The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Application Security Weekly
Application Security Weekly artwork

BadHost, Dead CTFs, Exploding NPMs, and the Verizon DBIR - ASW #385

Application Security Weekly · 2026-06-02 · 45 min

0:00--:--

Episode notes

We dedicate an episode to catching up on appsec news with Kalyani Pawar. We see parsing problems that led to the BadHost vuln, which exposed lots of LLMs, MCPs, and agents to potential compromise. We wonder where to look for security education and practice as the camaraderie of the CTF community becomes infiltrated by LLMs. We talk about the tradeoffs in trust between using public packages vs. having agents write replacements from scratch. And we examine some of the appsec details that the Verizon DBIR reveals about how orgs are being attacked - and how orgs might use that information to protect themselves. Visit for all the latest episodes! Show Notes:

More from Application Security Weekly

All episodes →
  • Reducing Attack Surface & Evaluating Efficiency in Agents - Itamar Apelblat, David Goldschlag - ASW #38978 / 100
  • How AI Is Reshaping Identity Security at the Infrastructure Layer - Amit Masand, Neha Duggal, Ev Kontsevoy - ASW #388
  • Why Does It Matter Who or What Created the Code? - Matias Madou - ASW #387
  • Scanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386
  • AppSec Conversations on Agents, LLMs, and OWASP from RSAC - Merritt Maxim, Scott Clinton, Janet Worthington - ASW #384
Explore the best B2B Engineering & DevTools podcasts →
All Application Security Weekly episodes →