Topics
Industry
Events
Podcasts
Research
Recognition
Leadership
Application Security WeeklySubscribe
DevOps, Hardware security, Attack surface mgmt, Bug bounties, Endpoint Security, Endpoint Security

ASW #136

January 11, 2021
Section 0

Fuzzing can be successful appsec strategy for finding software bugs. And deploying a fuzzer no longer needs to be a cumbersome process. Find out how fuzzing can help secure software beyond just memory safety issues and what the future holds for making this strategy more effective for modern apps. Visit https://www.securityweekly.com/asw for all the latest episodes!

Full Episode Show Notes

Fuzz Testing

None

Hosts

John Kinsella

John Kinsella – Chief Architect

Matt Alderman

Matt Alderman – Executive Director

Mike Shema

Mike Shema – Product Security Lead

Guests

Andrei Serban

Andrei Serban – Co-Founder

Announcements

  • Do you have a specific guest or topic that you want us to cover on one of the shows? Submit your suggestions for guests by visiting https://securityweekly.com/guests and completing the form! We review suggestions monthly and will reach out to you once reviewed!

  • Learn how to conquer cloud complexity in our first Security Weekly webcast of 2021 on January 28th @ 11am ET! Register at https://securityweekly.com/webcasts. If you missed any of our 2020 webcasts or technical trainings, they are available at https://securityweekly.com/ondemand

http://traffic.libsyn.com/sw-all/ASW_136_-_Andrei_Serban_Fuzzbuzz-0_converted.mp3
Section 1

Significant source code leak from misconfigured repo, side-channel attack on hardware authentication keys, a third bug bounty for the U.S. Army, the cost of poor software quality, the benefits of DevOps approaches to building systems. Visit https://www.securityweekly.com/asw for all the latest episodes!

Full Episode Show Notes

Google 2FA Cloning, Speed vs. Security, & “Hack The Army” Bug Bounty 3.0

None

Hosts

John Kinsella

John Kinsella – Chief Architect

Matt Alderman

Matt Alderman – Executive Director

Mike Shema

Mike Shema – Product Security Lead

Announcements

  • Do you want to stay in the loop on all things Security Weekly? Visit https://securityweekly.com/subscribe to subscribe on your favorite podcast catcher or our Youtube channel, sign up for our mailing list, and join our Discord Server!

  • If you missed Security Weekly Unlocked, you can now access all of the content on-demand, whether you registered before the live event or not, by visiting https://securityweekly.com/unlocked and clicking either the button to register or the button to login!

http://traffic.libsyn.com/sw-all/ASW_136_-_AppSec_News-0_converted.mp3

Related

Zero trust
Few IT pros say they have ‘mastered’ security in cloud-native environments

Steve ZurierMay 20, 2022

Security researchers say managing hybrid- and multi-cloud environments has become more complex than ever – and that’s why so few are confident of security in the cloud.

DevOps
CEO David Stewart talks about how Approov’s cloud-native technology protects API keys

Steve ZurierMay 19, 2022

Approov plans to expand its staff fivefold in the next few years as it focuses on using the cloud to protect API secrets for customers.

DevOps
Open Source Burnout: An opening to more security gaps?

Mike McGuire May 17, 2022

Companies need to take care of their developers – or face even more security issues down the road.

prestitial ad

About Us
SC MediaCyberRisk AllianceContact UsCareersPrivacy
Get Involved
SubscribeContribute/SpeakAttend an eventJoin a peer groupPartner With Us
Explore
Product reviewsResearchWhite papersWebcastsPodcasts

Copyright © 2022 CyberRisk Alliance, LLC All Rights Reserved This material may not be published, broadcast, rewritten or redistributed in any form without prior authorization.

Your use of this website constitutes acceptance of CyberRisk Alliance Privacy Policy and Terms & Conditions.