Skip to content

Podcasts

Application Security Weekly

Hosted by Mike Shema & John Kinsella & Kalyani Pawar

An hour a week on finding and fixing software flaws, from secure design to LLM-written code.

Mixed format Weekly 60+ min· ~402 episodes· Started 2018
Level
Practitioner, assumes you work in or study security
Status
Active, last episode
Who's behind it
Media outlet, CyberRisk Alliance sourcePart of the Security Weekly network; some interview segments are sponsored and labelled in the show notes.
Last verified

Listed underAppSec

Editorial take

The most consistent weekly AppSec interview show running. It has published every week since 2018, now past episode 400, and the guest list is strong for the niche: James Kettle on the yearly Top 10 web hacking techniques, Bob Lord on secure by design, Aaron Parecki on OAuth for MCP, Daniel Stenberg on curl. Mike Shema steers it toward fixing flaws rather than collecting them, which makes it useful for engineers as well as testers. The honest caveat: it is a CyberRisk Alliance media product, and in a sample of the last 40 episodes 16 carried a labelled sponsored interview segment. Those segments are disclosed in the show notes, so check before you press play if that matters to you.

Last hand-checked 2026-09-30.

Listen if you …

  • build or secure software and want one reliable AppSec interview a week
  • want to track how LLM coding tools, agents, and supply chain risk are changing AppSec
  • like hearing standards people from OWASP, CISA, and the IETF explain their work

Skip if you …

  • sponsored interview segments bother you, roughly two in five recent episodes include one
  • you want short episodes, most run 60 to 75 minutes

Start with these 3 episodes

  1. 01

    Figuring Out Where to Start with Secure Code - ASW #358

    · 46 min · Beginner

    A host-only episode on the resources worth using first, including the OWASP Top 10 and ASVS. Good orientation.

  2. 02

    Secure By Design Is Better Than Secure By Myth - Bob Lord - ASW #365

    · 54 min · Practitioner

    A former CISA secure by design lead on what vendors should own, the show's focus on fixing at its best.

  3. 03

    Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 - James Kettle - ASW #380

    · 45 min · Expert

    PortSwigger's research director walks the year's best web attack research. A yearly tradition on the show.

About the show

Application Security Weekly is part of the Security Weekly podcast network, owned by CyberRisk Alliance. Mike Shema hosts, with co-hosts John Kinsella and Kalyani Pawar. Most episodes are an interview with a practitioner or researcher, followed by or mixed with discussion of recent AppSec news.

The show launched in January 2018 and reached episode 402 in September 2026. It covers AppSec, DevOps, and DevSecOps: secure design, code review, threat modeling, supply chain security, and, increasingly, the security of LLMs and agents.

Notable guests

  • James Kettle
  • Bob Lord
  • Aaron Parecki
  • Daniel Stenberg
  • Patrick Wardle
  • Chris Wysopal
  • Jack Cable
  • Runa Sandvik
  • Steve Wilson
  • Mark Curphey

If Application Security Weekly works for you, these likely will too.