Scanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386
9 June - 1 hour 16 minsMost AppSec teams are working through more findings than their teams can validate. SAST surfaces thousands of potential issues. DAST generates alert volume that outpaces triage capacity. Somewhere in that output are the vulnerabilities that matter, the ones that are actually exploitable in production. This conversation explores why automated testing often stops short of the hardest part of the job: proving what is real. We dig into how business logic flaws and authorization vulnerabilities get missed by tools that scan without reasoning, what exploit validation looks like at runtime, and how security engineers are shifting toward findings that developers will actually act on.
The segment i...
Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469
1 hour 50 mins
27 July Finished
Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland - SWN #601
34 mins
24 July Finished
MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392
1 hour 12 mins
21 July Finished