Skip to main content
Application security

Application security

Search complete. 220 mentions across 71 episodes found for "Application security".

Sep 12, 2026

AbidHOST
19:02
I guess the important one here will be, you know, the on-call, the pager, people are confused about that.
AbidHOST
19:07
We'll get to that, but you touched on a really important point when you said, well, you respond to incidents, you analyze the tickets, do that, but then you're like, well, sometimes you also do something like software security, which is AppSec, analyzing vulnerabilities in source code.
AbidHOST
19:22
That is funny because I'm literally editing a video that I'm making for YouTube about AppSec engineering, application security, it's like a roadmap and I talk a lot about that.
AbidHOST
19:32
And what people don't realize that you touched on is job titles are misleading.
AbidHOST
19:37
You can have a title of cybersecurity analyst and you do a whole bunch of tasks.
Jack BrandwoodHOST
18:07
You pivoted, right?
Matan Bar-EfratGUEST
18:08
So we started off, and that's where our roots come from, in the AppSec space.
Matan Bar-EfratGUEST
18:14
AppSec with AI has completely changed.
Matan Bar-EfratGUEST
18:18
And two things are happening that, again, are wonderful for us, for me, which is, you know, mythos and post-mythos security.
Matan Bar-EfratGUEST
18:27
And we touched on that a little bit about the exploitation window collapse and what do you do.
Keith HoodletGUEST
30:15
But when we look at even things like Opus 4.6, 4.7, 4.8, and now 5.0 as just the sort of benchmark that I think a lot of people use for vulnerability discovery today, capabilities for vulnerability discovery are definitely increasing.
Keith HoodletGUEST
30:31
A year ago, if you were to ask me that question, and while I was at Trail of Bits leading the AIML and AppSec team, it was around like a 10% true positive rate, 10 to 20%, right? Like that felt like maybe where we were going to peak because a lot of the research indicated that it was a memorization thing that was producing higher true positive rates for vulnerability discovery.
Keith HoodletGUEST
30:56
True positive rates, they've increased a ton over the last year in terms of what you can actually find with AI to produce real exploitable vulnerabilities and improve it.
Keith HoodletGUEST
31:07
Patching, not so much.
Jeremiah GrossmanGUEST
30:51
We've, we've gone through this many times.
Jeremiah GrossmanGUEST
30:53
We, you know, we did white hat security together, and at some point we pushed AppSec so high that the adversary shifted and they went to ransomware.
Jeremiah GrossmanGUEST
31:00
You know, they, they shifted tactics.
Jeremiah GrossmanGUEST
31:03
I did SentinelOne and helped them, and helped them out.
Nikhil GuptaGUEST
23:37
Yeah, in the layman terms, it's a vulnerability management.
Nikhil GuptaGUEST
23:40
So what happens is anytime when you are doing the security, whether it is physical security or software security, infrastructure security, there's a whole bunch of scanning you do right i may have a scanner or a pen testing and things like that and i'll do and i'll have let's say thousand ten thousand a million vulnerabilities are there For every AppSec engineer, there is 200, 300, 400 developers.
Nikhil GuptaGUEST
24:04
So that ratio is very skewed.
Nikhil GuptaGUEST
24:06
So you cannot fix all the million vulnerabilities or 100,000 vulnerabilities.
Mike ShimaHOST
0:41
As always, thank you for listening.
Mike ShimaHOST
0:43
We'll be back next week with more interviews and AppSec news.
Mike ShimaHOST
0:47
It's the show to learn the latest tools and techniques to understand DevOps, applications, and the cloud.
Mike ShimaHOST
0:53
Your trusted source for the latest AppSec news, it's time for Application Security Weekly.
Mike ShimaHOST
1:00
Welcome to Black Hat 2026.
Mike ShimaHOST
1:02
I'm Mike Shima.
Mike SchemaHOST
0:41
As always, thank you for listening.
Mike SchemaHOST
0:43
We'll be back next week with more interviews and AppSec news.
Mike SchemaHOST
0:47
It's the show to learn the latest tools and techniques to understand DevOps applications and the cloud.
Mike SchemaHOST
0:53
Your trusted source for the latest AppSec news.
Mike SchemaHOST
0:55
It's time for Application Security Weekly.
Mike SchemaHOST
1:00
Welcome to Black Hat 2026.
Mike SchemaHOST
0:41
As always, thank you for listening.
Mike SchemaHOST
0:43
We'll be back next week with more interviews and AppSec news.
Mike SchemaHOST
0:47
It's the show to learn the latest tools and techniques to understand DevOps, applications, and the cloud.
Mike SchemaHOST
0:53
Your trusted source for the latest AppSec news.
Mike SchemaHOST
0:55
It's time for Application Security Weekly.
Mike SchemaHOST
1:00
Welcome to Black Hat 2026.
Mike SchemaHOST
0:41
As always, thank you for listening.
Mike SchemaHOST
0:43
We'll be back next week with more interviews and AppSec news.
Mike SchemaHOST
0:47
It's the show to learn the latest tools and techniques to understand DevOps applications and the cloud.
Mike SchemaHOST
0:53
Your trusted source for the latest AppSec news.
Mike SchemaHOST
0:55
It's time for Application Security Weekly.
Mike SchemaHOST
1:00
Welcome to Black Hat 2026.
John YeohGUEST
17:54
But now that we have agentic harnesses and these components are going to act on the behaviors and the intents that we give them, it's really important to like, hey, what's in your harness? So, yeah, I think that'll be a big one.
Eve MalerGUEST
18:06
I don't know if this is really adding a control, but it's a reminder that we've been focusing on the identity aspects, or maybe the IAM aspects, if you will, but this is as much an AppSec thing, really, in its feel as it is about identity, and we don't want to forget the controls coming from that world.
Eve MalerGUEST
18:23
You mentioned supply chain management.
Eve MalerGUEST
18:26
Those are relevant here.

61 more episodes mention Application security.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.