DevCentral
AppSec Now
AppSec Now is a podcast aimed at delivering the top stories from the latest (mosttly application) security news and interesting guests from the application security community.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Tackling CVE Chaos, Parquet Tool Insights, and EU Cyber Resilience Act Unpacked 28.04.2025 30:46
🔒 Welcome to this week’s episode of AppSecNow , the DevCentral podcast dedicated to all things application security! 🚨 This week, we unpack critical updates including: 💥 A zero-day SAP CVE with a CVSS score of 10—what it means, how it's being exploited, and what you can do to defend against it. 🛠️ A groundbreaking Parquet tool from F5 Labs that simplifies vulnerability testing for critical...
EV Car Hacking, AI-Generated Passports, & Japan’s Active Cyber Defense Bill 21.04.2025 36:06
Join Merlyn Chase, MegaZone, and Aubrey on this week’s AppSec Now podcast as they dive into the latest topics in application security! 🚀 From the recent B-Sides Seattle conference to critical discussions on EV car hacking, cybersecurity quandaries, AI-generated passports bypassing KYC, and Japan’s groundbreaking Active Cyber Defense Bill—you don’t want to miss this one. Plus, learn how AppSecNow...
Amazon EC2 SSRF Breach, Oracle Cloud Breach & Malicious NPM Packages Exposed 14.04.2025 35:08
Join our AppSec experts—Merlyn, Malcolm, MegaZone, and host Chase Abbott—as they dig into some of the latest stories shaking up the cybersecurity world. This week's AppSec Now explores an active campaign targeting Amazon EC2 instance metadata via SSRF vulnerabilities, and why that's a wider-reaching problem than you might think. We discuss Oracle's controversial handling of their cloud breach and...
NGINX Kubernetes IngressNightmare, Critical Next.js CVE, Chrome Zero Day - Ep.32 07.04.2025 31:22
Dive into the latest episode of AppSecNow, where we break down the Ingress Nightmare vulnerability impacting NGINX and Kubernetes environments, plus the implications of a critical CVE in Next.js, one of the most widely-used JavaScript frameworks with 9 million weekly downloads. Join Aubrey, Chase, and Merlyn for expert analysis on the security landscape, from Chromium Zero Day concerns to ransomwa...
Vibe Coding, F5 Labs Bot Report, Google Buys Wiz And More | AppSec Now Ep 31 31.03.2025 45:13
Welcome to the 31st episode of AppSec Now! This week, our hosts Aubrey, David Warburton, Chase Abbott, and MegaZone get into some hot topics in the world of application security. Our focus is on the latest F5 Labs Advanced Persistent Bots report, highlighting the ever-evolving landscape of bot attacks and the importance of robust mitigation strategies. We analyze Google's hefty $32 million acq...
Latest AppSec Threats: Coinbase Phishing, BRUTED, OBSCURE#BAT, KoSpy And More! 24.03.2025 36:47
Join us for the thirtieth episode of AppSecNow, a DevCentral podcast dedicated to the latest trends and threats in the application security (AppSec) world. In this episode, host Aubrey King is joined by Malcolm Heath, Chase Abbott, and MegaZone to dive into recent security incidents and developments, including a detailed analysis of the Coinbase phishing scam, the resurgence of user-mode rootkits...
Latest in AppSec: Apache Camel RCE, X DDoS, Silk Typhoon, and Encryption Debates 18.03.2025 33:00
Welcome to the latest episode of AppSec Now, a DevCentral podcast dedicated to the ever-evolving world of application security. In this episode, Chase takes the reins while Aubrey is away, joined by Malcolm Heath, a principal researcher at F5 Labs, and the illustrious MegaZone, a principal security engineer on the SIRT team. We dive deep into the recent Apache Camel remote code execution vulnerabi...
Exploring CISA Layoffs, Microsoft's Quantum Chip, MongoDB Vulnerabilities & More 03.03.2025 27:33
Join Aubrey, MegaZone, and Merlyn in this week's episode of AppSec Now as they dive into the latest in application security. This week, we discuss Microsoft's groundbreaking Majorana One chip, capable of scaling up to a million qubits and its potential impact on quantum computing. We also explore the recent critical vulnerabilities in MongoDB libraries and OpenSSH, analyzing their implicat...
Understanding The TikTok Ban, Salt Typhoon And More | AppSec Monthly January Ep.27 31.01.2025 34:43
In this episode of AppSec Monthly, join our host, MegaZone, joined by Malcolm Heath, Merlyn Albery-Speyer and Aubrey King, as they dive into the latest cybersecurity news. We explore the complexities of the TikTok ban, the impact of geopolitical decisions on internet freedom, and the nuances of data sovereignty. Our experts also discuss the implications of recent breaches by Chinese state actors a...
Cybersecurity Predictions 2025: Insights from F5 Labs | December Special AppSec Monthly Ep.26 30.12.2024 1:08:31
Welcome to our special year-end episode of AppSec Monthly, a DevCentral podcast! In this exciting edition, we join forces with the experts at F5 Labs to bring you our highly anticipated cybersecurity predictions for the year ahead. Our panel, including David Warburton, Aubrey King, and Megazone, dives deep into the trends and emerging threats that are set to shape the cybersecurity landscape in 20...
Episode 25 - November 2024 - F5 Labs Black Friday Report, 2025 OWASP LLM Apps Top 10 And More 30.11.2024 1:03:25
Welcome to the latest episode of AppSec Monthly! In this episode, we delve into IT policies, recent cybersecurity trends, and sophisticated attack detection with industry experts David Warburton, Malcolm Heath, and MegaZone. Special guests Adeolu and Shuang from F5 Labs share their latest research on Black Friday shopping trends, automation, and bot attacks, providing insights into the types of bo...
Episode 24 - October 2024 - F5 Labs APIWorld CTF, CUPS & Hyundai Vulnerabilities And More 05.11.2024 32:21
Welcome to another exciting episode of AppSec Monthly, brought to you by DevCentral! This month, we dive deep into various aspects of application security with contributions from Aaron Brailsford, Malcolm Heath, and MegaZone! We discuss the importance of integrating security early in the development process, the critical role of trust in cybersecurity, and the recent buzz around CUPS vulnerabiliti...
Episode 23 - July 2024 - F5 Labs DDoS Report, CrowdStrike 06.08.2024 1:11:20
After a small summer break, the gang's back and talking DDoS with F5 Labs' new DDoS Report. David Warburton lays it all out for us after a healthy dose of news with Aaron Brailsford, Malcolm Heath and, for the first time, MegaZone! Tune in for this action packed episode 23 for July of 2024!
Episode 22 - May 2024 - Security Authoring, Speaking At RSAC 31.05.2024 52:08
In May of 2024, Aubrey King, from DevCentral, went to #RSAC. While there, he got a chance to hook up with Steve Wilson and Ken Huang to talk about security authoring - 'how to get going' and 'what's the process like?' - before catching up with Akira Brand, who talks about speaking at RSA and more! It's an action packed Episode 22 before we even get to our roundtable, where...
Episode 21 - April 2024 - How AI Changes The Game For Red And Blue Teamers 30.04.2024 57:15
In Episode 21, we change our name! Welcome AppSec Monthly, goodbye This Month In Security. In addition to that new in April of 2024, DevCentral's Aubrey King catches up with Semgrep's Jonathan Werrett to talk about how the AI phenomenon changes the game for Red and Blue Teamers out there in the security world. Also, Aubrey catches up with DevCentral OG, Peter Silva, to talk about 5g securi...
Episode 20 - March 2024 - APISec University's 2024 API Security Market Review 29.03.2024 1:00:51
DevCentral's Aubrey King is joined by Dave Warburton, Malcolm Heath and Aaron Brailsford this month for the roundtable and he shares a conversation with Dan Barahona about the APISec University 2024 API Security Market Review they just published and shares the news about APISec Con, coming up on May 22. There's also a teaser of an #AppWorld2024 AI API Security panel conversation between Au...
Episode 19 - February 2024 - AI App Security For IoT Edge Devices 01.03.2024 41:10
In Episode 19 of This Month In Security, Aubrey King catches back up with Tashaffi Samin Yeasar to talk about her daily grind and an IoT coder who's using AI at the edge and some of the security implications of Edge AI. Also, Byron McNaught jumps into the monthly roundtable with Aaron Brailsford and David Warburton, where they talked a bit about AI and deepfakes, as well as some of the latest...
Episode 18 - Jan 2024 - From SBOM To WAF Policy 31.01.2024 59:30
This Month In Security, Aubrey King gets to talk to DevCentral MVP Daniel Wolf about how he recommends customers build WAF policy from SBOM. Aaron Brailsford shares the roundtable with Malcolm Heath and Sander Vinberg. Also, we get a sample from This Week In Security.
Bonus: This Week In Security Jan 15 - 21 2024 - Ancient VMWare Exploit, 37C3 Videos And More! 26.01.2024 2:13
This week in security, our editor is AaronJB, who brings news of a VMWare exploit that might be older than Aubrey! Also, countless exploits and some amazing videos from The 37th Chaos Communication Congress. Read the full article here: https://community.f5.com/t5/technical-articles/time-to-exploit-and-large-scale-breaches-jan-15th-21st-2024-f5/ta-p/327201 This Week In Security is a contribution to...
Bonus: This Week In Security Jan 7 - 14 2024 - Github Runner Poisoning, F-Bot, Hadoop Attacks 24.01.2024 2:04
This Week In Security, our editor is Jordan_Zebor, who shows the community about Github's Runner Poisoning, a cloud threat called F-Bot and an attack on Hadoop! Read the full article here: https://community.f5.com/t5/technical-articles/compromised-ci-cd-fbot-and-hadoop-attacks-jan-7th-14th-2023-f5/ta-p/326973 This Week In Security is a contribution to DevCentral by the F5 Security Incident Res...
Bonus: This Week In Security Jan 1 - 5 2024 - Gmail Guidelines, GPS Spoofing And More 22.01.2024 1:41
This Week In Security, our editor was Koichi and he brings us news about a faked public website, new Gmail Sender Guidelines, a GPS Spoofing attack and the OWASP Top 10 For Large Language Model Applications. Read the full article here: https://community.f5.com/t5/technical-articles/fake-website-gmail-guideline-gps-spoofing-owasp-llm-jan-1st-5th/ta-p/326724 This Week In Security is a contribution t...
Episode 17 - Dec. - 2023 Look Back, F5 Labs 2024 Predictions Report 11.01.2024 54:25
Aubrey King recaps 2023 in a look back for the podcast before he's joined by Aaron Brailsford, Malcolm Heath and David Warburton to go over the F5 Labs 2024 Predictions report. Happy New Year to all of our listeners and viewers out there!
Bonus: This Week In Security Dec. 10 - Dec. 17 - Play Ransomware, OpenSSH 9.6, Google Privacy 11.01.2024 2:10
This Week In Security, our editor was Nagi, who filled us in on the Play Ransomware Advisory, the OpenSSH 9.6 release, the latest Bruce Schneier essay, Google's ending of geofence warrants via Google Maps and so much more! Read the full article here: https://community.f5.com/t5/technical-articles/ransomware-openssh-ai-and-trust-google-geofence-dec-10-17-2023/ta-p/325857 This Week In Security i...
Bonus: This Week In Security Dec. 3 - Dec. 10 - HuggingFace API Token Exposure, Glass Storage 11.01.2024 2:01
This Week In Security for 11/27-12/3, 2023, can be found on F5 DevCentral here: https://community.f5.com/t5/technical-articles/exposed-hf-api-tokens-hacks-ms-news-dec-3-10-2023-f5-sirt-this/ta-p/325561 This Week In Security is a contribution to DevCentral by the F5 Security Incident Response Team and you can find it in our Technical Articles section every week.
Bonus: This Week In Security Nov. 20 - Nov. 26, 2023: MeridianLink Attack, MOVEit Look Back & More 11.01.2024 1:51
This Week In Security for 11/20-11/26, 2023, can be found on F5 DevCentral here: https://community.f5.com/t5/technical-articles/once-more-with-feeling-nov-20-26-2023-f5-sirt-this-week-in/ta-p/324985 This Week In Security is a contribution to DevCentral by the F5 Security Incident Response Team and you can find it in our Technical Articles section every week.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.