Chris Elgee, Counter Hack Challenge – Application Security Weekly #43

Chris Elgee is a full time husband, father of four, and technical engineer at Counter Hack Challenges. Chris joins Keith and Paul this week to talk about the Counter Hack Challenge, how it’s been working on the challenge vs. playing it, and more!… Continue reading Chris Elgee, Counter Hack Challenge – Application Security Weekly #43

NSA Malware, AFL Fuzzer, & Firecracker – Application Security Weekly #42

Hackers are opening SMB ports on routers to infect PCs with NSA malware, bug detectives whip up smarter version of classic AFL fuzzer to hunt code vulnerabilities, malware & rogue users can spy on some apps’ HTTPS crypto, exploiting developer… Continue reading NSA Malware, AFL Fuzzer, & Firecracker – Application Security Weekly #42

Aleksei Tiurin, Acunetix – Application Security Weekly #42

Aleksei Tiurin is the Senior Security Researcher for Acunetix. He is performing a technical segment on reverse proxies using weblogic, Tomcat, and Nginx. To learn more about Acunetix, go to: www.acunetix.com/securityweekly Full Show Notes Follow us on … Continue reading Aleksei Tiurin, Acunetix – Application Security Weekly #42

Drupalgeddon, USPS, & JavaScript – Application Security Weekly #41

Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers, second WordPress hacking campaign underway, USPS took a year to fix a vulnerability that exposed all 60 million users’ data, this JavaScript can snoop on other Browser Ta… Continue reading Drupalgeddon, USPS, & JavaScript – Application Security Weekly #41

Brent Dukes – Application Security Weekly #41

Brent Dukes is a hacker, and Director of Information Security for an established manufacturing company. He joins Keith and Paul this week to talk about WAF’s, Pentesting, Burp Suite, and more! Full Show NotesFollow us on Twitter: https://www.twitter.co… Continue reading Brent Dukes – Application Security Weekly #41

Instagram, Kraken, GitMiner – Application Security Weekly #40

Instagram leaks passwords to the public, Clickjacking on Google MyAccount Worth $7,500, James Wickett’s thread on Open Source SAST options, an advanced search tool for sensitive information stored in GitHub repos, and more! News Bugs, Breaches, a… Continue reading Instagram, Kraken, GitMiner – Application Security Weekly #40

John Kinsella, Layered Insight – Application Security Weekly #40

Previously co-founder and head of product at Layered Insight, John now leads container security engineering at Qualys after it’s acquisition of Layered Insight. John talks about Qualys’ Container Security that centralized, continuous discov… Continue reading John Kinsella, Layered Insight – Application Security Weekly #40

ColdFusion, Destroying Logs, & Tracing Meme’s – Application Security Weekly #39

DJI Drone Vulnerability, Hackers are increasingly destroying logs to hide attacks, Adobe ColdFusion servers under attack from APT group, understanding Open Source Code use in your business, and more! News Bugs, Breaches, and More! 1.) No need for Russi… Continue reading ColdFusion, Destroying Logs, & Tracing Meme’s – Application Security Weekly #39

Brian Kelly, CyberArk – Application Security Weekly #39

Brian Kelly is Head of Conjur Engineering at CyberArk, where he focuses on creating products that add much-needed security and identity management to the landscape of DevOps tools and cloud systems. Full Show NotesFollow us on Twitter: https://www.twit… Continue reading Brian Kelly, CyberArk – Application Security Weekly #39

‘Stalkerware’, DHCPv6 Packets , & Python – Application Security Weekly #38

In the Application Security News, a nasty DHCPv6 packet can Pwn vulnerable Linux Boxes, ‘Stalkerware’ website let anyone intercept texts of tens of thousands of people, twelve malicious Python libraries found and removed from PyPI, the U.S…. Continue reading ‘Stalkerware’, DHCPv6 Packets , & Python – Application Security Weekly #38