{"podcast":{"title":"Application Security Weekly (Audio)","slug":"application-security-weekly-audio-436682","podcast_index_feed_id":436682,"rss_url":"https://aswaudio.libsyn.com/rss","website_url":"https://securityweekly.com/asw","image_url":"https://static.libsyn.com/p/assets/0/a/1/5/0a15d1d27c1a4bbc27a2322813b393ee/ASW_Cover_1920x1920-20240930-x3a3ohx73b.png","author":"Security Weekly Productions","episode_count":405,"summary":"About all things AppSec, DevOps, and DevSecOps. Hosted by Mike Shema and John Kinsella, the podcast focuses on helping its audience find and fix software flaws effectively.","last_synced_at":"2026-07-14T18:20:04.472781+00:00","page_url":"https://stenobird.com/podcast/application-security-weekly-audio-436682"},"episode":{"title":"BadHost, Dead CTFs, Exploding NPMs, and the Verizon DBIR - ASW #385","slug":"badhost-dead-ctfs-exploding-npms-and-the-verizon-dbir-asw-385","published_at":"2026-06-02T09:00:00+00:00","page_url":"https://stenobird.com/podcast/application-security-weekly-audio-436682/badhost-dead-ctfs-exploding-npms-and-the-verizon-dbir-asw-385","show_page_url":"https://stenobird.com/podcast/application-security-weekly-audio-436682","url":"https://aswaudio.libsyn.com/badhost-dead-ctfs-exploding-npms-and-the-verizon-dbir-asw-385","audio_url":"https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/aswaudio/ASW_385_1--712b8b4e-9c6b-4baf-bb8c-4ac589cd0726--audio-converted--bfd89aae-78b8-401c-a354-c344f289a50e.mp3?dest-id=626765","summary":"We dedicate an episode to catching up on appsec news with Kalyani Pawar. We see parsing problems that led to the BadHost vuln, which exposed lots of LLMs, MCPs, and agents to potential compromise. We wonder where to look for security education and practice as the camaraderie of the CTF community becomes infiltrated by LLMs. We talk about the tradeoffs in trust between using public packages vs. having agents write replacements from scratch. And we examine some of the appsec details that the Verizon DBIR reveals about how orgs are being attacked -- and how orgs might use that information to protect themselves. Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-385","meta_description":"We dedicate an episode to catching up on appsec news with Kalyani Pawar. We see parsing problems that led to the BadHost vuln, which exposed lots of LLMs,…","key_points":[],"chapters":[],"topics":[],"duration_seconds":2722,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/application-security-weekly-audio-436682/episodes/badhost-dead-ctfs-exploding-npms-and-the-verizon-dbir-asw-385/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/application-security-weekly-audio-436682/badhost-dead-ctfs-exploding-npms-and-the-verizon-dbir-asw-385.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}