Rephonic
Artwork for Application Security Weekly

Application Security Weekly (Video)

Mike Shema
Application Security
Cybersecurity
Generative AI
Artificial Intelligence
Devops
Threat Modeling
OWASP
Large Language Models
Fuzzing
SQL Injection
Appsec
OWASP Top 10
Ransomware
Supply Chain Security
Open Source Software
CISA
Devsecops
Vulnerability Management
Software Supply Chain Security
Apis

About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

PublishesWeeklyEpisodes715Founded8 years ago
Number of ListenersCategories
NewsTech NewsTechnology

Listen to this Podcast

Artwork for Application Security Weekly

Latest Episodes

Appsec has seen machine identities from daemons and processes to services, microservices, and cloud accounts. And now we have agents. Ev Kontsevoy talks about what it means to have engineers and agents interacting in an environment, and why a focus o... more

YouTube

Agents and LLMs are creating and reviewing code. They're a new tool to help developers write software and they're a new abstraction layer for expressing what code should do. But if we're focused on determining whether code is secure, where do we focu... more

YouTube

Most AppSec teams are working through more findings than their teams can validate. SAST surfaces thousands of potential issues. DAST generates alert volume that outpaces triage capacity. Somewhere in that output are the vulnerabilities that matter, t... more

YouTube

We dedicate an episode to catching up on appsec news with Kalyani Pawar. We see parsing problems that led to the BadHost vuln, which exposed lots of LLMs, MCPs, and agents to potential compromise. We wonder where to look for security education and pr... more

YouTube

Key Facts

Accepts Guests
Accepts Sponsors
Contact Information
Podcast Host
Number of Listeners
Find out how many people listen to this podcast per episode and each month.

Similar Podcasts

People also subscribe to these shows.

Recent Guests

Federico Kirschbaum
Head of the XBOW Security Lab; cybersecurity expert
XBOW
Episode: Scanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386
Scott Clinton
Co-chair and co-founder of OWASP GenAI Security Project
OWASP GenAI Security Project
Episode: AppSec Conversations on Agents, LLMs, and OWASP from RSAC - Scott Clinton, Janet Worthington, Merritt Maxim - ASW #384
Merritt Maxim
VP Research Director at Forrester
Forrester
Episode: AppSec Conversations on Agents, LLMs, and OWASP from RSAC - Scott Clinton, Janet Worthington, Merritt Maxim - ASW #384
Rob Allen
Chief Product Officer at ThreatLocker
ThreatLocker
Episode: Why Basic Security Practices Still Work - Rob Allen - ASW #382
James Kettle
Director of Research at PortSwigger
PortSwigger
Episode: Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 - James Kettle - ASW #380
Gwyddon Data Owen
Retired Air Force Cyber Warfare Officer; Director of Cybersecurity and Technology for Universal Strategy Group
Universal Strategy Group
Episode: The Human Aspect of Red Teams - Brian Fox, Tom Tovar, T. Gwyddon 'Data' Owen - ASW #379
Tom Tovar
CEO at Appdome
Appdome
Episode: The Human Aspect of Red Teams - Brian Fox, Tom Tovar, T. Gwyddon 'Data' Owen - ASW #379
Cameron Walters
Director of Application Security and Security Engineering
Unknown (OWASP SPVS project co-lead)
Episode: Securing Software's Journey with the OWASP SPVS - Cameron W., Farshad Abasi, Rohan Ravindranath, Ido Geffen - ASW #378
Rohan Ravindranath
Founder/CEO at Zappsec
Zappsec
Episode: Securing Software's Journey with the OWASP SPVS - Cameron W., Farshad Abasi, Rohan Ravindranath, Ido Geffen - ASW #378

Hosts

Mike Shema
Host of the show
John Kinsella
Co-host

Reviews

4.9 out of 5 stars from 8 ratings
  • Occasional good content

    Keith occasionally has something worth saying, but he lacks solid experience with hardcore software development, and knows almost nothing about lean/agile. He approaches software like an operations problem.

    Paul is unpleasant to listen to and seldom adds anything of value. I wouild not listent to this podcast at all if Paul was the only contributor.

    This week's episode is particularlt vexing, as the bros bray on about American Football. Please find another forum for that. Your listeners are he... more

    Apple Podcasts
    2
    jdtangney
    United States7 years ago

Listeners Say

Key themes from listener reviews, highlighting what works and what could be improved about the show.

Overall, strong technical depth and timely topics, but some listeners want deeper hardcore AppSec focus.
Guests are generally solid experts though pacing and chemistry can vary by episode.
Audiences may seek more examples and measurable outcomes from episodes.
Content is highly relevant for teams building secure software in AI-enabled environments.
Sponsors help bring practical tooling discussions but may color some segments.

Chart Rankings

How this podcast ranks in the Apple Podcasts, Spotify and YouTube charts.

Apple Podcasts
#250
United Kingdom/News/Tech News
Apple Podcasts
#245
Australia/News/Tech News
Apple Podcasts
#29
Finland/News/Tech News
Apple Podcasts
#29
Philippines/News/Tech News
Apple Podcasts
#79
Norway/News/Tech News
Apple Podcasts
#93
Switzerland/News/Tech News

Talking Points

Recent interactions between the hosts and their guests.

Scanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386
Q: What role do humans play when LLMs are doing the heavy lifting?
Humans provide creativity, judgment, and the ability to set strategic targets and interpret results; LLMs handle large-scale triage, recall, and systematic exploration, while humans guide direction and validate outcomes.
Scanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386
Q: Federico, how do you see vuln research changing with the advent of LLMs and harnesses?
LLMs plus smart harnesses allow us to tailor probes to the target, ask the right questions, and prioritize fixes by economic value and risk, moving from volume-based brute force to context-driven testing and rapid patching.
Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 - James Kettle - ASW #380
Q: How do you view the balance between AI-generated findings and human oversight in ensuring novelty and usefulness?
The host and James discuss that while AI can unlock rapid exploration, human judgment is essential to validate novelty and avoid mislabeling routine findings as new, with governance and open-source practices helping to balance innovation with responsibility.
Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 - James Kettle - ASW #380
Q: What can you tease about the direction of your research and the role of LLMs in your system?
James explains that the system is a harness-driven approach where AI accelerates discovery, but meaningful results come from carefully designed tooling, prompts, and human guidance rather than relying on the model alone.
Securing Software's Journey with the OWASP SPVS - Cameron W., Farshad Abasi, Rohan Ravindranath, Ido Geffen - ASW #378
Q: What is Zero Trust as code and how does it work in practice?
Zero Trust as code embeds security policies in the same repositories and pipelines as infrastructure code, enabling drift detection, automatic remediation, and uniform policy deployment across multiple vendors.

Audience Metrics

Listeners, social reach, demographics and more for this podcast.

Listeners per Episode
Gender Skew
Location
Interests
Professions
Age Range
Household Income
Social Media Reach

Frequently Asked Questions About Application Security Weekly

What is Application Security Weekly about and what kind of topics does it cover?

This show covers application security, DevSecOps, and related security tooling with a practical, defender-focused lens. Episodes frequently explore proactive defense, AI-assisted security, software supply chain, and secure development practices, often featuring practitioners or researchers explaining how to implement guardrails, threat modeling, and secure-by-design workflows at scale. A notable pattern is hosting technical guests who bring hands-on expertise and real-world anecdotes, along with sponsor segments that anchor practical guidance for enterprise AppSec programs. The format tends to blend deep-dive technical discussion with industry context, making it useful for security teams, developers, and product security and DevOps leaders ... more

Where can I find podcast stats for Application Security Weekly?

Rephonic provides a wide range of podcast stats for Application Security Weekly. We scanned the web and collated all of the information that we could find in our comprehensive podcast database. See how many people listen to Application Security Weekly and access YouTube viewership numbers, download stats, audience demographics, chart rankings, ratings, reviews and more.

How many listeners does Application Security Weekly get?

Rephonic provides a full set of podcast information for three million podcasts, including the number of listeners. View further listenership figures for Application Security Weekly, including podcast download numbers and subscriber numbers, so you can make better decisions about which podcasts to sponsor or be a guest on. You will need to upgrade your account to access this premium data.

What are the audience demographics for Application Security Weekly?

Rephonic provides comprehensive predictive audience data for Application Security Weekly, including gender skew, age, country, political leaning, income, professions, education level, and interests. You can access these listener demographics by upgrading your account.

How many subscribers and views does Application Security Weekly have?

To see how many followers or subscribers Application Security Weekly has on Spotify and other platforms such as Castbox and Podcast Addict, simply upgrade your account. You'll also find viewership figures for their YouTube channel if they have one.

Which podcasts are similar to Application Security Weekly?

These podcasts share a similar audience with Application Security Weekly:

1. The Application Security Podcast
2. Security Weekly News (Audio)
3. Cloud Security Podcast by Google
4. Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec
5. AI Security Podcast

How many episodes of Application Security Weekly are there?

Application Security Weekly launched 8 years ago and published 715 episodes to date. You can find more information about this podcast including rankings, audience demographics and engagement in our podcast database.

How do I contact Application Security Weekly?

Our systems regularly scour the web to find email addresses and social media links for this podcast. We scanned the web and collated all of the contact information that we could find in our podcast database. But in the unlikely event that you can't find what you're looking for, our concierge service lets you request our research team to source better contacts for you.

Where can I see ratings and reviews for Application Security Weekly?

Rephonic pulls ratings and reviews for Application Security Weekly from multiple sources, including Spotify, Apple Podcasts, Castbox, and Podcast Addict.

View all the reviews in one place instead of visiting each platform individually and use this information to decide if a show is worth pitching or not.

How do I access podcast episode transcripts for Application Security Weekly?

Rephonic provides full transcripts for episodes of Application Security Weekly. Search within each transcript for your keywords, whether they be topics, brands or people, and figure out if it's worth pitching as a guest or sponsor. You can even set-up alerts to get notified when your keywords are mentioned.

What guests have appeared on Application Security Weekly?

Recent guests on Application Security Weekly include:

1. Federico Kirschbaum
2. Scott Clinton
3. Merritt Maxim
4. Rob Allen
5. James Kettle
6. Gwyddon Data Owen
7. Tom Tovar
8. Cameron Walters

To view more recent guests and their details, simply upgrade your Rephonic account. You'll also get access to a typical guest profile to help you decide if the show is worth pitching.

Find and pitch the right podcasts

We help savvy brands, marketers and PR professionals to find the right podcasts for any topic or niche. Get the data and contacts you need to pitch podcasts at scale and turn listeners into customers.
Try it free for 7 days