
Avoiding Appsec's Worst Practices - ASW #324
1 April - 1 hour 11 minsWe take advantage of April Fools to look at some of appsec's myths, mistakes, and behaviors that lead to bad practices. It's easy to get trapped in a status quo of chasing CVEs or discussing which direction to shift security. But scrutinizing decimal points in CVSS scores or rearranging tools misses the opportunity for more strategic thinking. We satirize some worst practices in order to have a more serious discussion about a future where more software is based on secure designs.
Segment resources:
https://bsidessf2025.sched.com/event/1x8ST/secure-designs-ux-dragons-vuln-dungeons-application-security-weekly https://bsidessf2025.sched.com/event/1x8TU/preparing-for-dragons-dont-sharpen-...

Existential Dread, MCP, Cloudflare, ESXI, QR Codes, Salt Typhoon, Aaran Leyland... - SWN #495
33 mins
18 July Finished

AI meltdowns, Gigabyte, NCSC, Rowhammer, Gravity Form, Grok, AsyncRat, Josh Marpet... - SWN #494
30 mins
15 July Finished

Getting Started with Security Basics on the Way to Finding a Specialization - ASW #339
1 hour 7 mins
15 July Finished

Monzy Merza, How Much AI is Too Much, and the Weekly News - Monzy Merza - ESW #415
1 hour 43 mins
14 July Finished