309 episódios
- Most fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents. Petra traded emergency medicine for application security and now heads information security at Numan — and she joins Chris Romeo and Robert Hurlbut to make the case for fault tree analysis (FTA), the deductive method that picks up exactly where threat modeling stops. Petra walks through a "wrong customer refund" AI agent scenario step by step, showing how AND/OR gates and minimal cut sets turn vague worry into ranked, data backed probabilities. They dig into where AI helps build a tree, and where garbage in, garbage out still applies, why "comprehensive test coverage" is a myth, and how attaching real dollar figures to failure paths makes it easier to sell security controls to leadership.
This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
→ Learn more about Corgea
Connect with Petra Vukmirovic:
→ Petra Vukmirovic on LinkedIn
→ OWASP Threat Model Library
Mentioned in this episode:
→ Adam Shostack: "Stop Trying to 'Manage Risk'" (keynote)
→ OWASP Global AppSec USA 2026 (San Francisco, Nov 5–6)
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
Chapters:
00:00 Cold open — the math behind where to put your controls
01:09 Meet Petra Vukmirovic
01:28 Petra's origin story: from ER doctor to AppSec
02:50 Career path: engineer to Head of InfoSec at Numan
04:18 What is fault tree analysis, and where threat modeling ends
06:22 Can AI actually do fault tree analysis?
08:12 Walking the "wrong customer refund" agent example
12:33 Storing your trees: JSON vs. Markdown
16:08 Why conjunctive failures trip up narrow thinking
17:27 Top 3 failure modes when agents touch downstream systems
19:29 Real story: an agent pushed code to main without approval
21:27 Testing: why "comprehensive coverage" is a myth
23:54 How rough is rough? Assigning probabilities
28:08 Getting started without a six week science project
31:35 Using FTA to sell controls and build credibility
33:43 The epiphany: FTA is about controls, not faults
34:48 The one thing every agentic team should add today
35:48 Closing thoughts and OWASP Global AppSec USA preview - Most security champions programs don't fail on tooling — they fail on people. Lisi Hocke spent three years as a champion before moving fully into product security, which means she has argued both sides of this from inside the trenches. Drawing on the talk she and Mireia Cano gave at OWASP Global AppSec EU 2026, Lisi walks us through the four things that actually make these programs work: psychological safety first, then cognitive load, then influence when you hold no formal authority, then a champions community so the whole thing doesn't stall the week security goes on vacation. We also get into cutting security wait times, winning organizational support, what AI does and doesn't change here, and why she will tell you never to record the champions meeting.
This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
→ Learn more about Corgea
Connect with Lisi Hocke:
→ Lisi Hocke on LinkedIn
→ A Tester's Journey — Lisi's blog
Mentioned in this episode:
→ Slides: Security Champions — Lessons from Opposite Trenches (with Mireia Cano)
→ OWASP Juice Shop
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
Chapters:
00:00 Cold open — what psychological safety actually means
00:56 Meet Lisi Hocke
02:25 Lisi's security origin story
05:42 "That place was taken" — becoming a champion anyway
07:39 Moving into a full-time product security role
08:39 Meeting Björn Kimminich, the Juice Shop project lead
09:23 Why role play instead of a normal conference talk
12:27 Security and development, disconnected
14:19 The first full-time security role
15:14 Making people wait is the real damage
17:10 Cutting the backlog and the turnaround time
19:31 What Lisi got dead wrong
20:08 What testing and quality work taught her
21:31 The four things that make champions programs work
22:07 One: fostering psychological safety
24:50 Champions without their manager's blessing
28:45 Two: managing cognitive load
29:46 Three kinds of load, and which one to cut
31:21 Three: power sources when you have no formal authority
33:03 Four: build a champions community
34:38 Keeping security people from burning out
36:37 How AI changes who you recruit and what you need
39:32 Should AI change champions programs at all?
40:33 Psychological safety when a bot joins the meeting
42:25 Don't record the champions meetings
43:26 Programs that outlive the person who started them
45:59 Key takeaway and homework
47:21 Closing thoughts - Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generated with context about your actual application, agents that chase findings the way a human tester would, and results a scanner was never going to produce. We get into what it costs once tokens enter the picture, who pays for them, whether a pentest on every pull request is realistic, and what stops an autonomous tester from going further than it should. Then we look further out: the future of bug bounties, what happens when cloud and model providers absorb today's security tooling, and who is accountable when an agent deletes your production database.
This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
→ Learn more about Corgea
Connect with James Berthoty:
→ James Berthoty on LinkedIn
→ Latio
→ Latio Pulse
Mentioned in this episode:
→ Latio's free reports
→ James on the podcast the first time: Is DAST Dead? And the future of API security
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
Chapters:
00:00 Cold open — the results speak for themselves
01:01 Meet James Berthoty and the "Is DAST dead?" fallout
01:31 Chickens, eggs, and getting away from screens
03:46 Why we're revisiting the DAST question
04:14 A working definition of AI pentesting
05:47 Contextual payloads and application awareness
06:47 Determinism, repeatability, and what buyers actually want
07:46 Can you run an AI pentest on every code change?
09:43 What it really costs
10:40 Incumbents vs. AI-native vendors
13:27 Who pays for the tokens?
14:29 Bundling, platforms, and competitive pressure
16:25 AI across the whole development workflow
18:22 Agents that run all the way to deployment
19:21 A pentest on every pull request
21:52 What stops a pentest from going too far?
23:10 Permission scoping and guardrails
26:07 Where the findings actually land
28:02 The future of bug bounties
30:50 Why pentests command more budget than DAST
31:45 Could the cloud providers absorb security tooling?
34:38 What model providers could build instead
36:36 The same story on the code scanning side
39:24 Accountability when the tool misses something
40:22 Shared responsibility when an agent deletes production
41:23 The verdict on DAST
42:19 Where to find Latio's free reports
43:15 Closing thoughts - AI security has no shortage of standards — the problem is turning them into something a team can actually use. Rob van der Veer has spent 34 years in AI and security, founded the OWASP AI Exchange, and created MOSAIC, the agreement that brought eight standards bodies together with SANS to stop the fragmentation. Rob explains what responsible AI really means, what the EU AI Act actually asks of you, and why most AppSec teams are still missing the point on AI-generated code. We also get into agentic red teaming, what happens when agents quietly exceed their scope, and whether AI finally levels the playing field between attackers and defenders. If you build software with AI in it — or with AI — this one is worth your time.
This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
→ Learn more about Corgea
Connect with Rob van der Veer:
→ Rob van der Veer on LinkedIn
→ OWASP AI Exchange
→ MOSAIC
Mentioned in this episode:
→ OpenCRE
→ Luna and the Magic AI Paintbrush
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
Chapters:
00:00 Cold open — don't be surprised when the AI breaks out of the cage
01:15 Meet Rob van der Veer: music, cycling, and the Hoodoo 500
05:24 Defining responsible AI
07:41 Fairness, protected attributes, and transparency
09:34 The EU AI Act and what regulation actually asks of you
11:27 How AI changes every part of software development
13:23 Where responsibility lands
15:20 You're not defending your own data center
17:19 What traditional AppSec teams consistently miss about AI
18:18 Finding vulnerabilities in AI-generated code
19:19 Too many standards — and using AI to write them
20:51 MOSAIC: eight standards bodies, one agreement
22:09 One machine-readable taxonomy with OpenCRE
23:06 Can AI level the field between attackers and defenders?
25:59 When AI security becomes security theater
26:56 What agentic red teaming actually looks like
29:44 When agents exceed their scope
32:43 Luna and the Magic AI Paintbrush
33:40 Do we sandbox the agents?
34:40 Guardrails without killing creativity
36:39 Skill atrophy when AI is your only way forward
40:04 "How do we hit this quarter?" and the pressure to ship
43:16 Everyone is selling agentic security
45:07 Key takeaways and where to start with the AI Exchange
47:12 Closing thoughts - You don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. Vikram created Precogly, an open-source threat modeling platform now running as an OWASP project, and he walks us through what it took to build a free tool on par with commercial vendors. We dig into the tension among speed, compliance, and real risk; whether the Threat Modeling Manifesto needs amending for AI; and what it means to "fight the AI" so critical thinking stays sharp. If you care about AppSec, AI, and the future of threat modeling, this conversation will give you a lot to think about.
This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
→ Learn more about Corgea
Connect with Vikram Narayan:
→ Vikram Narayan on LinkedIn
→ Precogly — open-source threat modeling (OWASP project)
Mentioned in this episode:
→ Threat Modeling Manifesto
→ ThreatModCon
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
Chapters:
00:00 Cold open — the threat model that "feels wrong"
01:22 Welcome and introductions
02:17 Vikram's security origin story
05:43 From machine learning research into LLMs
06:42 Hospital chatbots, hallucination, and knowing when to escalate
07:51 ThreatModCon and the case for an open-source threat modeling tool
09:35 IoT, emergence, and the traffic-light problem
11:17 The OWASP Vienna talk and the Threat Modeling Manifesto
12:26 Why "AI, just do the threat model" falls apart
15:14 What AI is actually good at in threat modeling
18:07 Human discomfort vs. the machine's confident answer
20:29 Inside Precogly: accelerant, not replacement
20:58 Library packs and the skills layer
24:50 Where AI kicks in — and where it shouldn't
27:48 Should the Threat Modeling Manifesto be amended for AI?
30:28 Where Chris and Robert land
31:36 Wi-Fi sensing, privacy, and modeling what you can't see
33:15 If you can't explain it, can you trust it?
35:11 Beyond checklists — design-level questions
35:59 Fight the AI — Vikram's key takeaway
39:10 Closing thoughts
Mais podcasts de Empreendedorismo
Podcasts em tendência em Empreendedorismo
Sobre The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
Site de podcastOuça The Application Security Podcast, O Conselho e muitos outros podcasts de todo o mundo com o aplicativo o radio.net

Obtenha o aplicativo gratuito radio.net
- Guardar rádios e podcasts favoritos
- Transmissão via Wi-Fi ou Bluetooth
- Carplay & Android Audo compatìvel
- E ainda mais funções
Obtenha o aplicativo gratuito radio.net
- Guardar rádios e podcasts favoritos
- Transmissão via Wi-Fi ou Bluetooth
- Carplay & Android Audo compatìvel
- E ainda mais funções


The Application Security Podcast
Leia o código,
baixe o aplicativo,
ouça.
baixe o aplicativo,
ouça.


















