Rephonic
Artwork for The Boring AppSec Podcast

The Boring AppSec Podcast

The Boring AppSec Podcast
Cybersecurity
Application Security
AI Security
Vulnerability Management
Artificial Intelligence
Agentic AI
AI In Cybersecurity
Generative AI
Appsec
Vulnerabilities
AI Agents
Dryrun Security
Software Development
Cloud Security
Context Engineering
API Security
Acto
Kubernetes
OWASP
Security Culture

In this podcast, we will talk about our experiences having worked at different companies - from startups to big enterprises, from tech companies to security companies, and from building side projects to building startups. We will talk about the good, the bad, and everything in between. So join us for some fun, some real, and some super hot takes about all things Security in the Boring AppSec Podca... more

PublishesTwice monthlyEpisodes37Founded2 years ago
Category
Technology

Listen to this Podcast

Artwork for The Boring AppSec Podcast

Latest Episodes

In this episode, Jason Haddix (CEO of Arcanum Information Security and creator of the Bug Hunter’s Methodology) joins us to examine how AI is changing penetration testing and security research. He explains that while AI agents can automate reconnaiss... more

In this episode, we examine what is shifting in AI, AppSec, and product security and what remains fundamentally the same.

For years, application security has operated on a familiar model: siloed reviews, tool-driven findings, and periodic assessment... more

In this episode, we sit down with Jens to explore why AI agents fundamentally break traditional security assumptions, from API keys and browser sessions to composability and access control.

Drawing parallels to DeFi exploits and smart contract failu... more

In this episode, Ankur Chakraborty discusses the evolution of AI security, emphasizing the importance of foundational security principles in the context of generative AI. He explores the challenges of scaling security measures in an era of rapid feat... more

In this conversation, Ian Livingstone discusses the changing landscape of AI and security, focusing on the challenges of agent identity and the need for a new approach to application security. He emphasizes the importance of understanding the non-det... more

In this episode, we sit down with Kane Narraway to unpack how enterprise security is changing as AI, platforms, and developer-driven security become the norm. Kane shares his path from digital forensics to leading security at Canva, and why understan... more

In this episode, we sit down with Travis McPeak, one of the most prominent thinkers in the space of developer security. Travis, who built his career at the intersection of security automation and developer productivity, shares his philosophy on achie... more

In this episode, we sit down with Teja Myneedu, Sr. Director, Security and Trust at Navan. He shares his philosophy on achieving security at scale, discussing some challenges and approaches specially in the AI era. Teja's career spans over two decade... more

Key Facts

Accepts Guests
Contact Information
Podcast Host

Similar Podcasts

People also subscribe to these shows.

Prof G Markets
Prof G MarketsVox Media Podcast Network

Recent Guests

Jason Haddix
CEO of Arcanum Information Security; architect of the Bug Hunter's Methodology; experienced bug hunter and CISO
Arcanum Information Security
Episode: Ep 37: The Future of Security Testing in an AI-Driven World with Jason Haddix
Jens Ernstberger
Co-founder of Context.dev, focused on safe agent management and authorization
Context.dev
Episode: Ep 35: Exploring Security After Determinism with Jens Ernstberger
Ian Livingstone
CEO and co-founder of Keycard, a builder specializing in infrastructure abstraction.
Keycard
Episode: The Future of Identity in AI Agents with Ian Livingstone
Travis McPeak
Founder and security leader with extensive experience in developer security and automation.
Cursor
Episode: The Future of Developer Security with Travis McPeak
Aryaman Behera
Co-founder and CEO of Repello AI
Repello AI
Episode: The Attacker's Perspective on AI Security with Aryaman Behera
Ads Dawson
Staff AI security researcher at Dreadnode with over 13 years of experience in offensive security and web application pentesting, and a founding figure in AI security.
Dreadnode
Episode: The Future of Autonomous Red Teaming with Ads Dawson
Vineeth Sai
Generative AI security engineer and project lead for the OASP AI Vulnerability Scoring System
Meta
Episode: Navigating AI's New Security Landscape with Vineeth Sai
Harry Wetherald
Co-founder and CEO of Maze
Maze
Episode: Agentic AI: Transforming Vulnerability Management with Harry Wetherald
Ken Johnson
Co-founder and CTO of DryRun Security, an AI native code security company
DryRun Security
Episode: Ken Johnson

Hosts

Anshuman Bh
Host with a strong presence in security discussions, likely focusing on practical security topics and industry insights.
Sandesh
Co-host with a focus on discussing security topics, tooling, and practical industry trends.

Top Technology Podcasts

Smart Talks with IBM
Smart Talks with IBMPushkin Industries and iHeartPodcasts
Tomorrow, Today
Tomorrow, TodayShekhar Natarajan
Acquired
AcquiredBen Gilbert and David Rosenthal
The Room Podcast
The Room PodcastClaudia Laurie and Madison McIlwain
Better Offline
Better OfflineCool Zone Media and iHeartPodcasts

Talking Points

Recent interactions between the hosts and their guests.

Ep 37: The Future of Security Testing in an AI-Driven World with Jason Haddix
Q: What role do AI agents like Claude Code play in enterprise security work today?
They accelerate scouting, analysis, and experimentation while requiring human oversight to ensure accuracy and relevance; agents enable faster kickoffs, parallelization of tasks, and automation of routine work, but humans still determine the order of operations, risk, and verification of results.
Ep 37: The Future of Security Testing in an AI-Driven World with Jason Haddix
Q: How do you see training evolving for new pentesters in an AI-augmented era?
Training should emphasize deep research, context engineering, and the ability to prompt effectively; newcomers can reach competence quickly via AI-assisted paths, but they must learn to combine AI outputs with human insight and craft their own methodology rather than outsourcing thinking entirely to AI.
The Future of Identity in AI Agents with Ian Livingstone
Q: How does Keycard technically prevent a confused deputy attack when an agent is tricked into calling a destructive tool?
Keycard helps to identify and authenticate tools and agents, applying access controls to prevent unauthorized actions.
The Future of Identity in AI Agents with Ian Livingstone
Q: How do you think about verifying the agent intent in an agent tech sort of workflow?
We need to step back and talk about the three pillars of problems when it comes to agentic security, focusing on supply chain problems, Denny and Axis problem, and data security challenges.
Architecting AI Security: Standards and Agentic Systems with Ken Huang
Q: What should security professionals do to contribute to AI security?
They should engage in research-oriented learning, collaborate with groups like Owasp, and consistently code or write about their findings.

Audience Metrics

Listeners, social reach, demographics and more for this podcast.

Gender Skew
Location
Interests
Professions
Age Range
Household Income
Social Media Reach

Frequently Asked Questions About The Boring AppSec Podcast

What is The Boring AppSec Podcast about and what kind of topics does it cover?

This show centers on practical, practitioner-focused discussions about security in modern software environments, with a strong emphasis on AI's impact on AppSec, vulnerability management, and secure development. Many episodes explore how AI agents and tooling are changing testing, risk assessment, identity management, and security operations, often contrasting human expertise with automated capabilities. Listeners can expect deep dives into topics like AI-assisted testing, agent-based security models, threat modeling for AI-enabled systems, and pragmatic security strategies (security by design, context-aware access, and incident response) across both enterprise and startup contexts. The format tends to pair industry veterans with technologi... more

Where can I find podcast stats for The Boring AppSec Podcast?

Rephonic provides a wide range of podcast stats for The Boring AppSec Podcast. We scanned the web and collated all of the information that we could find in our comprehensive podcast database. See how many people listen to The Boring AppSec Podcast and access YouTube viewership numbers, download stats, audience demographics, chart rankings, ratings, reviews and more.

How many listeners does The Boring AppSec Podcast get?

Rephonic provides a full set of podcast information for three million podcasts, including the number of listeners. View further listenership figures for The Boring AppSec Podcast, including podcast download numbers and subscriber numbers, so you can make better decisions about which podcasts to sponsor or be a guest on. You will need to upgrade your account to access this premium data.

What are the audience demographics for The Boring AppSec Podcast?

Rephonic provides comprehensive predictive audience data for The Boring AppSec Podcast, including gender skew, age, country, political leaning, income, professions, education level, and interests. You can access these listener demographics by upgrading your account.

How many subscribers and views does The Boring AppSec Podcast have?

To see how many followers or subscribers The Boring AppSec Podcast has on Spotify and other platforms such as Castbox and Podcast Addict, simply upgrade your account. You'll also find viewership figures for their YouTube channel if they have one.

Which podcasts are similar to The Boring AppSec Podcast?

These podcasts share a similar audience with The Boring AppSec Podcast:

1. Prof G Markets
2. Bloomberg Tech

How many episodes of The Boring AppSec Podcast are there?

The Boring AppSec Podcast launched 2 years ago and published 37 episodes to date. You can find more information about this podcast including rankings, audience demographics and engagement in our podcast database.

How do I contact The Boring AppSec Podcast?

Our systems regularly scour the web to find email addresses and social media links for this podcast. We scanned the web and collated all of the contact information that we could find in our podcast database. But in the unlikely event that you can't find what you're looking for, our concierge service lets you request our research team to source better contacts for you.

Where can I see ratings and reviews for The Boring AppSec Podcast?

Rephonic pulls ratings and reviews for The Boring AppSec Podcast from multiple sources, including Spotify, Apple Podcasts, Castbox, and Podcast Addict.

View all the reviews in one place instead of visiting each platform individually and use this information to decide if a show is worth pitching or not.

How do I access podcast episode transcripts for The Boring AppSec Podcast?

Rephonic provides full transcripts for episodes of The Boring AppSec Podcast. Search within each transcript for your keywords, whether they be topics, brands or people, and figure out if it's worth pitching as a guest or sponsor. You can even set-up alerts to get notified when your keywords are mentioned.

What guests have appeared on The Boring AppSec Podcast?

Recent guests on The Boring AppSec Podcast include:

1. Jason Haddix
2. Jens Ernstberger
3. Ian Livingstone
4. Travis McPeak
5. Aryaman Behera
6. Ads Dawson
7. Vineeth Sai
8. Harry Wetherald

To view more recent guests and their details, simply upgrade your Rephonic account. You'll also get access to a typical guest profile to help you decide if the show is worth pitching.

Find and pitch the right podcasts

We help savvy brands, marketers and PR professionals to find the right podcasts for any topic or niche. Get the data and contacts you need to pitch podcasts at scale and turn listeners into customers.
Try it free for 7 days