More The Secure Disclosure episodes

OWASP Top 10, Vibe Coding, and What Developers Miss w/ Tanya Janca thumbnail

OWASP Top 10, Vibe Coding, and What Developers Miss w/ Tanya Janca

Published 22 Apr 2026

Duration: 00:38:13

Gaps in cybersecurity education, persistent vulnerabilities like SQL injection, OWASP data limitations, evolving supply chain risks, high training costs, AI's contextual challenges, and the need for secure-by-design principles and collaboration highlight systemic challenges in addressing evolving cyber threats.

Episode Description

Tanya Janca joins the podcast for a sharp, no-nonsense conversation on the OWASP Top 10, why secure coding still gets skipped, and how AI is reshaping...

Overview

The podcast explores critical challenges in cybersecurity education and practice, emphasizing a lack of formal training in concepts like access control, which leaves developers unprepared for real-world threats. Despite collaborative efforts like the OWASP Top 10 projectwhich identifies top web application risksgaps in breach reporting and persistent issues such as broken access control highlight ongoing struggles to address foundational security principles. Industry-wide, repetitive vulnerabilities like SQL injection and injection flaws persist due to inadequate education, outdated tools, and a developer focus on feature-building over early security integration. Efforts to democratize training, such as community programs and open resources, aim to overcome cost barriers and improve awareness, though challenges remain in making security education accessible and effective.

AIs emerging role in security is both promising and complex. While AI can reduce vulnerabilities in code generation and prompt secure practices, its effectiveness is limited by contextual understanding and reliance on human review. Persistent debates around supply chain vulnerabilities underscore the need for systemic solutions beyond third-party dependencies, especially in high-stakes areas like medical devices, where low-level languages introduce memory safety risks. Behavioral economics and nudgessuch as default settings and choice architectureare proposed to encourage secure coding without coercion. Additionally, the discussion emphasizes shifting from reactive security tools to proactive "security by design," layered defenses, and fostering collaboration between developers and security teams through community engagement and shared knowledge.

The evolving landscape also raises questions about the future of security roles amid AI advancements. While automation may streamline tasks like penetration testing, it risks displacing entry-level positions, pushing the field toward specialized expertise in creative problem-solving and ethical oversight. Persistent challenges include balancing automation with human judgment, ensuring AI-driven tools maintain accuracy, and addressing systemic gaps in risk prioritization and training quality. The conversation culminates in calls for integrated security practices, pragmatic risk management, and the reimagining of security education to meet the demands of an AI-driven era while preserving the critical role of human insight and accountability.

Recent Episodes of The Secure Disclosure

3 Sept 2026 Email Security in the Age of AI | Josh Kamdjou, Sublime Security CEO

"Email security faces growing threats from AI-driven phishing, prompt injection, and malicious calendar invites, outpacing traditional defenses; Sublime Security's real-time, agentic approach offers a solution, while cyber warfare increasingly exploits human cognitive vulnerabilities."

19 Aug 2026 Tearing Down Vendor Fluff: The Real State of AI Security | James Berthoty

"AI's rapid adoption in cybersecurity, driven by executive pressure and fear of obsolescence, contrasts with slower cloud security uptake, as vendors overpromise solutions while breaches persist; AI both enables attacks (like supply chain malware) and enhances defenses, reshaping security roles and workflows, with governance and real-world gaps (e.g., Hugging Face breach) remaining critical."

14 Jul 2026 How to Stop Supply Chain Attacks Without Destroying Developer Productivity

"Cybersecurity threats, especially supply chain attacks on developers and open-source packages, demand balanced mitigation strategies, AI-driven security challenges, and early integration of security in development, with collaboration and adaptability key to addressing evolving risks."

More The Secure Disclosure episodes