
Episode 319 - Vercel Breach, Security vs. Compliance, Pull Request Flows w/ AI Agents
Episode 319 covers a range of industry developments, primarily focusing on the recent Vercel security incident and the evolving landscape of...
Radio and PodcastLive Radio & PodcastsOpening Radio and Podcast...

Radio and PodcastLive Radio & PodcastsFetching podcast shows and categories...
Radio and PodcastLive Radio & PodcastsFetching podcast episodes...

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

Episode 319 covers a range of industry developments, primarily focusing on the recent Vercel security incident and the evolving landscape of...

Episode 318 examines critical vulnerabilities and the evolving impact of AI on the security industry. The episode details a recent sophistic...

Ken Johnson and Seth Law reflect on the 2026 RSA Conference and BSidesSF, noting an industry-wide "awakening" regarding the high costs and e...

In episode 316 of Absolute AppSec, hosts Ken Johnson and Seth Law participate in a crossover with Kurt Hendle and Cameron Walters from the C...

In episode 315 of Absolute AppSec, Ken Johnson and Seth Law discuss the rapidly evolving challenges of securing software in an era of AI-ass...

In this episode, the hosts discuss the seismic shift in the application security landscape triggered by the rise of Large Language Models (L...

Ken Johnson and Seth Law examine the intensifying pressure on security practitioners as AI-driven development causes an unprecedented accele...

In episode 312 of Absolute AppSec, the hosts discuss the double-edged sword of "vibe coding", noting that while AI agents often write better...

Ken Johnson and Seth Law examine the profound transformation of the security industry as AI tooling moves from simple generative models to s...

In this episode of Absolute AppSec, hosts Ken Johnson and Seth Law interview Mohan Kumar and Naveen K Mahavisnu, the practitioner-founders o...

In this episode of Absolute AppSec, Nathan Hunstad, Director of Security at Vanta, discusses the intersection of security policy, governance...

Ken Johnson (cktricky on social media) and Seth Law are happy to announce a special episode of Absolute AppSec with Avi Douglen (sec_tigger...

In episode 307 of Absolute AppSec, hosts Ken and Seth conduct a retrospective on the application security landscape of 2025. They conclude t...

Given the spate of recent npm news stories, we've arranged a topical show with software supply-chain security researcher and npm hacker Paul...

The latest episode of Absolute AppSec is here, with Ken Johnson and Seth Law checking in during the busy Q4 holiday season to share some fas...

This episode, the 304th of Absolute AppSec, features hosts Ken Johnson (@cktricky) and Seth Law (@sethlaw) discussing the crush of Q4 expect...

Prof. Brian Glas (infosecdad on social media) joins Seth Law (sethlaw) and Ken Johnson (cktricky) for a timely episode of Absolute AppSec. I...

Episode 302 of Absolute AppSec has hosts Ken Johnson and Seth Law speculating on the upcoming Global AppSec DC conference, predicting the an...

In this episode, Seth and Ken debate OpenAI's Atlas browser, which embeds AI into web browsing. Ken views it as a major privacy concern, pot...

For the 300th (!!!!) episode of the podcast, Seth and Ken reminisce on changes to the industry and overall approach to application security...

The duo is back after a short hiatus. Today's episode is inspired by recent articles related to startups, funding, and the grind that happen...

In what is (sadly) becoming a weekly segment, this episode starts with talk of the latest installment of npm package takeovers, dubbed Shai...

The Absolute AppSec duo returns with an in-depth episode talking about true and false positives, where context matters and business impact m...

Ken and Seth kickoff a podcast by reviewing current state of the OWASP Top 10 project, given recent requests and interactions on Absolute Ap...

Seth and Ken return with a new episode summarizing their experience at DEF CON 33 and all things Las Vegas over the past month. This include...

Just in time for AppSec sweeps week, Anshuman Bhartiya is joining Seth Law (sethlaw on social media) and Ken Johnson (cktricky) on the Absol...

Spurred by a recent article from Venture in Security, this episode delves deep into the practical application of security into an organizati...

Seth and Ken are _back_ to talk through some recent experiences and news across the industry. To start the episode, Seth highlights the edge...

Sean Varga, current regional sales manager with noted ASPM company Cycode joins Ken (@cktricky) and Seth (@sethlaw) to discuss the dawning r...

Ken returns after a week's hiatus to review the latest AppSec news with Seth. Specifically, the idea that authentication fatigue exists for...

With @cktricky out on a grand tour across the country (or just unable to record for the day), @sethlaw succumbs to the dark side to give @lo...

Seth and Ken return with an in-depth discussion around the future of security due to use of AI. The landscape of security is changing quickl...

Hayden Smith, Hunted Labs Co-Founder comes on Absolute AppSec to discuss, among other things, the Hunted Labs work discovering and publicizi...

We are happy to have Kayra Otaner as a special guest on the Absolute AppSec podcast. Kayra (kayraotaner on LinkedIn and X/twitter), the curr...

News this week has been dominated by dependency issues and attribution towards unwanted nation states and actors. Specifically, easyjson is...

Back after a hiatus for both BSidesSF and RSA, Seth and Ken recap their experience at both conferences. TL;DR - BSidesSF is great for techni...

Ok, so vulnerable MCP tools are a thing now? Ken demonstrates installing and running an intentionally vulnerable MCP server with a bunch of...

It is time to talk about Model Context Protocol (MCP), Google's Agent 2 Agent specification, and get back to the crocs and socks of authenti...

The duo are back for a discussion on securing machine learning models using Sigstore, based on a recent blog post from Google Security. Foll...

Seth and Ken are back with an episode dedicated to a review of the recent Next.js middleware vulnerability and how that impacts application...

After a week's hiatus, Ken and Seth return and start with a discussion on OWASP conferences and the effectiveness of attendance for vendors....

Seth and Ken return without a guest to discuss recent news, breaches, and research. Initial discussions around the purposes of the various s...

Kyle Rippee, currently staff product security engineer at Tines, joins Seth and Ken for another episode of Absolute AppSec. Kyle has over a...

Myles is currently Product Lead for Developer Platform at Snowflake. Previously, he directed project management at GitHub, overseeing projec...

Ken and Seth are back for another episode that starts with a summary of the Semgrep and OpenGrep break. This is followed by Google's recent...

Seth and Ken return for another week to review current articles and happenings in the application security world. Specifically, they spend s...

Josh Larsen, co-founder of CTO of Ghost Security, joins Seth Law and Ken Johnson on January 28th at 12 Noon Eastern time. Before Ghost Secur...

Ken and Seth start with a demo and discussion on some newer tools that use integrated AI in both the code and workflow spaces. Specifically,...

Seth and Ken return once again to talk through the overall effectiveness and purpose of Portswigger's Top 10 Web Hacking Techniques and how...

Ken and Seth return for 2025 to review the accuracy of their predictions from 2024 and make a few new ones for this new year. Some hits and...