
CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321
11 March - 1 hour 13 minsJust three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s. Common defenses have been known since the early 2000s. Jack Cable talks about CISA's Secure by Design principles and how they're trying to refocus businesses on addressing vuln classes and prioritizing software quality -- with security one of those important dimensions of quality.
Segment Resources:
https://www.cisa.gov/securebydesign https://www.cisa.gov/securebydesign/pledge https://www.cisa.gov/resources-tools/resources/product-security-bad-practices https://www.lawfaremedia.org/projects-series/reviews-essays/security-by-design https...

Security That Sticks: Shaping Human Behavior - Rinki Sethi, Nicole Jiang - BSW #418
1 hour 3 mins
22 October Finished

The Afterlife, AWS, ClickFix, Agentic AI, Robot Lumberjacks, Robocalls, Aaran Leyland - SWN #522
37 mins
21 October Finished

Reacting to Ransomware and Setting Secure Defaults - Rob Allen - ASW #353
1 hour 3 mins
21 October Finished

Mitigating attacks against AI-enabled Apps, Replacing the CIA triad, Enterprise News - David Brauchler - ESW #429
1 hour 38 mins
20 October Finished

Erotic Chats, UEFI, F5, Cisco, Doug Sings, Insiders, Lastpass, Sora, Aaran Leyland... - SWN #521
35 mins
17 October Finished