The Elephant in AppSec
The Elephant in AppSec
Podcast Description
Time to discuss AppSec issues no one talks about.
Podcast Insights
Content Themes
The podcast covers a wide range of application security topics, including measuring AppSec ROI, API security, threat modeling, and the integration of security with product management. For example, episodes like 'Can You Really Quantify AppSec ROI?' challenge listeners to think critically about how security initiatives are evaluated, while 'How to Fix API Security Before It's Too Late' dives deep into proactive measures for securing APIs.

Time to discuss AppSec issues no one talks about.
Today I'm joined by Advait Patel, Senior Site Reliability Engineer and the creator of DockSec, an open-source, AI-powered Docker security scanner that's now an official OWASP Incubator project.
In this episode, we get into:
Why dumping 200 container findings into a Jira ticket is the fastest way to get developers to fix nothing and how DockSec cuts that down to the 5 that actually matter
The AI support agent that got hijacked by a single malicious ticket and emailed customer data straight to an attacker
Why you should treat AI as an assistant on a leash, not an engineer with root access
the Docker mistakes Advait sees everywhere (stale base images, root by default, and secrets baked right into the image)
…and much more!
Get ready, Advait doesn't hold back his opinions. Let's dive right in!
Connect with Advait: https://www.linkedin.com/in/advaitpatel93/
Connect with Alexandra: https://www.linkedin.com/in/alexandra-charikova/
This podcast is brought to you by
Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining ASM business-logic-aware DAST, and AI-powered pentesting solutions.
Mentioned
DockSec on GitHub (now the OWASP org repo):https://github.com/OWASP/DockSec
OWASP project page:https://owasp.org/www-project-docksec/
Open Policy Agent (his ”open policy” reference): https://www.openpolicyagent.org/
OWASP Top 10 for LLM Applications: https://genai.owasp.org/

Disclaimer
This podcast’s information is provided for general reference and was obtained from publicly accessible sources. The Podcast Collaborative neither produces nor verifies the content, accuracy, or suitability of this podcast. Views and opinions belong solely to the podcast creators and guests.
For a complete disclaimer, please see our Full Disclaimer on the archive page. The Podcast Collaborative bears no responsibility for the podcast’s themes, language, or overall content. Listener discretion is advised. Read our Terms of Use and Privacy Policy for more details.