CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321
11 March 2025 - 1 hour 13 minsJust three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s. Common defenses have been known since the early 2000s. Jack Cable talks about CISA's Secure by Design principles and how they're trying to refocus businesses on addressing vuln classes and prioritizing software quality -- with security one of those important dimensions of quality.
Segment Resources:
https://www.cisa.gov/securebydesign https://www.cisa.gov/securebydesign/pledge https://www.cisa.gov/resources-tools/resources/product-security-bad-practices https://www.lawfaremedia.org/projects-series/reviews-essays/security-by-design https...
Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477
1 hour 37 mins
21 September Finished
Bacteria, Spartans, AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet - SWN #617
31 mins
18 September Finished
Followership, CyberSecurity Leadership, and Judgement as a Defining Skill - Kenyada Meadows - BSW #465
57 mins
16 September Finished
RoboGators, HBOMAX, Microsoft, DAS, Horsebot 3000, Aaran Leyland does AI, and More - SWN #616
32 mins
15 September Finished
The AI Threat Multiplier: Securing Mobile Apps in the Automated Era - Ryan Lloyd, Jason Cortlund - ASW #400
52 mins
15 September Finished