Rephonic
Artwork for Application Security Weekly

Application Security Weekly (Video)

Mike Shema
Application Security
Cybersecurity
Generative AI
Artificial Intelligence
Devops
Threat Modeling
OWASP
Large Language Models
Fuzzing
SQL Injection
Appsec
OWASP Top 10
Ransomware
Supply Chain Security
Open Source Software
CISA
Devsecops
Vulnerability Management
API Security
Software Supply Chain Security

About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

PublishesWeeklyEpisodes724Founded9 years ago
Number of ListenersCategories
Tech NewsNewsTechnology

Listen to this Podcast

Artwork for Application Security Weekly

Latest Episodes

Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kier... more

YouTube

All sorts of cybersecurity disciplines are adopting agents to help humans save time and automate routine activities. Sai Kiran Uppu describes his work on creating a platform for agents to analyze external threat intel, examine internal systems, and p... more

YouTube

Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven secur... more

YouTube

There's already an increase in volume of security flaws found by LLMs. And orgs are already turning to LLMs to write code. So, what happens when orgs lean on LLMs to create patches for those security flaws? Keith Hoodlet gives an exclusive early look... more

YouTube

Key Facts

Accepts Guests
Accepts Sponsors
Contact Information
Podcast Host
Number of Listeners
Find out how many people listen to this podcast per episode and each month.

Similar Podcasts

People also subscribe to these shows.

Recent Guests

Rishi Sharma
Co-founder and CEO of Project Discovery
Project Discovery
Episode: Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395
Mert Saltimaz
Founder of Sec Portal and project lead for OWASP Agent Security Regression Harness
Sec Portal / OWASP
Episode: Inside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393
Patrick Wardle
Co-founder of the Objective-C Foundation, CEO and co-founder of W and author of The Art of Mac Malware
W and Objective-C Foundation
Episode: MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
Jeremy Snyder
Founder and CEO of firetail.io
firetail.io
Episode: Discovering & Securing Your AI Agent Attack Surface - Jeremy Snyder - ASW #391
Ryan Lloyd
Chief Product Officer at Guardsquare
Guardsquare
Episode: Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390
Itamar Apelblat
Co-founder and CEO at Token Security
Token Security
Episode: Reducing Attack Surface & Evaluating Efficiency in Agents - Itamar Apelblat, David Goldschlag - ASW #389
David Goldschlag
CEO and co-founder at Aembit
Aembit
Episode: Reducing Attack Surface & Evaluating Efficiency in Agents - Itamar Apelblat, David Goldschlag - ASW #389
Ev Kontsevoy
CEO and co-founder of Teleport
Teleport
Episode: How AI Is Reshaping Identity Security at the Infrastructure Layer - Ev Kontsevoy, Neha Duggal, Amit Masand - ASW #388
Neha Duggal
Chief Product Officer at P0 Security
P0 Security
Episode: How AI Is Reshaping Identity Security at the Infrastructure Layer - Ev Kontsevoy, Neha Duggal, Amit Masand - ASW #388

Hosts

Mike Shema
Host of the show
John Kinsella
Co-host of the show
Tyler Shields
Co-host and fellow host

Reviews

4.9 out of 5 stars from 8 ratings
  • Occasional good content

    Keith occasionally has something worth saying, but he lacks solid experience with hardcore software development, and knows almost nothing about lean/agile. He approaches software like an operations problem.

    Paul is unpleasant to listen to and seldom adds anything of value. I wouild not listent to this podcast at all if Paul was the only contributor.

    This week's episode is particularlt vexing, as the bros bray on about American Football. Please find another forum for that. Your listeners are he... more

    Apple Podcasts
    2
    jdtangney
    United States8 years ago

Listeners Say

Key themes from listener reviews, highlighting what works and what could be improved about the show.

The host presence is noted, with appreciation for deep dives but occasional critiques on topic breadth.
Some listeners want more hands-on guidance and less theory or industry chatter.
Guests are generally high-signal but balance with sponsor segments can affect pacing.
Overall quality varies with episode pacing and depth; strong technical focus when guests are deep experts.

Chart Rankings

How this podcast ranks in the Apple Podcasts, Spotify and YouTube charts.

Apple Podcasts
#197
United States/News/Tech News
Apple Podcasts
#239
Canada/News/Tech News
Apple Podcasts
#101
Australia/News/Tech News
Apple Podcasts
#8
Poland/News/Tech News
Apple Podcasts
#35
Norway/News/Tech News
Apple Podcasts
#60
Israel/News/Tech News

Talking Points

Recent interactions between the hosts and their guests.

Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394
Q: How often did patches pass the practical test of actually fixing the vulnerability in a real-world context?
About a third of the scenario-one patches patched the POC, but only around 17% were robust in terms of truly fixing the vulnerability when considering real-world behavior and downstream effects.
Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394
Q: Tell us about the five scenarios you considered for the patching outcomes and why they matter.
We reviewed best-case robustness where the patch solves the underlying vulnerability, followed by cases where functionality changes, cases that merely rearrange code, patches that add new vulnerabilities, and worst-case patches that fail to patch and introduce new issues, highlighting both the potential and the risks of LLM-generated patches.
Why Does It Matter Who or What Created the Code? - Matias Madou - ASW #387
Q: Can we train LLMs to stop writing vulnerabilities, or avoid certain flaws entirely?
Yes, to some extent: researchers are creating rules and guardrails, and some systems attempt to restrict specific classes of vulnerabilities, but the AI's non-deterministic nature and the complexity of programming mean we may never eliminate all vulnerabilities purely through prompts or training.
Why Does It Matter Who or What Created the Code? - Matias Madou - ASW #387
Q: Why does it matter who writes the code in the context of LLMs?
Because the source of code affects traceability, accountability, and the potential repetition of mistakes; LLMs introduce non-determinism and variability that complicates security, so organizations must decide how much trust to place in AI versus human developers and how to govern the process.
Scanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386
Q: What role do humans play when LLMs are doing the heavy lifting?
Humans provide creativity, judgment, and the ability to set strategic targets and interpret results; LLMs handle large-scale triage, recall, and systematic exploration, while humans guide direction and validate outcomes.

Audience Metrics

Listeners, social reach, demographics and more for this podcast.

Listeners per Episode
Gender Skew
Location
Interests
Professions
Age Range
Household Income
Social Media Reach

Frequently Asked Questions About Application Security Weekly

What is Application Security Weekly about and what kind of topics does it cover?

A technically focused show that centers on application security, DevSecOps, and the evolving role of AI, identity, and tooling in software protection. Across episodes, conversations frequently cover secure coding practices, vulnerability disclosure, threat modeling, and practical defenses for apps, APIs, mobile, and infrastructure. A distinctive thread is the integration of cutting-edge research with real-world deployment considerations, including harness design, AI-assisted testing, and governance for AI-enabled security workflows. The show tends to feature deep-dive interviews with security researchers, founders, and practitioners, plus sponsored segments that illustrate concrete security controls in action. It's likely to appeal to secur... more

Where can I find podcast stats for Application Security Weekly?

Rephonic provides a wide range of podcast stats for Application Security Weekly. We scanned the web and collated all of the information that we could find in our comprehensive podcast database. See how many people listen to Application Security Weekly and access YouTube viewership numbers, download stats, audience demographics, chart rankings, ratings, reviews and more.

How many listeners does Application Security Weekly get?

Rephonic provides a full set of podcast information for four million podcasts, including the number of listeners. View further listenership figures for Application Security Weekly, including podcast download numbers and subscriber numbers, so you can make better decisions about which podcasts to sponsor or be a guest on. You will need to upgrade your account to access this premium data.

What are the audience demographics for Application Security Weekly?

Rephonic provides comprehensive predictive audience data for Application Security Weekly, including gender skew, age, country, political leaning, income, professions, education level, and interests. You can access these listener demographics by upgrading your account.

How many subscribers and views does Application Security Weekly have?

To see how many followers or subscribers Application Security Weekly has on Spotify and other platforms such as Castbox and Podcast Addict, simply upgrade your account. You'll also find viewership figures for their YouTube channel if they have one.

Which podcasts are similar to Application Security Weekly?

These podcasts share a similar audience with Application Security Weekly:

1. Cloud Security Podcast by Google
2. CyberWire Daily

How many episodes of Application Security Weekly are there?

Application Security Weekly launched 9 years ago and published 724 episodes to date. You can find more information about this podcast including rankings, audience demographics and engagement in our podcast database.

How do I contact Application Security Weekly?

Our systems regularly scour the web to find email addresses and social media links for this podcast. We scanned the web and collated all of the contact information that we could find in our podcast database. But in the unlikely event that you can't find what you're looking for, our concierge service lets you request our research team to source better contacts for you.

Where can I see ratings and reviews for Application Security Weekly?

Rephonic pulls ratings and reviews for Application Security Weekly from multiple sources, including Spotify, Apple Podcasts, Castbox, and Podcast Addict.

View all the reviews in one place instead of visiting each platform individually and use this information to decide if a show is worth pitching or not.

How do I access podcast episode transcripts for Application Security Weekly?

Rephonic provides full transcripts for episodes of Application Security Weekly. Search within each transcript for your keywords, whether they be topics, brands or people, and figure out if it's worth pitching as a guest or sponsor. You can even set-up alerts to get notified when your keywords are mentioned.

What guests have appeared on Application Security Weekly?

Recent guests on Application Security Weekly include:

1. Rishi Sharma
2. Mert Saltimaz
3. Patrick Wardle
4. Jeremy Snyder
5. Ryan Lloyd
6. Itamar Apelblat
7. David Goldschlag
8. Ev Kontsevoy

To view more recent guests and their details, simply upgrade your Rephonic account. You'll also get access to a typical guest profile to help you decide if the show is worth pitching.

Find and pitch the right podcasts

We help savvy brands, marketers and PR professionals to find the right podcasts for any topic or niche. Get the data and contacts you need to pitch podcasts at scale and turn listeners into customers.
Try it free for 7 days