
Threat Modeling That Helps the Business - Akira Brand, Sandy Carielli - ASW #316
4 February - 1 hour 11 minsThreat modeling has been in the appsec toolbox for decades. But it hasn't always been used and it hasn't always been useful. Sandy Carielli shares what she's learned from talking to orgs about what's been successful, and what's failed, when they've approached this practice. Akira Brand joins to talk about her direct experience with building threat models with developers.
Speculative data flow attacks demonstrated against Apple chips with SLAP and FLOP, the design and implementation choices that led to OCSP's demise, an appsec angle on AI, updating the threat model and recommendations for implementing OAuth 2.0, and more!
Visit https://www.securityweekly.com/asw for all the latest episode...

ISO 42001 Certification, CIOs Struggle to Align Strategies, and CISOs Rethink Hiring - Martin Tschammer - BSW #392
1 hour 3 mins
23 April Finished

Brains, Elusive Comet, AI Scams, Microsoft Dog Food, Deleting Yourself, Josh Marpet - SWN #470
31 mins
22 April Finished

The past, present, and future of enterprise AI - Matthew Toussain, Pravi Devineni - ESW #403
2 hours 11 mins
21 April Finished

HR Chatbots, MITRE, 4chan, Oracle, Identity, Port 53, NTLM, Zambia, Josh Marpet... - SWN #469
36 mins
18 April Finished