Home Podcasts The AppSec Insiders
The AppSec Insiders

The AppSec Insiders

Farshad Abasi 19 Episodes Mar 21, 2026

The AppSec Insiders is a podcast dedicated to exploring application and cloud security topics. The hosts are software developers, white-hat hackers, and code security experts who share insights on the latest trends in the field. They also help organizations with their cybersecurity needs outside of the show. The podcast encourages AppSec professionals and developers interested in security to explore career opportunities at Forward Security. Listeners are invited to subscribe and follow the team on social media.

Episodes

The Leakiest Year Ever: A Deep Dive into the 2026 State of Secret | The AppSec Insiders Podcast Ep.20
The Leakiest Year Ever: A Deep Dive into the 2026 State of Secret | The AppSec Insiders Podcast Ep.20 Mar 21, 2026 1840 In this episode, we sit down with Dwayne McDaniel, Principal Developer Advocate at GitGuardian, to discuss the alarming rise of secret sprawl in 2025. With over 28 million hard-coded secrets leaked on public GitHub last year alone — a 34% increase year-over-year — 2025 is officially the leakiest year on record. We dig into why it's getting worse, how AI coding tools like Claude Code are contr
LLM Vulnerabilities and Prompt Injection: AppSec News Deep Dive | The AppSec Insiders Podcast Ep.19
LLM Vulnerabilities and Prompt Injection: AppSec News Deep Dive | The AppSec Insiders Podcast Ep.19 Oct 28, 2025 1716 In this episode, we explore the emerging security risks of AI and LLMs in modern applications. Iman shares real-world experiences bypassing AI guardrails like LlamaGuard and OpenAI Shield, while the team discusses prompt injection attacks, system prompt exposure, excessive agency vulnerabilities, and data poisoning. Learn about the OWASP Top 10 for LLMs, why AI usage policies are critical, and how
Fake Extensions to AI Bug Hunters: AppSec News Deep Dive | The AppSec Insiders Podcast Ep.18
Fake Extensions to AI Bug Hunters: AppSec News Deep Dive | The AppSec Insiders Podcast Ep.18 Sep 26, 2025 1129 In this episode of The AppSec Insiders Podcast, we dive into two major security stories making headlines: a fake Solidity extension that drained a developer’s crypto wallets, and Google’s AI-powered tool “Big Sleep” uncovering a critical Chrome vulnerability. From malicious packages to AI-driven defenses, we break down what these cases reveal about today’s evolving AppSec landscape.
SQL Injection to RCE: Fortinet's Critical Vulnerability Exposed | The AppSec Insiders Podcast Ep. 17
SQL Injection to RCE: Fortinet's Critical Vulnerability Exposed | The AppSec Insiders Podcast Ep. 17 Aug 27, 2025 1051 On this episode of The AppSec Insiders Podcast, we dive into CVE-2025-25257, a Fortinet FortiWeb Fabric Connector SQL injection vulnerability that escalates to RCE. We break down how this exploit works, why it’s so impactful, and what lessons organizations can learn, from proper network segmentation to the importance of SAST in your pipeline. We also touch on broader trends, from IoT security issu
Prompt Injection to RCE: When AI Gets Compromised | The AppSec Insiders Ep.16
Prompt Injection to RCE: When AI Gets Compromised | The AppSec Insiders Ep.16 Jul 25, 2025 1109 In this episode, we unpack CVE-2025-49596, where prompt injection, CSRF, and localhost access were chained to achieve RCE in the MCP Inspector AI tool. Learn how the exploit worked, what it reveals about LLM security risks, and how to defend against similar threats with sandboxing, access controls, and DevSecOps monitoring.  
What Existing AWS Services are Important to AppSec? (Part 2 of 2) | The AppSec Insiders Ep.15
What Existing AWS Services are Important to AppSec? (Part 2 of 2) | The AppSec Insiders Ep.15 Oct 29, 2024 2008 Welcome to The AppSec Insiders Podcast. This is a show where we discuss the hottest topics and latest trends in application and cloud security, and tell you what you need to know   For those who don’t know who we are, we are all software developers, white-hat hackers, and code security experts. When we’re not recording the podcast, we help organizations of all sizes with their cybersecurity needs.
What Existing AWS Services are Important to AppSec? (Part 1 of 2) | The AppSec Insiders Ep.14
What Existing AWS Services are Important to AppSec? (Part 1 of 2) | The AppSec Insiders Ep.14 Oct 29, 2024 1560 Welcome to The AppSec Insiders Podcast. This is a show where we discuss the hottest topics and latest trends in application and cloud security, and tell you what you need to know   For those who don’t know who we are, we are all software developers, white-hat hackers, and code security experts. When we’re not recording the podcast, we help organizations of all sizes with their cybersecurity needs.
2023 Year-End Review
2023 Year-End Review Dec 20, 2023 2348 In this episode, we discuss 2023 Security Threats & Newcomers Recap
The AppSec Insiders Ep. 11 - Flipper Zero and IoT Security
The AppSec Insiders Ep. 11 - Flipper Zero and IoT Security Nov 15, 2023 1859 In this episode, we discuss the Flipper Zero and IoT Security. 
Exploring the Challenges of Testing Against the ASVS Standard - Part 4
Exploring the Challenges of Testing Against the ASVS Standard - Part 4 Oct 27, 2023 1880 In this episode, we return to the topic from the previous episodes and continue explore the challenges of testing against the ASVS standard.
Exploring the Challenges of Testing Against the ASVS Standard - Part 3
Exploring the Challenges of Testing Against the ASVS Standard - Part 3 Sep 27, 2023 2033 In this episode, we explore the challenges of testing against the ASVS standard - Part 3
Exploring the Challenges of Testing Against the ASVS Standard - Part 2
Exploring the Challenges of Testing Against the ASVS Standard - Part 2 Sep 8, 2023 1955 In this episode, we continue to explore the challenges of testing against the ASVS standard.

Recommended