Application security
220
MENTIONS
71
EPISODES
52
PODCASTS
Search complete. 220 mentions across 71 episodes found for "Application security".
Sep 12, 2026
Watch This Before Becoming a SOC Analyst
A
19:02AbidHOST
I guess the important one here will be, you know, the on-call, the pager, people are confused about that.
A
19:07AbidHOST
We'll get to that, but you touched on a really important point when you said, well, you respond to incidents, you analyze the tickets, do that, but then you're like, well, sometimes you also do something like software security, which is AppSec, analyzing vulnerabilities in source code.
A
19:22AbidHOST
That is funny because I'm literally editing a video that I'm making for YouTube about AppSec engineering, application security, it's like a roadmap and I talk a lot about that.
A
19:32AbidHOST
And what people don't realize that you touched on is job titles are misleading.
A
19:37AbidHOST
You can have a title of cybersecurity analyst and you do a whole bunch of tasks.
Matan Bar-Efrat (CEO, Rein Security): The chatbot gave us their API key! | S6 E3
J
18:07Jack BrandwoodHOST
You pivoted, right?
M
18:08Matan Bar-EfratGUEST
So we started off, and that's where our roots come from, in the AppSec space.
M
18:14Matan Bar-EfratGUEST
AppSec with AI has completely changed.
M
18:18Matan Bar-EfratGUEST
And two things are happening that, again, are wonderful for us, for me, which is, you know, mythos and post-mythos security.
M
18:27Matan Bar-EfratGUEST
And we touched on that a little bit about the exploitation window collapse and what do you do.
AI models can find security vulnerabilities. Can they fix them? with Keith Hoodlet
K
30:15Keith HoodletGUEST
But when we look at even things like Opus 4.6, 4.7, 4.8, and now 5.0 as just the sort of benchmark that I think a lot of people use for vulnerability discovery today, capabilities for vulnerability discovery are definitely increasing.
K
30:31Keith HoodletGUEST
A year ago, if you were to ask me that question, and while I was at Trail of Bits leading the AIML and AppSec team, it was around like a 10% true positive rate, 10 to 20%, right? Like that felt like maybe where we were going to peak because a lot of the research indicated that it was a memorization thing that was producing higher true positive rates for vulnerability discovery.
K
30:56Keith HoodletGUEST
True positive rates, they've increased a ton over the last year in terms of what you can actually find with AI to produce real exploitable vulnerabilities and improve it.
K
31:07Keith HoodletGUEST
Patching, not so much.
DtSR Episode 722 - Vulnerability Math Ain't Mathing
J
30:51Jeremiah GrossmanGUEST
We've, we've gone through this many times.
J
30:53Jeremiah GrossmanGUEST
We, you know, we did white hat security together, and at some point we pushed AppSec so high that the adversary shifted and they went to ransomware.
J
31:00Jeremiah GrossmanGUEST
You know, they, they shifted tactics.
J
31:03Jeremiah GrossmanGUEST
I did SentinelOne and helped them, and helped them out.
The Unusual Strategy That Helps ArmorCode Grow 100% YOY | Nikhil Gupta
N
23:37Nikhil GuptaGUEST
Yeah, in the layman terms, it's a vulnerability management.
N
23:40Nikhil GuptaGUEST
So what happens is anytime when you are doing the security, whether it is physical security or software security, infrastructure security, there's a whole bunch of scanning you do right i may have a scanner or a pen testing and things like that and i'll do and i'll have let's say thousand ten thousand a million vulnerabilities are there For every AppSec engineer, there is 200, 300, 400 developers.
N
24:04Nikhil GuptaGUEST
So that ratio is very skewed.
N
24:06Nikhil GuptaGUEST
So you cannot fix all the million vulnerabilities or 100,000 vulnerabilities.
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Sean Murphy, Idan Plotnik, Ido Geffen - ASW #399
M
0:41Mike ShimaHOST
As always, thank you for listening.
M
0:43Mike ShimaHOST
We'll be back next week with more interviews and AppSec news.
M
0:47Mike ShimaHOST
It's the show to learn the latest tools and techniques to understand DevOps, applications, and the cloud.
M
0:53Mike ShimaHOST
Your trusted source for the latest AppSec news, it's time for Application Security Weekly.
M
1:00Mike ShimaHOST
Welcome to Black Hat 2026.
M
1:02Mike ShimaHOST
I'm Mike Shima.
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Ido Geffen, Sean Murphy, Idan Plotnik - ASW #399
M
0:41Mike SchemaHOST
As always, thank you for listening.
M
0:43Mike SchemaHOST
We'll be back next week with more interviews and AppSec news.
M
0:47Mike SchemaHOST
It's the show to learn the latest tools and techniques to understand DevOps applications and the cloud.
M
0:53Mike SchemaHOST
Your trusted source for the latest AppSec news.
M
0:55Mike SchemaHOST
It's time for Application Security Weekly.
M
1:00Mike SchemaHOST
Welcome to Black Hat 2026.
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Sean Murphy, Idan Plotnik, Ido Geffen - ASW #399
M
0:41Mike SchemaHOST
As always, thank you for listening.
M
0:43Mike SchemaHOST
We'll be back next week with more interviews and AppSec news.
M
0:47Mike SchemaHOST
It's the show to learn the latest tools and techniques to understand DevOps, applications, and the cloud.
M
0:53Mike SchemaHOST
Your trusted source for the latest AppSec news.
M
0:55Mike SchemaHOST
It's time for Application Security Weekly.
M
1:00Mike SchemaHOST
Welcome to Black Hat 2026.
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Ido Geffen, Sean Murphy, Idan Plotnik - ASW #399
M
0:41Mike SchemaHOST
As always, thank you for listening.
M
0:43Mike SchemaHOST
We'll be back next week with more interviews and AppSec news.
M
0:47Mike SchemaHOST
It's the show to learn the latest tools and techniques to understand DevOps applications and the cloud.
M
0:53Mike SchemaHOST
Your trusted source for the latest AppSec news.
M
0:55Mike SchemaHOST
It's time for Application Security Weekly.
M
1:00Mike SchemaHOST
Welcome to Black Hat 2026.
NHI & AI Identity Summit : The Next 24 Months
J
17:54John YeohGUEST
But now that we have agentic harnesses and these components are going to act on the behaviors and the intents that we give them, it's really important to like, hey, what's in your harness? So, yeah, I think that'll be a big one.
E
18:06Eve MalerGUEST
I don't know if this is really adding a control, but it's a reminder that we've been focusing on the identity aspects, or maybe the IAM aspects, if you will, but this is as much an AppSec thing, really, in its feel as it is about identity, and we don't want to forget the controls coming from that world.
E
18:23Eve MalerGUEST
You mentioned supply chain management.
E
18:26Eve MalerGUEST
Those are relevant here.
61 more episodes mention Application security.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.