeted - ASW #85</title><link>https://www.spreaker.com/user/securityweekly/notoriously-targeted-asw-85_1</link><description><![CDATA[This week, we welcome back Pawan Shankar, Senior Product Marketing Manager of Sysdig, to announce the launch of Sysdig Secure 3.0! In the Application Security News, Mirantis' Docker Enterprise acquisition a lifeline as industry shifts to Kubernetes, Attackers' Costs Increasing as Businesses Focus on Security, Soft Skills: 6 Nontechnical Traits CISOs Need to Succeed, and Three Ways Developers Can Worry Less About Security!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode85" rel="noopener">https://wiki.securityweekly.com/ASWEpisode85</a> To learn more about Sysdig, visit: <a href="https://securityweekly.com/sysdig" rel="noopener">https://securityweekly.com/sysdig</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">99611173-6930-4b52-b753-894d15d35e69</guid><pubDate>Tue, 19 Nov 2019 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/20114629/asw85_0.mp3" length="63183470" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome back Pawan Shankar, Senior Product Marketing Manager of Sysdig, to announce the launch of Sysdig Secure 3.0! In the Application Security News, Mirantis' Docker Enterprise acquisition a lifeline as industry shifts to Kubernetes,...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome back Pawan Shankar, Senior Product Marketing Manager of Sysdig, to announce the launch of Sysdig Secure 3.0! In the Application Security News, Mirantis' Docker Enterprise acquisition a lifeline as industry shifts to Kubernetes, Attackers' Costs Increasing as Businesses Focus on Security, Soft Skills: 6 Nontechnical Traits CISOs Need to Succeed, and Three Ways Developers Can Worry Less About Security!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode85" rel="noopener">https://wiki.securityweekly.com/ASWEpisode85</a> To learn more about Sysdig, visit: <a href="https://securityweekly.com/sysdig" rel="noopener">https://securityweekly.com/sysdig</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3949</itunes:duration><itunes:keywords>applicationsecurity,cloudsecurity,coding,containersecurity,cybersecuritytraining,devsecops,docker,ethicalhacker,ethicalhacking,exploits,hacking,openshift,opensource,programmer,programming,software,threathunting,threats,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/58166ab5bfacbfd660b965a6d5e37247.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Destroying Your Tree - ASW #84</title><link>https://www.spreaker.com/user/securityweekly/destroying-your-tree-asw-84_1</link><description><![CDATA[This week, in the first segment, Mike, Matt, and John talk Security Testing! In the Application Security News, Pwn2Own Tokyo Roundup: Amazon Echo, Routers, Smart TVs Fall to Hackers, Robinhood Traders Discovered a Glitch That Gave Them 'Infinite Leverage', Bugcrowd Pays Out Over $500K in Bounties in One Week, GWP-ASan: Sampling heap memory error detection in-the-wild, and more!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode84" rel="noopener">https://wiki.securityweekly.com/ASWEpisode84</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">c3ec02176da0498e95036e3f04251028</guid><pubDate>Wed, 13 Nov 2019 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/20005831/asw84_0.mp3" length="62906363" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, in the first segment, Mike, Matt, and John talk Security Testing! In the Application Security News, Pwn2Own Tokyo Roundup: Amazon Echo, Routers, Smart TVs Fall to Hackers, Robinhood Traders Discovered a Glitch That Gave Them 'Infinite...</itunes:subtitle><itunes:summary><![CDATA[This week, in the first segment, Mike, Matt, and John talk Security Testing! In the Application Security News, Pwn2Own Tokyo Roundup: Amazon Echo, Routers, Smart TVs Fall to Hackers, Robinhood Traders Discovered a Glitch That Gave Them 'Infinite Leverage', Bugcrowd Pays Out Over $500K in Bounties in One Week, GWP-ASan: Sampling heap memory error detection in-the-wild, and more!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode84" rel="noopener">https://wiki.securityweekly.com/ASWEpisode84</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3932</itunes:duration><itunes:keywords>aws,azure,cloud,cloudsecurity,compliance,cybersecurityawareness,cybersecuritytraining,devops,devsecops,gcp,johnkinsella,mattalderman,mikeshema,phishing,policy,securityeducation,securitynews,software,threats,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/161c0053e864608f71850a55b606d875.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Disrupting the Office - ASW #83</title><link>https://www.spreaker.com/user/securityweekly/disrupting-the-office-asw-83_1</link><description><![CDATA[This week, we interview Daniel Lowrie and Justin Dennison, Edutainers at ITProTV, to discuss how to bridge the gap between a Developer and Security! In the Application Security News, Stable Channel Update for Desktop Chrome users should upgrade to, Overcoming the container security conundrum: What enterprises need to know, Security Think Tank: In the cloud, the buck stops with you, PHP Bug Allows Remote Code-Execution on NGINX, Servers and patch details at Sec Bug #78599, Raising Security Awareness: Why Tools Can't Replace People, and much more!   To learn more about ITProTV, visit: <a href="https://securityweekly.com/itprotv" rel="noopener">https://securityweekly.com/itprotv</a> Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode83" rel="noopener">https://wiki.securityweekly.com/ASWEpisode83</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>  ]]></description><guid isPermaLink="false">430a9ed707b54798a0c66036bf856ce4</guid><pubDate>Tue, 05 Nov 2019 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/19865487/asw83_0.mp3" length="63901524" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we interview Daniel Lowrie and Justin Dennison, Edutainers at ITProTV, to discuss how to bridge the gap between a Developer and Security! In the Application Security News, Stable Channel Update for Desktop Chrome users should upgrade to,...</itunes:subtitle><itunes:summary><![CDATA[This week, we interview Daniel Lowrie and Justin Dennison, Edutainers at ITProTV, to discuss how to bridge the gap between a Developer and Security! In the Application Security News, Stable Channel Update for Desktop Chrome users should upgrade to, Overcoming the container security conundrum: What enterprises need to know, Security Think Tank: In the cloud, the buck stops with you, PHP Bug Allows Remote Code-Execution on NGINX, Servers and patch details at Sec Bug #78599, Raising Security Awareness: Why Tools Can't Replace People, and much more!   To learn more about ITProTV, visit: <a href="https://securityweekly.com/itprotv" rel="noopener">https://securityweekly.com/itprotv</a> Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode83" rel="noopener">https://wiki.securityweekly.com/ASWEpisode83</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>  ]]></itunes:summary><itunes:duration>3994</itunes:duration><itunes:keywords>applicationsecurity,cloudsecurity,coding,containersecurity,cybersecurityawareness,cybersecuritytraining,devops,devsecops,digitaltransformation,docker,exploits,openshift,opensource,phishing,policy,programmer,programming,software,threats,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/044536b3f128690ac373ba787a6e4de4.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Scary World - ASW #82</title><link>https://www.spreaker.com/user/securityweekly/the-scary-world-asw-82_1</link><description><![CDATA[This week, Mike Shema, Matt Alderman, and John Kinsella talk about Bug Bounties, Pentesting, & Scanners! In the Application Security News, Top cloud security controls you should be using, State of Software Security X, Developers: The Cause of and Solution to Security's Biggest Problems, and much more!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode82" rel="noopener">https://wiki.securityweekly.com/ASWEpisode82</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">19e50191493547058760c98a05dc7d7b</guid><pubDate>Tue, 29 Oct 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/19746480/asw82_0.mp3" length="63007927" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Mike Shema, Matt Alderman, and John Kinsella talk about Bug Bounties, Pentesting, &amp; Scanners! In the Application Security News, Top cloud security controls you should be using, State of Software Security X, Developers: The Cause of and...</itunes:subtitle><itunes:summary><![CDATA[This week, Mike Shema, Matt Alderman, and John Kinsella talk about Bug Bounties, Pentesting, & Scanners! In the Application Security News, Top cloud security controls you should be using, State of Software Security X, Developers: The Cause of and Solution to Security's Biggest Problems, and much more!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode82" rel="noopener">https://wiki.securityweekly.com/ASWEpisode82</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3938</itunes:duration><itunes:keywords>applicationsecurity,cloudsecurity,coding,devops,devsecops,digitaltransformation,ethicalhacker,ethicalhacking,exploits,hacked,hacker,hacking,johnkinsella,mattalderman,mikeshema,penetrationtesting,securityservices,software,threats,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/85c5c31415b2ef17ac2884cc8d3b9d28.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Exceedingly Happy - ASW #81</title><link>https://www.spreaker.com/user/securityweekly/exceedingly-happy-asw-81_1</link><description><![CDATA[This week, we welcome Doug Coburn, Director of Professional Services at Signal Sciences, discussing Containers, Layer 7, and Application Security! In the Application Security News, From Stackoverflow to CVE, with some laughs along the way, Four-Year-Old Critical Linux Wi-Fi Bug Allows System Compromise, Recent Site Isolation improvements in Chrome, policy_sentry is an IAM Least Privilege Policy Generator, auditor, and analysis database, and much more!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode81" rel="noopener">https://wiki.securityweekly.com/ASWEpisode81</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">5657216faabf4cdf8422dfb852ac7596</guid><pubDate>Tue, 22 Oct 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/19626669/asw81_0.mp3" length="67613002" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Doug Coburn, Director of Professional Services at Signal Sciences, discussing Containers, Layer 7, and Application Security! In the Application Security News, From Stackoverflow to CVE, with some laughs along the way,...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Doug Coburn, Director of Professional Services at Signal Sciences, discussing Containers, Layer 7, and Application Security! In the Application Security News, From Stackoverflow to CVE, with some laughs along the way, Four-Year-Old Critical Linux Wi-Fi Bug Allows System Compromise, Recent Site Isolation improvements in Chrome, policy_sentry is an IAM Least Privilege Policy Generator, auditor, and analysis database, and much more!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode81" rel="noopener">https://wiki.securityweekly.com/ASWEpisode81</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4226</itunes:duration><itunes:keywords>accesscontrol,applicationsecurity,authorization,aws,azure,cloud,cloudsecurity,coding,containersecurity,devops,devsecops,docker,exploits,openshift,opensource,programmer,programming,software,threats,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/d921d772a26e51753a0f9b6af5edd63d.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Spaghetti Code - ASW #80</title><link>https://www.spreaker.com/user/securityweekly/spaghetti-code-asw-80_1</link><description><![CDATA[This week, we welcome Francois Lacelles, Field CTO of Ping Identity for an interview! In the Application Security News, Key takeaways from Imperva breach, From Automated Cloud Deployment to Progressive Delivery, Designing Your First App in Kubernetes: An Overview Food for Thought, Autonomy and the death of CVEs?, and AppSec 'Spaghetti on the Wall' Tool Strategy Undermining Security!   To learn more about Ping Identity, visit: <a href="https://securityweekly.com/ping" rel="noopener">https://securityweekly.com/ping</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode80" rel="noopener">https://wiki.securityweekly.com/ASWEpisode80</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>  ]]></description><guid isPermaLink="false">d612d2e902674674bf55a1e4483079bf</guid><pubDate>Tue, 15 Oct 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/19514886/asw80_0.mp3" length="62760078" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Francois Lacelles, Field CTO of Ping Identity for an interview! In the Application Security News, Key takeaways from Imperva breach, From Automated Cloud Deployment to Progressive Delivery, Designing Your First App in Kubernetes:...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Francois Lacelles, Field CTO of Ping Identity for an interview! In the Application Security News, Key takeaways from Imperva breach, From Automated Cloud Deployment to Progressive Delivery, Designing Your First App in Kubernetes: An Overview Food for Thought, Autonomy and the death of CVEs?, and AppSec 'Spaghetti on the Wall' Tool Strategy Undermining Security!   To learn more about Ping Identity, visit: <a href="https://securityweekly.com/ping" rel="noopener">https://securityweekly.com/ping</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode80" rel="noopener">https://wiki.securityweekly.com/ASWEpisode80</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>  ]]></itunes:summary><itunes:duration>3923</itunes:duration><itunes:keywords>accesscontrol,applicationsecurity,authorization,aws,cloud,cloudsecurity,coding,compliance,devsecops,gcp,iam,identity,mfa,microsegmentation,password,policy,software,threats,vulnerabilities,zerotrust</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5c58d007b2346a3ad188f156ba358dad.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>A Sea of Orange - ASW #79</title><link>https://www.spreaker.com/user/securityweekly/a-sea-of-orange-asw-79_1</link><description><![CDATA[This week, Mike, Matt, and John talk about Cloud Security for Small Teams! In the Application Security News, Ex-Yahoo Engineer Abused Access to Hack 6,000 User Accounts, American Express Insider Breaches Cardholder Information, How a double-free bug in, WhatsApp turns to RCE, Flare-on 6 2019 Writeups, and Five Trends Shaping the Future of Container Security!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode79" rel="noopener">https://wiki.securityweekly.com/ASWEpisode79</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>  ]]></description><guid isPermaLink="false">d85e208f697a45e2aa60eb6b255dbc15</guid><pubDate>Tue, 08 Oct 2019 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/19413483/asw79_0.mp3" length="72707088" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Mike, Matt, and John talk about Cloud Security for Small Teams! In the Application Security News, Ex-Yahoo Engineer Abused Access to Hack 6,000 User Accounts, American Express Insider Breaches Cardholder Information, How a double-free bug...</itunes:subtitle><itunes:summary><![CDATA[This week, Mike, Matt, and John talk about Cloud Security for Small Teams! In the Application Security News, Ex-Yahoo Engineer Abused Access to Hack 6,000 User Accounts, American Express Insider Breaches Cardholder Information, How a double-free bug in, WhatsApp turns to RCE, Flare-on 6 2019 Writeups, and Five Trends Shaping the Future of Container Security!   Show Notes: <a href="https://wiki.securityweekly.com/ASWEpisode79" rel="noopener">https://wiki.securityweekly.com/ASWEpisode79</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>  ]]></itunes:summary><itunes:duration>4545</itunes:duration><itunes:keywords>applicationsecurity,aws,azure,cloud,cloudsecurity,coding,compliance,containersecurity,devops,devsecops,docker,exploits,gcp,openshift,opensource,policy,programmer,software,threats,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6db33c902f8017b7951aeedc232b8e6a.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Notorious Bucket - ASW #78</title><link>https://www.spreaker.com/user/securityweekly/the-notorious-bucket-asw-78_1</link><description><![CDATA[This week, we welcome Ryan Kelso, Application Security Engineer at 10-Sec, Inc., to discuss Information Disclosure Vulnerabilities! In the Application Security News, Threat Actors Use Percentage-Based URL Encoding to Bypass Email Gateways, Intelligent Tracking Prevention 2.3 and a discussion to Limit the length of the Referer header with some background on Browser Side Channels, Serverless Security Threats Loom as Enterprises Go Cloud Native, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode78" rel="noopener">https://wiki.securityweekly.com/ASW_Episode78</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">23415359f61d40c78aa57d17d4d0a0dc</guid><pubDate>Tue, 01 Oct 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/19305732/asw78_1.mp3" length="60783131" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Ryan Kelso, Application Security Engineer at 10-Sec, Inc., to discuss Information Disclosure Vulnerabilities! In the Application Security News, Threat Actors Use Percentage-Based URL Encoding to Bypass Email Gateways, Intelligent...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Ryan Kelso, Application Security Engineer at 10-Sec, Inc., to discuss Information Disclosure Vulnerabilities! In the Application Security News, Threat Actors Use Percentage-Based URL Encoding to Bypass Email Gateways, Intelligent Tracking Prevention 2.3 and a discussion to Limit the length of the Referer header with some background on Browser Side Channels, Serverless Security Threats Loom as Enterprises Go Cloud Native, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode78" rel="noopener">https://wiki.securityweekly.com/ASW_Episode78</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3799</itunes:duration><itunes:keywords>applicationsecurity,aws,azure,cloud,cloudsecurity,devops,devsecops,exploits,gcp,linux,macosx,malware,mattalderman,mikeshema,networksecurity,software,threats,vm,vulnerabilities,windows</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cf1a7e8ec5cf901735c21fca29274c98.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Something Should Exist - ASW #77</title><link>https://www.spreaker.com/user/securityweekly/something-should-exist-asw-77</link><description><![CDATA[This week, we welcome Nicolas Valcarcel, Security Engineer at NextRoll! In the Application Security News, BSIMM10 Emphasizes DevOps' Role in Software Security and the BSIMM10 report, Crowdsourced Security & the Gig Economy, Lessons learned through 15 years of SDL at work, Software eats the world, jobs double US employment growth rate, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode77" rel="noopener">https://wiki.securityweekly.com/ASW_Episode77</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">bd4198bf438240cdb8347d8a89ec57cf</guid><pubDate>Mon, 23 Sep 2019 20:23:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/19203892/asw77_0.mp3" length="65888084" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Nicolas Valcarcel, Security Engineer at NextRoll! In the Application Security News, BSIMM10 Emphasizes DevOps' Role in Software Security and the BSIMM10 report, Crowdsourced Security &amp; the Gig Economy, Lessons learned through 15...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Nicolas Valcarcel, Security Engineer at NextRoll! In the Application Security News, BSIMM10 Emphasizes DevOps' Role in Software Security and the BSIMM10 report, Crowdsourced Security & the Gig Economy, Lessons learned through 15 years of SDL at work, Software eats the world, jobs double US employment growth rate, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode77" rel="noopener">https://wiki.securityweekly.com/ASW_Episode77</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4118</itunes:duration><itunes:keywords>applicationsecurity,cloudsecurity,coding,devops,devsecops,digitaltransformation,johnkinsella,mattalderman,mikeshema,nicolasvalcrcel,software</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b32d0298992d51711827a56d1c078962.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Pick Your Example - ASW #76</title><link>https://www.spreaker.com/user/securityweekly/pick-your-example-asw-76_1</link><description><![CDATA[This week, we welcome Jay Durga, IT Architect at CIRCOR International, to discuss the excel tool he developed, and how it can be used to measure metrics or as a guidance document for testing effectiveness of security controls put in place in your SDLC and DevOps process! In the Application Security News, Simjacker Next Generation Spying Over Mobile, Intel CPUs Vulnerable to Sensitive Data Leakage in NetCAT Attack and NetCAT: Practical Cache Attacks from the Network, What is PSD2? And how it will impact the payments processing industry, Better Together: Why Software-Development Toolmakers Should Embrace Integration, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode76" rel="noopener">https://wiki.securityweekly.com/ASW_Episode76</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">6e0c622448ce4efea1f64aa410a9e8ff</guid><pubDate>Mon, 16 Sep 2019 20:36:57 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/19120544/asw76_0.mp3" length="70390341" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Jay Durga, IT Architect at CIRCOR International, to discuss the excel tool he developed, and how it can be used to measure metrics or as a guidance document for testing effectiveness of security controls put in place in your SDLC...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Jay Durga, IT Architect at CIRCOR International, to discuss the excel tool he developed, and how it can be used to measure metrics or as a guidance document for testing effectiveness of security controls put in place in your SDLC and DevOps process! In the Application Security News, Simjacker Next Generation Spying Over Mobile, Intel CPUs Vulnerable to Sensitive Data Leakage in NetCAT Attack and NetCAT: Practical Cache Attacks from the Network, What is PSD2? And how it will impact the payments processing industry, Better Together: Why Software-Development Toolmakers Should Embrace Integration, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode76" rel="noopener">https://wiki.securityweekly.com/ASW_Episode76</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4400</itunes:duration><itunes:keywords>applicationsecurity,asset,assetdiscovery,assetmanagement,cloudsecurity,coding,devops,devsecops,digitaltransformation,jaydurga,johnkinsella,mattalderman,mikeshema,sca,software</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a07951e1252aa6e9fb2d2cfe70ec48e5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Man With A Plan - ASW #75</title><link>https://www.spreaker.com/user/securityweekly/the-man-with-a-plan-asw-75_1</link><description><![CDATA[Ty Sbano is the Cloud Chief Information Security Officer of Sisense. Ty will be discussing Tools in the DevOps Pipeline, Component Analysis, and Anything Application Security! ***** A very deep dive into iOS Exploit chains found in the wild followed by Heap Exploit Development, Twitter turns off SMS texting after @Jack hijacking, CVE-2019-15846: Unauthenticated Remote Command Execution Flaw Disclosed for Exim, 7 Steps to Web App Security, Fuzzing 101: Why Bug Hunters Still Love It After All These Years, and more! Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode75" rel="noopener">https://wiki.securityweekly.com/ASW_Episode75</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">8ac73cac04364cabaf3fb3e9350a11b6</guid><pubDate>Tue, 10 Sep 2019 15:52:42 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/19059497/asw_75_complete_0.mp3" length="68981818" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>Ty Sbano is the Cloud Chief Information Security Officer of Sisense. Ty will be discussing Tools in the DevOps Pipeline, Component Analysis, and Anything Application Security! ***** A very deep dive into iOS Exploit chains found in the wild followed...</itunes:subtitle><itunes:summary><![CDATA[Ty Sbano is the Cloud Chief Information Security Officer of Sisense. Ty will be discussing Tools in the DevOps Pipeline, Component Analysis, and Anything Application Security! ***** A very deep dive into iOS Exploit chains found in the wild followed by Heap Exploit Development, Twitter turns off SMS texting after @Jack hijacking, CVE-2019-15846: Unauthenticated Remote Command Execution Flaw Disclosed for Exim, 7 Steps to Web App Security, Fuzzing 101: Why Bug Hunters Still Love It After All These Years, and more! Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode75" rel="noopener">https://wiki.securityweekly.com/ASW_Episode75</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>4312</itunes:duration><itunes:keywords>application,applicationsecurity,asset,assetmanagement,cloudsecurity,coding,devops,devsecops,digitaltransformation,epp,exploit,exploits,inventory,isolation,prevention,protection,sca,software,threats,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/4f366688a4fd7e6e82aa8219811e2420.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Still Alive - ASW #74</title><link>https://www.spreaker.com/user/securityweekly/still-alive-asw-74_1</link><description><![CDATA[This week, we welcome Pawan Shankar, Senior Product Marketing Manager of Sysdig! In our second segment, we air two pre-recorded interviews with Azi Cohen, Co-Founder of WhiteSource, and Jeff Hudson, CEO of Venafi from BlackHat USA 2019!   To learn more about Sysdig, visit: <a href="https://securityweekly.com/sysdig" rel="noopener">https://securityweekly.com/sysdig</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode74" rel="noopener">https://wiki.securityweekly.com/ASW_Episode74</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">488a87e73fe04284b2de607d43a4d31a</guid><pubDate>Tue, 27 Aug 2019 17:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18931197/asw74_0.mp3" length="64209560" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Pawan Shankar, Senior Product Marketing Manager of Sysdig! In our second segment, we air two pre-recorded interviews with Azi Cohen, Co-Founder of WhiteSource, and Jeff Hudson, CEO of Venafi from BlackHat USA 2019!   To learn...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Pawan Shankar, Senior Product Marketing Manager of Sysdig! In our second segment, we air two pre-recorded interviews with Azi Cohen, Co-Founder of WhiteSource, and Jeff Hudson, CEO of Venafi from BlackHat USA 2019!   To learn more about Sysdig, visit: <a href="https://securityweekly.com/sysdig" rel="noopener">https://securityweekly.com/sysdig</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode74" rel="noopener">https://wiki.securityweekly.com/ASW_Episode74</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4014</itunes:duration><itunes:keywords>applicationsecurity,appsec,blackhat,devsecops,intelligence,secops,software,threat</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/7b771c0577303f00595cdd101f1ebed6.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Dark Data - ASW #73</title><link>https://www.spreaker.com/user/securityweekly/the-dark-data-asw-73_1</link><description><![CDATA[This week, in the Application Security News, HTTP/2 Denial of Service Advisory with seven vulns that affects the protocol implemented by several vendors, SSH certificate authentication for GitHub Enterprise Cloud works well with tools like Sharkey and BLESS, Polaris Points the Way to Kubernetes Best Practices, and much more! In our second segment, we air three pre-recorded interviews from Black Hat 2019, with Ameya Talwalker from Cequence, Mark Batchelor from PING Identity, and Michael Krueger from NowSecure!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode73" rel="noopener">https://wiki.securityweekly.com/ASW_Episode73</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">137828487f824c34a216a9c3cd082d27</guid><pubDate>Tue, 20 Aug 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18863464/asw73_0.mp3" length="78048189" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, in the Application Security News, HTTP/2 Denial of Service Advisory with seven vulns that affects the protocol implemented by several vendors, SSH certificate authentication for GitHub Enterprise Cloud works well with tools like Sharkey and...</itunes:subtitle><itunes:summary><![CDATA[This week, in the Application Security News, HTTP/2 Denial of Service Advisory with seven vulns that affects the protocol implemented by several vendors, SSH certificate authentication for GitHub Enterprise Cloud works well with tools like Sharkey and BLESS, Polaris Points the Way to Kubernetes Best Practices, and much more! In our second segment, we air three pre-recorded interviews from Black Hat 2019, with Ameya Talwalker from Cequence, Mark Batchelor from PING Identity, and Michael Krueger from NowSecure!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode73" rel="noopener">https://wiki.securityweekly.com/ASW_Episode73</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4878</itunes:duration><itunes:keywords>appsec,certificates,ddos,devops,kubernetes,ssh,vendors,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/16fc5cfa5f0a186716c12334e07d1774.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Highly Distributed - ASW #72</title><link>https://www.spreaker.com/user/securityweekly/highly-distributed-asw-72_1</link><description><![CDATA[This week, Mike Shema and Matt Alderman discuss Hacker Summer Camp as the Security Weekly team has returned from Las Vegas all in one piece! In the Application Security News, From Equifax to Capital One: The problem with web application security, Apple extends its bug bounty program to cover macOS with $1 million in rewards, Azure Security Lab: a new space for Azure research and collaboration, Awarding Google Cloud Vulnerability Research, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode72" rel="noopener">https://wiki.securityweekly.com/ASW_Episode72</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">f1076363d51c46dd925c1b5e4b746425</guid><pubDate>Wed, 14 Aug 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18814015/asw72_0.mp3" length="61563043" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Mike Shema and Matt Alderman discuss Hacker Summer Camp as the Security Weekly team has returned from Las Vegas all in one piece! In the Application Security News, From Equifax to Capital One: The problem with web application security,...</itunes:subtitle><itunes:summary><![CDATA[This week, Mike Shema and Matt Alderman discuss Hacker Summer Camp as the Security Weekly team has returned from Las Vegas all in one piece! In the Application Security News, From Equifax to Capital One: The problem with web application security, Apple extends its bug bounty program to cover macOS with $1 million in rewards, Azure Security Lab: a new space for Azure research and collaboration, Awarding Google Cloud Vulnerability Research, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode72" rel="noopener">https://wiki.securityweekly.com/ASW_Episode72</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3848</itunes:duration><itunes:keywords>azure,devsecops,exploits,facebook</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/4bf0b8f3631ce6ee5d6e1a8b5a06345f.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Off Guard - Application Security Weekly #71</title><link>https://www.spreaker.com/user/securityweekly/off-guard-application-security-weekly-71_1</link><description><![CDATA[This week, in the Application Security News, Rare Steganography Hack Can Compromise Fully Patched Websites, Bug Bounties Continue to Rise as Google Boosts its Payouts, Snyk Acquires DevSecCon to Boost DevSecOps Community, and much more! In our second segment, we welcome Murray Goldschmidt, COO & Co-founder of Sense of Security, to talk about The State of Container Security in the Enterprise!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode71" rel="noopener">https://wiki.securityweekly.com/ASW_Episode71</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">fc98e61f722547c0812e6b4846ae48ee</guid><pubDate>Tue, 30 Jul 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18675777/asw71_0.mp3" length="71234618" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, in the Application Security News, Rare Steganography Hack Can Compromise Fully Patched Websites, Bug Bounties Continue to Rise as Google Boosts its Payouts, Snyk Acquires DevSecCon to Boost DevSecOps Community, and much more! In our second...</itunes:subtitle><itunes:summary><![CDATA[This week, in the Application Security News, Rare Steganography Hack Can Compromise Fully Patched Websites, Bug Bounties Continue to Rise as Google Boosts its Payouts, Snyk Acquires DevSecCon to Boost DevSecOps Community, and much more! In our second segment, we welcome Murray Goldschmidt, COO & Co-founder of Sense of Security, to talk about The State of Container Security in the Enterprise!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode71" rel="noopener">https://wiki.securityweekly.com/ASW_Episode71</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4453</itunes:duration><itunes:keywords>71,applicationsecurityweekly,appsec,asw,bugbounties,containersecurity,devops,devsecops,enterprise,google,hacking,murraygoldschmidt,patching,podcast,security,securityweekly,senseofsecurity,snyk,vulns</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/739f4d22df5dbdff509a837a18fdf660.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Help Us! - Application Security Weekly #70</title><link>https://www.spreaker.com/user/securityweekly/help-us-application-security-weekly-70_1</link><description><![CDATA[This week, we welcome Ian Eyberg, CEO of NanoVMs! In the Application Security News, detecting malware in package manager repositories, Attacking SSL VPN, Solving Digital Transformation Cybersecurity Concerns With DevSecOps, How I Could Have Hacked Any Instagram Account, Tracking Anonymized Bluetooth Devices and Bluetooth Bug, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode70" rel="noopener">https://wiki.securityweekly.com/ASW_Episode70</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">1b18111770404d3483c733902e8461d3</guid><pubDate>Tue, 23 Jul 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18619379/asw70_0.mp3" length="62707833" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Ian Eyberg, CEO of NanoVMs! In the Application Security News, detecting malware in package manager repositories, Attacking SSL VPN, Solving Digital Transformation Cybersecurity Concerns With DevSecOps, How I Could Have Hacked Any...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Ian Eyberg, CEO of NanoVMs! In the Application Security News, detecting malware in package manager repositories, Attacking SSL VPN, Solving Digital Transformation Cybersecurity Concerns With DevSecOps, How I Could Have Hacked Any Instagram Account, Tracking Anonymized Bluetooth Devices and Bluetooth Bug, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode70" rel="noopener">https://wiki.securityweekly.com/ASW_Episode70</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3920</itunes:duration><itunes:keywords>70,applicationsecurityweekly,appsec,cybersecurity,deployment,devops,devsecops,gitlab,ios,macos,news,secureappdeploymentwithunikern,secureapplications,ssl,suppychain,unikernels,vpn</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/4a68d1dd89af63be30c02646cd4ff9c0.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Paving the Road - Application Security Weekly #69</title><link>https://www.spreaker.com/user/securityweekly/paving-the-road-application-security-wee_1</link><description><![CDATA[This week, we welcome Gururaj Pandurangi, Founder and CEO of Cloudneeti, to discuss Security in Multi-Cloud Environments! In the Application Security News, yes, the Zoom thing, 50 ways to leak your data in 1,300 popular Android apps access data, without proper permissions, GE Aviation exposed internal configs via open Jenkins instance, and more!   To learn more about Cloudneeti, visit: <a href="https://securityweekly.com/cloudneeti" rel="noopener">https://securityweekly.com/cloudneeti</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode69" rel="noopener">https://wiki.securityweekly.com/ASW_Episode69</a>   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">e85b0897fc254114af8b3978da4420f9</guid><pubDate>Tue, 16 Jul 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18561091/asw69_0.mp3" length="71980675" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Gururaj Pandurangi, Founder and CEO of Cloudneeti, to discuss Security in Multi-Cloud Environments! In the Application Security News, yes, the Zoom thing, 50 ways to leak your data in 1,300 popular Android apps access data,...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Gururaj Pandurangi, Founder and CEO of Cloudneeti, to discuss Security in Multi-Cloud Environments! In the Application Security News, yes, the Zoom thing, 50 ways to leak your data in 1,300 popular Android apps access data, without proper permissions, GE Aviation exposed internal configs via open Jenkins instance, and more!   To learn more about Cloudneeti, visit: <a href="https://securityweekly.com/cloudneeti" rel="noopener">https://securityweekly.com/cloudneeti</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode69" rel="noopener">https://wiki.securityweekly.com/ASW_Episode69</a>   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4499</itunes:duration><itunes:keywords>50waystoleakdata,69,androidapps,applicationnews,ceo,cloud,complianceassurance,devops,environments,geaviation,gururaj,gururajpandurangi,jenkins,news,podcast,securingmulticloudenvironments,security,zoom</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/aa3fa4d2b3795324827cfa1261d17c6a.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Wise Words - Application Security Weekly #68</title><link>https://www.spreaker.com/user/securityweekly/wise-words-application-security-weekly-6_1</link><description><![CDATA[This week, Mike Shema, John Kinsella, and Matt Alderman talk Cloud Native from an application perspective! In the Application Security News, WordPress Plugin WP Statistics Patches XSS Flaw, Three RCEs in Android's Media framework, Nine Best Practices For Integrating Application Security Testing Into DevOps, 6 Traits That Define DevSecOps, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode68" rel="noopener">https://wiki.securityweekly.com/ASW_Episode68</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">3f3c85c36c5a491a9f19eb8a65a542c8</guid><pubDate>Tue, 09 Jul 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18499095/asw68_0.mp3" length="61606510" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Mike Shema, John Kinsella, and Matt Alderman talk Cloud Native from an application perspective! In the Application Security News, WordPress Plugin WP Statistics Patches XSS Flaw, Three RCEs in Android's Media framework, Nine Best Practices...</itunes:subtitle><itunes:summary><![CDATA[This week, Mike Shema, John Kinsella, and Matt Alderman talk Cloud Native from an application perspective! In the Application Security News, WordPress Plugin WP Statistics Patches XSS Flaw, Three RCEs in Android's Media framework, Nine Best Practices For Integrating Application Security Testing Into DevOps, 6 Traits That Define DevSecOps, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode68" rel="noopener">https://wiki.securityweekly.com/ASW_Episode68</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3851</itunes:duration><itunes:keywords>68,6traits,applicationnews,applications,applicationsecuritytesting,applicationsecurityweekly,appsec,asw,cloudnative,devops,devsecops,johnkinsella,mikeshema,plugin,podcast,security,securityweekly,wordpress,xss</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/d37493fda202b44eab172455a852bc01.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Everybody Learns Differently - Application Security Weekly #67</title><link>https://www.spreaker.com/user/securityweekly/everybody-learns-differently-application_1</link><description><![CDATA[This week, Mike Shema, John Kinsella, & Matt Alderman discuss security training for Devs! In the Application Security News, GKE improves authentication with Workload Identity, AWS reinforce reveals traffic tools and security solutions that improve support for DevOps, Brief history of Trusted Execution Environments, From the Enterprise's Project: How to Explain Service Mesh in Plain English, and Developers and Security Teams Under Pressure to Collaborate!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode67" rel="noopener">https://wiki.securityweekly.com/ASW_Episode67</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">2a3f5597908c400f9fdc2b84b9c71c64</guid><pubDate>Tue, 02 Jul 2019 16:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18443335/asw67_0.mp3" length="61880692" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Mike Shema, John Kinsella, &amp; Matt Alderman discuss security training for Devs! In the Application Security News, GKE improves authentication with Workload Identity, AWS reinforce reveals traffic tools and security solutions that improve...</itunes:subtitle><itunes:summary><![CDATA[This week, Mike Shema, John Kinsella, & Matt Alderman discuss security training for Devs! In the Application Security News, GKE improves authentication with Workload Identity, AWS reinforce reveals traffic tools and security solutions that improve support for DevOps, Brief history of Trusted Execution Environments, From the Enterprise's Project: How to Explain Service Mesh in Plain English, and Developers and Security Teams Under Pressure to Collaborate!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode67" rel="noopener">https://wiki.securityweekly.com/ASW_Episode67</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3868</itunes:duration><itunes:keywords>67,applicationnews,applications,applicationsecurityweekly,appsec,asw,aws,devops,episode67,gke,johnkinsella,mattalderman,mikeshema,podcast,s3buckets,security,securityweekly,topic,workloadidentity</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9308c446f3f357bd158eff22512fa213.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Breaking Down the Walls - Application Security Weekly #66</title><link>https://www.spreaker.com/user/securityweekly/breaking-down-the-walls-application-secu_1</link><description><![CDATA[This week, Matt, John, and Mike discuss a guide to API Security! They also discuss Public vs. Private APIs, and if the best practice should be segregation of the two! In the Application Security News, Mozilla pushes a patch onto an Array, Netflix shares a stream of patches, Breach to bankruptcy for healthcare company, Osquery becomes a foundational tool, Avoiding DevOps dangers, and Assigning DevOps directions!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode66" rel="noopener">https://wiki.securityweekly.com/ASW_Episode66</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">5f29cc02b80b492ca727b1d4a1ea6847</guid><pubDate>Tue, 25 Jun 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18371749/asw66_0.mp3" length="63326412" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Matt, John, and Mike discuss a guide to API Security! They also discuss Public vs. Private APIs, and if the best practice should be segregation of the two! In the Application Security News, Mozilla pushes a patch onto an Array, Netflix...</itunes:subtitle><itunes:summary><![CDATA[This week, Matt, John, and Mike discuss a guide to API Security! They also discuss Public vs. Private APIs, and if the best practice should be segregation of the two! In the Application Security News, Mozilla pushes a patch onto an Array, Netflix shares a stream of patches, Breach to bankruptcy for healthcare company, Osquery becomes a foundational tool, Avoiding DevOps dangers, and Assigning DevOps directions!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode66" rel="noopener">https://wiki.securityweekly.com/ASW_Episode66</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3958</itunes:duration><itunes:keywords>66,apisecurity,applicationsecurityweekly,appsec,asw,bankruptcy,breach,devops,dontignoreapis,healthcare,mozilla,netflix,osquery,securityweekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/34f05cc848cfde42c71594df1abe411e.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Buzzword Bingo - Application Security Weekly #65</title><link>https://www.spreaker.com/user/securityweekly/buzzword-bingo-application-security-week_1</link><description><![CDATA[This week, we interview Shannon Lietz, the Director Information Security at Intuit, to talk about DevOps! In the Application Security News, there's no escape that will save you..., the privilege of running a Chrome extension, and Four practices towards DevSecOps!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode65" rel="noopener">https://wiki.securityweekly.com/ASW_Episode65</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></description><guid isPermaLink="false">b0235cb41b854f1c97ec3a6d7ffce7cf</guid><pubDate>Tue, 18 Jun 2019 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18311438/asw65_0.mp3" length="66871542" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we interview Shannon Lietz, the Director Information Security at Intuit, to talk about DevOps! In the Application Security News, there's no escape that will save you..., the privilege of running a Chrome extension, and Four practices...</itunes:subtitle><itunes:summary><![CDATA[This week, we interview Shannon Lietz, the Director Information Security at Intuit, to talk about DevOps! In the Application Security News, there's no escape that will save you..., the privilege of running a Chrome extension, and Four practices towards DevSecOps!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode65" rel="noopener">https://wiki.securityweekly.com/ASW_Episode65</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></itunes:summary><itunes:duration>4180</itunes:duration><itunes:keywords>65,applications,applicationsecurityweekly,appsec,asw,breaches,bugs,chromeextension,devops,devsecops,intuit,noescape,podcast,security,securityweekly,shannonlietz,tipsandtricks,toolsandtips</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/604792217699aba6029d11a319b04d59.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Everyone Looks Smart - Application Security Weekly #64</title><link>https://www.spreaker.com/user/securityweekly/everyone-looks-smart-application-securit_1</link><description><![CDATA[This week, we welcome Tanya Janca, also known as SheHacksPurple, a senior cloud advocate for Microsoft, specializing in application, cloud security, and more! Tanya is joining us on the show to talk about DevSecOps and Securing Software Supply Chains! In the Application Security News, "Waiting for the worms to come." -- Pink Floyd and RDP's CVE-2019-0708. Even the NSA warns about the population of exposed systems, A patch commands attention for mail servers, In macOS Catalina and iOS 13, Apples finds a way to find devices and not lose privacy, iOS App Transport Security has strong benefits, but weak adoption, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode64" rel="noopener">https://wiki.securityweekly.com/ASW_Episode64</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">27e593223ef441c392cb349d934d0a76</guid><pubDate>Tue, 11 Jun 2019 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18242951/asw64_0.mp3" length="67136528" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Tanya Janca, also known as SheHacksPurple, a senior cloud advocate for Microsoft, specializing in application, cloud security, and more! Tanya is joining us on the show to talk about DevSecOps and Securing Software Supply Chains!...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Tanya Janca, also known as SheHacksPurple, a senior cloud advocate for Microsoft, specializing in application, cloud security, and more! Tanya is joining us on the show to talk about DevSecOps and Securing Software Supply Chains! In the Application Security News, "Waiting for the worms to come." -- Pink Floyd and RDP's CVE-2019-0708. Even the NSA warns about the population of exposed systems, A patch commands attention for mail servers, In macOS Catalina and iOS 13, Apples finds a way to find devices and not lose privacy, iOS App Transport Security has strong benefits, but weak adoption, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode64" rel="noopener">https://wiki.securityweekly.com/ASW_Episode64</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4196</itunes:duration><itunes:keywords>64,app,applicationsecurityweekly,asw,cloud,cloudsecurity,cve,devops,devsecops,ios,microsoft,nsa,openshift,pinkfloyd,podcast,rdp,secops,security,securityweekly,worms</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f5ce7abc7a62e81492b696d2c203b89e.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Rainbows - Application Security Weekly #63</title><link>https://www.spreaker.com/user/securityweekly/rainbows-application-security-weekly-63_1</link><description><![CDATA[This week, Mike and John delve into some DevSecOps topics. They discuss good design patterns that emerged from cloud native environments, Kubernetes and containers, and building blocks of unique services in the AppSec world. In the Application Security News, Duo reveals a path from a Docker container to its host, Google fumbles some password functionality, GitHub makes dependency tracking more dependable, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode63" rel="noopener">https://wiki.securityweekly.com/ASW_Episode63</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">8ec78b7d7410492c9e14ccb477256730</guid><pubDate>Tue, 04 Jun 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18167186/asw63_0.mp3" length="55342138" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Mike and John delve into some DevSecOps topics. They discuss good design patterns that emerged from cloud native environments, Kubernetes and containers, and building blocks of unique services in the AppSec world. In the Application...</itunes:subtitle><itunes:summary><![CDATA[This week, Mike and John delve into some DevSecOps topics. They discuss good design patterns that emerged from cloud native environments, Kubernetes and containers, and building blocks of unique services in the AppSec world. In the Application Security News, Duo reveals a path from a Docker container to its host, Google fumbles some password functionality, GitHub makes dependency tracking more dependable, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode63" rel="noopener">https://wiki.securityweekly.com/ASW_Episode63</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3459</itunes:duration><itunes:keywords>63,applicationsecurityweekly,appsec,asw,autodesk,cloud,devsecops,docker,facebook,github,johnkinsella,kubernetes,mikeshema,podcast,razzer,repo,security</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/8fc82d09f770cf04608698313b2ae0ac.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Third Degree Sunburns - Application Security Weekly #62</title><link>https://www.spreaker.com/user/securityweekly/third-degree-sunburns-application-securi_1</link><description><![CDATA[This week, we welcome Cody Wood, AppSec Product Support Engineer at Signal Sciences! In the AppSec News, Cisco Expressway goes off path and a Cisco IOS XE vuln goes for emojis, More erosion of CPU data boundaries, RDP patches a pre-auth problem and even resuscitates a patch process for XP, Microsoft's Attack Surface Analyzer gives DevSecOps teams more data, Clear design goals for better privacy and security, and Google Security blogs that basics are best!   To get involved with Signal Sciences, visit: <a href="https://securityweekly.com/signalsciences" rel="noopener">https://securityweekly.com/signalsciences</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode62" rel="noopener">https://wiki.securityweekly.com/ASW_Episode62</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">ff93a5eba0c54eaa977dd44d974774b1</guid><pubDate>Tue, 21 May 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/18031992/asw62_0.mp3" length="60630576" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Cody Wood, AppSec Product Support Engineer at Signal Sciences! In the AppSec News, Cisco Expressway goes off path and a Cisco IOS XE vuln goes for emojis, More erosion of CPU data boundaries, RDP patches a pre-auth problem and...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Cody Wood, AppSec Product Support Engineer at Signal Sciences! In the AppSec News, Cisco Expressway goes off path and a Cisco IOS XE vuln goes for emojis, More erosion of CPU data boundaries, RDP patches a pre-auth problem and even resuscitates a patch process for XP, Microsoft's Attack Surface Analyzer gives DevSecOps teams more data, Clear design goals for better privacy and security, and Google Security blogs that basics are best!   To get involved with Signal Sciences, visit: <a href="https://securityweekly.com/signalsciences" rel="noopener">https://securityweekly.com/signalsciences</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode62" rel="noopener">https://wiki.securityweekly.com/ASW_Episode62</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3790</itunes:duration><itunes:keywords>62,applicationnews,applicationsecurityweekly,appsec,cisco,codywood,cpu,devops,devsecops,interview,johnkinsella,microsoft,mikeshema,news,podcast,secops,security,signalsciences,square,surfaceanalyzer</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/62938e1af8e6b45929a2a1a0b784f512.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Right Direction - Application Security Weekly #61</title><link>https://www.spreaker.com/user/securityweekly/the-right-direction-application-security_1</link><description><![CDATA[This week, Derek Weeks joins us to talk about DevSecOps and Securing Software Supply Chains! Derek is the VP and DevOps Advocate at Sonatype! In the Application News, Chrome constrains the cookies and Edge pushes privacy, Windows builds a sandbox for Linux, Android Q for more quarantined code with more LLVM features, Steve Singh stepping down as Docker CEO, and Verizon releases its 2019 DBIR!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode61" rel="noopener">https://wiki.securityweekly.com/ASW_Episode61</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">710f69e5be3c44cbaff91247ecb69924</guid><pubDate>Tue, 14 May 2019 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17930061/asw61_0.mp3" length="68214445" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Derek Weeks joins us to talk about DevSecOps and Securing Software Supply Chains! Derek is the VP and DevOps Advocate at Sonatype! In the Application News, Chrome constrains the cookies and Edge pushes privacy, Windows builds a sandbox for...</itunes:subtitle><itunes:summary><![CDATA[This week, Derek Weeks joins us to talk about DevSecOps and Securing Software Supply Chains! Derek is the VP and DevOps Advocate at Sonatype! In the Application News, Chrome constrains the cookies and Edge pushes privacy, Windows builds a sandbox for Linux, Android Q for more quarantined code with more LLVM features, Steve Singh stepping down as Docker CEO, and Verizon releases its 2019 DBIR!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode61" rel="noopener">https://wiki.securityweekly.com/ASW_Episode61</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4264</itunes:duration><itunes:keywords>61,applicationsecurityweekly,appsec,asw,chrome,dbir,devops,devsecops,docker,edge,hacking,interview,linux,llvm,mattalderman,secops,securityweekly,sonatype,square,vp</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f0dbf9ead86a94cc01680a222c4e4723.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Defense In Depth - Application Security Weekly #60</title><link>https://www.spreaker.com/user/securityweekly/defense-in-depth-application-security-we_1</link><description><![CDATA[This week, we welcome Sven Morgenroth, Security Researcher at Netsparker to talk about securing our applications, web applications, and how we can make it easier to build applications! In the AppSec News, Firefox gives more scrutiny to add-ons but Firefox also forgot to give more scrutiny to a cert, Path traversals trampled by ransomware, Secure Software Design: The Next Frontier In Cybersecurity, Trust the Stack, Not the People, VRT adds a CAN, and MDM, parental controls, and security!   To learn more about Netsparker, visit: <a href="https://securityweekly.com/netsparker" rel="noopener">https://securityweekly.com/netsparker</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode60" rel="noopener">https://wiki.securityweekly.com/ASW_Episode60</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">7c5e2bb16f494e5d88bf82bc6d8c58e0</guid><pubDate>Tue, 07 May 2019 16:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17860481/asw60.mp3" length="67066729" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Sven Morgenroth, Security Researcher at Netsparker to talk about securing our applications, web applications, and how we can make it easier to build applications! In the AppSec News, Firefox gives more scrutiny to add-ons but...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Sven Morgenroth, Security Researcher at Netsparker to talk about securing our applications, web applications, and how we can make it easier to build applications! In the AppSec News, Firefox gives more scrutiny to add-ons but Firefox also forgot to give more scrutiny to a cert, Path traversals trampled by ransomware, Secure Software Design: The Next Frontier In Cybersecurity, Trust the Stack, Not the People, VRT adds a CAN, and MDM, parental controls, and security!   To learn more about Netsparker, visit: <a href="https://securityweekly.com/netsparker" rel="noopener">https://securityweekly.com/netsparker</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode60" rel="noopener">https://wiki.securityweekly.com/ASW_Episode60</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4192</itunes:duration><itunes:keywords>10,60,addons,application,applications,apps,asw,can,interview,john,matt,mdm,mike,news,podcast,secure,security,the,top,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/edacf3aff00c129e9f1bb6708e2a09c9.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Other Side - Application Security Weekly #59</title><link>https://www.spreaker.com/user/securityweekly/the-other-side-application-security-week_1</link><description><![CDATA[This week, we welcome Larry Maccherone, Senior Director of Comcast, to talk about the world of SecOps vs. DevSecOps! In the Application Security News, Software update gums up fingerprints, a counterproductive security practice expires thanks to well-considered guidelines, Docker Hub breach response, a path to hacking Ruby Gems, 5 Security Challenges to API Protection, and more!    Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode59" rel="noopener">https://wiki.securityweekly.com/ASW_Episode59</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">bce8c9bfc06f49529fd23d7f6fd8325d</guid><pubDate>Tue, 30 Apr 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17791523/asw59.mp3" length="62647229" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Larry Maccherone, Senior Director of Comcast, to talk about the world of SecOps vs. DevSecOps! In the Application Security News, Software update gums up fingerprints, a counterproductive security practice expires thanks to...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Larry Maccherone, Senior Director of Comcast, to talk about the world of SecOps vs. DevSecOps! In the Application Security News, Software update gums up fingerprints, a counterproductive security practice expires thanks to well-considered guidelines, Docker Hub breach response, a path to hacking Ruby Gems, 5 Security Challenges to API Protection, and more!    Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode59" rel="noopener">https://wiki.securityweekly.com/ASW_Episode59</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3916</itunes:duration><itunes:keywords>59,alderman,appliation,asw,comcast,john,kinsella,larry,maccherone,matt,mike,podcast,security,shema,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/e8c86d00d429dd4f21bbb7fc2129fc8e.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Hacking for Lazy People - Application Security Weekly #58</title><link>https://www.spreaker.com/user/securityweekly/hacking-for-lazy-people-application-secu_1</link><description><![CDATA[This week, we welcome Thomas Hatch, the creator of the Salt open source software project, and is the CTO of SaltStack, the company behind Salt! In the Application Security News, Breach at IT outsourcer Wipro, SCP serves the file it wants, Confluence Path traverses to RCE, another Local PrivEsc on Windows, easier sandboxing for C and C++ APIs, and Computer Science plus Ethics!   To learn more about SaltStack, visit: <a href="https://securityweekly.com/saltstack" rel="noopener">https://securityweekly.com/saltstack</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode58" rel="noopener">https://wiki.securityweekly.com/ASW_Episode58</a>   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></description><guid isPermaLink="false">a7db7b26f878482c801fa7c55aa82a44</guid><pubDate>Tue, 23 Apr 2019 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17726483/asw58_0.mp3" length="68499493" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Thomas Hatch, the creator of the Salt open source software project, and is the CTO of SaltStack, the company behind Salt! In the Application Security News, Breach at IT outsourcer Wipro, SCP serves the file it wants, Confluence...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Thomas Hatch, the creator of the Salt open source software project, and is the CTO of SaltStack, the company behind Salt! In the Application Security News, Breach at IT outsourcer Wipro, SCP serves the file it wants, Confluence Path traverses to RCE, another Local PrivEsc on Windows, easier sandboxing for C and C++ APIs, and Computer Science plus Ethics!   To learn more about SaltStack, visit: <a href="https://securityweekly.com/saltstack" rel="noopener">https://securityweekly.com/saltstack</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode58" rel="noopener">https://wiki.securityweekly.com/ASW_Episode58</a>   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></itunes:summary><itunes:duration>4282</itunes:duration><itunes:keywords>58,applicationsecurityweekly,appsec,asw,cto,devops,johnkinsella,malware,mattalderman,mikeshema,podcast,saltprotection,saltstack,sandboxing,security,securityweekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/f059dce568d3dd1d41f5adfe600e1165.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Containers and Kubernetes - Application Security Weekly #57</title><link>https://www.spreaker.com/user/securityweekly/containers-and-kubernetes-application-se_1</link><description><![CDATA[This last week was pretty busy with announcements and presentations from the Google Next Conference. In 2018 they previewed some security tools and this year many of them are now GA along with a lot of other developer-focused services. In the news, 3D fingerprints and unlocking Android, Ticking off another command injection, Alexa, audio, and annotations, STS no longer just for HTTP, and Hardenize goes beyond TLS. Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode57" rel="noopener">https://wiki.securityweekly.com/ASW_Episode57</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></description><guid isPermaLink="false">49fc4ebb4dbc49f7be0ee47c6cb0d697</guid><pubDate>Tue, 16 Apr 2019 15:00:19 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17657434/asw_57_final.mp3" length="59661746" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This last week was pretty busy with announcements and presentations from the Google Next Conference. In 2018 they previewed some security tools and this year many of them are now GA along with a lot of other developer-focused services. In the news, 3D...</itunes:subtitle><itunes:summary><![CDATA[This last week was pretty busy with announcements and presentations from the Google Next Conference. In 2018 they previewed some security tools and this year many of them are now GA along with a lot of other developer-focused services. In the news, 3D fingerprints and unlocking Android, Ticking off another command injection, Alexa, audio, and annotations, STS no longer just for HTTP, and Hardenize goes beyond TLS. Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode57" rel="noopener">https://wiki.securityweekly.com/ASW_Episode57</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></itunes:summary><itunes:duration>3729</itunes:duration><itunes:keywords>2018,3d,57,alexa,android,application,applicationsecurityweekly,appsec,asw,containers,docker,ga,http,kubernetes,mattalderman,news,securitynews,sts,tls,topic</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a1c49aae3dcbb84e9e599a1508432a9f.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Underlying Capabilities - Application Security Weekly #56</title><link>https://www.spreaker.com/user/securityweekly/underlying-capabilities-application-secu</link><description><![CDATA[This week, we welcome Loris Degioanni from Sysdig to discuss their open source container native runtime security project called Falco! In the News segment, The Matrix turns 20, Containers are Weakest Security Leak Again, The Evolution of Application Security in the Serverless World, and more! To learn more about Sysdig, visit: <a href="https://securityweekly.com/sysdig" rel="noopener">https://securityweekly.com/sysdig</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode56" rel="noopener">https://wiki.securityweekly.com/ASW_Episode56</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></description><guid isPermaLink="false">5ee3986f2afa42adb100cc51b48fb63f</guid><pubDate>Tue, 09 Apr 2019 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17578833/asw56_1.mp3" length="76842794" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Loris Degioanni from Sysdig to discuss their open source container native runtime security project called Falco! In the News segment, The Matrix turns 20, Containers are Weakest Security Leak Again, The Evolution of Application...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Loris Degioanni from Sysdig to discuss their open source container native runtime security project called Falco! In the News segment, The Matrix turns 20, Containers are Weakest Security Leak Again, The Evolution of Application Security in the Serverless World, and more! To learn more about Sysdig, visit: <a href="https://securityweekly.com/sysdig" rel="noopener">https://securityweekly.com/sysdig</a> Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode56" rel="noopener">https://wiki.securityweekly.com/ASW_Episode56</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></itunes:summary><itunes:duration>4803</itunes:duration><itunes:keywords>2019,56,applicationsecurityweekly,appsec,arm,asw,containers,devops,docker,evolution,mattalderman,news,secops,selfie,serverless,thematrix</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b0425268991860a7c5d80f7ee00db333.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Until Next Time - Application Security Weekly #55</title><link>https://www.spreaker.com/user/securityweekly/until-next-time-application-security-wee_1</link><description><![CDATA[This week, we welcome Mike Shema, Product Security Lead of Square! Mike joins us on the show to talk about where the wins and challenges are in AppSec! In the Application Security News, XSS Vulnerability in Abandoned Cart Plugin Leads to WordPress Site Takeover, The RedMonk Programming Language Rankings: January 2019, I Deleted Facebook Last Year; Here's What Changed (and What Didn't), CommitStrip: Over-excited, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode55" rel="noopener">https://wiki.securityweekly.com/ASW_Episode55</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">d82be09f01bc4867a423b66d96391495</guid><pubDate>Thu, 28 Mar 2019 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17467559/asw55_0.mp3" length="66019741" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Mike Shema, Product Security Lead of Square! Mike joins us on the show to talk about where the wins and challenges are in AppSec! In the Application Security News, XSS Vulnerability in Abandoned Cart Plugin Leads to WordPress...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Mike Shema, Product Security Lead of Square! Mike joins us on the show to talk about where the wins and challenges are in AppSec! In the Application Security News, XSS Vulnerability in Abandoned Cart Plugin Leads to WordPress Site Takeover, The RedMonk Programming Language Rankings: January 2019, I Deleted Facebook Last Year; Here's What Changed (and What Didn't), CommitStrip: Over-excited, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode55" rel="noopener">https://wiki.securityweekly.com/ASW_Episode55</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4127</itunes:duration><itunes:keywords>55,andmore,applications,applicationsecurityweekly,appsec,breaches,bugs,devops,facebook,language,mattalderman,news,paulasadoorian,podcast,redmonk,secops,security,square,vulnerabilities,wordpress</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/594a5348a211de44a52602dd4198f142.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>A Bittersweet Ending - Application Security Weekly #54</title><link>https://www.spreaker.com/user/securityweekly/a-bittersweet-ending-application-securit_1</link><description><![CDATA[This week, we welcome Jamie Duncan, a recovering history major who has been at Red Hat for just over 7 years! Beginning with his role as a TAM, his focus has increasingly centered on the operations-oriented features of OpenShift, including the May 2018 publication of OpenShift In Action by Manning Publishing. Jamie has had this discussion with customers, OpenShift advocates, and technology fans on multiple continents to date. In the Application Security News, Owner of MAGA-Friendly Yelp Knockoff Threatens to Call FBI After Researcher Exposes Security Holes, Chinese Data Breach Exposes 'Breed Ready' Status Of Almost 2 Million Women, Dozens of companies leaked sensitive data thanks to misconfigured Box accounts, DARPA Is Building a $10 Million, Open Source, Secure Voting System, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode54" rel="noopener">https://wiki.securityweekly.com/ASW_Episode54</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">4aaf2724b8f14176832ad36b69c6532b</guid><pubDate>Wed, 20 Mar 2019 22:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17387554/asw54_0.mp3" length="60354305" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we welcome Jamie Duncan, a recovering history major who has been at Red Hat for just over 7 years! Beginning with his role as a TAM, his focus has increasingly centered on the operations-oriented features of OpenShift, including the May...</itunes:subtitle><itunes:summary><![CDATA[This week, we welcome Jamie Duncan, a recovering history major who has been at Red Hat for just over 7 years! Beginning with his role as a TAM, his focus has increasingly centered on the operations-oriented features of OpenShift, including the May 2018 publication of OpenShift In Action by Manning Publishing. Jamie has had this discussion with customers, OpenShift advocates, and technology fans on multiple continents to date. In the Application Security News, Owner of MAGA-Friendly Yelp Knockoff Threatens to Call FBI After Researcher Exposes Security Holes, Chinese Data Breach Exposes 'Breed Ready' Status Of Almost 2 Million Women, Dozens of companies leaked sensitive data thanks to misconfigured Box accounts, DARPA Is Building a $10 Million, Open Source, Secure Voting System, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode54" rel="noopener">https://wiki.securityweekly.com/ASW_Episode54</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3773</itunes:duration><itunes:keywords>2019,54,applicationsecurityweekly,appsec,chinese,darpa,databreach,devops,discussion,fbi,interview,openshift,paulasadoorian,podcast,redhat,security,securityweekly,tam,troll,yelp</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a01625a122772771c40ee92de3cf2209.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Spot On - Application Security Weekly #53</title><link>https://www.spreaker.com/user/securityweekly/spot-on-application-security-weekly-53_1</link><description><![CDATA[This week, Keith and Paul discuss the structure and experiences of 2019's RSA Conference! In the Application Security News, WordPress accounted for 90 percent of all hacked CMS sites in 2018, Japanese police charge 13-year-old for sharing 'unclosable popup' prank online, Facebook exploit – Confirm website visitor identities, NSA's top policy advisor: It's time to start putting teeth in cyber deterrence, study shows programmers will take the easy way out and not implement proper password security, and the CommitStrip for the week on Why check for incognito mode?   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode53" rel="noopener">https://wiki.securityweekly.com/ASW_Episode53</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">1c1f0400c29c40e4b953120bece0e86f</guid><pubDate>Fri, 15 Mar 2019 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17335026/asw53_0.mp3" length="54953854" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul discuss the structure and experiences of 2019's RSA Conference! In the Application Security News, WordPress accounted for 90 percent of all hacked CMS sites in 2018, Japanese police charge 13-year-old for sharing 'unclosable...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul discuss the structure and experiences of 2019's RSA Conference! In the Application Security News, WordPress accounted for 90 percent of all hacked CMS sites in 2018, Japanese police charge 13-year-old for sharing 'unclosable popup' prank online, Facebook exploit – Confirm website visitor identities, NSA's top policy advisor: It's time to start putting teeth in cyber deterrence, study shows programmers will take the easy way out and not implement proper password security, and the CommitStrip for the week on Why check for incognito mode?   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode53" rel="noopener">https://wiki.securityweekly.com/ASW_Episode53</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3435</itunes:duration><itunes:keywords>120,2019,53,application,applicationsecuritynews,applicationsecurityweekly,asw,cms,commitstrip,conversation,keithhoodlet,news,nsa,paulasadoorian,podcast,rsa19,rsac,rsaconference,security</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/49e6fb373353840e5224cd38c284e66c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Lose Weight - Application Security Weekly #52</title><link>https://www.spreaker.com/user/securityweekly/lose-weight-application-security-weekly-_1</link><description><![CDATA[This week, many websites threatened by highly critical code-execution bug in Drupal, UK parliament calls for antitrust, data abuse probe of Facebook, CommitStrip: Get rich quick, Google says the built-in microphone it never told Nest users about was 'never supposed to be a secret', and more! In our second segment, we welcome Matt Springfield, is the Founder of 12Feet, Inc., an information security consulting firm based in the Dallas area! Matt has more than 23 years of information security experience spanning operations, architecture and consulting with a focus on large scale retail and service provider environments!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode52" rel="noopener">https://wiki.securityweekly.com/ASW_Episode52</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">20c9a5ac2cf246a5917f703c6e56a1c6</guid><pubDate>Wed, 27 Feb 2019 22:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17176306/asw52_0.mp3" length="58345593" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, many websites threatened by highly critical code-execution bug in Drupal, UK parliament calls for antitrust, data abuse probe of Facebook, CommitStrip: Get rich quick, Google says the built-in microphone it never told Nest users about was...</itunes:subtitle><itunes:summary><![CDATA[This week, many websites threatened by highly critical code-execution bug in Drupal, UK parliament calls for antitrust, data abuse probe of Facebook, CommitStrip: Get rich quick, Google says the built-in microphone it never told Nest users about was 'never supposed to be a secret', and more! In our second segment, we welcome Matt Springfield, is the Founder of 12Feet, Inc., an information security consulting firm based in the Dallas area! Matt has more than 23 years of information security experience spanning operations, architecture and consulting with a focus on large scale retail and service provider environments!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode52" rel="noopener">https://wiki.securityweekly.com/ASW_Episode52</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3647</itunes:duration><itunes:keywords>52,abuse,antitrust,application,appsec,asw,breaches,bug,dallas,devops,drupal,facebook,inc,more,parliament,paulasadoorian,podcast,security,securityweekly,uk</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/d397c745390b2cea236fb2a07e28fb1c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Level of Trust - Application Security Weekly #51</title><link>https://www.spreaker.com/user/securityweekly/level-of-trust-application-security-week_1</link><description><![CDATA[This week, Matt and Paul interview Gurpreet S. Sachdeva, the Assistant Vice President of Technology for Altran! Gurpreet will be discussing "Integrating Security into DevOps"! In the Application Security News, A PNG Android Vulnerability, 620 million stolen accounts for sale on the dark web, how shifting security left speeds development, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode51" rel="noopener">https://wiki.securityweekly.com/ASW_Episode51</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">119f42bdf56143879f6c07d0f41a0314</guid><pubDate>Wed, 20 Feb 2019 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17094052/asw51_0.mp3" length="50105527" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Matt and Paul interview Gurpreet S. Sachdeva, the Assistant Vice President of Technology for Altran! Gurpreet will be discussing "Integrating Security into DevOps"! In the Application Security News, A PNG Android Vulnerability, 620 million...</itunes:subtitle><itunes:summary><![CDATA[This week, Matt and Paul interview Gurpreet S. Sachdeva, the Assistant Vice President of Technology for Altran! Gurpreet will be discussing "Integrating Security into DevOps"! In the Application Security News, A PNG Android Vulnerability, 620 million stolen accounts for sale on the dark web, how shifting security left speeds development, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode51" rel="noopener">https://wiki.securityweekly.com/ASW_Episode51</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3132</itunes:duration><itunes:keywords>51,altran,android,applicationsecurityweekly,asw,breach,darkweb,development,devops,devsecops,gurpreetssachdeva,hacking,interview,leftists,mattalderman,paulasadoorian,png,podcast,security,technology</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/ff8ae1f86910399fc050b3476edd2170.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The World Traveler - Application Security Weekly #50</title><link>https://www.spreaker.com/user/securityweekly/the-world-traveler-application-security-_1</link><description><![CDATA[This week, Paul is joined by Joff Thyer to interview Tim Eades, CEO of vArmour, to talk about basic flow of problem, solution, and value! In the Application Security News, many popular iPhone apps secretly record your screen without asking, MongoDB databases still being held for ransom, most of the Fortune 100 still use flawed software that led to the Equifax breach, and a Chrome extension with millions of users is now serving popup ads!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode50" rel="noopener">https://wiki.securityweekly.com/ASW_Episode50</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">4823952b1ff1451aab0d7d44b4f46966</guid><pubDate>Wed, 13 Feb 2019 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17030421/asw50_0.mp3" length="54749472" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Paul is joined by Joff Thyer to interview Tim Eades, CEO of vArmour, to talk about basic flow of problem, solution, and value! In the Application Security News, many popular iPhone apps secretly record your screen without asking, MongoDB...</itunes:subtitle><itunes:summary><![CDATA[This week, Paul is joined by Joff Thyer to interview Tim Eades, CEO of vArmour, to talk about basic flow of problem, solution, and value! In the Application Security News, many popular iPhone apps secretly record your screen without asking, MongoDB databases still being held for ransom, most of the Fortune 100 still use flawed software that led to the Equifax breach, and a Chrome extension with millions of users is now serving popup ads!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode50" rel="noopener">https://wiki.securityweekly.com/ASW_Episode50</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3422</itunes:duration><itunes:keywords>50,application,asw,breaches,chrome,devops,equifax,hacking,infosec,interview,iphone,mongodb,podcast,security,securitynews,securityweekly,solution,stories,tim,vulnerability</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/7eb19710cce2e492caaf1747f84132d2.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Golden Generation - Application Security Weekly #49</title><link>https://www.spreaker.com/user/securityweekly/the-golden-generation-application-securi_1</link><description><![CDATA[This week, Keith and Paul discuss the current state of privacy and software development! They discuss how Facebook pays teens to install VPN that spies on them, how Apple blocks Facebook from running its internal iOS apps, and more! In the Application Security News, Three UK customer details exposed in homepage blunder, Microsoft cloud services see global authentication outage, the age of surveillance capitalism, the rise of DevXOps, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode49" rel="noopener">https://wiki.securityweekly.com/ASW_Episode49</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">f394bc1bf2ee4cccbd31e6aa5c10876c</guid><pubDate>Wed, 06 Feb 2019 22:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16969970/asw49_0.mp3" length="58771075" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul discuss the current state of privacy and software development! They discuss how Facebook pays teens to install VPN that spies on them, how Apple blocks Facebook from running its internal iOS apps, and more! In the Application...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul discuss the current state of privacy and software development! They discuss how Facebook pays teens to install VPN that spies on them, how Apple blocks Facebook from running its internal iOS apps, and more! In the Application Security News, Three UK customer details exposed in homepage blunder, Microsoft cloud services see global authentication outage, the age of surveillance capitalism, the rise of DevXOps, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode49" rel="noopener">https://wiki.securityweekly.com/ASW_Episode49</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3674</itunes:duration><itunes:keywords>49,apple,applicationsecurityweekly,appsec,asw,capitalism,devsecops,facebook,global,google,hacking,ios,microsoft,microsoftcloud,news,paulasadoorian,securitynews,surveillance,uk,vpn</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c34338b20d8a639bc7067fd0d6d2d02b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Human Brain - Application Security Weekly #48</title><link>https://www.spreaker.com/user/securityweekly/the-human-brain-application-security-wee_1</link><description><![CDATA[This week, Keith and Paul start the show with the Application Security News, discussing concerns about WordPress’ new “White Screen of Death”, Google Chrome changes could ‘destroy’ ad-blockers, Mozilla is adding and ad-blocker to Firefox Focus 9.0, websites can steal browser data via extensions APIs, and a Fortnite security issue would have granted hackers access to accounts! In the second segment, Keith and Paul interview Jing Xie, Product Manager at Venafi, to talk about Static Analysis, Secure Code Signing, and more!!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode48" rel="noopener">https://wiki.securityweekly.com/ASW_Episode48</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">738ed1a747a8414c9107ec809834ba49</guid><pubDate>Wed, 30 Jan 2019 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/17012505/asw48_0.mp3" length="67406112" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul start the show with the Application Security News, discussing concerns about WordPress’ new “White Screen of Death”, Google Chrome changes could ‘destroy’ ad-blockers, Mozilla is adding and ad-blocker to Firefox Focus 9.0,...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul start the show with the Application Security News, discussing concerns about WordPress’ new “White Screen of Death”, Google Chrome changes could ‘destroy’ ad-blockers, Mozilla is adding and ad-blocker to Firefox Focus 9.0, websites can steal browser data via extensions APIs, and a Fortnite security issue would have granted hackers access to accounts! In the second segment, Keith and Paul interview Jing Xie, Product Manager at Venafi, to talk about Static Analysis, Secure Code Signing, and more!!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode48" rel="noopener">https://wiki.securityweekly.com/ASW_Episode48</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4213</itunes:duration><itunes:keywords>48,adblockers,andmore,api,applicationsecurityweekly,asw,breaches,bugs,chrome,episode48,firefoxfocus90,fornite,googlechromeupdates,interview,jingxie,mozilla,researcher,venafi,whitescreenofdeath,wordpress</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/1a6148806ee6877771b7ad600dc9962c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Different Checkpoints - Application Security Weekly #47</title><link>https://www.spreaker.com/user/securityweekly/different-checkpoints-application-securi_1</link><description><![CDATA[This week on Application Security Weekly, Matt Alderman takes the reigns and is joined by Co-Host James Wickett, who is the Head of Research at Signal Sciences! They talk about the human element of application security training and testing! In the Application Security News, Oracle patches 284 vulnerabilities, a bug in Twitter Android app exposed protected tweets, four tips for better API Security in 2019, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode47" rel="noopener">https://wiki.securityweekly.com/ASW_Episode47</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">87d7f0b5c1164de39f6cf78f62045b37</guid><pubDate>Wed, 23 Jan 2019 22:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16825286/asw47_0.mp3" length="50131441" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week on Application Security Weekly, Matt Alderman takes the reigns and is joined by Co-Host James Wickett, who is the Head of Research at Signal Sciences! They talk about the human element of application security training and testing! In the...</itunes:subtitle><itunes:summary><![CDATA[This week on Application Security Weekly, Matt Alderman takes the reigns and is joined by Co-Host James Wickett, who is the Head of Research at Signal Sciences! They talk about the human element of application security training and testing! In the Application Security News, Oracle patches 284 vulnerabilities, a bug in Twitter Android app exposed protected tweets, four tips for better API Security in 2019, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode47" rel="noopener">https://wiki.securityweekly.com/ASW_Episode47</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3134</itunes:duration><itunes:keywords>2019,47,andmore,androidapp,applications,asw,breaches,bugs,devops,hacknaked,mattalderman,news,oracle,secops,securityweekly,signalsciences,technicalsegment,tweets,twitter,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a3c6388431746dac4a3112a3e1462134.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Wind Beneath My Wings - Application Security Weekly #46</title><link>https://www.spreaker.com/user/securityweekly/the-wind-beneath-my-wings-application-se_1</link><description><![CDATA[This week, Keith and Paul interview Rey Bango, Security Advocate for Microsoft! Rey is focused on helping the community build secure systems & being a voice for researchers within MS! In the Application Security News, Another server security lapse at NASA exposed staff and project data, CRLF Injection Into PHP’s cURL Options, System Down: A systemd-journald exploit, GitHub now gives free users unlimited private repositories, Twitter is broken, Government shutdown: TLS certificates not renewed, many websites are down, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode46" rel="noopener">https://wiki.securityweekly.com/ASW_Episode46</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">b0f084d3ca7d496d8dc2c4c77507fba4</guid><pubDate>Wed, 16 Jan 2019 19:45:38 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16731244/asw46_2.mp3" length="53477204" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Rey Bango, Security Advocate for Microsoft! Rey is focused on helping the community build secure systems &amp; being a voice for researchers within MS! In the Application Security News, Another server security lapse at...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Rey Bango, Security Advocate for Microsoft! Rey is focused on helping the community build secure systems & being a voice for researchers within MS! In the Application Security News, Another server security lapse at NASA exposed staff and project data, CRLF Injection Into PHP’s cURL Options, System Down: A systemd-journald exploit, GitHub now gives free users unlimited private repositories, Twitter is broken, Government shutdown: TLS certificates not renewed, many websites are down, and much more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode46" rel="noopener">https://wiki.securityweekly.com/ASW_Episode46</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3343</itunes:duration><itunes:keywords>46,application,applicationsecurityweekly,appsec,asw,breaches,crlf,devops,devsecops,github,hacking,interview,keithhoodlet,microsoft,nasa,news,paulasadoorian,reybango,securitynews</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6fb3e4384e79df93fb25231bed66e2c8.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Iceberg Problem - Application Security Weekly #45</title><link>https://www.spreaker.com/user/securityweekly/the-iceberg-problem-application-security_1</link><description><![CDATA[This week, Keith and Paul interview Ken Johnson, Application Security Engineer at GitHub! Ken joins us to discuss approaching AppSec the right way, "running a scanner without context", getting the right context/importance of context, and how to figure what's real and what's legit! In the Application Security News, Wormable stored XSS on WordPress.org, a security lapse revealed private complaints from Silicon Valley employees, hackers hijack thousands of Chromecasts to warn of latest security bug, a linting tool for checking accessibility, speed, and security, host websites on GitHub, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode45" rel="noopener">https://wiki.securityweekly.com/ASW_Episode45</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">b3dec9ac4eaa4d308f027bcef379d0b4</guid><pubDate>Wed, 09 Jan 2019 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16667347/asw45_0.mp3" length="57647183" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Ken Johnson, Application Security Engineer at GitHub! Ken joins us to discuss approaching AppSec the right way, "running a scanner without context", getting the right context/importance of context, and how to figure...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Ken Johnson, Application Security Engineer at GitHub! Ken joins us to discuss approaching AppSec the right way, "running a scanner without context", getting the right context/importance of context, and how to figure what's real and what's legit! In the Application Security News, Wormable stored XSS on WordPress.org, a security lapse revealed private complaints from Silicon Valley employees, hackers hijack thousands of Chromecasts to warn of latest security bug, a linting tool for checking accessibility, speed, and security, host websites on GitHub, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode45" rel="noopener">https://wiki.securityweekly.com/ASW_Episode45</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3603</itunes:duration><itunes:keywords>10years,45,application,applicationsecurityweekly,approachingappsec,asw,bug,github,hijacking,importance,interview,keithhoodlet,kenjohnson,paulasadoorian,securityweekly,siliconvalley,speed,wordpress,worms,xss</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/76104bd6d2cdcf4baeda4f9b3ca10675.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>In Flames - Application Security Weekly #44</title><link>https://www.spreaker.com/user/securityweekly/in-flames-application-security-weekly-44_1</link><description><![CDATA[This week, Keith and Paul interview Harry Sverdlove, CTO and Founder of Edgewise! Harry joins us to discuss what Edgewise does in the AppSec world, segmentation, cloud migration, trying different architectures, and more! In the Application Security News, Facebook bug exposed private photos of 6.8 million users, thousands of Jenkins servers will let anonymous users become admins, Signal app can't include a backdoor for the Australian government, WordPress plugs bug that led to Google indexing some user passwords, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode44" rel="noopener">https://wiki.securityweekly.com/ASW_Episode44</a> To get involved with Edgewise, go to: <a href="https://www.edgewise.net/securityweekly" rel="noopener">https://www.edgewise.net/securityweekly</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter! Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a>   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></description><guid isPermaLink="false">568c6ac3300740c980b82f6cbc48c7ed</guid><pubDate>Wed, 19 Dec 2018 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16519496/asw44_0.mp3" length="58426259" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Harry Sverdlove, CTO and Founder of Edgewise! Harry joins us to discuss what Edgewise does in the AppSec world, segmentation, cloud migration, trying different architectures, and more! In the Application Security...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Harry Sverdlove, CTO and Founder of Edgewise! Harry joins us to discuss what Edgewise does in the AppSec world, segmentation, cloud migration, trying different architectures, and more! In the Application Security News, Facebook bug exposed private photos of 6.8 million users, thousands of Jenkins servers will let anonymous users become admins, Signal app can't include a backdoor for the Australian government, WordPress plugs bug that led to Google indexing some user passwords, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode44" rel="noopener">https://wiki.securityweekly.com/ASW_Episode44</a> To get involved with Edgewise, go to: <a href="https://www.edgewise.net/securityweekly" rel="noopener">https://www.edgewise.net/securityweekly</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter! Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a>   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></itunes:summary><itunes:duration>3652</itunes:duration><itunes:keywords>44,admins,application,appsec,asw,australian,bug,containers,devops,devsecops,dock,google,interview,jenkins,passwords,paulasadoorian,securityweekly,segmentation,signal,wordpress</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/54888613bcbe52e1d9636b4b1fbd070e.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Top Secret - Application Security Weekly #43</title><link>https://www.spreaker.com/user/securityweekly/top-secret-application-security-weekly-4_1</link><description><![CDATA[This week, Keith and Paul interview Chris Elgee, the Technical Engineer at Counter Hack Challenges! Chris joins Keith and Paul this week to talk about the Counter Hack Challenge, how it’s been working on the challenge vs. playing it, and more! In the Application Security News, Kubernetes instances are being hijacked worldwide, malicious sites abuse 11-year old Firefox bug that Mozilla failed to fix, Google is on a Witch Hunt for Internal Leakers, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode43" rel="noopener">https://wiki.securityweekly.com/ASW_Episode43</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">973bdde046854a43b0cc436c21882058</guid><pubDate>Wed, 12 Dec 2018 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16450399/asw43_0.mp3" length="48739219" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Chris Elgee, the Technical Engineer at Counter Hack Challenges! Chris joins Keith and Paul this week to talk about the Counter Hack Challenge, how it’s been working on the challenge vs. playing it, and more! In the...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Chris Elgee, the Technical Engineer at Counter Hack Challenges! Chris joins Keith and Paul this week to talk about the Counter Hack Challenge, how it’s been working on the challenge vs. playing it, and more! In the Application Security News, Kubernetes instances are being hijacked worldwide, malicious sites abuse 11-year old Firefox bug that Mozilla failed to fix, Google is on a Witch Hunt for Internal Leakers, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode43" rel="noopener">https://wiki.securityweekly.com/ASW_Episode43</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3047</itunes:duration><itunes:keywords>43,applicationsecurityweekly,asw,botnet,edskoudis,firefox,google,interview,keithhoodlet,kubernetes,mozilla,news,paulasadoorian,podcast,security,securityweekly,studiocode,witchhunt,wordpress,worldwide</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/1b08a5e746983e0402e9c30b33ae81c8.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Stuck In My Teeth - Application Security Weekly #42</title><link>https://www.spreaker.com/user/securityweekly/stuck-in-my-teeth-application-security-w_1</link><description><![CDATA[This week, Keith and Paul interview Aleksei Tiurin, Senior Security Researcher at Acunetix! Aleksei joins Keith and Paul this week for a Technical Segment on reverse proxies using WebLogic, Nginx, and Tomcat! In the Application Security News, hackers are opening SMB ports on routers to infect PC’s with NSA malware, bug detectives whip up smarter version of classic AFL fuzzer to hunt code vulnerabilities, malware & rogue users can spy on some apps' HTTPS crypto, exploiting developer infrastructure is insanely easy, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode42" rel="noopener">https://wiki.securityweekly.com/ASW_Episode42</a> To learn more about Acunetix, go to: <a href="http://www.acunetix.com/securityweekly" rel="noopener">www.acunetix.com/securityweekly</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">5770c67ac8794280ab1ed81cbaa16365</guid><pubDate>Wed, 05 Dec 2018 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16389697/asw42_0.mp3" length="58360221" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Aleksei Tiurin, Senior Security Researcher at Acunetix! Aleksei joins Keith and Paul this week for a Technical Segment on reverse proxies using WebLogic, Nginx, and Tomcat! In the Application Security News, hackers...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Aleksei Tiurin, Senior Security Researcher at Acunetix! Aleksei joins Keith and Paul this week for a Technical Segment on reverse proxies using WebLogic, Nginx, and Tomcat! In the Application Security News, hackers are opening SMB ports on routers to infect PC’s with NSA malware, bug detectives whip up smarter version of classic AFL fuzzer to hunt code vulnerabilities, malware & rogue users can spy on some apps' HTTPS crypto, exploiting developer infrastructure is insanely easy, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode42" rel="noopener">https://wiki.securityweekly.com/ASW_Episode42</a> To learn more about Acunetix, go to: <a href="http://www.acunetix.com/securityweekly" rel="noopener">www.acunetix.com/securityweekly</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3648</itunes:duration><itunes:keywords>42,amazon,app,appsec,asw,developer,devops,devsecops,firecracker,hacker,hacking,nginx,paulasadoorian,pc,podcast,security,securityweekly,smb,tomcat,weblogic</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b0046cc266c35cbf272d4c8712529dcf.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Good Ol' Days - Application Security Weekly #41</title><link>https://www.spreaker.com/user/securityweekly/good-ol-days-application-security-weekly_1</link><description><![CDATA[This week, Keith and Paul interview Brent Dukes! Brent is a hacker, and Director of Information Security for an established manufacturing company. He joins Keith and Paul this week to talk about WAF’s, Pentesting, Burp Suite, and more! In the Application Security News, Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers, second WordPress hacking campaign underway, USPS took a year to fix a vulnerability that exposed all 60 million users' data, this JavaScript can snoop on other Browser Tabs to work out what you're visiting, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode41" rel="noopener">https://wiki.securityweekly.com/ASW_Episode41</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></description><guid isPermaLink="false">47eeeb498b53430f87a6fac245491f55</guid><pubDate>Wed, 28 Nov 2018 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16329046/asw41_0.mp3" length="68445158" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Brent Dukes! Brent is a hacker, and Director of Information Security for an established manufacturing company. He joins Keith and Paul this week to talk about WAF’s, Pentesting, Burp Suite, and more! In the...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Brent Dukes! Brent is a hacker, and Director of Information Security for an established manufacturing company. He joins Keith and Paul this week to talk about WAF’s, Pentesting, Burp Suite, and more! In the Application Security News, Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers, second WordPress hacking campaign underway, USPS took a year to fix a vulnerability that exposed all 60 million users' data, this JavaScript can snoop on other Browser Tabs to work out what you're visiting, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode41" rel="noopener">https://wiki.securityweekly.com/ASW_Episode41</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a>]]></itunes:summary><itunes:duration>4278</itunes:duration><itunes:keywords>41,applicationsecurityweekly,burpsuite,developers,dirtycow,drupalgeddon,hackers,hacknaked,informationsecurity,infosec,interview,javascript,keithhoodlet,paulasadoorian,pentesting,podast,security,securityweekly,usps,waf</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/50fda089efd04ff58766c9f1b3144298.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Buffet Overflow - Application Security Weekly #40</title><link>https://www.spreaker.com/user/securityweekly/buffet-overflow-application-security-wee_1</link><description><![CDATA[This week, Keith and Paul interview John Kinsella, Vice President of Container Security at Qualys! John discusses Qualys’ Container Security, continuous discovery, and tracking for containers and images! In the Application Security News, Instagram leaks passwords to the public, Clickjacking on Google MyAccount Worth $7,500, James Wickett's thread on Open Source SAST options, an advanced search tool for sensitive information stored in GitHub repos, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode40" rel="noopener">https://wiki.securityweekly.com/ASW_Episode40</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">9a8fabdc0ce74b7a90f0e8df21fd14e4</guid><pubDate>Wed, 21 Nov 2018 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16275575/asw40_0.mp3" length="62342118" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview John Kinsella, Vice President of Container Security at Qualys! John discusses Qualys’ Container Security, continuous discovery, and tracking for containers and images! In the Application Security News, Instagram...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview John Kinsella, Vice President of Container Security at Qualys! John discusses Qualys’ Container Security, continuous discovery, and tracking for containers and images! In the Application Security News, Instagram leaks passwords to the public, Clickjacking on Google MyAccount Worth $7,500, James Wickett's thread on Open Source SAST options, an advanced search tool for sensitive information stored in GitHub repos, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode40" rel="noopener">https://wiki.securityweekly.com/ASW_Episode40</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3897</itunes:duration><itunes:keywords>40,applications,applicationsecurityweekly,appsec,clickjacking,containers,docker,github,infosec,instagram,interview,johnkinsella,keithhoodlet,kraken,layeredinsight,opensource,paulasadoorian,podcast,qualys,security</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/80befd4e1e869caa5b708a21cf5942cd.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Boston Accent - Application Security Weekly #39</title><link>https://www.spreaker.com/user/securityweekly/boston-accent-application-security-weekl_1</link><description><![CDATA[This week, Keith and Paul interview Brian Kelly, Head of Conjur Engineering at CyberArk! Brian focuses on creating products that add much-needed security and identity management to the landscape of DevOps tools and cloud systems. In the Application Security News, DJI Drone Vulnerability, Hackers are increasingly destroying logs to hide attacks, Adobe ColdFusion servers under attack from APT group, understanding Open Source Code use in your business, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode39" rel="noopener">https://wiki.securityweekly.com/ASW_Episode39</a> To learn more about Conjur, go to: <a href="http://www.conjur.org/asw" rel="noopener">www.conjur.org/asw</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">afdf8a9a85a345ef8c26210456bc9988</guid><pubDate>Wed, 14 Nov 2018 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16215625/asw39_2.mp3" length="59574811" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Brian Kelly, Head of Conjur Engineering at CyberArk! Brian focuses on creating products that add much-needed security and identity management to the landscape of DevOps tools and cloud systems. In the Application...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Brian Kelly, Head of Conjur Engineering at CyberArk! Brian focuses on creating products that add much-needed security and identity management to the landscape of DevOps tools and cloud systems. In the Application Security News, DJI Drone Vulnerability, Hackers are increasingly destroying logs to hide attacks, Adobe ColdFusion servers under attack from APT group, understanding Open Source Code use in your business, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode39" rel="noopener">https://wiki.securityweekly.com/ASW_Episode39</a> To learn more about Conjur, go to: <a href="http://www.conjur.org/asw" rel="noopener">www.conjur.org/asw</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3724</itunes:duration><itunes:keywords>39,adobe,applicationsecurity,apt,asw,briankelly,cloudsystems,coldfusion,conjur,cyberark,devopstools,engineering,hackers,interview,news,paulasadoorian,podcast,products,security,securityweekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/0c403e78717e19bb50bd23dafb35f530.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Ultimate Nirvana - Application Security Weekly #38</title><link>https://www.spreaker.com/user/securityweekly/ultimate-nirvana-application-security-we_1</link><description><![CDATA[This week, Keith and Paul interview Daniel Cuthbert, Global Head of Security Research for Banco Santander! In the Application Security News, a nasty DHCPv6 packet can Pwn vulnerable Linux Boxes, 'Stalkerware' website let anyone intercept texts of tens of thousands of people, twelve malicious Python libraries found and removed from PyPI, the U.S. Department of Defense Guide for "Detecting Agile BS", and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode38" rel="noopener">https://wiki.securityweekly.com/ASW_Episode38</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">4970c73809a849e8939cda65a89ebc6e</guid><pubDate>Wed, 07 Nov 2018 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16156532/asw38_0.mp3" length="49719751" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Daniel Cuthbert, Global Head of Security Research for Banco Santander! In the Application Security News, a nasty DHCPv6 packet can Pwn vulnerable Linux Boxes, 'Stalkerware' website let anyone intercept texts of tens...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Daniel Cuthbert, Global Head of Security Research for Banco Santander! In the Application Security News, a nasty DHCPv6 packet can Pwn vulnerable Linux Boxes, 'Stalkerware' website let anyone intercept texts of tens of thousands of people, twelve malicious Python libraries found and removed from PyPI, the U.S. Department of Defense Guide for "Detecting Agile BS", and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode38" rel="noopener">https://wiki.securityweekly.com/ASW_Episode38</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3108</itunes:duration><itunes:keywords>38,application,applicationsecurityweekly,asw,bancosantander,bs,defenseguide,detecting,detectingagile,dhcpv6,globalheadofsecurityresearch,interview,keithhoodlet,linuxboxes,packets,pwn,python,securitynews,stalkerware</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/2367858b8fd94076ec071a86b0829896.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Eggplant Volcanoes - Application Security Weekly #37</title><link>https://www.spreaker.com/user/securityweekly/eggplant-volcanoes-application-security-_1</link><description><![CDATA[This week, Keith and Paul interview Johnny Xmas, Director of Field Engineering at Kasada.io! In the Application Security News, Millions of passengers affected by Cathay Pacific Airline Hack, China has been hijacking the internet backbone of Western countries, how proficient are developers at fixing Application Security flaws, MicroTik Router Bug is as bad as it gets, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode37" rel="noopener">https://wiki.securityweekly.com/ASW_Episode37</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">873aa02c28514f9c8f616b6340f1ba15</guid><pubDate>Wed, 31 Oct 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16099881/asw37_0.mp3" length="66744065" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Johnny Xmas, Director of Field Engineering at Kasada.io! In the Application Security News, Millions of passengers affected by Cathay Pacific Airline Hack, China has been hijacking the internet backbone of Western...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Johnny Xmas, Director of Field Engineering at Kasada.io! In the Application Security News, Millions of passengers affected by Cathay Pacific Airline Hack, China has been hijacking the internet backbone of Western countries, how proficient are developers at fixing Application Security flaws, MicroTik Router Bug is as bad as it gets, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode37" rel="noopener">https://wiki.securityweekly.com/ASW_Episode37</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4172</itunes:duration><itunes:keywords>37,airlinehacks,applicationnews,applicationsecurityweekly,asw,breaches,bugs,china,hacker,johnnyxmas,kasadaio,keithhoodlet,microtikbug,paulasadoorian,paymentapps,penetrationtesting,securityweekly,vulnerabilities,wipingwordpress,wordpress</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/cf84918501234b7a4cafc9fcd97922a3.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Two Phones - Application Security Weekly #36</title><link>https://www.spreaker.com/user/securityweekly/two-phones-application-security-weekly-3_1</link><description><![CDATA[This week, Paul and April Wright discuss a jQuery Plugin that has been exploited for years is finally getting patched, a flaw in LibSSH leaves thousands of servers at risk, a remote code implantation flaw found in Medtronic Cardiac Programmers, hackers hiding Cryptocurrency malware in Adobe flash updates, how the government is finally rolling out 2 Factor Authentication for Federal Agency Domains, and how Disney is helping women from across their company to become Developers!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode36" rel="noopener">https://wiki.securityweekly.com/ASW_Episode36</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com" rel="noopener">https://www.facebook.com</a>/secweekly ]]></description><guid isPermaLink="false">42dab0a33700460ba2d3f886ec74b9d5</guid><pubDate>Wed, 24 Oct 2018 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/16044708/asw36_0.mp3" length="54568078" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Paul and April Wright discuss a jQuery Plugin that has been exploited for years is finally getting patched, a flaw in LibSSH leaves thousands of servers at risk, a remote code implantation flaw found in Medtronic Cardiac Programmers,...</itunes:subtitle><itunes:summary><![CDATA[This week, Paul and April Wright discuss a jQuery Plugin that has been exploited for years is finally getting patched, a flaw in LibSSH leaves thousands of servers at risk, a remote code implantation flaw found in Medtronic Cardiac Programmers, hackers hiding Cryptocurrency malware in Adobe flash updates, how the government is finally rolling out 2 Factor Authentication for Federal Agency Domains, and how Disney is helping women from across their company to become Developers!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode36" rel="noopener">https://wiki.securityweekly.com/ASW_Episode36</a> Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes! Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> Like us on Facebook: <a href="https://www.facebook.com" rel="noopener">https://www.facebook.com</a>/secweekly ]]></itunes:summary><itunes:duration>3411</itunes:duration><itunes:keywords>2fa,2factorauthentication,36,adobeflash,applicationsecurityweekly,appsec,asw,breaches,bugs,cryptocurrency,developers,devops,devsecops,disney,jquery,more,podcast,security,securityweekly,women</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/e65c93e785c7e8648ca373c4df0c68dd.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Git On That - Application Security Weekly #35</title><link>https://www.spreaker.com/user/securityweekly/git-on-that-application-security-weekly-_1</link><description><![CDATA[This week, Keith and Paul interview Garrett Gross, Senior Solutions Engineer at Rapid7! They talk about catching bugs earlier in the process of development, what can lead to certain successes in development, and more! In the Application Security News, Git Project patches Remote Code Execution Vulnerability, Google is shutting down Google+ after 500k accounts potentially affected by a data breach, Facebook wants people to Invite its cameras into their homes, GitHub introduces user blocking notifications, DevOps producing more insecure apps than ever, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode35" rel="noopener">https://wiki.securityweekly.com/ASW_Episode35</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">ec09b09d7bdf430c91a7ddf1dea13e47</guid><pubDate>Wed, 17 Oct 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15982906/asw35.mp3" length="58165452" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Garrett Gross, Senior Solutions Engineer at Rapid7! They talk about catching bugs earlier in the process of development, what can lead to certain successes in development, and more! In the Application Security News,...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Garrett Gross, Senior Solutions Engineer at Rapid7! They talk about catching bugs earlier in the process of development, what can lead to certain successes in development, and more! In the Application Security News, Git Project patches Remote Code Execution Vulnerability, Google is shutting down Google+ after 500k accounts potentially affected by a data breach, Facebook wants people to Invite its cameras into their homes, GitHub introduces user blocking notifications, DevOps producing more insecure apps than ever, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode35" rel="noopener">https://wiki.securityweekly.com/ASW_Episode35</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3636</itunes:duration><itunes:keywords>35,7,application,asw,change,climate,devops,engineer,facebook,garrett,google,gross,keith,paul,podcast,rapid,security,senior,solutions,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/306a37f99f7773703e1c802c32924090.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Bring Yoga Pants - Application Security Weekly #34</title><link>https://www.spreaker.com/user/securityweekly/bring-yoga-pants-application-security-we_1</link><description><![CDATA[This week, Keith and Paul talk about landing a job in Application Security! They discuss attending local meetups and conferences, practicing your coding skills, getting educated by World Class security researchers, doing your homework, and much more! In the Application Security News, Facebook discloses the loss of at least 50 millions access tokens, Google admits to allowing hundreds of companies to read your email, FireFox Monitor will alert you when your accounts have been Pwned, Microsoft releases MS-DOS v1.25 and v2.0 as Open Source, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode34" rel="noopener">https://wiki.securityweekly.com/ASW_Episode34</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">89a4ccd7c90f45ca84604cc05893e7d8</guid><pubDate>Wed, 03 Oct 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15867811/asw34.mp3" length="60477185" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul talk about landing a job in Application Security! They discuss attending local meetups and conferences, practicing your coding skills, getting educated by World Class security researchers, doing your homework, and much more!...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul talk about landing a job in Application Security! They discuss attending local meetups and conferences, practicing your coding skills, getting educated by World Class security researchers, doing your homework, and much more! In the Application Security News, Facebook discloses the loss of at least 50 millions access tokens, Google admits to allowing hundreds of companies to read your email, FireFox Monitor will alert you when your accounts have been Pwned, Microsoft releases MS-DOS v1.25 and v2.0 as Open Source, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode34" rel="noopener">https://wiki.securityweekly.com/ASW_Episode34</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3780</itunes:duration><itunes:keywords>34,application,asw,chrome,facebook,firefox,google,job,jobs,keith,microsoft,ms,open,paul,podcast,security,skills,source,training,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bef4d3ceb90af8eb2ca7b5ccc02f725b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Don't Hit Me Up - Application Security Weekly #33</title><link>https://www.spreaker.com/user/securityweekly/dont-hit-me-up-application-security-week_1</link><description><![CDATA[This week, Keith and special guest host April Wright interview Ron Gula, Founder of Tenable and Gula Tech Adventures! They discuss security in the upcoming elections, how to maintain separation of duties, attack simulation, and more! In the Application Security News, Hackers stole customer credit cards in Newegg data breach, John Hancock now requires monitoring bracelets to buy insurance, the man who broke Ticketmaster, new security settings available in iOS 12, State Department confirms data breach exposed employee data, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode33" rel="noopener">https://wiki.securityweekly.com/ASW_Episode33</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">a4548da3563f41dab7e4dbf88ab63fc6</guid><pubDate>Wed, 26 Sep 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15809764/asw33.mp3" length="73262556" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and special guest host April Wright interview Ron Gula, Founder of Tenable and Gula Tech Adventures! They discuss security in the upcoming elections, how to maintain separation of duties, attack simulation, and more! In the...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and special guest host April Wright interview Ron Gula, Founder of Tenable and Gula Tech Adventures! They discuss security in the upcoming elections, how to maintain separation of duties, attack simulation, and more! In the Application Security News, Hackers stole customer credit cards in Newegg data breach, John Hancock now requires monitoring bracelets to buy insurance, the man who broke Ticketmaster, new security settings available in iOS 12, State Department confirms data breach exposed employee data, and more!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode33" rel="noopener">https://wiki.securityweekly.com/ASW_Episode33</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4579</itunes:duration><itunes:keywords>adventures,apple,application,architect,asw,attack,elections,founder,google,hackers,hancock,john,keith,midterm,network,ron,security,tech,weekly,wright</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/7c7a9300cf8abdc92abf7219772d0fda.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Sharks With Laser Beams - Application Security Weekly #32</title><link>https://www.spreaker.com/user/securityweekly/sharks-with-laser-beams-application-secu</link><description><![CDATA[This week, Keith Hoodlet and Paul Asadoorian interview April Wright from ArchitectSecurity.org! Next, bugs, breaches, and more in the Application Security News! Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode32" rel="noopener">https://wiki.securityweekly.com/ASW_Episode32</a> Visit <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a>/asw for all the latest episodes!]]></description><guid isPermaLink="false">a1dfca036917467bb5aae5e3afdc7431</guid><pubDate>Wed, 19 Sep 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15752823/asw32_final.mp3" length="68825337" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith Hoodlet and Paul Asadoorian interview April Wright from ArchitectSecurity.org! Next, bugs, breaches, and more in the Application Security News! Full Show Notes: https://wiki.securityweekly.com/ASW_Episode32...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith Hoodlet and Paul Asadoorian interview April Wright from ArchitectSecurity.org! Next, bugs, breaches, and more in the Application Security News! Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode32" rel="noopener">https://wiki.securityweekly.com/ASW_Episode32</a> Visit <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a>/asw for all the latest episodes!]]></itunes:summary><itunes:duration>4302</itunes:duration><itunes:keywords>application,april,architectsecurityorg,asadoorian,documenting,hoodlet,interview,keith,paul,process,reward,security,systems,weekly,workplace,wright</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/13029a2acdc752f3a884848173e69369.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Around the World - Application Security Weekly #31</title><link>https://www.spreaker.com/user/securityweekly/around-the-world-application-security-we_1</link><description><![CDATA[This week, Keith and Paul interview Zane Lackey, Chief Security Officer and Founder of Signal Sciences! In the news, U.S. government releases Post-mortem on Equifax, Microsoft Windows Zero-Day found in Task Scheduler, British Airways breached via XSS, Windows subsystem Linux for Linux Distros, Bug Bounties and mental health, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode31" rel="noopener">https://wiki.securityweekly.com/ASW_Episode31</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">eddfc58556b0428b8bd41de561deea94</guid><pubDate>Wed, 12 Sep 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15698532/asw31compressed.mp3" length="73309785" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Zane Lackey, Chief Security Officer and Founder of Signal Sciences! In the news, U.S. government releases Post-mortem on Equifax, Microsoft Windows Zero-Day found in Task Scheduler, British Airways breached via XSS,...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Zane Lackey, Chief Security Officer and Founder of Signal Sciences! In the news, U.S. government releases Post-mortem on Equifax, Microsoft Windows Zero-Day found in Task Scheduler, British Airways breached via XSS, Windows subsystem Linux for Linux Distros, Bug Bounties and mental health, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode31" rel="noopener">https://wiki.securityweekly.com/ASW_Episode31</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4582</itunes:duration><itunes:keywords>application,asw,british,day,founder,government,job,keith,lackey,linux,paul,podcast,sciences,security,skills,training,us,weekly,windows,zero</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/3a9a023a217871efb6b3d6895f07e1e1.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>A Mixture of Spices - Application Security Weekly #30</title><link>https://www.spreaker.com/user/securityweekly/a-mixture-of-spices-application-security_1</link><description><![CDATA[This week, Keith and Paul discuss The Apache Struts2 RCE Vulnerability! In the news, Using Signal Sciences to defend against Apache Struts, PHP flaw puts WordPress sites at risk, Oracle will charge for Java starting in 2019, how Netflix does Failovers in 7 minutes flat, Burp Suite 2.0 Beta released, even anonymous coders leave fingerprints, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode30" rel="noopener">https://wiki.securityweekly.com/ASW_Episode30</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">f82446a66645487d8d3180734bba2c9f</guid><pubDate>Wed, 29 Aug 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15595822/asw30compressed.mp3" length="56990151" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul discuss The Apache Struts2 RCE Vulnerability! In the news, Using Signal Sciences to defend against Apache Struts, PHP flaw puts WordPress sites at risk, Oracle will charge for Java starting in 2019, how Netflix does Failovers...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul discuss The Apache Struts2 RCE Vulnerability! In the news, Using Signal Sciences to defend against Apache Struts, PHP flaw puts WordPress sites at risk, Oracle will charge for Java starting in 2019, how Netflix does Failovers in 7 minutes flat, Burp Suite 2.0 Beta released, even anonymous coders leave fingerprints, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode30" rel="noopener">https://wiki.securityweekly.com/ASW_Episode30</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3562</itunes:duration><itunes:keywords>30,apache,application,asw,burp,java,job,keith,netflix,oracle,paul,php,podcast,security,skills,suite,training,vulnerability,weekly,wordpress</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9920a9ffe472d9d592df9288064aaa98.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Always More to Learn - Application Security Weekly #29</title><link>https://www.spreaker.com/user/securityweekly/always-more-to-learn-application-securit_1</link><description><![CDATA[This week, Keith and Paul interview Tom McLaughlin, Founder of ServerlessOps! In the final segment, we air a Pre-Recorded segment with Paul and Matt Alderman, as they sat down at DEF CON to talk all things AppSec, vendors that were there, and companies they had briefings with from our pool cabana!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode29" rel="noopener">https://wiki.securityweekly.com/ASW_Episode29</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">b4f92136acfc4dd39707ebc8e7b3085c</guid><pubDate>Wed, 22 Aug 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15543809/asw29compressed.mp3" length="58921958" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Tom McLaughlin, Founder of ServerlessOps! In the final segment, we air a Pre-Recorded segment with Paul and Matt Alderman, as they sat down at DEF CON to talk all things AppSec, vendors that were there, and...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Tom McLaughlin, Founder of ServerlessOps! In the final segment, we air a Pre-Recorded segment with Paul and Matt Alderman, as they sat down at DEF CON to talk all things AppSec, vendors that were there, and companies they had briefings with from our pool cabana!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode29" rel="noopener">https://wiki.securityweekly.com/ASW_Episode29</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3683</itunes:duration><itunes:keywords>alderman,application,appsec,asw,blackhat,containers,cybersecurity,defcon,devops,job,keith,matt,mclaughlin,paul,podcast,security,skills,tom,training,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/839a0d6c22b89dfcaf7324b842e16c3a.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Don't Trust Them - Application Security Weekly #28</title><link>https://www.spreaker.com/user/securityweekly/dont-trust-them-application-security-wee_1</link><description><![CDATA[This week, Keith is joined by Dr. Doug White to discuss Secure Coding Practices! In the news, Comcast security flaws, Facebook plans to partner with banks, hacker finds ‘God Mode’ in x86 CPU’s, bypassing CSP using polyglot JPEGs, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode28" rel="noopener">https://wiki.securityweekly.com/ASW_Episode28</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">deec07373422439093c39d12dd95b065</guid><pubDate>Wed, 15 Aug 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15495133/asw28compressed.mp3" length="62619225" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith is joined by Dr. Doug White to discuss Secure Coding Practices! In the news, Comcast security flaws, Facebook plans to partner with banks, hacker finds ‘God Mode’ in x86 CPU’s, bypassing CSP using polyglot JPEGs, and more on this...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith is joined by Dr. Doug White to discuss Secure Coding Practices! In the news, Comcast security flaws, Facebook plans to partner with banks, hacker finds ‘God Mode’ in x86 CPU’s, bypassing CSP using polyglot JPEGs, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode28" rel="noopener">https://wiki.securityweekly.com/ASW_Episode28</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3914</itunes:duration><itunes:keywords>28,application,asw,coding,doug,facebook,god,hackers,job,keith,mode,paul,podcast,practices,secure,security,skills,training,weekly,white</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c4aa417bff2450aabcf13a9c23e88ef2.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>We Do Not Discriminate - Application Security Weekly #27</title><link>https://www.spreaker.com/user/securityweekly/we-do-not-discriminate-application-secur_1</link><description><![CDATA[This week, Keith and James Wickett interview Galen Hunt, Distinguished Engineer and Director at Microsoft! In the news, hackers automate the laundering of money via Clash of Clans, Epic Games sidesteps the Play Store with Fortnite for Android launch, the most exciting game, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode27" rel="noopener">https://wiki.securityweekly.com/ASW_Episode27</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">c64e310447814456b3b3aeb3b84cb0b7</guid><pubDate>Wed, 08 Aug 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15446334/asw27compressed.mp3" length="59877831" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and James Wickett interview Galen Hunt, Distinguished Engineer and Director at Microsoft! In the news, hackers automate the laundering of money via Clash of Clans, Epic Games sidesteps the Play Store with Fortnite for Android launch,...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and James Wickett interview Galen Hunt, Distinguished Engineer and Director at Microsoft! In the news, hackers automate the laundering of money via Clash of Clans, Epic Games sidesteps the Play Store with Fortnite for Android launch, the most exciting game, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode27" rel="noopener">https://wiki.securityweekly.com/ASW_Episode27</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3743</itunes:duration><itunes:keywords>27,application,asw,azure,containers,galen,hunt,james,job,keith,microsoft,paul,podcast,sciences,security,signal,skills,sphere,training,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a3632a006a9591ea8ae4ad19c26ab5a5.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Wu-Tang for Life - Application Security Weekly #26</title><link>https://www.spreaker.com/user/securityweekly/wu-tang-for-life-application-security-we_1</link><description><![CDATA[This week, Keith and Paul interview Jessica Rozhin, Security Engineer at Marqeta! In the news, New Spectre attack can remotely steal secrets, Microsoft discovers supply chain attack at unnamed maker of PDF Software, XSS filter in edge, and OWASP iGoat is a vulnerable swift application for iOS!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode26" rel="noopener">https://wiki.securityweekly.com/ASW_Episode26</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">9d67c286f9e54a4381fe2b7496ae9355</guid><pubDate>Wed, 01 Aug 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15395681/asw26compressed.mp3" length="58369834" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Jessica Rozhin, Security Engineer at Marqeta! In the news, New Spectre attack can remotely steal secrets, Microsoft discovers supply chain attack at unnamed maker of PDF Software, XSS filter in edge, and OWASP iGoat...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Jessica Rozhin, Security Engineer at Marqeta! In the news, New Spectre attack can remotely steal secrets, Microsoft discovers supply chain attack at unnamed maker of PDF Software, XSS filter in edge, and OWASP iGoat is a vulnerable swift application for iOS!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode26" rel="noopener">https://wiki.securityweekly.com/ASW_Episode26</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3649</itunes:duration><itunes:keywords>application,asw,containers,cybersecurity,devops,engineer,filter,jessica,job,keith,microsoft,paul,pdf,podcast,security,skills,software,spectre,training,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5f5c6830e2d271f316234881d07c61af.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>A Friendly Tip - Application Security Weekly #25</title><link>https://www.spreaker.com/user/securityweekly/a-friendly-tip-application-security-week_1</link><description><![CDATA[This week, Keith and Paul interview Joe Garcia, Global Corporate Solutions Engineer at CyberArk! In the news, Venmo caught publishing all transactions publicly, Oracle releases critical patches, Microsoft releases PowerShell Core for Linux, Health insurers are vacuuming up details about you, changing your screen to Grayscale can help fight phone addiction, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode25" rel="noopener">https://wiki.securityweekly.com/ASW_Episode25</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">e0130579c8a04fb9bba02c3f8c55a0a6</guid><pubDate>Wed, 25 Jul 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15325075/asw25compressed.mp3" length="67439549" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Joe Garcia, Global Corporate Solutions Engineer at CyberArk! In the news, Venmo caught publishing all transactions publicly, Oracle releases critical patches, Microsoft releases PowerShell Core for Linux, Health...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Joe Garcia, Global Corporate Solutions Engineer at CyberArk! In the news, Venmo caught publishing all transactions publicly, Oracle releases critical patches, Microsoft releases PowerShell Core for Linux, Health insurers are vacuuming up details about you, changing your screen to Grayscale can help fight phone addiction, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode25" rel="noopener">https://wiki.securityweekly.com/ASW_Episode25</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4215</itunes:duration><itunes:keywords>application,asw,containers,garcia,health,insurance,job,joe,keith,linux,microsoft,oracle,patches,paul,podcast,powershell,security,skills,training,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/d69edade53b2763bb769d6a40a1af54f.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The World of History - Application Security Weekly #24</title><link>https://www.spreaker.com/user/securityweekly/the-world-of-history-application-securit_1</link><description><![CDATA[This week, Keith and Paul discuss AppSec Solutions is a DevOps World! In the news, Compromised JavaScript Package Caught Stealing npm Credentials, remote iOS bugs, a $39 device that can defeat iOS USB Restricted mode, Broadcom buys CA Technologies, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode24" rel="noopener">https://wiki.securityweekly.com/ASW_Episode24</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">92f9067bb6d34eba82235651e81a781e</guid><pubDate>Wed, 18 Jul 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15277988/asw24compressed.mp3" length="62606269" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul discuss AppSec Solutions is a DevOps World! In the news, Compromised JavaScript Package Caught Stealing npm Credentials, remote iOS bugs, a $39 device that can defeat iOS USB Restricted mode, Broadcom buys CA Technologies,...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul discuss AppSec Solutions is a DevOps World! In the news, Compromised JavaScript Package Caught Stealing npm Credentials, remote iOS bugs, a $39 device that can defeat iOS USB Restricted mode, Broadcom buys CA Technologies, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode24" rel="noopener">https://wiki.securityweekly.com/ASW_Episode24</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3913</itunes:duration><itunes:keywords>24,application,asw,broadcom,bugs,ca,containers,javascript,job,keith,mode,paul,podcast,restricted,security,skills,technologies,training,usb,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b80b3fca6ec4f901d62de22e04fca65e.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Uncle Teeth - Application Security Weekly #23</title><link>https://www.spreaker.com/user/securityweekly/uncle-teeth-application-security-weekly-_1</link><description><![CDATA[This week, Keith and Paul talk The Hardest Problem in Application Security: Visibility. In the news, Google patches critical remote code execution bugs in Android OS, JavaScript API for face recognition in the browser with tensorflow.js, Social media apps are 'deliberately' addictive to users, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode23" rel="noopener">https://wiki.securityweekly.com/ASW_Episode23</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">b582730d2c9f409dab3ab2df0a53fc4c</guid><pubDate>Wed, 11 Jul 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15232992/asw23compressed.mp3" length="55759261" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul talk The Hardest Problem in Application Security: Visibility. In the news, Google patches critical remote code execution bugs in Android OS, JavaScript API for face recognition in the browser with tensorflow.js, Social media...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul talk The Hardest Problem in Application Security: Visibility. In the news, Google patches critical remote code execution bugs in Android OS, JavaScript API for face recognition in the browser with tensorflow.js, Social media apps are 'deliberately' addictive to users, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode23" rel="noopener">https://wiki.securityweekly.com/ASW_Episode23</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   Visit <a href="https://www.activecountermeasures/asw" rel="noopener">https://www.activecountermeasures/asw</a> to sign up for a demo or buy our AI Hunter!!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3485</itunes:duration><itunes:keywords>23,android,application,appsec,asadoorian,asw,containers,cybersecurity,devops,google,javascript,job,keith,os,paul,podcast,security,skills,training,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/527ac5c51a766fd17926f3fe4f4bd335.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>A Bunch Of Robots - Application Security Weekly #23</title><link>https://www.spreaker.com/user/securityweekly/a-bunch-of-robots-application-security-w_1</link><description><![CDATA[This week, Keith is joined by James Wickett from Signal Sciences to interview Thomas GX, CEO of Yelda and Founder of CommitStrip! In the news, Keith and James talk GitHub Hackers, Ticketmaster breach, Sniffing network traffic, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode22" rel="noopener">https://wiki.securityweekly.com/ASW_Episode22</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">ebfecf4aca30416dbc568bba2a99a3c4</guid><pubDate>Fri, 06 Jul 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15203139/asw22compressed.mp3" length="65442122" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith is joined by James Wickett from Signal Sciences to interview Thomas GX, CEO of Yelda and Founder of CommitStrip! In the news, Keith and James talk GitHub Hackers, Ticketmaster breach, Sniffing network traffic, and more on this episode...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith is joined by James Wickett from Signal Sciences to interview Thomas GX, CEO of Yelda and Founder of CommitStrip! In the news, Keith and James talk GitHub Hackers, Ticketmaster breach, Sniffing network traffic, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode22" rel="noopener">https://wiki.securityweekly.com/ASW_Episode22</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4091</itunes:duration><itunes:keywords>22,application,asw,developers,fisher,hack,hacking,james,keith,naked,network,paul,podcast,sciences,scientific,security,signal,thomas,traffic,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/59e6a5abd9107ef095eeeb60fe98c835.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Close The Pod Bay Doors - Application Security Weekly #21</title><link>https://www.spreaker.com/user/securityweekly/close-the-pod-bay-doors-application-secu_1</link><description><![CDATA[This week, Keith and Paul interview Dan Kuykendall, Sr. Director of Application Security Products at Rapid7! In the news, Flaw in macOS 'Quick Look' could reveal encrypted data, the man who was fired by a machine, Deploy to Azure with Docker and VS Code, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode21" rel="noopener">https://wiki.securityweekly.com/ASW_Episode21</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">8f351b7020ef4d03ba5550eb51b10d9f</guid><pubDate>Wed, 27 Jun 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15139771/asw21compressed.mp3" length="62596656" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Dan Kuykendall, Sr. Director of Application Security Products at Rapid7! In the news, Flaw in macOS 'Quick Look' could reveal encrypted data, the man who was fired by a machine, Deploy to Azure with Docker and VS...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Dan Kuykendall, Sr. Director of Application Security Products at Rapid7! In the news, Flaw in macOS 'Quick Look' could reveal encrypted data, the man who was fired by a machine, Deploy to Azure with Docker and VS Code, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode21" rel="noopener">https://wiki.securityweekly.com/ASW_Episode21</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3913</itunes:duration><itunes:keywords>21,7,application,asw,azure,code,containers,dan,director,keith,macos,of,paul,podcast,rapid,security,sr,to,vs,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/61aa13db9e2e60146a9686464301aa1a.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>It's All Working - Application Security Weekly #20</title><link>https://www.spreaker.com/user/securityweekly/its-all-working-application-security-wee_1</link><description><![CDATA[This week, we share our Pre-Recorded interview with Ron Gula, Founder of Gula Tech Adventures! In the news, Paul is joined by Business Security Weekly host Michael Santarcangelo to discuss Microsoft Windows remote kernel crash vulnerability, Cops are confident that iPhone hackers found a workaround to Apple's new security feature, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode20" rel="noopener">https://wiki.securityweekly.com/ASW_Episode20</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">aa0865dc434146c39f64132cdfc6056a</guid><pubDate>Wed, 20 Jun 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15090139/asw20compressed.mp3" length="93782262" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, we share our Pre-Recorded interview with Ron Gula, Founder of Gula Tech Adventures! In the news, Paul is joined by Business Security Weekly host Michael Santarcangelo to discuss Microsoft Windows remote kernel crash vulnerability, Cops are...</itunes:subtitle><itunes:summary><![CDATA[This week, we share our Pre-Recorded interview with Ron Gula, Founder of Gula Tech Adventures! In the news, Paul is joined by Business Security Weekly host Michael Santarcangelo to discuss Microsoft Windows remote kernel crash vulnerability, Cops are confident that iPhone hackers found a workaround to Apple's new security feature, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode20" rel="noopener">https://wiki.securityweekly.com/ASW_Episode20</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>5862</itunes:duration><itunes:keywords>20,adventures,apple,application,asw,crash,hack,iphone,keith,mac,michael,microsoft,naked,paul,podcast,ron,security,tech,weekly,windows</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/8eb1dfccf4998b8c5d02c89ce3d9ed50.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Off The Cuff - Application Security Weekly #19</title><link>https://www.spreaker.com/user/securityweekly/off-the-cuff-application-security-weekly</link><description><![CDATA[This week, Keith and Paul interview Peter Chestna, Director of Developer Engagement at Veracode! In the news, Windows 10 update April 2018 update breaks SMBv1, GitHub vs. GitLab, ThoughtWorks Technology Radar, DevOps brings value to security, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode19" rel="noopener">https://wiki.securityweekly.com/ASW_Episode19</a>   Visit <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a>/asw for all the latest episodes!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">746fd55ad33f457fab5bb9bd5c59a0d4</guid><pubDate>Wed, 13 Jun 2018 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/15042716/asw19compressed.mp3" length="64388447" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Peter Chestna, Director of Developer Engagement at Veracode! In the news, Windows 10 update April 2018 update breaks SMBv1, GitHub vs. GitLab, ThoughtWorks Technology Radar, DevOps brings value to security, and more...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Peter Chestna, Director of Developer Engagement at Veracode! In the news, Windows 10 update April 2018 update breaks SMBv1, GitHub vs. GitLab, ThoughtWorks Technology Radar, DevOps brings value to security, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode19" rel="noopener">https://wiki.securityweekly.com/ASW_Episode19</a>   Visit <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a>/asw for all the latest episodes!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>4025</itunes:duration><itunes:keywords>10,19,application,appsec,asadoorian,asw,devops,github,gitlab,hoodlet,keith,paul,peter,podcast,security,smbv1,thoughtworks,veracode,weekly,windows</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/bf3aa19e652f90a9cb8ea5f25dbf4613.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Eyeballs Everywhere - Application Security Weekly #18</title><link>https://www.spreaker.com/user/securityweekly/eyeballs-everywhere-application-security_1</link><description><![CDATA[This week, Keith and Paul discuss what the difference is between Agile and DevOps! In the Learning and Tools, OWASP Top 10 Proactive Controls v3.0 released, VS Live Share, Bob Ross Lorem Ipsum, and more! In the news, we have updates from Oracle, Microsoft, GDPR, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode18" rel="noopener">https://wiki.securityweekly.com/ASW_Episode18</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></description><guid isPermaLink="false">450cce3f3c924271932c6111e7c17d41</guid><pubDate>Wed, 06 Jun 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14982466/asw18compressed.mp3" length="58689991" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul discuss what the difference is between Agile and DevOps! In the Learning and Tools, OWASP Top 10 Proactive Controls v3.0 released, VS Live Share, Bob Ross Lorem Ipsum, and more! In the news, we have updates from Oracle,...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul discuss what the difference is between Agile and DevOps! In the Learning and Tools, OWASP Top 10 Proactive Controls v3.0 released, VS Live Share, Bob Ross Lorem Ipsum, and more! In the news, we have updates from Oracle, Microsoft, GDPR, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode18" rel="noopener">https://wiki.securityweekly.com/ASW_Episode18</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!   →Visit our website: <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a> →Follow us on Twitter: <a href="https://www.twitter.com/securityweekly" rel="noopener">https://www.twitter.com/securityweekly</a> →Like us on Facebook: <a href="https://www.facebook.com/secweekly" rel="noopener">https://www.facebook.com/secweekly</a>]]></itunes:summary><itunes:duration>3669</itunes:duration><itunes:keywords>18,agile,application,appsec,asw,ci,devops,github,google,hack,keith,live,microsoft,naked,oracle,paul,podcast,security,vs,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/af92dab0a72f6c1484f58c5b33710727.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Just Go With It - Application Security Weekly #17</title><link>https://www.spreaker.com/user/securityweekly/just-go-with-it-application-security-wee_1</link><description><![CDATA[This week, Keith and Paul interview James Wickett, Head of Research at Signal Sciences! In the news, we have updates from Nest, Node.js, Google, F.Secure, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode17" rel="noopener">https://wiki.securityweekly.com/ASW_Episode17</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">44bebb6ac5a94f119da1496d45d63067</guid><pubDate>Wed, 23 May 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14864105/asw17compressed.mp3" length="61170161" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview James Wickett, Head of Research at Signal Sciences! In the news, we have updates from Nest, Node.js, Google, F.Secure, and more on this episode of Application Security Weekly!   Full Show Notes:...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview James Wickett, Head of Research at Signal Sciences! In the news, we have updates from Nest, Node.js, Google, F.Secure, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode17" rel="noopener">https://wiki.securityweekly.com/ASW_Episode17</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3824</itunes:duration><itunes:keywords>application,appsec,asadoorian,google,hack,head,james,keith,naked,nest,nodejs,of,paul,podcast,research,sciences,security,signal,weekly,wickett</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/579c529718a508bb492f4712489cba9c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Happy Dances - Application Security Weekly #16</title><link>https://www.spreaker.com/user/securityweekly/happy-dances-application-security-weekly_1</link><description><![CDATA[This week, Keith and Paul interview Adam Gordon, Edutainer at ITPro.TV! In the news, we have updates from Uber, WhatsApp, Microsoft, and more on this episode of Application Security Weekly!   →Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode16" rel="noopener">https://wiki.securityweekly.com/ASW_Episode16</a>   →Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">7efc24d0fa76edb5836cbab37ba28f98</guid><pubDate>Wed, 16 May 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14806945/asw16compressed.mp3" length="55609214" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul interview Adam Gordon, Edutainer at ITPro.TV! In the news, we have updates from Uber, WhatsApp, Microsoft, and more on this episode of Application Security Weekly!   →Full Show Notes:...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul interview Adam Gordon, Edutainer at ITPro.TV! In the news, we have updates from Uber, WhatsApp, Microsoft, and more on this episode of Application Security Weekly!   →Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode16" rel="noopener">https://wiki.securityweekly.com/ASW_Episode16</a>   →Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3476</itunes:duration><itunes:keywords>adam,application,asadoorian,containers,devops,devsecops,docker,edutainer,gordon,hoodlet,itprotv,keith,microsoft,paul,podcast,security,uber,weekly,whatsapp</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/4161a0909fc260faada56b66e1634c46.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Creating An Awesome Dish - Application Security Weekly #15</title><link>https://www.spreaker.com/user/securityweekly/creating-an-awesome-dish-application-sec_1</link><description><![CDATA[This week, Keith and Paul continue to talk about building your AppSec program! In the Learning and Tools Segment, Keith and Paul discuss Snipe-IT: Open Source Asset Management, Astra: Automated Security Testing for REST API's, GREP: A whiteboard by Julia Evans, and more! In the news, we have updates from Twitter, Meltdown, JavaScript, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode15" rel="noopener">https://wiki.securityweekly.com/ASW_Episode15</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">f17e86d312bacedd3bfe2a2b10ef3450</guid><pubDate>Wed, 09 May 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14742140/asw15compressed.mp3" length="62120182" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul continue to talk about building your AppSec program! In the Learning and Tools Segment, Keith and Paul discuss Snipe-IT: Open Source Asset Management, Astra: Automated Security Testing for REST API's, GREP: A whiteboard by...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul continue to talk about building your AppSec program! In the Learning and Tools Segment, Keith and Paul discuss Snipe-IT: Open Source Asset Management, Astra: Automated Security Testing for REST API's, GREP: A whiteboard by Julia Evans, and more! In the news, we have updates from Twitter, Meltdown, JavaScript, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode15" rel="noopener">https://wiki.securityweekly.com/ASW_Episode15</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3883</itunes:duration><itunes:keywords>application,appsec,asadoorian,automated,devops,evans,grep,hack,hoodlet,javascript,julia,keith,meltdown,naked,paul,podcast,security,testing,twitter,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/8cae91a80dba09ed3d9f14281e0e2943.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Save The Developers Time - Application Security Weekly #14</title><link>https://www.spreaker.com/user/securityweekly/save-the-developers-time-application-sec</link><description><![CDATA[This week, Paul and Keith discuss Building Your AppSec Program and how to get started! In the news, we have updates from Microsoft, Android, the FDA, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode14" rel="noopener">https://wiki.securityweekly.com/ASW_Episode14</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">6221786e21fd3f42329174855cb88d89</guid><pubDate>Wed, 02 May 2018 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14688319/asw14compressed.mp3" length="55804819" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Paul and Keith discuss Building Your AppSec Program and how to get started! In the news, we have updates from Microsoft, Android, the FDA, and more on this episode of Application Security Weekly!   Full Show Notes:...</itunes:subtitle><itunes:summary><![CDATA[This week, Paul and Keith discuss Building Your AppSec Program and how to get started! In the news, we have updates from Microsoft, Android, the FDA, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode14" rel="noopener">https://wiki.securityweekly.com/ASW_Episode14</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3488</itunes:duration><itunes:keywords>android,apple,application,appsec,asadoorian,devsecops,fda,hack,hoodlet,keith,macos,microsoft,naked,paul,podcast,security,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/38f394822f006b85a8376ad9033bf9a3.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Bigger Than My Home - Application Security Weekly #13</title><link>https://www.spreaker.com/user/securityweekly/bigger-than-my-home-application-security</link><description><![CDATA[This week, Paul and Keith discuss Drupal 7 and 8 core critical releases, Irony of Leaky App at RSAC not lost on attendees, avoiding XSS in React is still hard, and more! In our Pre-Recorded interview, Paul and Keith sit down with Rami Sass, CEO and Co-Founder of WhiteSource, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode13" rel="noopener">https://wiki.securityweekly.com/ASW_Episode13</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">9b01d62355fe223e8bc28950b34c4399</guid><pubDate>Tue, 01 May 2018 19:54:51 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14678061/asw13compressed.mp3" length="67030785" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Paul and Keith discuss Drupal 7 and 8 core critical releases, Irony of Leaky App at RSAC not lost on attendees, avoiding XSS in React is still hard, and more! In our Pre-Recorded interview, Paul and Keith sit down with Rami Sass, CEO and...</itunes:subtitle><itunes:summary><![CDATA[This week, Paul and Keith discuss Drupal 7 and 8 core critical releases, Irony of Leaky App at RSAC not lost on attendees, avoiding XSS in React is still hard, and more! In our Pre-Recorded interview, Paul and Keith sit down with Rami Sass, CEO and Co-Founder of WhiteSource, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode13" rel="noopener">https://wiki.securityweekly.com/ASW_Episode13</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>4190</itunes:duration><itunes:keywords>application,appsec,asadoorian,ceo,containers,docker,drupal,hack,hoodlet,keith,naked,paul,podcast,rami,sass,security,secweekly,weekly,whitesource,xss</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/704c898075c19eb26eb0513b01217164.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Classy and Illustrious - Application Security Weekly #12</title><link>https://www.spreaker.com/user/securityweekly/classy-and-illustrious-application-secur_1</link><description><![CDATA[This week, Paul and Keith discuss Github's 10th Anniversary and talk about Open Source Software! In the news, we have updates from Rapid7, a new MacOS backdoor, your Windows PC can be hacked by just visiting a site, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode12" rel="noopener">https://wiki.securityweekly.com/ASW_Episode12</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">43d34c4b07699f609cf206d2cf862178</guid><pubDate>Tue, 17 Apr 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562753/asw12compressed.mp3" length="57927216" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Paul and Keith discuss Github's 10th Anniversary and talk about Open Source Software! In the news, we have updates from Rapid7, a new MacOS backdoor, your Windows PC can be hacked by just visiting a site, and more on this episode of...</itunes:subtitle><itunes:summary><![CDATA[This week, Paul and Keith discuss Github's 10th Anniversary and talk about Open Source Software! In the news, we have updates from Rapid7, a new MacOS backdoor, your Windows PC can be hacked by just visiting a site, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode12" rel="noopener">https://wiki.securityweekly.com/ASW_Episode12</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3621</itunes:duration><itunes:keywords>apple,application,appsec,asadoorian,github,hacking,hoodlet,infosec,keith,macos,open,paul,pc,podcast,rapid7,security,software,source,weekly,windows</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b4e9973623994fb9ae5c9ee84861502c.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Don't Pull My Nerd Card - Application Security Weekly #11</title><link>https://www.spreaker.com/user/securityweekly/dont-pull-my-nerd-card-application-secur_1</link><description><![CDATA[This week, Paul and Keith discuss One Language to Rule Them All: Node-Based Operating System, NodeOS! In the news, we have updates from Cloudflare, Slack, NASA’s Voyager 1 spacecraft, how Georgia passed an Anti-Infosec Legislation, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode11" rel="noopener">https://wiki.securityweekly.com/ASW_Episode11</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">a67b9e9545c2a49ccee0bbf01f0eb3cf</guid><pubDate>Mon, 09 Apr 2018 21:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562756/asw11compressed.mp3" length="55563728" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Paul and Keith discuss One Language to Rule Them All: Node-Based Operating System, NodeOS! In the news, we have updates from Cloudflare, Slack, NASA’s Voyager 1 spacecraft, how Georgia passed an Anti-Infosec Legislation, and more on this...</itunes:subtitle><itunes:summary><![CDATA[This week, Paul and Keith discuss One Language to Rule Them All: Node-Based Operating System, NodeOS! In the news, we have updates from Cloudflare, Slack, NASA’s Voyager 1 spacecraft, how Georgia passed an Anti-Infosec Legislation, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode11" rel="noopener">https://wiki.securityweekly.com/ASW_Episode11</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3473</itunes:duration><itunes:keywords>1,anti,application,appsec,asadoorian,atlanta,based,cloudflare,georgia,hackers,infosec,keith,nasa,node,paul,podcast,security,slack,voyager,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b055807c99924e162b002905a9eb7b64.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Coming Up 7's - Application Security Weekly #10</title><link>https://www.spreaker.com/user/securityweekly/coming-up-7s-application-security-weekly_1</link><description><![CDATA[This week, Keith and Paul have the debate as to whether it's DevOps or DevSecOps, they discuss OWASP vulnerable web apps directory project, Red Team wisdom, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode10" rel="noopener">https://wiki.securityweekly.com/ASW_Episode10</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">50d39287ad215b9f7ca9ada46828e7bc</guid><pubDate>Tue, 03 Apr 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562762/asw10compressed.mp3" length="127223176" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul have the debate as to whether it's DevOps or DevSecOps, they discuss OWASP vulnerable web apps directory project, Red Team wisdom, and more on this episode of Application Security Weekly!   Full Show Notes:...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul have the debate as to whether it's DevOps or DevSecOps, they discuss OWASP vulnerable web apps directory project, Red Team wisdom, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode10" rel="noopener">https://wiki.securityweekly.com/ASW_Episode10</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3181</itunes:duration><itunes:keywords>application,appsec,asadoorian,blue,devops,devsecops,hoodlet,infosec,keith,paul,podcast,redteam,security,team,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/d31534a19a208c437ba74d89f0972d39.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>More Crypto, More Problems - Application Security Weekly #09</title><link>https://www.spreaker.com/user/securityweekly/more-crypto-more-problems-application-se_1</link><description><![CDATA[This week, Keith and Paul discuss Uber's open source tool for adversarial simulation, AMD processors, Hijacked MailChimp accounts  used to distribute banking malware, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode09" rel="noopener">https://wiki.securityweekly.com/ASW_Episode09</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">df4e0306c8d9dbb4f4c755443a7bc9cd</guid><pubDate>Mon, 19 Mar 2018 09:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562763/asw09compressed.mp3" length="137898376" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul discuss Uber's open source tool for adversarial simulation, AMD processors, Hijacked MailChimp accounts  used to distribute banking malware, and more on this episode of Application Security Weekly!   Full Show Notes:...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul discuss Uber's open source tool for adversarial simulation, AMD processors, Hijacked MailChimp accounts  used to distribute banking malware, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode09" rel="noopener">https://wiki.securityweekly.com/ASW_Episode09</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3448</itunes:duration><itunes:keywords>amd,application,asadoorian,crypto,cryptocurrency,hoodlet,infosec,intel,keith,mailchimp,paul,podcast,security,uber,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6a495d34d518e62aecae3dd9e3e122fd.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Early Bird Gets The Worm - Application Security Weekly #08</title><link>https://www.spreaker.com/user/securityweekly/early-bird-gets-the-worm-application-sec_1</link><description><![CDATA[This week, Paul and Keith talk about “The Phoenix Project”, Amazon admits Alexa is creepily laughing at people, Ethereum fixes serious ‘eclipse’ flaw, Kali Linux is now an app in the Windows App Store, Docker + Minecraft = Dockercraft, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode08" rel="noopener">https://wiki.securityweekly.com/ASW_Episode08</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">7874531c85b6cc6151ee9312436be534</guid><pubDate>Mon, 12 Mar 2018 21:27:15 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562759/asw008compressed.mp3" length="51488972" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Paul and Keith talk about “The Phoenix Project”, Amazon admits Alexa is creepily laughing at people, Ethereum fixes serious ‘eclipse’ flaw, Kali Linux is now an app in the Windows App Store, Docker + Minecraft = Dockercraft, and more on...</itunes:subtitle><itunes:summary><![CDATA[This week, Paul and Keith talk about “The Phoenix Project”, Amazon admits Alexa is creepily laughing at people, Ethereum fixes serious ‘eclipse’ flaw, Kali Linux is now an app in the Windows App Store, Docker + Minecraft = Dockercraft, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode08" rel="noopener">https://wiki.securityweekly.com/ASW_Episode08</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3219</itunes:duration><itunes:keywords>alexa,amazon,application,asadoorian,crypto,cryptocurrency,cyber,docker,ethereum,hoodlet,infosec,inux,kali,keith,minecraft,paul,podcast,security,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/46745cadf68cf15474ac77f46046bd3d.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Everything Old Is New Again - Application Security Weekly #07</title><link>https://www.spreaker.com/user/securityweekly/everything-old-is-new-again-application-_1</link><description><![CDATA[This week, Keith and Paul discuss Facebook’s mandatory malware scan, GitLeaks: Check git repos for secrets and keys, New York quietly working to prevent a major cyber attack, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode07" rel="noopener">https://wiki.securityweekly.com/ASW_Episode07</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></description><guid isPermaLink="false">22ab67f04605b194778fe27315bb3565</guid><pubDate>Mon, 05 Mar 2018 15:23:37 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562769/asw07_mixdowncompressed.mp3" length="135931336" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul discuss Facebook’s mandatory malware scan, GitLeaks: Check git repos for secrets and keys, New York quietly working to prevent a major cyber attack, and more on this episode of Application Security Weekly!   Full Show Notes:...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul discuss Facebook’s mandatory malware scan, GitLeaks: Check git repos for secrets and keys, New York quietly working to prevent a major cyber attack, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode07" rel="noopener">https://wiki.securityweekly.com/ASW_Episode07</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3399</itunes:duration><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c995ec81e675c8c1bccffc0affdd30b8.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>It's Just Beautiful - Application Security Weekly #06</title><link>https://www.spreaker.com/user/securityweekly/its-just-beautiful-application-security-_1</link><description><![CDATA[This week, Keith and Paul discuss Data Security and Bug Bounty programs! In the news, Lenovo warns of critical Wifi vulnerability, Russian nuclear scientists arrested for Bitcoin mining plot, remote workers outperforming office workers, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode06" rel="noopener">https://wiki.securityweekly.com/ASW_Episode06</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!  ]]></description><guid isPermaLink="false">affd878e68290ea960516ed8e21aa101</guid><pubDate>Sat, 17 Feb 2018 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562765/asw06compressed.mp3" length="56185998" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul discuss Data Security and Bug Bounty programs! In the news, Lenovo warns of critical Wifi vulnerability, Russian nuclear scientists arrested for Bitcoin mining plot, remote workers outperforming office workers, and more on...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul discuss Data Security and Bug Bounty programs! In the news, Lenovo warns of critical Wifi vulnerability, Russian nuclear scientists arrested for Bitcoin mining plot, remote workers outperforming office workers, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode06" rel="noopener">https://wiki.securityweekly.com/ASW_Episode06</a>   Visit <a href="https://www.securityweekly.com/asw" rel="noopener">https://www.securityweekly.com/asw</a> for all the latest episodes!  ]]></itunes:summary><itunes:duration>3512</itunes:duration><itunes:keywords>asadoorian,bitcoin,bounties,bug,bugcrowd,crowd,cyber,hoodlet,keith,lenovo,monero,nuclear,paul,podcast,russia,scientists,security,weekly,wifi</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/4202e84e83470f2084400e5c8729d2e7.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Jim Carrey Hacked My Facebook - Application Security Weekly #05</title><link>https://www.spreaker.com/user/securityweekly/jim-carrey-hacked-my-facebook-applicatio_1</link><description><![CDATA[This week, Keith and Paul continue to discuss OWASP Application Security Verification Standard! In the news, Cisco investigation reveals ASA vulnerability is worse than originally thought, Google Chrome HTTPS certificate apocalypse, Intel made smart glasses that look normal, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode05" rel="noopener">https://wiki.securityweekly.com/ASW_Episode05</a>   Visit <a href="https://www.securityweekly.com/" rel="noopener">https://www.securityweekly.com/</a> for all the latest episodes!]]></description><guid isPermaLink="false">492ad59dacfbaa50d73eb1113a613eb0</guid><pubDate>Sat, 10 Feb 2018 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562767/asw05compressed.mp3" length="48647686" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul continue to discuss OWASP Application Security Verification Standard! In the news, Cisco investigation reveals ASA vulnerability is worse than originally thought, Google Chrome HTTPS certificate apocalypse, Intel made smart...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul continue to discuss OWASP Application Security Verification Standard! In the news, Cisco investigation reveals ASA vulnerability is worse than originally thought, Google Chrome HTTPS certificate apocalypse, Intel made smart glasses that look normal, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode05" rel="noopener">https://wiki.securityweekly.com/ASW_Episode05</a>   Visit <a href="https://www.securityweekly.com/" rel="noopener">https://www.securityweekly.com/</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3041</itunes:duration><itunes:keywords>application,asa,asadoorian,bitcoin,chrome,cisco,coinhive,cyber,google,hoodlet,keith,nsa,paul,podcast,security,weekly</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/dd136b138529f3089e0494fd6e1a089e.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Stay Classy - Application Security Weekly #04</title><link>https://www.spreaker.com/user/securityweekly/stay-classy-application-security-weekly-_1</link><description><![CDATA[This week, Keith and Paul discuss OWASP Application Security Verification Standard! In the news, Intel warns Chinese companies of chip flaw before U.S. government, bypassing CloudFair using Internet-wide scan data, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode04" rel="noopener">https://wiki.securityweekly.com/ASW_Episode04</a>   Visit <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a>/ for all the latest episodes!]]></description><guid isPermaLink="false">b9b8627362511db5c1de0cf3eebeac15</guid><pubDate>Mon, 05 Feb 2018 18:13:57 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562771/asw04compressed.mp3" length="56358615" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith and Paul discuss OWASP Application Security Verification Standard! In the news, Intel warns Chinese companies of chip flaw before U.S. government, bypassing CloudFair using Internet-wide scan data, and more on this episode of...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith and Paul discuss OWASP Application Security Verification Standard! In the news, Intel warns Chinese companies of chip flaw before U.S. government, bypassing CloudFair using Internet-wide scan data, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode04" rel="noopener">https://wiki.securityweekly.com/ASW_Episode04</a>   Visit <a href="https://www.securityweekly.com" rel="noopener">https://www.securityweekly.com</a>/ for all the latest episodes!]]></itunes:summary><itunes:duration>3523</itunes:duration><itunes:keywords>application,asadoorian,cloudfair,government,hoodlet,intel,internet,keith,lenovo,owasp,paul,podcast,security</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/91c1b5d1247b90239a432dfe70e94649.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>The Doctor's Here - Application Security Weekly #03</title><link>https://www.spreaker.com/user/securityweekly/the-doctors-here-application-security-we_1</link><description><![CDATA[This week, Keith is joined by Doug White, host of Secure Digital Life! Matias Madou of Secure Code Warrior joins us for an interview! In the news, Red Hat has now reverted CPU patches for Spectre, Russian Twitterbots are blaming the US shutdown on Democrats, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode03" rel="noopener">https://wiki.securityweekly.com/ASW_Episode03</a>   Visit <a href="https://www.securityweekly.com/" rel="noopener">https://www.securityweekly.com/</a> for all the latest episodes!]]></description><guid isPermaLink="false">3cdb0c43d08d9e1f557738051f728b43</guid><pubDate>Sat, 27 Jan 2018 10:00:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562773/asw03compressed.mp3" length="56869361" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Keith is joined by Doug White, host of Secure Digital Life! Matias Madou of Secure Code Warrior joins us for an interview! In the news, Red Hat has now reverted CPU patches for Spectre, Russian Twitterbots are blaming the US shutdown on...</itunes:subtitle><itunes:summary><![CDATA[This week, Keith is joined by Doug White, host of Secure Digital Life! Matias Madou of Secure Code Warrior joins us for an interview! In the news, Red Hat has now reverted CPU patches for Spectre, Russian Twitterbots are blaming the US shutdown on Democrats, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode03" rel="noopener">https://wiki.securityweekly.com/ASW_Episode03</a>   Visit <a href="https://www.securityweekly.com/" rel="noopener">https://www.securityweekly.com/</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3555</itunes:duration><itunes:keywords>asadoorian,code,cpu,doug,hoodlet,keith,madou,matias,meltdown,patches,paul,russia,secure,shutdown,spectre,twitterbots,us,warrior,white</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/1eeea84e46cdd78ed94a9eb0276f4b8f.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Punishing Trojan Horses - Application Security Weekly #02</title><link>https://www.spreaker.com/user/securityweekly/punishing-trojan-horses-application-secu_1</link><description><![CDATA[This week, Paul and Keith discuss the second half of the OWASP 2017 Top Ten! In the news, Facebook can track you by the dust on your camera lens, Apple health data used in murder trial, the stress of remote working, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode02" rel="noopener">https://wiki.securityweekly.com/ASW_Episode02</a>   Visit <a href="https://www.securityweekly.com/" rel="noopener">https://www.securityweekly.com/</a> for all the latest episodes!]]></description><guid isPermaLink="false">f6c9ee9bcd3eb290fac43d0250ec3990</guid><pubDate>Fri, 19 Jan 2018 20:58:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562775/asw02compressed.mp3" length="55353841" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Paul and Keith discuss the second half of the OWASP 2017 Top Ten! In the news, Facebook can track you by the dust on your camera lens, Apple health data used in murder trial, the stress of remote working, and more on this episode of...</itunes:subtitle><itunes:summary><![CDATA[This week, Paul and Keith discuss the second half of the OWASP 2017 Top Ten! In the news, Facebook can track you by the dust on your camera lens, Apple health data used in murder trial, the stress of remote working, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode02" rel="noopener">https://wiki.securityweekly.com/ASW_Episode02</a>   Visit <a href="https://www.securityweekly.com/" rel="noopener">https://www.securityweekly.com/</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3460</itunes:duration><itunes:keywords>apple,application,asadoorian,facebook,hoodlet,intel,keith,paul,podcast,remote,security,weekly,working</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/97d627ed391303691b62b642f097936b.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Pushing To Master - Application Security Weekly #01</title><link>https://www.spreaker.com/user/securityweekly/pushing-to-master-application-security-w_1</link><description><![CDATA[This week, Paul and Keith will discuss the ten most critical web application risks! In the news, how malicious NPM packages could harvest credit card numbers and passwords, NVIDIA updates video drivers to help address CPU memory security, multiple vulnerabilities in PHP could allow for arbitrary code execution, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode01" rel="noopener">https://wiki.securityweekly.com/ASW_Episode01</a>   Visit <a href="https://www.securityweekly.com/" rel="noopener">https://www.securityweekly.com/</a> for all the latest episodes!]]></description><guid isPermaLink="false">9f507fc45276f115bb016c9827b6d503</guid><pubDate>Mon, 15 Jan 2018 17:42:47 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562776/asw01compressed.mp3" length="58686230" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>This week, Paul and Keith will discuss the ten most critical web application risks! In the news, how malicious NPM packages could harvest credit card numbers and passwords, NVIDIA updates video drivers to help address CPU memory security, multiple...</itunes:subtitle><itunes:summary><![CDATA[This week, Paul and Keith will discuss the ten most critical web application risks! In the news, how malicious NPM packages could harvest credit card numbers and passwords, NVIDIA updates video drivers to help address CPU memory security, multiple vulnerabilities in PHP could allow for arbitrary code execution, and more on this episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode01" rel="noopener">https://wiki.securityweekly.com/ASW_Episode01</a>   Visit <a href="https://www.securityweekly.com/" rel="noopener">https://www.securityweekly.com/</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3668</itunes:duration><itunes:keywords>application,applications,arbitrary,asadoorian,code,containers,cpu,ecurity,execution,memory,npm,nvidia,paul,php,risks</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5f4ad7c341c4fc7c6abba24f997bb5d8.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Where's My Starbucks - Application Security Weekly #00</title><link>https://www.spreaker.com/user/securityweekly/wheres-my-starbucks-application-security_1</link><description><![CDATA[Paul Asadoorian and Keith Hoodlet bring you our brand new show, Application Security Weekly! On our first episode, Paul and Keith will discuss the history of application security and software security! In the news, what you need to know about CPU vulnerabilities, negative results testing Intel CPU design, Mozilla Firefox patches, and Starbucks Wi-Fi mines Monero via CoinHive! All that and more, on the first episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode00" rel="noopener">https://wiki.securityweekly.com/ASW_Episode00</a>   Visit <a href="https://www.securityweekly.com/psw" rel="noopener">https://www.securityweekly.com/psw</a> for all the latest episodes!]]></description><guid isPermaLink="false">002c602306af654706302b24a06a4fba</guid><pubDate>Mon, 08 Jan 2018 14:20:38 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/14562784/asw00compressed.mp3" length="127683976" type="audio/mpeg"/><itunes:author>Security Weekly</itunes:author><itunes:subtitle>Paul Asadoorian and Keith Hoodlet bring you our brand new show, Application Security Weekly! On our first episode, Paul and Keith will discuss the history of application security and software security! In the news, what you need to know about CPU...</itunes:subtitle><itunes:summary><![CDATA[Paul Asadoorian and Keith Hoodlet bring you our brand new show, Application Security Weekly! On our first episode, Paul and Keith will discuss the history of application security and software security! In the news, what you need to know about CPU vulnerabilities, negative results testing Intel CPU design, Mozilla Firefox patches, and Starbucks Wi-Fi mines Monero via CoinHive! All that and more, on the first episode of Application Security Weekly!   Full Show Notes: <a href="https://wiki.securityweekly.com/ASW_Episode00" rel="noopener">https://wiki.securityweekly.com/ASW_Episode00</a>   Visit <a href="https://www.securityweekly.com/psw" rel="noopener">https://www.securityweekly.com/psw</a> for all the latest episodes!]]></itunes:summary><itunes:duration>3193</itunes:duration><itunes:keywords>application,asadoorian,coinhive,cpu,firefox,hoodlet,intel,keith,monero,mozilla,paul,podcast,security,starbucks,vulnerabilities</itunes:keywords><itunes:explicit>clean</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/085808c5bcf31f1e684e2511152ad5cf.jpg"/><itunes:episodeType>full</itunes:episodeType></item></channel></rss>
