
Free Daily Podcast Summary
by The Elephant in AppSec
Time to discuss AppSec issues no one talks about.
The most recent episodes — sign up to get AI-powered summaries of each one.
My guest today is Petra Vukmirovic, Head of Information Security and IT at Numan, and she also works with DevArmor on automating threat modeling and security design reviews. Outside of that she started the OWASP Threat Model Library, an open collection of real threat models the community can learn from.What makes her path unusual is that she didn't come to AppSec through development, she came through emergency medicine, where she worked as a doctor.In this episode, we talked about what transfers from the ER to incident response, which is mostly the protocols: risk scores, runbooks, decision trees you can follow when things are on fire. She also thinks threat modeling stops too early. Most teams model protective controls and stop, when recovery deserves the same attention. We also got into automating threat models with LLMs, catching drift between the model and the code, and where design reviews end and threat modeling begins.And much more!This podcast is brought to you byEscape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
Today I'm joined by Advait Patel, Senior Site Reliability Engineer and the creator of DockSec, an open-source, AI-powered Docker security scanner that's now an official OWASP Incubator project.In this episode, we get into:Why dumping 200 container findings into a Jira ticket is the fastest way to get developers to fix nothing and how DockSec cuts that down to the 5 that actually matterThe AI support agent that got hijacked by a single malicious ticket and emailed customer data straight to an attackerWhy you should treat AI as an assistant on a leash, not an engineer with root accessthe Docker mistakes Advait sees everywhere (stale base images, root by default, and secrets baked right into the image)…and much more!Get ready, Advait doesn't hold back his opinions. Let's dive right in!Connect with Advait: https://www.linkedin.com/in/advaitpatel93/Connect with Alexandra: https://www.linkedin.com/in/alexandra-charikova/This podcast is brought to you byEscape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining ASM business-logic-aware DAST, and AI-powered pentesting solutions.MentionedDockSec on GitHub (now the OWASP org repo): https://github.com/OWASP/DockSecOWASP project page: https://owasp.org/www-project-docksec/Open Policy Agent (his "open policy" reference): https://www.openpolicyagent.org/OWASP Top 10 for LLM Applications: https://genai.owasp.org/
Today, I'm joined by Kavia Venkatesh, Director of Product Security at a large healthcare organization. She didn't take the traditional path into cybersecurity — she came from biotech. But that outsider lens turned out to be her edge. With over 10 years of experience leading cybersecurity strategy for hyper-scale ecosystems, she's built many security programs from the ground up, navigating 9 acquisitions in 18 months at a large tech org, and along the way developed a rare ability to translate risk into language that executives actually act on. Kavia is also a frequent speaker at premier global conferences, including DEF CON, BSides San Francisco, and Nullcon. In this episode, we talked about what most security teams get completely wrong during integrations, what she'd change about how security teams show up in organizations and the "breachability mindset" that changes how you approach risk. And much more!Get ready, Kavia doesn't hold back her opinions. Let's dive right in!This podcast is brought to you by Escape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.Connect with Kavia: https://www.linkedin.com/in/kaviavenkatesh/
Today, I’m joined by Jason Fernandes, VP of security and privacy at Mercari, the Japanese-born global marketplace now spanning e-commerce, FinTech, and crypto. It is this rare combination that puts him at the intersection of some of the strictest regulatory environments in tech. He oversees everything from product and platform security to threat detection, privacy, and, since last year, AI security and AI governance. In this episode, we also talked about the challenges of AI governance, the lethal trifecta for AI agents, the confused deputy problem, and how to justify AI security investments to the leadership and working with FinOps teams. And much more! Dive right in!This podcast is brought to you byEscape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.MentionedFACADE (Google's internal fraud detection model) https://arxiv.org/abs/2412.06700Meta Practical AI Agent Security (Rule of Two) https://ai.meta.com/blog/practical-ai-agent-security/Simon Willison The Lethal Trifecta https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/Hiroki's AI Security blog (Mercari) https://hi120ki.github.io/blog/posts/20260103/Anthropic Project Vend https://www.anthropic.com/research/project-vend-2
Today, I’m joined by Sam Stepanyan, an OWASP Global Board member and an OWASP London Chapter Leader. Sam is an Independent Application Security Consultant and Security Architect with over 20 years of experience in the IT industry.Sam has worked for various financial services institutions in the City of London specialising in Application Security consulting, Secure Software Development Lifecycle (SDLC), developer training, source code reviews and vulnerability management. He is also a Subject Matter Expert in Web Application Firewalls (WAF) and SIEM systems.In this episode, we explore why, despite OWASP being around for over 25 years, many developers are still unaware of it—and why shifting focus toward developer conferences might be key to spreading security knowledge more effectively.We also discuss the impact of AI on modern security practices, the growing role of automated penetration testing tools, and how even small changes—like adding the word “secure” to a vibe coding prompt—can help nudge developers toward more security-conscious decisions.Dive right in! This podcast is brought to you byEscape: https://escape.tech — Offensive security for the teams that are 100x outnumbered, combining Attack Surface Management, business-logic-aware DAST and AI pentesting solutions.
Today, I’m joined by Amol Deshpande, a seasoned security engineer currently at Stripe, where he focuses on building secure systems at massive scale. With a background spanning product security and penetration testing at companies like Salesforce, Splunk, and Early Warning, Amol brings deep hands-on experience in securing complex, real-world platforms. He’s also been a HackMIT judge and a long-time CTF competitor at DEF CON, giving him a very practical view of modern security challenges.In this episode, we cover whether security must now belong in every AI strategy meeting, and how to embed it into AI development from the outset.We also touch on how privacy concerns will only grow as agents are trained on sensitive data and why human oversight is essential for critical AI operations. Dive right in!
Today, I’m joined by Aleksandra Kornecka, a security engineer with a global mindset. She recently transitioned from Senior AppSec Engineer to Cloud Infrastructure Security Engineer, and has a background in software testing and cognitive science — a combination that gives her a unique take on both the technical and human sides of security.As a member of the OWASP Security Champions Guide and the project's Artifact stream, Aleksandra also put efforts to collect templates, documents, and other artifacts useful to build the security champions program.In this episode, we dive into the mindset shift developers need to successfully break into security and why security champions are critical for scaling security awareness across organizations.We also explore how curiosity fuels a lasting passion for security, and unpack why Zero Trust is often misunderstood and overhyped.Dive right in!
Today, I’m joined by Gowtham Sundar, a Senior Lead Engineer - 3A Security (AI and API included as you can guess) at SPH Media and a seasoned AppSec leader with over a decade of experience across enterprise security, penetration testing, and secure product development.In this episode, Gowtham brings a real practitioner’s point of view on what it actually takes to secure AI systems. We dive into why APIs are at the heart of AI, why securing them is non-negotiable, and why automated API discovery is becoming critical for governance as systems scale.We also talk about how AI security is evolving at lightning speed, sometimes changing week by week, and what that means for security teams trying to keep up.And with that, get ready to hear Gowtham’s opinions. Dive right in!
Time to discuss AppSec issues no one talks about.
AI-powered recaps with compact key takeaways, quotes, and insights.
Get key takeaways from The Elephant in AppSec in a 5-minute read.
Stay current on your favorite podcasts without falling behind.
It's a free AI-powered email that summarizes new episodes of The Elephant in AppSec as soon as they're published. You get the key takeaways, notable quotes, and links & mentions — all in a quick read.
When a new episode drops, our AI transcribes and analyzes it, then generates a personalized summary tailored to your interests and profession. It's delivered to your inbox every morning.
No. Podzilla is an independent service that summarizes publicly available podcast content. We're not affiliated with or endorsed by The Elephant in AppSec.
Absolutely! The free plan covers up to 3 podcasts. Upgrade to Pro for 15, or Premium for 50. Browse our full catalog at /podcasts.
The Elephant in AppSec publishes weekly. Our AI generates a summary within hours of each new episode.
The Elephant in AppSec covers topics including Technology. Our AI identifies the specific themes in each episode and highlights what matters most to you.
Free forever for up to 3 podcasts. No credit card required.
Free forever for up to 3 podcasts. No credit card required.