Application Security Weekly
Hosted by Mike Shema & John Kinsella & Kalyani Pawar
An hour a week on finding and fixing software flaws, from secure design to LLM-written code.
- Level
- Practitioner, assumes you work in or study security
- Status
- Active, last episode
- Who's behind it
- Media outlet, CyberRisk Alliance sourcePart of the Security Weekly network; some interview segments are sponsored and labelled in the show notes.
- Last verified
Listed underAppSec
Editorial take
The most consistent weekly AppSec interview show running. It has published every week since 2018, now past episode 400, and the guest list is strong for the niche: James Kettle on the yearly Top 10 web hacking techniques, Bob Lord on secure by design, Aaron Parecki on OAuth for MCP, Daniel Stenberg on curl. Mike Shema steers it toward fixing flaws rather than collecting them, which makes it useful for engineers as well as testers. The honest caveat: it is a CyberRisk Alliance media product, and in a sample of the last 40 episodes 16 carried a labelled sponsored interview segment. Those segments are disclosed in the show notes, so check before you press play if that matters to you.
Last hand-checked 2026-09-30.
Listen if you …
- build or secure software and want one reliable AppSec interview a week
- want to track how LLM coding tools, agents, and supply chain risk are changing AppSec
- like hearing standards people from OWASP, CISA, and the IETF explain their work
Skip if you …
- sponsored interview segments bother you, roughly two in five recent episodes include one
- you want short episodes, most run 60 to 75 minutes
Start with these 3 episodes
- 01
Figuring Out Where to Start with Secure Code - ASW #358
· 46 min · Beginner
A host-only episode on the resources worth using first, including the OWASP Top 10 and ASVS. Good orientation.
- 02
Secure By Design Is Better Than Secure By Myth - Bob Lord - ASW #365
· 54 min · Practitioner
A former CISA secure by design lead on what vendors should own, the show's focus on fixing at its best.
- 03
Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 - James Kettle - ASW #380
· 45 min · Expert
PortSwigger's research director walks the year's best web attack research. A yearly tradition on the show.
About the show
Application Security Weekly is part of the Security Weekly podcast network, owned by CyberRisk Alliance. Mike Shema hosts, with co-hosts John Kinsella and Kalyani Pawar. Most episodes are an interview with a practitioner or researcher, followed by or mixed with discussion of recent AppSec news.
The show launched in January 2018 and reached episode 402 in September 2026. It covers AppSec, DevOps, and DevSecOps: secure design, code review, threat modeling, supply chain security, and, increasingly, the security of LLMs and agents.
Notable guests
- James Kettle
- Bob Lord
- Aaron Parecki
- Daniel Stenberg
- Patrick Wardle
- Chris Wysopal
- Jack Cable
- Runa Sandvik
- Steve Wilson
- Mark Curphey
Pairs with
If Application Security Weekly works for you, these likely will too.
Absolute AppSec
Ken Johnson · Seth Law
Two working AppSec practitioners arguing about what actually helps developers ship safer code.
Listen if you run or work on an application security program and want peers' honest opinions.
panelweekly60m+Open Source Security
Josh Bressers
Half-hour conversations with the maintainers and foundations who keep open source secure.
Listen if you own dependency risk, SBOMs, or vulnerability management for a software team.
interviewweekly30–60mPaul's Security Weekly
Paul Asadoorian · Larry Pesce · Josh Marpet · Jeff Man · Mandy Logan · Tyler Robinson
Two hours of hacker news, hardware hacking, and Linux tech segments from a show running since 2005.
Listen if you like hardware, firmware, and IoT hacking and want a weekly dose of it.
mixedweekly60m+