Gotta hand it to the guys over at risky.biz, it seems like they are producing so much great content that I can’t get enough of it.

I really enjoy their stuff because it’s not just a bunch of news headlines with little context; they’ll actually go into in-depth conversations and talk about the implications of a current event or headline.

Are there any other podcasts I should be checking out?

  • _zi@infosec.pub
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 year ago

    Since I’ve made my career on the AppSec and research side of the fence I do have a few recommendations on that side of things:

    Absolute AppSec - Discussion of the week sort of podcast, from a couple of experience AppSec guys. I originally came across them because they seem to be one of the few resources really talking details about source code review (they offer a training on it). Which is just one of those areas that kinda easy to talk about but really hard to teach (imo). But yeah they’ll generaly just discuss a few topics from recent news and how it impacts AppSec. Good variety here, sometimes offensive, sometimes defensive, sometimes its something else. The hosts occasionally will disagree and will have some solid discussions on it.

    Critical Thinking: Bug Bounty Podcast - More of a bug bounty focus. While priorities differ between more general AppSec assessments and bug bounty, there is enough overlap to make the podcast worthwhile. Fairly discussional podcast, kinda a discussion of the week sometimes riffing off of recent vulnerability disclosures but also getting into other aspects like tooling and methodology.

    Dayzerosec - I cohost this podcast with a friend, we both work in vulnerability research and exploit development so we are kinda just doing a podcast on what we would find interesting. talking about root causes, and exploitation of whatever interesting bugs were disclosed in the last week-ish. Its a very technical podcast and we don’t really tend to cover news/attacks. We do two episodes a week, one focused on “bug bounty” style issues, just higher-level appsec and websec stuff, and one lower-level memory corruption and occasionally hardware layer attacks. Though we also put out summaries of many of the vulnerabilities we cover https://dayzerosec.com/vulns