80 subscribers
Pergi ke luar talian dengan aplikasi Player FM !
CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321
Manage episode 470762688 series 2086045
Just three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s. Common defenses have been known since the early 2000s. Jack Cable talks about CISA's Secure by Design principles and how they're trying to refocus businesses on addressing vuln classes and prioritizing software quality -- with security one of those important dimensions of quality.
Segment Resources:
- https://www.cisa.gov/securebydesign
- https://www.cisa.gov/securebydesign/pledge
- https://www.cisa.gov/resources-tools/resources/product-security-bad-practices
- https://www.lawfaremedia.org/projects-series/reviews-essays/security-by-design
- https://corridor.dev
Skype hangs up for good, over a million cheap Android devices may be backdoored, parallels between jailbreak research and XSS, impersonating AirTags, network reconnaissance via a memory disclosure vuln in the GFW, and more!
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-321
339 episod
Manage episode 470762688 series 2086045
Just three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s. Common defenses have been known since the early 2000s. Jack Cable talks about CISA's Secure by Design principles and how they're trying to refocus businesses on addressing vuln classes and prioritizing software quality -- with security one of those important dimensions of quality.
Segment Resources:
- https://www.cisa.gov/securebydesign
- https://www.cisa.gov/securebydesign/pledge
- https://www.cisa.gov/resources-tools/resources/product-security-bad-practices
- https://www.lawfaremedia.org/projects-series/reviews-essays/security-by-design
- https://corridor.dev
Skype hangs up for good, over a million cheap Android devices may be backdoored, parallels between jailbreak research and XSS, impersonating AirTags, network reconnaissance via a memory disclosure vuln in the GFW, and more!
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-321
339 episod
Semua episod
×
1 In Search of Secure Design - ASW #325 1:07:36

1 Avoiding Appsec's Worst Practices - ASW #324 1:11:19

1 Finding a Use for GenAI in AppSec - Keith Hoodlet - ASW #323 54:08

1 Redlining the Smart Contract Top 10 - Shashank . - ASW #322 53:01

1 CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321 1:13:50

1 Keeping Curl Successful and Secure Over the Decades - Daniel Stenberg - ASW #320 1:09:02

1 Developer Environments, Developer Experience, and Security - Dan Moore - ASW #319 1:10:21

1 Top 10 Web Hacking Techniques of 2024 - James Kettle - ASW #318 44:57

1 Code Scanning That Works With Your Code - Scott Norberg - ASW #317 1:12:52

1 Threat Modeling That Helps the Business - Akira Brand, Sandy Carielli - ASW #316 1:11:39

1 Security the AI SDLC - Niv Braun - ASW #315 1:08:34

1 Appsec Predictions for 2025 - Cody Scott - ASW #314 52:10

1 Discussing Useful Security Requirements with Developers - Ixchel Ruiz - ASW #313 1:07:41

1 DefectDojo and Bringing Quality Appsec Tools to Small Appsec Teams - Greg Anderson - ASW #312 1:07:10

1 Applying Usability and Transparency to Security - Hannah Sutor - ASW #311 1:09:42
Selamat datang ke Player FM
Player FM mengimbas laman-laman web bagi podcast berkualiti tinggi untuk anda nikmati sekarang. Ia merupakan aplikasi podcast terbaik dan berfungsi untuk Android, iPhone, dan web. Daftar untuk melaraskan langganan merentasi peranti.