CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321
11 March - 1 hour 13 minsJust three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s. Common defenses have been known since the early 2000s. Jack Cable talks about CISA's Secure by Design principles and how they're trying to refocus businesses on addressing vuln classes and prioritizing software quality -- with security one of those important dimensions of quality.
Segment Resources:
https://www.cisa.gov/securebydesign https://www.cisa.gov/securebydesign/pledge https://www.cisa.gov/resources-tools/resources/product-security-bad-practices https://www.lawfaremedia.org/projects-series/reviews-essays/security-by-design https...
The CISO Holiday Party 2025: Leadership Lessons from the Year That Was - BSW #427
49 mins
24 December Finished
Holiday Special Part 1: You’re Gonna Click the Link - Rob Allen - SWN #540
35 mins
23 December Finished
Internal threats are the hole in Cybersecurity’s donut - Frank Vukovits - ESW #438
1 hour 57 mins
22 December Finished
Auld Lang Syne, Ghostpairing, Centerstack, WAFS, React2Shell, Crypto, Josh Marpet... - SWN #539
32 mins
19 December Finished