PodcastsEducationThe Application Security Podcast

The Application Security Podcast

Chris Romeo and Robert Hurlbut
The Application Security Podcast
Latest episode

301 episodes

  • The Application Security Podcast

    Josh Grossman--AI & SAST: Is it a match?

    02/06/2026 | 40 mins.
    AI coding tools are accelerating development fast, but they’re also exposing the limits of traditional AppSec tooling. Josh Grossman, CTO of Bounce Security and longtime AppSec consultant, joins the podcast to break down AGHAST, his new open-source security tool that combines static analysis with AI to uncover business logic flaws and authorization issues that traditional scanners miss. 
    FOLLOW OUR SOCIAL MEDIA:
    ➜Twitter: @AppSecPodcast
    ➜LinkedIn: The Application Security Podcast
    ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast
    Thanks for Listening!
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • The Application Security Podcast

    Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets

    14/05/2026 | 45 mins.
    GitGuardian found 29 million hard-coded secrets leaked in public GitHub commits in a single year, a 34% jump and the biggest spike they've ever recorded. Dwayne McDaniel joins to break down why AI coding tools, MCP servers, and a false sense of security in private repos are making the problem worse, and what it'll actually take to fix it. Check out the report here - https://www.gitguardian.com/files/the-state-of-secrets-sprawl-report-2026. Dwayne McDaniel is a Principal Developer Advocate who has been on a mission to "help people figure stuff out" for over a decade. At GitGuardian, he specializes in secrets security and non-human identity governance across cloud and DevOps environments.
    FOLLOW OUR SOCIAL MEDIA:
    ➜Twitter: @AppSecPodcast
    ➜LinkedIn: The Application Security Podcast
    ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast
    Thanks for Listening!
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • The Application Security Podcast

    Tanya Janca - Secure Vibe Coding

    30/04/2026 | 47 mins.
    AI isn’t just helping developers anymore; it’s writing the code, and that changes everything. In this episode, Tanya Janca breaks down “vibe coding,” the hidden security risks behind it, and how teams need to rethink AppSec from the ground up. If you’re building with AI, this is the wake-up call you can’t afford to miss. Tanya Janca, AKA SheHacksPurple, is an author, founder, trainer, speaker, software developer, but most of all, a nerd obsessed with security. She speaks and teaches secure coding worldwide and through her podcast, DevSec Station. Check it out here: https://www.youtube.com/@DevSecStation

    FOLLOW OUR SOCIAL MEDIA:
    ➜Twitter: @AppSecPodcast
    ➜LinkedIn: The Application Security Podcast
    ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast
    Thanks for Listening!
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • The Application Security Podcast

    Caroline Wong--The AI Cybersecurity Handbook

    21/04/2026 | 44 mins.
    Caroline Wong, author of The AI Cybersecurity Handbook and Chief Strategy Officer at Axari, is back! Caroline shares how AI is rapidly changing AppSec, driving massive increases in code, accelerating risk, and challenging traditional security practices. The conversation covers AI-generated code, trust and explainability, and how security teams must adapt to keep up.
    FOLLOW OUR SOCIAL MEDIA:
    ➜Twitter: @AppSecPodcast
    ➜LinkedIn: The Application Security Podcast
    ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast
    Thanks for Listening!
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • The Application Security Podcast

    Steve Wilson--OpenClaw and Advanced AI Agents

    15/04/2026 | 49 mins.
    In this episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut welcome back Steve Wilson, a global leader in AI security and Chief AI and Product Officer at Exabeam, as well as founder of the OWASP Gen AI Security Project.

    Steve shares how his AI assistant was “hacked” using a simple phishing attack, highlighting a major shift in security—AI agents behave more like humans than traditional software. The conversation explores how this changes the threat model, why AppSec is struggling to keep up, and how organizations should approach the practical security of AI systems.

    They also cover the risks of autonomous agents, the expanding blast radius of failures, and what AppSec professionals can do now to adapt.
    FOLLOW OUR SOCIAL MEDIA:
    ➜Twitter: @AppSecPodcast
    ➜LinkedIn: The Application Security Podcast
    ➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast
    Thanks for Listening!
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
More Education podcasts
About The Application Security Podcast
Chris Romeo and Robert Hurlbut dig into the tips, tricks, projects, and tactics that make various application security professionals successful. They cover all facets of application security, from threat modeling and OWASP to DevOps+security and security champions. They approach these stories in an educational light, explaining the details in a way those new to the discipline can understand. Chris Romeo is the CEO of Devici and a General Partner at Kerr Ventures, and Robert Hurlbut is a Principal Application Security Architect focused on Threat Modeling at Aquia.
Podcast website

Listen to The Application Security Podcast, How to Be a Better Human and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features