Home Podcasts AppSec Now
AppSec Now

AppSec Now

DevCentral 41 Episodes Apr 28, 2025

AppSec Now covers the latest application security news and features interviews with guests from the application security community. Each episode highlights top stories and trends in appsec, offering insights for security professionals and enthusiasts. The show aims to keep listeners informed about emerging threats and best practices.

Episodes

Tackling CVE Chaos, Parquet Tool Insights, and EU Cyber Resilience Act Unpacked
Tackling CVE Chaos, Parquet Tool Insights, and EU Cyber Resilience Act Unpacked Apr 28, 2025 00:30:46 🔒 Welcome to this week’s episode of AppSecNow, the DevCentral podcast dedicated to all things application security! 🚨 This week, we unpack critical updates including:💥 A zero-day SAP CVE with a CVSS score of 10—what it means, how it's being exploited, and what you can do to defend against it.🛠️ A groundbreaking Parquet tool from F5 Labs that simplifies vulnerability testing for critical supply
EV Car Hacking, AI-Generated Passports, & Japan’s Active Cyber Defense Bill
EV Car Hacking, AI-Generated Passports, & Japan’s Active Cyber Defense Bill Apr 21, 2025 00:36:06 Join Merlyn Chase, MegaZone, and Aubrey on this week’s AppSec Now podcast as they dive into the latest topics in application security! 🚀 From the recent B-Sides Seattle conference to critical discussions on EV car hacking, cybersecurity quandaries, AI-generated passports bypassing KYC, and Japan’s groundbreaking Active Cyber Defense Bill—you don’t want to miss this one. Plus, learn how AppSecNow i
Amazon EC2 SSRF Breach, Oracle Cloud Breach & Malicious NPM Packages Exposed
Amazon EC2 SSRF Breach, Oracle Cloud Breach & Malicious NPM Packages Exposed Apr 14, 2025 00:35:08 Join our AppSec experts—Merlyn, Malcolm, MegaZone, and host Chase Abbott—as they dig into some of the latest stories shaking up the cybersecurity world. This week's AppSec Now explores an active campaign targeting Amazon EC2 instance metadata via SSRF vulnerabilities, and why that's a wider-reaching problem than you might think. We discuss Oracle's controversial handling of their cloud breach and
NGINX Kubernetes IngressNightmare, Critical Next.js CVE, Chrome Zero Day - Ep.32
NGINX Kubernetes IngressNightmare, Critical Next.js CVE, Chrome Zero Day - Ep.32 Apr 7, 2025 00:31:22 Dive into the latest episode of AppSecNow, where we break down the Ingress Nightmare vulnerability impacting NGINX and Kubernetes environments, plus the implications of a critical CVE in Next.js, one of the most widely-used JavaScript frameworks with 9 million weekly downloads.Join Aubrey, Chase, and Merlyn for expert analysis on the security landscape, from Chromium Zero Day concerns to ransomwar
Vibe Coding, F5 Labs Bot Report, Google Buys Wiz And More | AppSec Now Ep 31
Vibe Coding, F5 Labs Bot Report, Google Buys Wiz And More | AppSec Now Ep 31 Mar 31, 2025 00:45:13 Welcome to the 31st episode of AppSec Now! This week, our hosts Aubrey, David Warburton, Chase Abbott, and MegaZone get into some hot topics in the world of application security. Our focus is on the latest F5 Labs Advanced Persistent Bots report, highlighting the ever-evolving landscape of bot attacks and the importance of robust mitigation strategies. We analyze Google's hefty $32 million acq
Latest AppSec Threats: Coinbase Phishing, BRUTED, OBSCURE#BAT, KoSpy And More!
Latest AppSec Threats: Coinbase Phishing, BRUTED, OBSCURE#BAT, KoSpy And More! Mar 24, 2025 00:36:47 Join us for the thirtieth episode of AppSecNow, a DevCentral podcast dedicated to the latest trends and threats in the application security (AppSec) world. In this episode, host Aubrey King is joined by Malcolm Heath, Chase Abbott, and MegaZone to dive into recent security incidents and developments, including a detailed analysis of the Coinbase phishing scam, the resurgence of user-mode rootkits
Latest in AppSec: Apache Camel RCE, X DDoS, Silk Typhoon, and Encryption Debates
Latest in AppSec: Apache Camel RCE, X DDoS, Silk Typhoon, and Encryption Debates Mar 18, 2025 00:33:00 Welcome to the latest episode of AppSec Now, a DevCentral podcast dedicated to the ever-evolving world of application security. In this episode, Chase takes the reins while Aubrey is away, joined by Malcolm Heath, a principal researcher at F5 Labs, and the illustrious MegaZone, a principal security engineer on the SIRT team.We dive deep into the recent Apache Camel remote code execution vulnerabil
Exploring CISA Layoffs, Microsoft's Quantum Chip, MongoDB Vulnerabilities & More
Exploring CISA Layoffs, Microsoft's Quantum Chip, MongoDB Vulnerabilities & More Mar 3, 2025 00:27:33 Join Aubrey, MegaZone, and Merlyn in this week's episode of AppSec Now as they dive into the latest in application security. This week, we discuss Microsoft's groundbreaking Majorana One chip, capable of scaling up to a million qubits and its potential impact on quantum computing. We also explore the recent critical vulnerabilities in MongoDB libraries and OpenSSH, analyzing their implicat
Understanding The TikTok Ban, Salt Typhoon And More | AppSec Monthly January Ep.27
Understanding The TikTok Ban, Salt Typhoon And More | AppSec Monthly January Ep.27 Jan 31, 2025 00:34:43 In this episode of AppSec Monthly, join our host, MegaZone, joined by Malcolm Heath, Merlyn Albery-Speyer and Aubrey King, as they dive into the latest cybersecurity news. We explore the complexities of the TikTok ban, the impact of geopolitical decisions on internet freedom, and the nuances of data sovereignty. Our experts also discuss the implications of recent breaches by Chinese state actors a
Cybersecurity Predictions 2025: Insights from F5 Labs | December Special AppSec Monthly Ep.26
Cybersecurity Predictions 2025: Insights from F5 Labs | December Special AppSec Monthly Ep.26 Dec 30, 2024 01:08:31 Welcome to our special year-end episode of AppSec Monthly, a DevCentral podcast! In this exciting edition, we join forces with the experts at F5 Labs to bring you our highly anticipated cybersecurity predictions for the year ahead. Our panel, including David Warburton, Aubrey King, and Megazone, dives deep into the trends and emerging threats that are set to shape the cybersecurity landscape in 20
Episode 25 - November 2024 - F5 Labs Black Friday Report, 2025 OWASP LLM Apps Top 10 And More
Episode 25 - November 2024 - F5 Labs Black Friday Report, 2025 OWASP LLM Apps Top 10 And More Nov 30, 2024 01:03:25 Welcome to the latest episode of AppSec Monthly! In this episode, we delve into IT policies, recent cybersecurity trends, and sophisticated attack detection with industry experts David Warburton, Malcolm Heath, and MegaZone. Special guests Adeolu and Shuang from F5 Labs share their latest research on Black Friday shopping trends, automation, and bot attacks, providing insights into the types of bo
Episode 24 - October 2024 - F5 Labs APIWorld CTF, CUPS & Hyundai Vulnerabilities And More
Episode 24 - October 2024 - F5 Labs APIWorld CTF, CUPS & Hyundai Vulnerabilities And More Nov 5, 2024 00:32:21 Welcome to another exciting episode of AppSec Monthly, brought to you by DevCentral! This month, we dive deep into various aspects of application security with contributions from Aaron Brailsford, Malcolm Heath, and MegaZone! We discuss the importance of integrating security early in the development process, the critical role of trust in cybersecurity, and the recent buzz around CUPS vulnerabili

Recommended