About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.

Application Security Weekly (Video)
Claim This Podcastby Mike Shema
Podcast Authority
Beta
Podcast Overview
About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.
Language
🇺🇲
Publishing Since
1/6/2018
Unlock The Full Podcast Authority Score Report
See how your podcast performs across key metrics
Podcast Authority
Beta
Recommendations available
Unlock the full report to see detailed tips
Recommendations available
Unlock the full report to see detailed tips
Unlock comprehensive insights including:
- • YouTube presence analysis
- • Social media reach metrics
- • RSS compliance scoring
- • Podcast 2.0 features
- • Technical standards
Detailed Analytics
- Complete breakdown of all 19 authority metrics
- Personalized recommendations for each metric
- Industry benchmarks and comparisons
- Technical RSS feed analysis and compliance scoring
Growth Strategies
- Step-by-step action plans for improvement
- Quick wins to boost your score immediately
- Pro tips from successful podcasters
See how your show performs across every key metric
High authority scores make your podcast more attractive to industry leaders and influencers who want to appear on credible shows.
Sponsors look for podcasts with proven authority and engagement. Your score demonstrates your podcast's value to potential partners.
Understanding your strengths and weaknesses helps you make data-driven decisions to expand your listener base effectively.
1 verified contact email on file for Application Security Weekly (Video)
Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.
Recent Episodes

August 4, 2026
Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394
<p>There's already an increase in volume of security flaws found by LLMs. And orgs are already turning to LLMs to write code. So, what happens when orgs lean on LLMs to create patches for those security flaws? Keith Hoodlet gives an exclusive early look at his team's recent research into the success, quality, and failures of LLM-generated security patches. Notably, they saw scenarios across a spectrum from robust, effective patches to patches that changed the software's behavior to patches that introduced new vulns to patches that didn't even fix the original vuln while also introducing a new vuln.</p> <p>The research considers factors like quality and correctness of prompts, complexity of the target software, programming language, and expertise required to understand what a robust patch should look like. If you're going to spend tokens on fixing security flaws, you want a feedback loop that fixes them correctly -- not an infinite loop of new flaws creeping in with every LLM iteration.</p> <p>Watch for this research, its toolset, and data to be released on Thursday August 6th during Black Hat.</p> <p>Show Notes: <a rel="noopener" target="_blank" href= "https://securityweekly.com/asw-394">https://securityweekly.com/asw-394</a></p>

July 28, 2026
Inside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393
<p>Orgs need to be able to use agents, MCPs, and LLMs in ways that don't lead to unexpected actions and undesirable outcomes. The OWASP Agent Security Regression Harness project is an approach for defining customizable scenarios and testing whether those systems fail against known security threats. Mert Saltimaz talks about the background of the project, how orgs can use it as they bring more LLMs into their environment, and how the project intends to grow. Importantly, we also talk about the security controls and designs that orgs can build around the systems and data that models interact with in addition to evaluating the security of the agents and agent harnesses themselves.</p> <p>Segment Resources:</p> <ul> <li><a rel="noopener" target="_blank" href= "https://github.com/OWASP/Agent-Security-Regression-Harness">https://github.com/OWASP/Agent-Security-Regression-Harness</a></li> <li><a rel="noopener" target="_blank" href= "https://youtu.be/6DWs5EwbFQ0?si=r0IJ_F0SZnkPzzYg">https://youtu.be/6DWs5EwbFQ0?si=r0IJ_F0SZnkPzzYg</a> -- "What Trading Systems Taught Me About Breaking (And Defending) Infrastructure"</li> </ul> <p>Show Notes: <a rel="noopener" target="_blank" href= "https://securityweekly.com/asw-393">https://securityweekly.com/asw-393</a></p>

July 21, 2026
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
<p>Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's aggressive stance on deprecation benefits security, and the areas of the OS where he still sees plenty of opportunity for more security research. We discuss how developers make defensible design choices, why privacy needs security, and some security principles that any app developer should keep in mind regardless of their programming language or operating system.</p> <p>Resources:</p> <ul> <li><a rel="noopener" target="_blank" href= "https://objective-see.org/blog/blog_0x86.html">https://objective-see.org/blog/blog_0x86.html</a></li> <li><a rel="noopener" target="_blank" href= "https://objective-see.org/products/lulu.html">https://objective-see.org/products/lulu.html</a></li> <li><a rel="noopener" target="_blank" href= "https://objectivebythesea.org/v9/index.html">https://objectivebythesea.org/v9/index.html</a></li> </ul> <p>Show Notes: <a rel="noopener" target="_blank" href= "https://securityweekly.com/asw-392">https://securityweekly.com/asw-392</a></p>
721 total episodes available with 1 transcripts
Similar Podcasts
Discover related shows you might enjoy

Security Weekly News (Audio)
Doug White

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec
Jerry Bell and Andrew Kalat

Risky Business
Risky Business Media

CyberWire Daily
N2K Networks

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich

Hacking Humans
N2K Networks

Security Now (Audio)
TWiT

Darknet Diaries
Jack Rhysider
Deep-dive analytics for Application Security Weekly (Video)
Frequently asked questions
Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.
- What is Application Security Weekly (Video)?
- How often does this podcast release new episodes?
This podcast updates daily.
- Where can I listen to this podcast?
This podcast is available on 8 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.
- Does this podcast accept guests?
No, this podcast does not typically feature guests.
Legal Disclaimer
Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.
All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.
We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.
While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.
By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.