Hosted by @mutantzombie.bsky.social, @jlk.bsky.social, and Kalyani Pawar.
dangerouserrors.com/appsec/2025/...
dangerouserrors.com/appsec/2025/...
And since it’s @bandcamp.com Friday, you can make a musician’s day better by supporting their work and grabbing a track (or two or three).
dangerouserrors.com/synthwave-sh...
And since it’s @bandcamp.com Friday, you can make a musician’s day better by supporting their work and grabbing a track (or two or three).
dangerouserrors.com/synthwave-sh...
Buy a track. Buy an album. Enjoy some new music.
And if you like #synthwave (and adjacent) tunes, check out this list for a few ideas.
dangerouserrors.com/synthwave-sh...
Buy a track. Buy an album. Enjoy some new music.
And if you like #synthwave (and adjacent) tunes, check out this list for a few ideas.
dangerouserrors.com/synthwave-sh...
www.scworld.com/podcast-segm...
www.scworld.com/podcast-segm...
Later on in this episode Keith Hoodlet shared where he's seeing (and not seeing) #appsec potential from LLMs.
Articles and episode at www.scworld.com/podcast-epis...
youtu.be/zn3LT4BqOJo?...
Later on in this episode Keith Hoodlet shared where he's seeing (and not seeing) #appsec potential from LLMs.
Articles and episode at www.scworld.com/podcast-epis...
youtu.be/zn3LT4BqOJo?...
He tweaked model weights to subtly introduce a backdoor into generated code, regardless of prompt, and noted the difficultly in detecting such manipulation.
youtube.com/shorts/nB_KK...
He tweaked model weights to subtly introduce a backdoor into generated code, regardless of prompt, and noted the difficultly in detecting such manipulation.
youtube.com/shorts/nB_KK...
News articles and notes at www.scworld.com/podcast-epis...
www.youtube.com/watch?featur...
News articles and notes at www.scworld.com/podcast-epis...
www.youtube.com/watch?featur...
Keith Hoodlet returned to talk about those questions and put the capabilities of LLMs into perspective.
Show notes at www.scworld.com/podcast-epis...
youtu.be/zn3LT4BqOJo?...
Keith Hoodlet returned to talk about those questions and put the capabilities of LLMs into perspective.
Show notes at www.scworld.com/podcast-epis...
youtu.be/zn3LT4BqOJo?...
Show notes: www.scworld.com/podcast-epis...
youtu.be/0GlIbGgi1OY?...
Show notes: www.scworld.com/podcast-epis...
youtu.be/0GlIbGgi1OY?...
It reminds me of an old joke about oversimplifying models. We shouldn't treat appsec as a spherical CVE in a vacuum.
youtu.be/Cbzthj0s44I?...
It reminds me of an old joke about oversimplifying models. We shouldn't treat appsec as a spherical CVE in a vacuum.
youtu.be/Cbzthj0s44I?...
Show notes at www.scworld.com/podcast-epis...
youtu.be/fjc2zqEFcAI?...
Show notes at www.scworld.com/podcast-epis...
youtu.be/fjc2zqEFcAI?...
Register now: qualys.brighttalk.com?utm_source=i...
#Qualys #CyberRiskSeries
Register now: qualys.brighttalk.com?utm_source=i...
#Qualys #CyberRiskSeries
And you can't spell curl without C...
@daniel.haxx.se explains how curl keeps its code secure and some of the #appsec friction it has had to deal.
youtu.be/0UavY_kKKic
And you can't spell curl without C...
@daniel.haxx.se explains how curl keeps its code secure and some of the #appsec friction it has had to deal.
youtu.be/0UavY_kKKic
It has been 0 weeks since we did not mention AI and LLMs.
But I think we added helpful angles to what a secure architecture can look like for using them and what the implications are for backdoors like BadSeek.
Show notes at www.scworld.com/podcast-epis...
youtu.be/TIxLvtCT-CE?...
It has been 0 weeks since we did not mention AI and LLMs.
But I think we added helpful angles to what a secure architecture can look like for using them and what the implications are for backdoors like BadSeek.
Show notes at www.scworld.com/podcast-epis...
youtu.be/TIxLvtCT-CE?...
In our chat about the top 10 web hacking techniques of 2024, James talked about cookies and finding inspiration for research topics.
youtu.be/8XEK3NkbKOA?...
In our chat about the top 10 web hacking techniques of 2024, James talked about cookies and finding inspiration for research topics.
youtu.be/8XEK3NkbKOA?...
Show notes: www.scworld.com/podcast-epis...
youtu.be/TIxLvtCT-CE
Show notes: www.scworld.com/podcast-epis...
youtu.be/TIxLvtCT-CE
@jameskettle.com shares his favorites from 2024, the list's importance to the web hacking community, and what inspires the kind of research it highlights.
List at portswigger.net/research/top...
youtu.be/8XEK3NkbKOA?...
@jameskettle.com shares his favorites from 2024, the list's importance to the web hacking community, and what inspires the kind of research it highlights.
List at portswigger.net/research/top...
youtu.be/8XEK3NkbKOA?...
"I view it as my job not to find all the instances of three different classes of vulnerabilities; it's to find as many different classes of vulnerabilities as I can."
www.youtube.com/clip/Ugkx0N9...
"I view it as my job not to find all the instances of three different classes of vulnerabilities; it's to find as many different classes of vulnerabilities as I can."
www.youtube.com/clip/Ugkx0N9...
We applied it to vulns in the news, with some easy ones like DeepSeek disabling ATS on iOS. But then the categories get messier...
Show notes: www.scworld.com/podcast-epis...
youtu.be/AVkucIviAnI?...
We applied it to vulns in the news, with some easy ones like DeepSeek disabling ATS on iOS. But then the categories get messier...
Show notes: www.scworld.com/podcast-epis...
youtu.be/AVkucIviAnI?...
Scott Norberg talks about his experience looking for a scanner against .NET code and why he ended up writing his own.
www.scworld.com/podcast-epis...
Scott Norberg talks about his experience looking for a scanner against .NET code and why he ended up writing his own.
www.scworld.com/podcast-epis...
deadliestwebattacks.com/appsec/2025/...
deadliestwebattacks.com/appsec/2025/...