
Threat Modeling That Helps the Business - Akira Brand, Sandy Carielli - ASW #316
4 February - 1 hour 11 minsThreat modeling has been in the appsec toolbox for decades. But it hasn't always been used and it hasn't always been useful. Sandy Carielli shares what she's learned from talking to orgs about what's been successful, and what's failed, when they've approached this practice. Akira Brand joins to talk about her direct experience with building threat models with developers.
Speculative data flow attacks demonstrated against Apple chips with SLAP and FLOP, the design and implementation choices that led to OCSP's demise, an appsec angle on AI, updating the threat model and recommendations for implementing OAuth 2.0, and more!
Visit https://www.securityweekly.com/asw for all the latest episode...

Brains, kill switch, parking fees, CobaltStrike, Minja, Allstate, GitHub, Josh Marpet - SWN #458
33 mins
11 March Finished

CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321
1 hour 13 mins
11 March Finished

Ransomware Attacks a Decade In: What Changed? What Didn't? - benny Vasquez, Mike Mitchell - ESW #397
1 hour 58 mins
10 March Finished

Secret YouTube Videos, Thunderforge, ByBit, 365, Chrome, VMWARE, Aaran Leyland... - SWN #457
32 mins
7 March Finished