Rephonic
Artwork for Application Security Weekly

Application Security Weekly (Audio)

Mike Shema
Application Security
Cybersecurity
Generative AI
Devops
Open Source Software
Threat Modeling
Llms
Vulnerability Management
Software Development
Supply Chain Security
Zero Trust
Software Supply Chain Security
OWASP Genai Security Project
Appsec
Artificial Intelligence
Cloud Security
Large Language Models
Vulnerabilities
Bug Bounty Programs
API Security

About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

PublishesWeeklyEpisodes407Founded9 years ago
Number of ListenersCategories
Tech NewsTechnologyNews

Listen to this Podcast

Artwork for Application Security Weekly

Latest Episodes

Orgs need to be able to use agents, MCPs, and LLMs in ways that don't lead to unexpected actions and undesirable outcomes. The OWASP Agent Security Regression Harness project is an approach for defining customizable scenarios and testing whether thos... more

Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from W... more

While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order to help orgs understand and pr... more

Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'll dive into some of these def... more

Key Facts

Accepts Guests
Accepts Sponsors
Contact Information
Podcast Host
Number of Listeners
Find out how many people listen to this podcast per episode and each month.

Similar Podcasts

People also subscribe to these shows.

Recent Guests

Mert Saltimaz
Founder of Sec Portal; project lead for OWASP Agent Security Regression Harness
Sec Portal / OWASP
Episode: Inside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393
Patrick Wardle
Co-founder of the Objective-C Foundation, CEO and co-founder of [organization], author of The Art of Mac Malware
W and Objective-C Foundation
Episode: MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
Jeremy Snyder
Founder and CEO of firetail.io
firetail.io
Episode: Discovering & Securing Your AI Agent Attack Surface - Jeremy Snyder - ASW #391
Ryan Lloyd
Chief Product Officer, Guardsquare
Guardsquare
Episode: Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390
Itamar Apelblat
Co-founder and CEO at Token Security
Token Security
Episode: Reducing Attack Surface & Evaluating Efficiency in Agents - Itamar Apelblat, David Goldschlag - ASW #389
David Goldschlag
CEO and co-founder at Aembit
Aembit
Episode: Reducing Attack Surface & Evaluating Efficiency in Agents - Itamar Apelblat, David Goldschlag - ASW #389
Ev Kontsevoy
Co-founder and CEO of Teleport
Teleport
Episode: How AI Is Reshaping Identity Security at the Infrastructure Layer - Amit Masand, Neha Duggal, Ev Kontsevoy - ASW #388
Neha Duggal
Chief Product Officer at P0 Security
P0 Security
Episode: How AI Is Reshaping Identity Security at the Infrastructure Layer - Amit Masand, Neha Duggal, Ev Kontsevoy - ASW #388
Amit Masand
Founder and CEO at IDM Express
IDM Express
Episode: How AI Is Reshaping Identity Security at the Infrastructure Layer - Amit Masand, Neha Duggal, Ev Kontsevoy - ASW #388

Hosts

Mike Shema
Host focusing on application security, secure coding, and industry trends; frequently discusses SDLC, threat modeling, and tooling.
John Kinsella
Co-host who covers AppSec news, industry insights, and practical guidance for developers and security teams.

Reviews

4.7 out of 5 stars from 23 ratings
  • Yes

    It’s the best.

    Apple Podcasts
    5
    Alpha Gay
    United Statesa year ago
  • Great show

    Amazing show with great news and tips on making sure you code is secure.

    Apple Podcasts
    5
    DMLou
    United States4 years ago
  • One of the best podcast on planet 👍

    One of the best podcast on planet 👍

    Mike and john are the best and most funny host I had the pleasure dealing with.

    Also level of knowledge and precision is unbeatable

    Apple Podcasts
    5
    Fracipo
    United Kingdom4 years ago
  • Great show

    Best show I’ve found so far related to AppSec

    Apple Podcasts
    5
    jrod d
    United States5 years ago
  • Keith fails again

    Clearly doesn’t know or understand java but still keeps yapping regardless. And don’t get me started on the gdpr episode... so much misinformation and stupidity in one location is rare.

    Apple Podcasts
    1
    quasi42
    Denmark8 years ago

Listeners Say

Key themes from listener reviews, highlighting what works and what could be improved about the show.

Guests bring strong industry context and hands-on perspectives.
One reviewer notes misinformation on a certain episode; overall sentiment remains strongly positive.
Show blends humor with serious security topics, which listeners appreciate.
Audience consistently praises practical security guidance and deep technical dives.

Top Technology Podcasts

Tomorrow, Today
Tomorrow, TodayShekhar Natarajan
Acquired
AcquiredBen Gilbert and David Rosenthal
Hard Fork
Hard ForkThe New York Times
The Room Podcast
The Room PodcastClaudia Laurie and Madison McIlwain

Talking Points

Recent interactions between the hosts and their guests.

MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
Q: How do Apple's design choices impact malware development and defense?
Apple's notarization, kernel-space decisions, and privacy focus shape both attacker techniques and defender tools. Notarization acts as a gatekeeper, but complex inter-team handoffs can create blind spots; hardware and memory protection features also enable more secure defenses and encourage safer development practices.
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
Q: What attracted you to Mac OS malware research and what makes macOS malware unique compared to Windows?
Wardle explains that attackers target platforms with growing market share; macOS malware is evolving with both ported Windows techniques and new Mac-native capabilities, especially as macOS gains enterprise prominence. He notes the diversification of payloads and the need to understand platform-specific defenses.
Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390
Q: How do attackers exploit reverse engineering, and what defense does Guardsquare emphasize?
Attackers exploit exposed business logic via reverse engineering, so defense centers on obfuscation, runtime threat signals, and polymorphic checks that evolve with each app build to maintain the attacker's cost and reduce attack surface.
Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390
Q: What is the key approach to balancing security with user experience in mobile apps?
Adopt a layered, risk-based strategy that applies the most rigorous protections only to the most security-sensitive areas, while leveraging server-side attestation to reduce exposure and preserve performance and UX.
The State of AI & AppSec - Keith Hoodlet - ASW #383
Q: What is misalignment in the context of LLMs and mobile app security, and why does it matter?
Misalignment refers to AI agents acting in ways that can look like security or hacking behavior, which can trigger false positives or reveal real vulnerabilities. It matters because it necessitates new threat models and secure harnessing practices to keep automated systems from creating or missing security issues.

Audience Metrics

Listeners, social reach, demographics and more for this podcast.

Listeners per Episode
Gender Skew
Location
Interests
Professions
Age Range
Household Income
Social Media Reach

Frequently Asked Questions About Application Security Weekly

What is Application Security Weekly about and what kind of topics does it cover?

This show centers on application security, DevSecOps, and modern security tooling, with frequent focus on AI/GenAI's impact on secure software development, threat modeling, and secure SDLC practices. Episodes often feature hands-on discussions about vulnerability research, supply chain risk, agent-based security, and governance frameworks like OWASP GenAI and SPVS. A standout is the ongoing integration of AI into security workflows, including guardrails for non-human identities, proactive security strategies, and practical playbooks for engineers and CISOs alike. The format typically blends technical deep-dives with real-world case studies, conference takeaways, and community-driven tooling insights, making it valuable for practitioners who... more

Where can I find podcast stats for Application Security Weekly?

Rephonic provides a wide range of podcast stats for Application Security Weekly. We scanned the web and collated all of the information that we could find in our comprehensive podcast database. See how many people listen to Application Security Weekly and access YouTube viewership numbers, download stats, audience demographics, chart rankings, ratings, reviews and more.

How many listeners does Application Security Weekly get?

Rephonic provides a full set of podcast information for three million podcasts, including the number of listeners. View further listenership figures for Application Security Weekly, including podcast download numbers and subscriber numbers, so you can make better decisions about which podcasts to sponsor or be a guest on. You will need to upgrade your account to access this premium data.

What are the audience demographics for Application Security Weekly?

Rephonic provides comprehensive predictive audience data for Application Security Weekly, including gender skew, age, country, political leaning, income, professions, education level, and interests. You can access these listener demographics by upgrading your account.

How many subscribers and views does Application Security Weekly have?

To see how many followers or subscribers Application Security Weekly has on Spotify and other platforms such as Castbox and Podcast Addict, simply upgrade your account. You'll also find viewership figures for their YouTube channel if they have one.

Which podcasts are similar to Application Security Weekly?

These podcasts share a similar audience with Application Security Weekly:

1. The Application Security Podcast
2. CyberWire Daily
3. Risky Bulletin
4. SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
5. Security Now (Audio)

How many episodes of Application Security Weekly are there?

Application Security Weekly launched 9 years ago and published 407 episodes to date. You can find more information about this podcast including rankings, audience demographics and engagement in our podcast database.

How do I contact Application Security Weekly?

Our systems regularly scour the web to find email addresses and social media links for this podcast. We scanned the web and collated all of the contact information that we could find in our podcast database. But in the unlikely event that you can't find what you're looking for, our concierge service lets you request our research team to source better contacts for you.

Where can I see ratings and reviews for Application Security Weekly?

Rephonic pulls ratings and reviews for Application Security Weekly from multiple sources, including Spotify, Apple Podcasts, Castbox, and Podcast Addict.

View all the reviews in one place instead of visiting each platform individually and use this information to decide if a show is worth pitching or not.

How do I access podcast episode transcripts for Application Security Weekly?

Rephonic provides full transcripts for episodes of Application Security Weekly. Search within each transcript for your keywords, whether they be topics, brands or people, and figure out if it's worth pitching as a guest or sponsor. You can even set-up alerts to get notified when your keywords are mentioned.

What guests have appeared on Application Security Weekly?

Recent guests on Application Security Weekly include:

1. Mert Saltimaz
2. Patrick Wardle
3. Jeremy Snyder
4. Ryan Lloyd
5. Itamar Apelblat
6. David Goldschlag
7. Ev Kontsevoy
8. Neha Duggal

To view more recent guests and their details, simply upgrade your Rephonic account. You'll also get access to a typical guest profile to help you decide if the show is worth pitching.

Find and pitch the right podcasts

We help savvy brands, marketers and PR professionals to find the right podcasts for any topic or niche. Get the data and contacts you need to pitch podcasts at scale and turn listeners into customers.
Try it free for 7 days