w/ Tanya Janca, Security professional & educator
Tanya Janca joins the podcast for a sharp, no-nonsense conversation on the OWASP Top 10, why secure coding still gets skipped, and how AI is reshaping the way developers build and review software. She breaks down why broken access control keeps topping the charts, what security teams keep getting wrong, and how to create guardrails developers will actually use. The episode also dives into vibe coding, supply chain risk, and the future of secure software training. It’s fast, practical, and packed with opinions worth stealing. Sponsored link — Aikido Security Build fearlesly with Aikido Security. Protection from the first line of code to your production environments https://aikido.dev Tanya Janca Secure Code Training Want to level up your team’s secure coding skills? Tanya Janca’s SheHacksPurple delivers world-class secure coding training https://shehackspurple.ca/ Chapters 00:00 Intro to Tanya Janca 00:28 Is There Still a Path Into Security? 00:56 What the OWASP Top 10 Actually Is 02:53 Why Broken Access Control Keeps Winning 05:30 Why Old Vulnerabilities Still Won’t Die 07:38 Can AI Actually Improve Secure Coding? 10:47 What Changed in the New OWASP Top 10 14:22 How to Train Developers to Code More Securely 24:22 Vibe Coding: Friend or Foe for Security? 34:17 Would You Rather? Security Edition #TanyaJanca #SecureCoding #AppSec #OWASPTop10 #CyberSecurity #DevSecOps #VibeCoding #SoftwareSecurity #ApplicationSecurity #AikidoSecurity
Tell us who, why, and how to reach them. We read every submission.