CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321
11 March - 1 hour 13 minsJust three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s. Common defenses have been known since the early 2000s. Jack Cable talks about CISA's Secure by Design principles and how they're trying to refocus businesses on addressing vuln classes and prioritizing software quality -- with security one of those important dimensions of quality.
Segment Resources:
https://www.cisa.gov/securebydesign https://www.cisa.gov/securebydesign/pledge https://www.cisa.gov/resources-tools/resources/product-security-bad-practices https://www.lawfaremedia.org/projects-series/reviews-essays/security-by-design https...
Cloudflare, Gh0stRAT, npm, North Koreans, Arch, Steam, Documentaries, Aaran Leyland.. - SWN #530
35 mins
18 November Finished
Secure Coding as Critical Thinking Instead of Vulnspotting - Matias Madou - ASW #357
1 hour 3 mins
18 November Finished
Year of the (Clandestine) Linux Desktop, topic, and the news - Rob Allen - ESW #433
1 hour 56 mins
17 November Finished
Augustus De Morgan, Doordash, Fortiweb, Typosquatting, Vista, Ransomware, AI, More... - SWN #529
28 mins
14 November Finished
Securing Model Context Protocol as Companies Plan to Replace Entry Roles with AI - Rahul Parwani - BSW #421
58 mins
12 November Finished