Skip to content
PodcastsEducationThe Application Security Podcast

The Application Security Podcast

Chris Romeo and Robert Hurlbut
The Application Security Podcast
Latest episode

304 episodes

  • The Application Security Podcast

    Isaac Evans - AppSec in the Age of AI

    28/07/2026 | 49 mins.
    Send us Fan Mail
    In this episode, we sit down with Isaac Evans, co-founder and CEO of Semgrep, to talk about how AI is reshaping application security faster than almost anyone expected. Isaac walks us through why CI is losing its place as the central security control point, replaced by deep background jobs that hunt for vulnerabilities using large models and real-time plugins that sit inside coding agents and force them to regenerate code until it meets an organization's security bar. We dig into what this means for the role of the security engineer, why customization is replacing universal rule sets, and how trust, verification, and the limits of reasoning about model behavior remain the hardest problems in the room. We also talk about vibe coding at scale, the return of business logic flaws as SQL injection becomes easier for models to catch, and why Isaac sees more opportunity than threat in this shift, even as he expects a wave of new vulnerabilities and cleanup work along the way.

    FOLLOW OUR SOCIAL MEDIA:
    āžœTwitter: @AppSecPodcast
    āžœLinkedIn: The Application Security Podcast
    āžœYouTube: https://www.youtube.com/@ApplicationSecurityPodcast
    Thanks for Listening!
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • The Application Security Podcast

    JosƩ Carlos ChƔvez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists

    21/07/2026 | 52 mins.
    Send us Fan Mail
    In this episode, we sit down with Jose Carlos Chavez from Okta to break down the OWASP Top 10 for 2025 and what actually changed since 2021. We trace Jose's path from software engineering and observability into security, dig into why broken access control still holds the number one spot despite mature tooling, and ask the question that never seems to get old: why is injection still a top five risk after decades of parameterized queries and ORMs? Jose walks us through the growing role of supply chain and software integrity failures, the surprisingly weak security posture around AI skills and agent permissions, and why immutable, reliable logging still matters as much as ever. We close on root causes that show up across nearly every category on the list and why ownership, not tooling alone, is what actually moves the needle on security.
    FOLLOW OUR SOCIAL MEDIA:
    āžœTwitter: @AppSecPodcast
    āžœLinkedIn: The Application Security Podcast
    āžœYouTube: https://www.youtube.com/@ApplicationSecurityPodcast
    Thanks for Listening!
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • The Application Security Podcast

    Michael Burch - AI-Enabled Citizen Developers

    16/06/2026 | 48 mins.
    Send us Fan Mail
    AI adoption is accelerating faster than most organizations know how to handle it, and the gap between curiosity and confident use is where things go wrong. Michael Burch, VP of AI Enablement and Acceleration, joins to break down what it actually takes to move teams from "interested in AI" to using it responsibly and effectively in their day-to-day work. He shares why successful adoption depends less on the technology itself and more on trust, clear guidance, and making AI approachable for non-technical teams. Whether you are leading an AI initiative or just trying to figure out where to start, this episode is a practical look at what real adoption looks like inside organizations today.
    FOLLOW OUR SOCIAL MEDIA:
    āžœTwitter: @AppSecPodcast
    āžœLinkedIn: The Application Security Podcast
    āžœYouTube: https://www.youtube.com/@ApplicationSecurityPodcast
    Thanks for Listening!
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • The Application Security Podcast

    Josh Grossman--AI & SAST: Is it a match?

    02/06/2026 | 40 mins.
    Send us Fan Mail
    AI coding tools are accelerating development fast, but they’re also exposing the limits of traditional AppSec tooling. Josh Grossman, CTO of Bounce Security and longtime AppSec consultant, joins the podcast to break down AGHAST, his new open-source security tool that combines static analysis with AI to uncover business logic flaws and authorization issues that traditional scanners miss.Ā 
    FOLLOW OUR SOCIAL MEDIA:
    āžœTwitter: @AppSecPodcast
    āžœLinkedIn: The Application Security Podcast
    āžœYouTube: https://www.youtube.com/@ApplicationSecurityPodcast
    Thanks for Listening!
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • The Application Security Podcast

    Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets

    14/05/2026 | 45 mins.
    Send us Fan Mail
    GitGuardian found 29 million hard-coded secrets leaked in public GitHub commits in a single year, a 34% jump and the biggest spike they've ever recorded. Dwayne McDaniel joins to break down why AI coding tools, MCP servers, and a false sense of security in private repos are making the problem worse, and what it'll actually take to fix it. Check out the report here - https://www.gitguardian.com/files/the-state-of-secrets-sprawl-report-2026. Dwayne McDaniel is a Principal Developer Advocate who has been on a mission to "help people figure stuff out" for over a decade. At GitGuardian, he specializes in secrets security and non-human identity governance across cloud and DevOps environments.
    FOLLOW OUR SOCIAL MEDIA:
    āžœTwitter: @AppSecPodcast
    āžœLinkedIn: The Application Security Podcast
    āžœYouTube: https://www.youtube.com/@ApplicationSecurityPodcast
    Thanks for Listening!
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
More Education podcasts
About The Application Security Podcast
Chris Romeo and Robert Hurlbut dig into the tips, tricks, projects, and tactics that make various application security professionals successful. They cover all facets of application security, from threat modeling and OWASP to DevOps+security and security champions. They approach these stories in an educational light, explaining the details in a way those new to the discipline can understand. Chris Romeo is the CEO of Devici and a General Partner at Kerr Ventures, and Robert Hurlbut is a Principal Application Security Architect focused on Threat Modeling at Aquia.
Podcast website

Listen to The Application Security Podcast, The Mel Robbins Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Social
v8.13.0Ā | Ā© 2007-2026 radio.de GmbH
Generated: 8/11/2026 - 3:29:57 PM