Skip to content
zeno
Create a Station
Explore
Podcasts
Audiobooks
Bible
By Genre
By Location
By Language
Religious
Music
News
Download App
Opens in a new window
Toggle Sidebar
zeno
Mike Shema
Application Security Weekly (Audio)
Technology
Tech News
English
About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.
Website
Episodes
Episodes
300
29 September 2026
Going From Bug Bounty Bugs to More Secure Systems - Shlomie Liberow - ASW #402
Finding flaws with LLMs and agents is changing bug bounty programs. But it's not necessarily changing how orgs fix those flaws. Shlomie Liberow shares his experience across a decade of bounty programs and how they have changed for researchers and orgs. He explains why fixing the bug reported through a bug bounty is more about understanding interconnected systems than fixing a single piece of...
1 h 2 min
22 September 2026
Understanding Prompt Injection In Order to Contain It - Julie Brunias - ASW #401
Prompt injection demonstrates one of the major challenges in securing LLMs and agents -- how do you ensure an agent ignores attackers and only does what you instructed it to do. The flaw highlights how LLMs mix inputs, context, and outputs without any strict boundaries between them. Julie Brunias joins us to talk through examples of injections, why their consequences can go beyond information...
1 h 0 min
15 September 2026
The AI Threat Multiplier: Securing Mobile Apps in the Automated Era - Ryan Lloyd, Jason Cortlund - ASW #400
While agents and LLMs haven't fundamentally changed core mobile vulnerability types, they have supercharged speed, scale, and accessibility—democratizing threats like automated phishing, synthetic identity fraud, and easier identification of hard-coded secrets. Ryan Lloyd and Jason Cortlund break down how threat actors leverage LLMs as a force multiplier to accelerate mobile app attacks. Then we...
52 min
08 September 2026
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Ido Geffen, Sean Murphy, Idan Plotnik - ASW #399
We showcase recordings from this year's Black Hat. The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of the trust and security controls applied to traditional software. Michael Leland discusses Island's research uncovering...
1 h 9 min
01 September 2026
Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398
AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective...
1 h 8 min
25 August 2026
Applying Zero Trust Principles to Agents - Kieran Human - ASW #397
Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of the properties that a good sandbox should have and how monitoring creates a feedback loop to refine allow lists and...
1 h 6 min
18 August 2026
Augmenting Threat Intel Analysis with Agents - Chris Wallis, Sai Kiran Uppu, Ramin Farassat - ASW #396
All sorts of cybersecurity disciplines are adopting agents to help humans save time and automate routine activities. Sai Kiran Uppu describes his work on creating a platform for agents to analyze external threat intel, examine internal systems, and present triage decisions to operators. This type of work is especially useful to orgs that deal with petabytes of data and thousands of systems. And,...
1 h 9 min
11 August 2026
Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395
Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity,...
1 h 9 min
04 August 2026
Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394
There's already an increase in volume of security flaws found by LLMs. And orgs are already turning to LLMs to write code. So, what happens when orgs lean on LLMs to create patches for those security flaws? Keith Hoodlet gives an exclusive early look at his team's recent research into the success, quality, and failures of LLM-generated security patches. Notably, they saw scenarios across a...
1 h 3 min
28 July 2026
Inside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393
Orgs need to be able to use agents, MCPs, and LLMs in ways that don't lead to unexpected actions and undesirable outcomes. The OWASP Agent Security Regression Harness project is an approach for defining customizable scenarios and testing whether those systems fail against known security threats. Mert Saltimaz talks about the background of the project, how orgs can use it as they bring more LLMs...
1 h 9 min