Home Podcasts Absolute AppSec
Absolute AppSec

Absolute AppSec

Ken Johnson and Seth Law 330 Episodes Sep 15, 2026

A weekly podcast dedicated to application security, hosted by Ken Johnson and Seth Law. Each episode covers a range of topics related to securing software, from threat modeling and secure coding practices to industry trends and vulnerabilities. The show is aimed at developers, security professionals, and anyone interested in building more secure applications.

Episodes

Episode 334 - w/ Ryan Lloyd - Mobile Application Security
Episode 334 - w/ Ryan Lloyd - Mobile Application Security Sep 15, 2026 In episode 334 of Absolute AppSec, hosts Ken Johnson and Seth Law interview Ryan Lloyd, Chief Product Officer at GuardSquare, to explore mobile application security and product management strategy. Lloyd details GuardSquare's evolution from the open-source Java optimizer ProGuard—which introduced basic name obfuscation—into a commercial suite offering multi-layered code hardening, control flow fla
Episode 333 - LLM Patching Flaws, AI Code Regressions, Bug Bounty Economy
Episode 333 - LLM Patching Flaws, AI Code Regressions, Bug Bounty Economy Sep 8, 2026 Sponsored by GuardSquare (guardsquare.com), the discussion of Episode 333 opens with an analysis of a 1Password academic paper evaluating how frontier LLMs perform at autonomous vulnerability patching. The research indicates that LLMs successfully generate functional, side-effect-free patches only 26% of the time, often introducing new security flaws, breaking application behavior, or hallucinatin
Episode 332 - AI SDLC, Call for Cyber Defense, Rumor as the Exploit
Episode 332 - AI SDLC, Call for Cyber Defense, Rumor as the Exploit Sep 1, 2026 In episode 332, the discussion focuses on how artificial intelligence is reshaping the Software Development Lifecycle (SDLC). The episode analyzes Anthropic's blog post regarding an "AI-native SDLC," evaluating its vision of replacing traditional development bottlenecks with AI workflows. The commentary critiques Anthropic's reliance on simple Markdown files for tracking development decisions, not
Episode 331 - Being "Mythos" Ready, CRLF-Powered De-sync Attacks
Episode 331 - Being "Mythos" Ready, CRLF-Powered De-sync Attacks Aug 25, 2026 Sponsored by Guardsquare (guardsquare.com), Episode 331 focuses heavily on the growing role of AI agents in application security and how organizations should build and defend against agentic systems. Ken and Seth argue that effective AI security systems should combine deterministic tooling with the probabilistic reasoning of LLMs rather than handing an entire security workflow to a model. Determin
Episode 330 - w/ Jeevan Singh - Vulnerability Jail
Episode 330 - w/ Jeevan Singh - Vulnerability Jail Aug 18, 2026 In this special episode of Absolute AppSec, we cover a topic which started as a solution proposed by Rippling Security's Jeevan Singh: Vulnerability Jail. As Jeevan describes it: "In this new AI world, we have seen many more vulnerabilities, and we struggled to get Engineering to fix them all in a timely fashion. This changed when we created Vulnerability Jail. If any vulnerability goes over SLA,
Episode 329 - AI exploitability, IDOR prevention, Smart TV Proxies
Episode 329 - AI exploitability, IDOR prevention, Smart TV Proxies Jul 28, 2026 In this episode, sponsored by GuardSquare (guardsquare.com), Ken Johnson and Seth Law discuss OpenAI's reported Hugging Face security incident, questioning whether the model demonstrated genuinely novel offensive capability or mostly chained known vulnerability patterns at high inference cost, while also considering the defense-contract and marketing angles around "dangerous" frontier models. The
Episode 328 - Wordpress RCE, Vuln Prioritization, AI memory exfiltration
Episode 328 - Wordpress RCE, Vuln Prioritization, AI memory exfiltration Jul 21, 2026 In episode 328 of Absolute AppSec, sponsored by GuardSquare (guardsquare.com), Seth and Ken start by highlighting a newly disclosed, pre-authentication WordPress core Remote Code Execution (RCE) vulnerability ("WP2Shell"). The core discussion centers on Alex Gaynor's article regarding the influx of AI-assisted vulnerability disclosures. Gaynor and the hosts argue that attempting to fix bugs case-b
Episode 327 - w/Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization
Episode 327 - w/Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization Jul 14, 2026 In episode 327 of Absolute AppSec, co-hosts Ken Johnson and Seth Law present a highly anticipated quarterly crossover episode with Cameron and Kurt from the Coffee, Chaos, and ProdSec podcast. Sponsored by GuardSquare, the group begins with lighthearted banter about their personal footwear choices before tackling heavy architectural debates. The primary focus shifts to Application Security Posture
Episode 326 - AppSec Jobs, Benchmarking LLMs, Open Web Standards
Episode 326 - AppSec Jobs, Benchmarking LLMs, Open Web Standards Jul 7, 2026 In episode 326 of Absolute AppSec, sponsored by mobile application security provider GuardSquare (guardsquare.com), the hosts start with a deep-dive into pre-show discussions about the shifting macroeconomic landscape of AppSec jobs. They analyze an industry-wide trend where corporate hiring is pivoting away from external third-party consultancies and contractors. Instead, maturing organizations a
Episode 325 - Simplified Threat Modeling, Defining A Vulnerability
Episode 325 - Simplified Threat Modeling, Defining A Vulnerability Jun 30, 2026 In episode 325 of Absolute AppSec, co-hosts Ken Johnson and Seth Law first break down an informal guide to threat modeling, arguing that overly prescriptive frameworks like STRIDE induce a heavy cognitive load on developers. Instead, they advocate for simplified, creative questions to expose architectural gaps, citing a historical GitHub planning flaw where private repository images were left expo
Episode 324 - Three Week Trap, Malicious Extensions
Episode 324 - Three Week Trap, Malicious Extensions Jun 16, 2026 In episode 324 of Absolute AppSec, co-hosts Ken Johnson and Seth Law share a mix of security model critiques. Starting with industry dynamics, Ken recaps his recent presentation at OWASP Nova regarding the limits of human-scale AppSec, recounting a dramatic storm during the talk where patio chairs pelted the high-rise glass. The conversation pivots sharply to Anthropic being forced to pull its "Fa
Episode 323 - Secrets Logs, Prompt Injection Risks
Episode 323 - Secrets Logs, Prompt Injection Risks Jun 9, 2026 In episode 323 of Absolute AppSec, co-hosts Ken Johnson and Seth Law focus heavily on core application security vulnerabilities, legacy operational struggles, and the challenges of generative AI systems. After briefly discussing Seth’s recent trip to BSides Vancouver and confirming upcoming conference training logistics for Black Hat and DEF CON, the duo dives into the persistent problem of secret

Recommended