Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Ken Johnson and Seth Law, Ken Johnson, and Seth Law. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Ken Johnson and Seth Law, Ken Johnson, and Seth Law or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Episode 304 - More OWASP Top 10, AI Dynamic Testing

 
Share
 

Manage episode 520101967 series 2371855
Content provided by Ken Johnson and Seth Law, Ken Johnson, and Seth Law. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Ken Johnson and Seth Law, Ken Johnson, and Seth Law or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
This episode, the 304th of Absolute AppSec, features hosts Ken Johnson (@cktricky) and Seth Law (@sethlaw) discussing the crush of Q4 expectations, upcoming training opportunities, the recent updates to the OWASP Top Ten, and the impact of AI tools like XBow on application security (AppSec) consulting. The hosts discuss the shift in the OWASP Top Ten from focusing on vulnerabilities to focusing on risks, and the dual role the list now plays for both awareness/training and compliance. Shifting to recent funding of XBow, the overall consensus is that while AI tools dramatically improve process flow, scoping, and the speed of vulnerability identification for consultants, they won't replace the need for human experts for complex, bespoke systems, business logic flaws, or authorization issues. AI is commoditizing lower-level AppSec work.
  continue reading

351 episodes

Artwork
iconShare
 
Manage episode 520101967 series 2371855
Content provided by Ken Johnson and Seth Law, Ken Johnson, and Seth Law. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Ken Johnson and Seth Law, Ken Johnson, and Seth Law or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
This episode, the 304th of Absolute AppSec, features hosts Ken Johnson (@cktricky) and Seth Law (@sethlaw) discussing the crush of Q4 expectations, upcoming training opportunities, the recent updates to the OWASP Top Ten, and the impact of AI tools like XBow on application security (AppSec) consulting. The hosts discuss the shift in the OWASP Top Ten from focusing on vulnerabilities to focusing on risks, and the dual role the list now plays for both awareness/training and compliance. Shifting to recent funding of XBow, the overall consensus is that while AI tools dramatically improve process flow, scoping, and the speed of vulnerability identification for consultants, they won't replace the need for human experts for complex, bespoke systems, business logic flaws, or authorization issues. AI is commoditizing lower-level AppSec work.
  continue reading

351 episodes

모든 에피소드

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play