<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="https://feeds.captivate.fm/style.xsl" type="text/xsl"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:podcast="https://podcastindex.org/namespace/1.0"><channel><atom:link href="https://feeds.captivate.fm/appsec/" rel="self" type="application/rss+xml"/><title><![CDATA[AppSec]]></title><podcast:guid>9e45d83a-d6d5-51b5-a725-39db724e703c</podcast:guid><lastBuildDate>Thu, 02 Oct 2025 11:44:47 +0000</lastBuildDate><generator>Captivate.fm</generator><language><![CDATA[en]]></language><copyright><![CDATA[Published By AppSec Training, Inc. ]]></copyright><managingEditor>Jerry Hoff</managingEditor><itunes:summary><![CDATA[Application Security Discussion]]></itunes:summary><image><url>https://artwork.captivate.fm/66bc79a7-e45b-4dd7-8019-a80364a07459/AppSec-FM.png</url><title>AppSec</title><link><![CDATA[https://appsec.fm]]></link></image><itunes:image href="https://artwork.captivate.fm/66bc79a7-e45b-4dd7-8019-a80364a07459/AppSec-FM.png"/><itunes:owner><itunes:name>Jerry Hoff</itunes:name></itunes:owner><itunes:author>Jerry Hoff</itunes:author><description>Application Security Discussion</description><link>https://appsec.fm</link><atom:link href="https://pubsubhubbub.appspot.com" rel="hub"/><itunes:explicit>false</itunes:explicit><itunes:type>episodic</itunes:type><itunes:category text="Technology"></itunes:category><itunes:category text="Education"></itunes:category><itunes:category text="News"><itunes:category text="Tech News"/></itunes:category><podcast:locked>no</podcast:locked><podcast:medium>podcast</podcast:medium><item><title>Enterprise Secure Prompt Engineering</title><itunes:title>Enterprise Secure Prompt Engineering</itunes:title><description><![CDATA[<p>Prompt engineering is no longer just a developer experiment, it is becoming a critical enterprise skill. In this episode of AppSec.FM, Jerry Hoff talks with Jim Manico about the emerging practice of secure prompt engineering, how it affects AI-generated code, and what organizations can do to prepare. They cover the risks of third-party libraries, the evolving AISVS project, and how AI has the potential to transform application security if used correctly.</p><p>Highlights:</p><p>	•	Why secure prompt engineering is critical at the enterprise level.</p><p>	•	How AI-generated code introduces new security challenges.</p><p>	•	The role of prompt testing and continuous improvement.</p><p>	•	Minimizing third-party libraries to reduce vulnerabilities.</p><p>	•	How AISVS is evolving to address AI and secure coding.</p><p>	•	The future of secure coding in an AI-driven world.</p><p><br></p><p>Guest links:</p><p>https://www.linkedin.com/in/jmanico/</p><p>https://manicode.com</p><p>—</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></description><content:encoded><![CDATA[<p>Prompt engineering is no longer just a developer experiment, it is becoming a critical enterprise skill. In this episode of AppSec.FM, Jerry Hoff talks with Jim Manico about the emerging practice of secure prompt engineering, how it affects AI-generated code, and what organizations can do to prepare. They cover the risks of third-party libraries, the evolving AISVS project, and how AI has the potential to transform application security if used correctly.</p><p>Highlights:</p><p>	•	Why secure prompt engineering is critical at the enterprise level.</p><p>	•	How AI-generated code introduces new security challenges.</p><p>	•	The role of prompt testing and continuous improvement.</p><p>	•	Minimizing third-party libraries to reduce vulnerabilities.</p><p>	•	How AISVS is evolving to address AI and secure coding.</p><p>	•	The future of secure coding in an AI-driven world.</p><p><br></p><p>Guest links:</p><p>https://www.linkedin.com/in/jmanico/</p><p>https://manicode.com</p><p>—</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></content:encoded><link><![CDATA[https://appsec.fm/episode/ep8-enterprise-secure-prompt-engineering]]></link><guid isPermaLink="false">95c732d7-f159-469f-be93-5a96293b1d15</guid><itunes:image href="https://artwork.captivate.fm/66bc79a7-e45b-4dd7-8019-a80364a07459/AppSec-FM.png"/><pubDate>Thu, 02 Oct 2025 07:41:00 -0400</pubDate><enclosure url="https://episodes.captivate.fm/episode/95c732d7-f159-469f-be93-5a96293b1d15.mp3" length="52734474" type="audio/mpeg"/><itunes:duration>36:37</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:episode>8</itunes:episode><podcast:episode>8</podcast:episode></item><item><title>ZAP, Automation, and the Future of Open Source Security Testing</title><itunes:title>ZAP, Automation, and the Future of Open Source Security Testing</itunes:title><description><![CDATA[<p>The Zed Attack Proxy (ZAP) has grown from a personal project into one of the most widely used open-source security testing tools in the world. In this episode of AppSec.FM, Jerry Hoff talks with Simon Bennetts, founder and lead of ZAP, about its evolution, role in CI/CD automation, and the importance of community contributions. The conversation also explores the integration of AI, the unique position of ZAP in the security ecosystem, and where the project is headed next.</p><p>Highlights:</p><p>	•	The journey of ZAP from concept to millions of downloads.</p><p>	•	How ZAP is used by developers, security teams, and pen testers.</p><p>	•	Why automation in CI/CD pipelines is key for AppSec.</p><p>	•	The role of AI in modern security testing.</p><p>	•	How ZAP differs from other tools like Burp.</p><p>	•	Community involvement and the future of open-source AppSec.</p><p>	•	Handling modern protocols such as WebSockets.</p><p>	•	Future directions for ZAP and security testing with AI.</p><p><br></p><p>Guest links:</p><p>https://www.linkedin.com/in/psiinon/</p><p>https://www.zaproxy.org</p><p>—</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></description><content:encoded><![CDATA[<p>The Zed Attack Proxy (ZAP) has grown from a personal project into one of the most widely used open-source security testing tools in the world. In this episode of AppSec.FM, Jerry Hoff talks with Simon Bennetts, founder and lead of ZAP, about its evolution, role in CI/CD automation, and the importance of community contributions. The conversation also explores the integration of AI, the unique position of ZAP in the security ecosystem, and where the project is headed next.</p><p>Highlights:</p><p>	•	The journey of ZAP from concept to millions of downloads.</p><p>	•	How ZAP is used by developers, security teams, and pen testers.</p><p>	•	Why automation in CI/CD pipelines is key for AppSec.</p><p>	•	The role of AI in modern security testing.</p><p>	•	How ZAP differs from other tools like Burp.</p><p>	•	Community involvement and the future of open-source AppSec.</p><p>	•	Handling modern protocols such as WebSockets.</p><p>	•	Future directions for ZAP and security testing with AI.</p><p><br></p><p>Guest links:</p><p>https://www.linkedin.com/in/psiinon/</p><p>https://www.zaproxy.org</p><p>—</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></content:encoded><link><![CDATA[https://appsec.fm/episode/ep7-zap-open-source-security-testing]]></link><guid isPermaLink="false">31deb418-a645-4592-9225-7f7e94ecb0cd</guid><itunes:image href="https://artwork.captivate.fm/66bc79a7-e45b-4dd7-8019-a80364a07459/AppSec-FM.png"/><pubDate>Thu, 02 Oct 2025 07:36:00 -0400</pubDate><enclosure url="https://episodes.captivate.fm/episode/31deb418-a645-4592-9225-7f7e94ecb0cd.mp3" length="50506960" type="audio/mpeg"/><itunes:duration>35:04</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:episode>7</itunes:episode><podcast:episode>7</podcast:episode></item><item><title>The Future of Threat Modeling in the Age of AI</title><itunes:title>The Future of Threat Modeling in the Age of AI</itunes:title><description><![CDATA[<p>Threat modeling is shifting from a manual process to one supercharged by AI. In this episode of AppSec.FM, Jerry Hoff talks with Fraser Scott, Chief Scientist at IriusRisk, about how AI and LLMs are transforming the way organizations identify risks in software development. The conversation explores the current state of threat modeling, supply chain challenges, and the economic value of embedding proactive security practices into the SDLC.</p><p><strong>Highlights:</strong></p><p>	•	Why threat modeling remains critical in modern AppSec.</p><p>	•	How AI and LLMs are changing the threat modeling process.</p><p>	•	Inputs, outputs, and practical adoption in organizations.</p><p>	•	The growing importance of supply chain risk management.</p><p>	•	Integrating threat modeling into secure software design.</p><p>	•	The ROI of identifying risks early in development.</p><p>	•	The role of threat modeling in defending against AI-powered attackers.</p><p><br></p><p>Guest links:</p><p>https://www.linkedin.com/in/zeroxten/</p><p>https://www.iriusrisk.com/</p><p>—</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></description><content:encoded><![CDATA[<p>Threat modeling is shifting from a manual process to one supercharged by AI. In this episode of AppSec.FM, Jerry Hoff talks with Fraser Scott, Chief Scientist at IriusRisk, about how AI and LLMs are transforming the way organizations identify risks in software development. The conversation explores the current state of threat modeling, supply chain challenges, and the economic value of embedding proactive security practices into the SDLC.</p><p><strong>Highlights:</strong></p><p>	•	Why threat modeling remains critical in modern AppSec.</p><p>	•	How AI and LLMs are changing the threat modeling process.</p><p>	•	Inputs, outputs, and practical adoption in organizations.</p><p>	•	The growing importance of supply chain risk management.</p><p>	•	Integrating threat modeling into secure software design.</p><p>	•	The ROI of identifying risks early in development.</p><p>	•	The role of threat modeling in defending against AI-powered attackers.</p><p><br></p><p>Guest links:</p><p>https://www.linkedin.com/in/zeroxten/</p><p>https://www.iriusrisk.com/</p><p>—</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></content:encoded><link><![CDATA[https://appsec.fm/episode/ep6-threat-modeling-ai]]></link><guid isPermaLink="false">f2f6ab68-0eca-401a-ae7e-1560a07a7747</guid><itunes:image href="https://artwork.captivate.fm/66bc79a7-e45b-4dd7-8019-a80364a07459/AppSec-FM.png"/><pubDate>Thu, 02 Oct 2025 07:33:00 -0400</pubDate><enclosure url="https://episodes.captivate.fm/episode/f2f6ab68-0eca-401a-ae7e-1560a07a7747.mp3" length="50997853" type="audio/mpeg"/><itunes:duration>35:25</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:episode>6</itunes:episode><podcast:episode>6</podcast:episode></item><item><title>AI and the New Landscape of Application Security</title><itunes:title>AI and the New Landscape of Application Security</itunes:title><description><![CDATA[<p>AI is transforming the way organizations build and secure software. In this episode of AppSec.FM, Jerry Hoff talks with Chris Hertz, co-founder and CEO of Healer, about how AI is reshaping both development practices and attacker strategies. The discussion explores the economics of vulnerability remediation, the challenges of securing open source dependencies, and how collaboration between developers and security teams can build more resilient software.</p><p><strong>Highlights:</strong></p><p>	•	How AI is reshaping development and security.</p><p>	•	Why attackers are leveraging AI to scale their exploits.</p><p>	•	The economics of vulnerability remediation and barriers to fixing issues.</p><p>	•	Healer’s approach to identifying exploitable vulnerabilities.</p><p>	•	Guardrails for managing malicious or risky dependencies.</p><p>	•	The importance of collaboration between AppSec teams and developers.</p><p>	•	Building resilience into software as the ultimate defense.</p><p><br></p><p>Guest links:</p><p>https://www.linkedin.com/in/christopherhertz/</p><p>https://www.heeler.com/</p><p>—</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></description><content:encoded><![CDATA[<p>AI is transforming the way organizations build and secure software. In this episode of AppSec.FM, Jerry Hoff talks with Chris Hertz, co-founder and CEO of Healer, about how AI is reshaping both development practices and attacker strategies. The discussion explores the economics of vulnerability remediation, the challenges of securing open source dependencies, and how collaboration between developers and security teams can build more resilient software.</p><p><strong>Highlights:</strong></p><p>	•	How AI is reshaping development and security.</p><p>	•	Why attackers are leveraging AI to scale their exploits.</p><p>	•	The economics of vulnerability remediation and barriers to fixing issues.</p><p>	•	Healer’s approach to identifying exploitable vulnerabilities.</p><p>	•	Guardrails for managing malicious or risky dependencies.</p><p>	•	The importance of collaboration between AppSec teams and developers.</p><p>	•	Building resilience into software as the ultimate defense.</p><p><br></p><p>Guest links:</p><p>https://www.linkedin.com/in/christopherhertz/</p><p>https://www.heeler.com/</p><p>—</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></content:encoded><link><![CDATA[https://appsec.fm/episode/ep5-ai-application-security]]></link><guid isPermaLink="false">3e5cbc72-d4a7-4d59-96bd-75ad6b5ff201</guid><itunes:image href="https://artwork.captivate.fm/66bc79a7-e45b-4dd7-8019-a80364a07459/AppSec-FM.png"/><pubDate>Thu, 02 Oct 2025 07:29:00 -0400</pubDate><enclosure url="https://episodes.captivate.fm/episode/3e5cbc72-d4a7-4d59-96bd-75ad6b5ff201.mp3" length="38249047" type="audio/mpeg"/><itunes:duration>26:34</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:episode>5</itunes:episode><podcast:episode>5</podcast:episode></item><item><title>Investing in the Future of Application Security</title><itunes:title>Investing in the Future of Application Security</itunes:title><description><![CDATA[<p>Application security is at a turning point, with AI transforming development and new security challenges emerging every day. In this episode of AppSec.FM, Jerry Hoff talks with Michael Coates about the importance of investing in innovative security solutions and the companies that will define the next generation of AppSec. They discuss the role of shadow developers, the accelerating pace of development, and how investors and practitioners alike can prepare for the future.</p><p><strong>Highlights:</strong></p><ul><li>Why investment is critical to the future of AppSec.</li><li>How AI is changing the security and development landscape.</li><li>The rise of shadow developers and the risks they introduce.</li><li>Automatic remediation as a goal for the next generation of tools.</li><li>Why architects will play a larger role in managing software complexity.</li><li>Interconnected risks across the SDLC that demand new solutions.</li></ul><br/><p>Guest links:</p><p>https://www.linkedin.com/in/mcoates/</p><p>https://sevenhillventures.com</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></description><content:encoded><![CDATA[<p>Application security is at a turning point, with AI transforming development and new security challenges emerging every day. In this episode of AppSec.FM, Jerry Hoff talks with Michael Coates about the importance of investing in innovative security solutions and the companies that will define the next generation of AppSec. They discuss the role of shadow developers, the accelerating pace of development, and how investors and practitioners alike can prepare for the future.</p><p><strong>Highlights:</strong></p><ul><li>Why investment is critical to the future of AppSec.</li><li>How AI is changing the security and development landscape.</li><li>The rise of shadow developers and the risks they introduce.</li><li>Automatic remediation as a goal for the next generation of tools.</li><li>Why architects will play a larger role in managing software complexity.</li><li>Interconnected risks across the SDLC that demand new solutions.</li></ul><br/><p>Guest links:</p><p>https://www.linkedin.com/in/mcoates/</p><p>https://sevenhillventures.com</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></content:encoded><link><![CDATA[https://appsec.fm/episode/ep4-investing-in-appsec]]></link><guid isPermaLink="false">afb42f1b-d6f3-4e48-aa96-ef34e29eeaea</guid><itunes:image href="https://artwork.captivate.fm/66bc79a7-e45b-4dd7-8019-a80364a07459/AppSec-FM.png"/><pubDate>Thu, 02 Oct 2025 07:03:00 -0400</pubDate><enclosure url="https://episodes.captivate.fm/episode/afb42f1b-d6f3-4e48-aa96-ef34e29eeaea.mp3" length="40280335" type="audio/mpeg"/><itunes:duration>27:58</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:episode>4</itunes:episode><podcast:episode>4</podcast:episode></item><item><title>Does AppSec Still Matter? CVEs, Risk, and Real-World Security</title><itunes:title>Does AppSec Still Matter? CVEs, Risk, and Real-World Security</itunes:title><description><![CDATA[<p>Application security has never been more critical, but are we focusing on the wrong things? In this episode of AppSec.FM, Jerry Hoff sits down with Robert RSnake Hansen to explore the true relevance of AppSec in the age of CVEs, compliance, and adversaries who are evolving faster than ever.</p><p><strong>Highlights:</strong></p><ul><li>Why most security risk comes from a small subset of CVEs.</li><li>The gap between compliance frameworks and real security outcomes.</li><li>How adversaries actually prioritize targets (hint: money).</li><li>The cultural factors that shape AppSec debates.</li><li>Why vulnerability management needs more data-driven approaches.</li><li>The impact of LLMs on modern cyber attacks.</li><li>Practical steps for defending web applications.</li></ul><br/><p><br></p><p><strong>Guest links:</strong></p><p>https://www.linkedin.com/in/roberthansen3/</p><p>https://www.rootevidence.com/</p><p><br></p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></description><content:encoded><![CDATA[<p>Application security has never been more critical, but are we focusing on the wrong things? In this episode of AppSec.FM, Jerry Hoff sits down with Robert RSnake Hansen to explore the true relevance of AppSec in the age of CVEs, compliance, and adversaries who are evolving faster than ever.</p><p><strong>Highlights:</strong></p><ul><li>Why most security risk comes from a small subset of CVEs.</li><li>The gap between compliance frameworks and real security outcomes.</li><li>How adversaries actually prioritize targets (hint: money).</li><li>The cultural factors that shape AppSec debates.</li><li>Why vulnerability management needs more data-driven approaches.</li><li>The impact of LLMs on modern cyber attacks.</li><li>Practical steps for defending web applications.</li></ul><br/><p><br></p><p><strong>Guest links:</strong></p><p>https://www.linkedin.com/in/roberthansen3/</p><p>https://www.rootevidence.com/</p><p><br></p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></content:encoded><link><![CDATA[https://appsec.fm/episode/ep3-appsec-cves-risk]]></link><guid isPermaLink="false">20735f5e-413f-4d9a-88b0-04dc9ee2daa7</guid><itunes:image href="https://artwork.captivate.fm/66bc79a7-e45b-4dd7-8019-a80364a07459/AppSec-FM.png"/><pubDate>Thu, 02 Oct 2025 06:52:00 -0400</pubDate><enclosure url="https://episodes.captivate.fm/episode/20735f5e-413f-4d9a-88b0-04dc9ee2daa7.mp3" length="63823767" type="audio/mpeg"/><itunes:duration>44:19</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:episode>3</itunes:episode><podcast:episode>3</podcast:episode></item><item><title>Harnessing AI in Software Development: Code, Security, and Automation</title><itunes:title>Harnessing AI in Software Development: Code, Security, and Automation</itunes:title><description><![CDATA[<p>AI is reshaping the way we build and secure software. In this episode of AppSec.FM, Jerry Hoff talks with Arshan Dabirsiaghi about the practical realities of AI-generated code, the challenges it introduces, and the opportunities it creates for modern AppSec.</p><p><strong>Highlights:</strong></p><ul><li>How AI-generated code improves developer productivity.</li><li>Why prompt engineering matters for secure AI use.</li><li>Risks of hallucinated package names in generated code.</li><li>Adapting modern CI/CD pipelines to AI-assisted development.</li><li>Automating vulnerability triage and remediation.</li><li>The continued role of DAST and static analysis.</li><li>How AI might accelerate cyberattacks.</li></ul><br/><p><strong>Guest Links:</strong></p><p>https://www.linkedin.com/in/arshan-dabirsiaghi/</p><p>https://pixee.ai</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></description><content:encoded><![CDATA[<p>AI is reshaping the way we build and secure software. In this episode of AppSec.FM, Jerry Hoff talks with Arshan Dabirsiaghi about the practical realities of AI-generated code, the challenges it introduces, and the opportunities it creates for modern AppSec.</p><p><strong>Highlights:</strong></p><ul><li>How AI-generated code improves developer productivity.</li><li>Why prompt engineering matters for secure AI use.</li><li>Risks of hallucinated package names in generated code.</li><li>Adapting modern CI/CD pipelines to AI-assisted development.</li><li>Automating vulnerability triage and remediation.</li><li>The continued role of DAST and static analysis.</li><li>How AI might accelerate cyberattacks.</li></ul><br/><p><strong>Guest Links:</strong></p><p>https://www.linkedin.com/in/arshan-dabirsiaghi/</p><p>https://pixee.ai</p><p>AppSec.FM is the podcast for application security professionals, hosted by Jerry Hoff. Subscribe on Apple Podcasts, Spotify, or at appsec.fm.</p>]]></content:encoded><link><![CDATA[https://appsec.fm/episode/ep2-ai-software-development-security]]></link><guid isPermaLink="false">5f814737-1d64-42cc-9782-65d791397099</guid><itunes:image href="https://artwork.captivate.fm/66bc79a7-e45b-4dd7-8019-a80364a07459/AppSec-FM.png"/><pubDate>Thu, 02 Oct 2025 05:36:00 -0400</pubDate><enclosure url="https://episodes.captivate.fm/episode/5f814737-1d64-42cc-9782-65d791397099.mp3" length="42489667" type="audio/mpeg"/><itunes:duration>29:30</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:episode>2</itunes:episode><podcast:episode>2</podcast:episode></item><item><title>Is Threat Modeling Still Relevant in the Age of AI?</title><itunes:title>Is Threat Modeling Still Relevant in the Age of AI?</itunes:title><description><![CDATA[<p>Threat modeling has been a cornerstone of application security for decades — but is it still relevant in the era of AI-assisted development? In this episode of AppSec.FM, Jerry Hoff talks with Amir Kavousian about how threat modeling must evolve to keep pace with modern software practices.</p><p><strong>Highlights:</strong></p><ul><li>Why threat modeling is still essential for AppSec.</li><li>How AI-assisted development changes risk considerations.</li><li>Continuous threat modeling as a living document.</li><li>The role of compliance and legal in secure design.</li><li>Automating threat modeling to scale with modern pipelines.</li><li>Applying threat modeling to both new and legacy applications.</li><li>The business value of integrating threat modeling into security programs.</li></ul><br/><p><strong>Guest Links:</strong></p><p>https://www.linkedin.com/in/amir-kavousian/</p><p>https://www.devarmor.com/</p>]]></description><content:encoded><![CDATA[<p>Threat modeling has been a cornerstone of application security for decades — but is it still relevant in the era of AI-assisted development? In this episode of AppSec.FM, Jerry Hoff talks with Amir Kavousian about how threat modeling must evolve to keep pace with modern software practices.</p><p><strong>Highlights:</strong></p><ul><li>Why threat modeling is still essential for AppSec.</li><li>How AI-assisted development changes risk considerations.</li><li>Continuous threat modeling as a living document.</li><li>The role of compliance and legal in secure design.</li><li>Automating threat modeling to scale with modern pipelines.</li><li>Applying threat modeling to both new and legacy applications.</li><li>The business value of integrating threat modeling into security programs.</li></ul><br/><p><strong>Guest Links:</strong></p><p>https://www.linkedin.com/in/amir-kavousian/</p><p>https://www.devarmor.com/</p>]]></content:encoded><link><![CDATA[https://appsec.fm/episode/ep1-threat-modeling-ai]]></link><guid isPermaLink="false">2cb53e37-e267-4584-848c-ff6287aff0a1</guid><itunes:image href="https://artwork.captivate.fm/66bc79a7-e45b-4dd7-8019-a80364a07459/AppSec-FM.png"/><pubDate>Thu, 02 Oct 2025 05:22:00 -0400</pubDate><enclosure url="https://episodes.captivate.fm/episode/2cb53e37-e267-4584-848c-ff6287aff0a1.mp3" length="48701998" type="audio/mpeg"/><itunes:duration>33:49</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:episode>1</itunes:episode><podcast:episode>1</podcast:episode></item></channel></rss>