CISA's Secure by Design Principles, Pledge, and Progress - Jack Cable - ASW #321
About this episode
Just three months into 2025 and we already have several hundred CVEs for XSS and SQL injection. Appsec has known about these vulns since the late 90s. Common defenses have been known since the early 2000s. Jack Cable talks about CISA's Secure by Design principles and how they're trying to refocus businesses on addressing vuln classes and prioritizing software quality -- with security one of those important dimensions of quality.
Segment Resources:
- https://www.cisa.gov/securebydesign
- https://www.cisa.gov/securebydesign/pledge
- https://www.cisa.gov/resources-tools/resources/product-security-bad-practices
- https://www.lawfaremedia.org/projects-series/reviews-essays/security-by-design
- https://corridor.dev
Skype hangs up for good, over a million cheap Android devices may be backdoored, parallels between jailbreak research and XSS, impersonating AirTags, network reconnaissance via a memory disclosure vuln in the GFW, and more!
Visit https://www.securityweekly.com/asw for all the latest episodes!
Show Notes: https://securityweekly.com/asw-321
Get every episode summarized
Each time Security Weekly Podcast Network (Audio) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Security Weekly Podcast Network (Audio)
9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - S...
Security Weekly Podcast Network (Audio)
It's More Secure When It's Disabled - PSW #943
Security Weekly Podcast Network (Audio)
Security Money: The Index Explodes, as the History of AI Teaches Us About Invest...
Security Weekly Podcast Network (Audio)
Cybercabs, Robohobos, BigBear, Nightmare Eclipse, weChat, Flock, ASCII, Aaran Le...
Security Weekly Podcast Network (Audio)