Go offline with the Player FM app!
CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321
Fetch error
Hmmm there seems to be a problem fetching this series right now. Last successful fetch was on August 03, 2025 02:07 ()
What now? This series will be checked again in the next hour. If you believe it should be working, please verify the publisher's feed link below is valid and includes actual episode links. You can contact support to request the feed be immediately fetched.
Manage episode 470780001 series 2591184
Just three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s. Common defenses have been known since the early 2000s. Jack Cable talks about CISA's Secure by Design principles and how they're trying to refocus businesses on addressing vuln classes and prioritizing software quality -- with security one of those important dimensions of quality.
Segment Resources:
- https://www.cisa.gov/securebydesign
- https://www.cisa.gov/securebydesign/pledge
- https://www.cisa.gov/resources-tools/resources/product-security-bad-practices
- https://www.lawfaremedia.org/projects-series/reviews-essays/security-by-design
- https://corridor.dev
Skype hangs up for good, over a million cheap Android devices may be backdoored, parallels between jailbreak research and XSS, impersonating AirTags, network reconnaissance via a memory disclosure vuln in the GFW, and more!
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-321
3279 episodes
Fetch error
Hmmm there seems to be a problem fetching this series right now. Last successful fetch was on August 03, 2025 02:07 ()
What now? This series will be checked again in the next hour. If you believe it should be working, please verify the publisher's feed link below is valid and includes actual episode links. You can contact support to request the feed be immediately fetched.
Manage episode 470780001 series 2591184
Just three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s. Common defenses have been known since the early 2000s. Jack Cable talks about CISA's Secure by Design principles and how they're trying to refocus businesses on addressing vuln classes and prioritizing software quality -- with security one of those important dimensions of quality.
Segment Resources:
- https://www.cisa.gov/securebydesign
- https://www.cisa.gov/securebydesign/pledge
- https://www.cisa.gov/resources-tools/resources/product-security-bad-practices
- https://www.lawfaremedia.org/projects-series/reviews-essays/security-by-design
- https://corridor.dev
Skype hangs up for good, over a million cheap Android devices may be backdoored, parallels between jailbreak research and XSS, impersonating AirTags, network reconnaissance via a memory disclosure vuln in the GFW, and more!
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-321
3279 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.