
Thoughts on Security in the Modern Software Supply Chain
Caroline Wong, Paula Thrasher and I were having lunch at DevOps Enterprise Summit when the conversation took an interesting turn. Paula and Caroline had been on a panel the previous day and didn't get...
16 Marras 20171h 4min

Security Processes at the Apache Software Foundation w/ Mark Thomas and Brian Fox
In our continuing series on the Struts2 vulnerability announcement and the breach at Equifax, we spoke with Mark Thomas, Director, Apache Software Foundation, and Brian Fox, CTO, Sonatype to clarify t...
15 Syys 201727min

Struts2 Vulnerabilities: Who Is Responsible?
A conversation on the ramifications of recent Struts2 announcements, the exploit at Equifax and the responsibility of companies using open source software. David Blevins, CEO, TomiTribe Brian Fox, CT...
14 Syys 201730min

What you should know about the latest Struts2 vulnerability announcement
What you should know about the latest struts2 vulnerability announcement w/ Brian Fox, CTO Sonatype, and Matthew Konda , Chair, OWASP Board of Directors. If you're a developer and concerned about se...
7 Syys 201724min

OWASP Hacker Kids in Bangalore
Most of us want to help kids become proficient in programming and cybersecurity, but don't know how to get started or have time to manage such a project. Prashant Kv figured he'd put a team together w...
29 Elo 201715min

Less than 10 Minutes Series: OWASP DockerHub with Simon Bennetts
Earlier this week, Simon Bennetts from the OWASP ZAP Project announced the official availability of the OWASP DockerHub for housing projects. I caught up with Simon soon after to hear how ZAP was util...
8 Elo 20178min

Less than 10 Minutes Series - ModSecurity Core Rule Set Project
This segment of the "Less than 10 Minutes" series was recorded live at AppSec EU 2017 in Belfast. It is an update of the ModSecurity Core Rule Set Project with project co-lead Christian Folini. The ...
12 Touko 20178min

Less than 10 Minutes Series: OWASP Summit 2017
This segment of the "Less than 10 Minutes" series was recorded live at AppSec EU 2017 in Belfast. It is an update of the OWASP Summit 2017 with conference organizer Sebastien (Seba) Deleersnyder. OWAS...
11 Touko 20177min