Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Akansha Shukla - Modern AppSec: Securing APIs with Threat Modeling and DevSecOps

35:35
 
Share
 

Manage episode 503977464 series 2408745
Content provided by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Our guest today is Akansha Shukla, an information security professional with over 10 years of experience in application security, DevSecOps, and API security. We’re discussing why API security remains one of the least mature areas of AppSec today and exploring the challenges developers face when securing APIs. Akansha shares her insights on incorporating APIs into threat modeling exercises, the ongoing struggles with API discovery and inventory management, and the authorization challenges highlighted in the OWASP API Security Top 10. The conversation also touches on whether "shift left" is truly dead and why we still haven't solved basic security problems like input validation despite having the frameworks to address them.

FOLLOW OUR SOCIAL MEDIA:

➜Twitter: @AppSecPodcast
➜LinkedIn: The Application Security Podcast
➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast

Thanks for Listening!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  continue reading

318 episodes

Artwork
iconShare
 
Manage episode 503977464 series 2408745
Content provided by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Our guest today is Akansha Shukla, an information security professional with over 10 years of experience in application security, DevSecOps, and API security. We’re discussing why API security remains one of the least mature areas of AppSec today and exploring the challenges developers face when securing APIs. Akansha shares her insights on incorporating APIs into threat modeling exercises, the ongoing struggles with API discovery and inventory management, and the authorization challenges highlighted in the OWASP API Security Top 10. The conversation also touches on whether "shift left" is truly dead and why we still haven't solved basic security problems like input validation despite having the frameworks to address them.

FOLLOW OUR SOCIAL MEDIA:

➜Twitter: @AppSecPodcast
➜LinkedIn: The Application Security Podcast
➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast

Thanks for Listening!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  continue reading

318 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play