Code Scanning That Works With Your Code - Scott Norberg - ASW #317
11 February 2025 - 1 hour 12 minsCode scanning is one of the oldest appsec practices. In many cases, simple grep patterns and some fancy regular expressions are enough to find many of the obvious software mistakes. Scott Norberg shares his experience with encountering code scanners that didn't find the .NET vuln classes he needed to find and why that led him to creating a scanner from scratch. We talk about some challenges in testing tools, making smart investments in engineering time, and why working with .NET's compiler made his decisions easier.
Segment Resources:
-https://github.com/ScottNorberg-NCG/CodeSheriff.NET
Identifying and eradicating unforgivable vulns, an unforgivable flaw (and a few others) in DeepSeek'...
Fibonacci, Hidden Sounds, Teams, Zimbra, Entra-ID, z.ai, Schrödinger's, Aaran Leyland - SWN #610
35 mins
25 August Finished
Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473
1 hour 39 mins
24 August Finished
Surveillance, Murder Hornets, Portmantau, TrueCONF, Siemens, N-Able and More - SWN #609
41 mins
21 August Finished
Preventing a Breakout as AI Agent Threats Is One of Three Top CISO Concerns - Rob Allen - BSW #461
53 mins
19 August Finished