Home Podcasts Absolute AppSec
Absolute AppSec

Absolute AppSec

Ken Johnson and Seth Law 330 Episodes Aug 18, 2026

A weekly podcast dedicated to application security, hosted by Ken Johnson and Seth Law. Each episode covers a range of topics related to securing software, from threat modeling and secure coding practices to industry trends and vulnerabilities. The show is aimed at developers, security professionals, and anyone interested in building more secure applications.

Episodes

Episode 330 - w/ Jeevan Singh - Vulnerability Jail
Episode 330 - w/ Jeevan Singh - Vulnerability Jail Aug 18, 2026 In this special episode of Absolute AppSec, we cover a topic which started as a solution proposed by Rippling Security's Jeevan Singh: Vulnerability Jail. As Jeevan describes it: "In this new AI world, we have seen many more vulnerabilities, and we struggled to get Engineering to fix them all in a timely fashion. This changed when we created Vulnerability Jail. If any vulnerability goes over SLA,
Episode 329 - AI exploitability, IDOR prevention, Smart TV Proxies
Episode 329 - AI exploitability, IDOR prevention, Smart TV Proxies Jul 28, 2026 In this episode, sponsored by GuardSquare (guardsquare.com), Ken Johnson and Seth Law discuss OpenAI's reported Hugging Face security incident, questioning whether the model demonstrated genuinely novel offensive capability or mostly chained known vulnerability patterns at high inference cost, while also considering the defense-contract and marketing angles around "dangerous" frontier models. The
Episode 328 - Wordpress RCE, Vuln Prioritization, AI memory exfiltration
Episode 328 - Wordpress RCE, Vuln Prioritization, AI memory exfiltration Jul 21, 2026 In episode 328 of Absolute AppSec, sponsored by GuardSquare (guardsquare.com), Seth and Ken start by highlighting a newly disclosed, pre-authentication WordPress core Remote Code Execution (RCE) vulnerability ("WP2Shell"). The core discussion centers on Alex Gaynor's article regarding the influx of AI-assisted vulnerability disclosures. Gaynor and the hosts argue that attempting to fix bugs case-b
Episode 327 - w/Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization
Episode 327 - w/Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization Jul 14, 2026 In episode 327 of Absolute AppSec, co-hosts Ken Johnson and Seth Law present a highly anticipated quarterly crossover episode with Cameron and Kurt from the Coffee, Chaos, and ProdSec podcast. Sponsored by GuardSquare, the group begins with lighthearted banter about their personal footwear choices before tackling heavy architectural debates. The primary focus shifts to Application Security Posture
Episode 326 - AppSec Jobs, Benchmarking LLMs, Open Web Standards
Episode 326 - AppSec Jobs, Benchmarking LLMs, Open Web Standards Jul 7, 2026 In episode 326 of Absolute AppSec, sponsored by mobile application security provider GuardSquare (guardsquare.com), the hosts start with a deep-dive into pre-show discussions about the shifting macroeconomic landscape of AppSec jobs. They analyze an industry-wide trend where corporate hiring is pivoting away from external third-party consultancies and contractors. Instead, maturing organizations a
Episode 325 - Simplified Threat Modeling, Defining A Vulnerability
Episode 325 - Simplified Threat Modeling, Defining A Vulnerability Jun 30, 2026 In episode 325 of Absolute AppSec, co-hosts Ken Johnson and Seth Law first break down an informal guide to threat modeling, arguing that overly prescriptive frameworks like STRIDE induce a heavy cognitive load on developers. Instead, they advocate for simplified, creative questions to expose architectural gaps, citing a historical GitHub planning flaw where private repository images were left expo
Episode 324 - Three Week Trap, Malicious Extensions
Episode 324 - Three Week Trap, Malicious Extensions Jun 16, 2026 In episode 324 of Absolute AppSec, co-hosts Ken Johnson and Seth Law share a mix of security model critiques. Starting with industry dynamics, Ken recaps his recent presentation at OWASP Nova regarding the limits of human-scale AppSec, recounting a dramatic storm during the talk where patio chairs pelted the high-rise glass. The conversation pivots sharply to Anthropic being forced to pull its "Fa
Episode 323 - Secrets Logs, Prompt Injection Risks
Episode 323 - Secrets Logs, Prompt Injection Risks Jun 9, 2026 In episode 323 of Absolute AppSec, co-hosts Ken Johnson and Seth Law focus heavily on core application security vulnerabilities, legacy operational struggles, and the challenges of generative AI systems. After briefly discussing Seth’s recent trip to BSides Vancouver and confirming upcoming conference training logistics for Black Hat and DEF CON, the duo dives into the persistent problem of secret
Episode 322 - Megalodon, Staged Package Publishing, AI Powered Honeypots
Episode 322 - Megalodon, Staged Package Publishing, AI Powered Honeypots May 26, 2026 In episode 322, the co-hosts examine critical vulnerabilities, changing security standards, and adaptive defense mechanisms. They deep dive into the recent "Megalodon" breach, identifying it as a direct poisoned pipeline execution attack. Rather than exposing a flaw inside GitHub itself , researchers at Hudson Rock traced the root cause to credentials stolen from developer desktops via infostealer
Episode 321 - The Future of AppSec
Episode 321 - The Future of AppSec May 19, 2026 In episode 321 of Absolute AppSec, the co-hosts dive into a sprawling discussion about the future of Application Security amid the heavy noise of artificial intelligence and automated tools. The hosts start with a debate on whether traditional AppSec fundamentals remain relevant. Drawing analogies to the industrialization of car manufacturing and the transition to autonomous labor, they predict th
Episode 320 - Return of @lojikil - LLM Bug Hunting, AI OffSec, Defender Burnout
Episode 320 - Return of @lojikil - LLM Bug Hunting, AI OffSec, Defender Burnout May 12, 2026 Ken is away, so Stefan Edwards (lojikil) joins Seth to talk all things AppSec. This episode starts by exploring the acceleration of AI on the offensive side of security, enabling threat actors to automate complex tasks like patch diffing, gadget discovery, and reverse engineering binaries. The conversation highlights a recent milestone where an AI-driven tool, Mythos, successfully identified a vul
Episode 319 - Vercel Breach, Security vs. Compliance, Pull Request Flows w/ AI Agents
Episode 319 - Vercel Breach, Security vs. Compliance, Pull Request Flows w/ AI Agents Apr 21, 2026 Episode 319 covers a range of industry developments, primarily focusing on the recent Vercel security incident and the evolving landscape of AI-driven compliance. The hosts detail how a Vercel employee's use of a consumer-level Context AI plan led to a workspace compromise via a leaked OAuth token, eventually allowing attackers to access sensitive environment variables. This leads to a critical di

Recommended