All the News -- Just Six Months Later - ASW #265

Published: Dec. 5, 2023, 7:05 p.m.

We cover appsec news on a weekly basis, but sometimes that news is merely about the start of a new project, sometimes it's yet another example of a vuln class, and sometimes it's a topic we hope doesn't become a trend.

So, what themes have we seen and where do we see them going? Here are a few headline topics that have alternately generated yays and yawns.

  • CISA's Secure by Design and Secure by Default
  • CVSS 4.0
  • Generative AI
  • MFA mandates
  • Microsoft, Rust, and Memory Safety
  • New TLDs
  • OAuth
  • OpenSSF and OWASP

Show Notes: https://securityweekly.com/asw-265