More The Secure Disclosure episodes

OWASP Top 10, Vibe Coding, and What Developers Miss w/ Tanya Janca thumbnail

OWASP Top 10, Vibe Coding, and What Developers Miss w/ Tanya Janca

Published 22 Apr 2026

Duration: 00:38:13

Gaps in cybersecurity education, persistent vulnerabilities like SQL injection, OWASP data limitations, evolving supply chain risks, high training costs, AI's contextual challenges, and the need for secure-by-design principles and collaboration highlight systemic challenges in addressing evolving cyber threats.

Episode Description

Tanya Janca joins the podcast for a sharp, no-nonsense conversation on the OWASP Top 10, why secure coding still gets skipped, and how AI is reshaping...

Overview

The podcast explores critical challenges in cybersecurity education and practice, emphasizing a lack of formal training in concepts like access control, which leaves developers unprepared for real-world threats. Despite collaborative efforts like the OWASP Top 10 projectwhich identifies top web application risksgaps in breach reporting and persistent issues such as broken access control highlight ongoing struggles to address foundational security principles. Industry-wide, repetitive vulnerabilities like SQL injection and injection flaws persist due to inadequate education, outdated tools, and a developer focus on feature-building over early security integration. Efforts to democratize training, such as community programs and open resources, aim to overcome cost barriers and improve awareness, though challenges remain in making security education accessible and effective.

AIs emerging role in security is both promising and complex. While AI can reduce vulnerabilities in code generation and prompt secure practices, its effectiveness is limited by contextual understanding and reliance on human review. Persistent debates around supply chain vulnerabilities underscore the need for systemic solutions beyond third-party dependencies, especially in high-stakes areas like medical devices, where low-level languages introduce memory safety risks. Behavioral economics and nudgessuch as default settings and choice architectureare proposed to encourage secure coding without coercion. Additionally, the discussion emphasizes shifting from reactive security tools to proactive "security by design," layered defenses, and fostering collaboration between developers and security teams through community engagement and shared knowledge.

The evolving landscape also raises questions about the future of security roles amid AI advancements. While automation may streamline tasks like penetration testing, it risks displacing entry-level positions, pushing the field toward specialized expertise in creative problem-solving and ethical oversight. Persistent challenges include balancing automation with human judgment, ensuring AI-driven tools maintain accuracy, and addressing systemic gaps in risk prioritization and training quality. The conversation culminates in calls for integrated security practices, pragmatic risk management, and the reimagining of security education to meet the demands of an AI-driven era while preserving the critical role of human insight and accountability.

Recent Episodes of The Secure Disclosure

14 Jul 2026 How to Stop Supply Chain Attacks Without Destroying Developer Productivity

"Cybersecurity threats, especially supply chain attacks on developers and open-source packages, demand balanced mitigation strategies, AI-driven security challenges, and early integration of security in development, with collaboration and adaptability key to addressing evolving risks."

1 Jul 2026 Solving the Supply Chain Security & Malware Crisis w/John Amaral

Escalating software supply chain threats target open-source ecosystems through credential exploitation, AI-fueled malware, and upstream compromises, with challenges in dependency management and outdated libraries driving AI-driven remediation strategies like automated patching and version pinning, though human oversight remains critical for validating fixes.

16 Jun 2026 Your Microphone Became a Keylogger w/ David vonThenen

Machine learning analyzes keystroke acoustic signatures to infer typed characters over remote platforms, highlighting high accuracy with known keyboards, privacy risks from surveillance, and challenges in noise and variability, while proposing defenses and noting AI's dual-use implications.

9 Jun 2026 Understand the Software Supply Chain Chaos w/ Roeland Delrue

Rapidly evolving supply chain security threats, including malicious open-source components and AI-driven malware, demand advanced AI-powered solutions like Akito Securitys self-securing software and tailored tools to address vulnerabilities in developer environments and package repositories.

More The Secure Disclosure episodes