エピソード

  • S2E2: Developer Security Training - Beyond Annual Compliance
    2025/02/03

    Season 2: Training & Awareness

    Episode 2: Developer Security Training - Beyond Annual Compliance


    In our last episode, we talked about building an effective Security Champions program. Today, we're tackling something even bigger: How to make security training actually work for developers.

    続きを読む 一部表示
    7 分
  • S2E1: Building a Security Champions Program That Actually Works
    2025/01/20

    Season 2: Training & Awareness

    Episode 1: Building a Security Champions Program That Actually Works


    In this episode we'll talk about the most important security program you're not running correctly: The Security Champions program.

    続きを読む 一部表示
    7 分
  • Season 2 Intro: Training and Awareness
    2025/01/20

    Intro to Season 2 of AppSec Unlocked


    Welcome to Season 2 where we're diving into something critical that often gets overlooked in the world of cybersecurity: Training and Awareness.

    続きを読む 一部表示
    4 分
  • Help! There’s too many Vulnerabilities! A Practical Guide to Tackling Open-Source Security
    2024/12/02

    Season 1: Open Source Security

    Episode 11: Help! There’s too many Vulnerabilities! A Practical Guide to Tackling Open-Source Security

    続きを読む 一部表示
    7 分
  • S1E10 - A FAIR Approach to Vulnerability Patch Prioritization
    2024/11/18

    Season 1: Open Source Security

    Episode 10: A FAIR Approach to Vulnerability Patch Prioritization

    In this episode of AppSec Unlocked, we dive into the fascinating topic of using a FAIR approach to Vulnerability Patch prioritization, where we explore how organizations can better prioritize vulnerabilities in their open-source software using the FAIR model and EPSS. And we have Denny Wan, an expert on FAIR analysis sharing his insights on this innovative approach.

    続きを読む 一部表示
    24 分
  • S1E9 - Open-Source Vulnerability Management Policy: A Balanced Approach
    2024/11/11

    Season 1: Open Source Security Episode 9: Open-Source Vulnerability Management Policy: A Balanced Approach

    In today's rapidly evolving cybersecurity landscape, managing vulnerabilities in open-source components has become increasingly complex. While traditional approaches relying solely on CVSS scores have their merits, they may not be sufficient to address the exponential growth in discovered vulnerabilities. A more nuanced and scalable approach is needed, one that considers not only severity but also exploitability and potential impact.

    続きを読む 一部表示
    10 分
  • S1S8 - A Cautionary Tale on Supply Chain Attacks: My Recent Encounter with a Compromised NPM Library
    2024/11/04

    Season 1: Open Source Security Episode 8: A Cautionary Tale on Supply Chain Attacks: My Recent Encounter with a Compromised NPM Library

    This is a rebroadcast from the CyberBites podcast as it is related to application security and open source supply chain.

    続きを読む 一部表示
    6 分
  • S1E7 - Introduction to SSVC
    2024/10/21

    Season 1: Open Source Security Episode 7: Introduction to StakeholderSpecific Vulnerability Categorization (SSVC)


    Introduction to a transformative risk-based approach to vulnerability management

    • Why SSVC, especially when we already have CVSS
    • How SSVC works and how to use it
    • Challenges and considerations
    • Real-world example
    続きを読む 一部表示
    9 分