Application Paranoia: Recent Episodes

Colin Bell, Rob Cuddy & Kris Duer

A podcast about Application Security DevSecOps and AppScan. Twice a month, we aim to bring you some technical insights, assorted facts and the latest news from the world of HCL AppScan. Our underlying mission is to deliver continuous application security to the masses.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another insightful application paranoia session.

In this weeks episode our special guest is Tanya Janca who is helping the team discuss all things Security in the Devlopment space.

Tanya Janca, also known as SheHacksPurple, is the author of ‘Alice and Bob Learn Application Security’. She is also the head of education and community at Semgrep! As the founder of We Hack Purple, Tanya is bringing her security training to Semgrep customers and beyond. Tanya has been coding and working in IT for over twenty years, won numerous awards, and has been everywhere from startups to public service to tech giants (Microsoft, Adobe, & Nokia). She has worn many hats; startup founder, pentester, CISO, AppSec Engineer, and software developer. She is an Advisor for NordSec and Katilyst and the Founder of We Hack Purple, OWASP DevSlop, WoSECShe and the very popular #CyberMentoringMonday. She is an award-winning public speaker, active blogger & streamer and has delivered hundreds of talks and trainings on 6 continents. She values diversity, inclusion and kindness, which shines through in her countless initiatives.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another insightful application paranoia session.

In this weeks episode our special guest is Ray [Redacted] who is helping the team discuss all things Posture Management.

Ray is a Technologist & researcher for a Fortune 50 corporation and Associate Producer Emeritus of Jack Rhysider’s critically acclaimed hacker podcast “Darknet Diaries.” “Ray is particularly interested in researching nation state APT activities, and he is known online for being passionate about Mental Health Care issues as it relates to information and cybersecurity.

https://twitter.com/RayRedacted
https://twitter.com/DarknetDiaries

View Details

Hey everyone, welcome back to Application Paranoia! Colin Bell, Rob Cuddy, and Kris Duer are excited to kick off season 5!

For our first episode of 2024, we're joined by a special guest: Mike Khusid! Mike is the new Head of Product Management for HCL AppScan, and he brings a wealth of experience from companies like Codacy, Contrast, Red Hat, Akamai, Veracode, and Zerto. We're thrilled to have him on the show!

In this episode, we're diving deep into the hottest application security trends for 2024. Get ready for insights from a seasoned pro and buckle up for a season packed with valuable information!

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another insightful application paranoia session.

In this weeks episode our special guest is Ken Fanger who is an acclaimed speaker, author, and cyber security expert, who is focused on making a better world with less fear and more function.

Ken's current campaign is to "humanize security," a fundamental change toward a more holistic approach to cyber resilience and recovery. Ken is also one of fewer than 2,000 people to hold the designation of CMMC-RP (Cybersecurity Maturity Model Certification Registered Practitioner), helping businesses with federal contracts to meet the new Department of Defense cybersecurity standards.

Ken also has a new book that was released this past summer called Relax A Guide to True Cybersecurity which is available through Amazon.

The team also outline the Words of 2023.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another insightful application paranoia session.

In this weeks episode our special guest is Pete Morgan who is a leading expert in cloud security and compliance. He is the co-founder and CSO of Phylum (https://www.phylum.io/), a cloud security company that helps organizations to protect their cloud environments and achieve compliance with industry regulations.

Pete helps unpack some best practices around software supply chain security and outlines how his company Phylum helps organizations contextualize the associated risks from open source.

The team also discuss College Football, the Rugby World Cup, U2 in Las Vegas, room temperature semiconductors and the invention of starlite https://en.wikipedia.org/wiki/Starlite in the 1980's.

View Details

If you are interested in generative AI, we have got a real treat in store for you!.  In this episode we are thrilled to be joined by startup co-founder, self-proclaimed tech geek and corporate, nonprofit and government executive Stephanie Sylvestre.  Stephanie is a Harvard's Advanced Leadership (ALI) fellow and her company, Avatar Buddy, uses generative AI to close the achievement gap and address vexing social justice issues. You can learn more about the awesome work Stephanie is doing to help promote black professionals and places where people can be free to be vulnerable in their journey to wealth by going to https://www.avatarbuddy.ai/products

We also take a few minutes to discuss some of the great new capabilities in the latest versions of AppScan AND you won't want to miss the discussion on some of the most amazing story of "GPS art meets love story" that we have ever heard about

So join us as we dive into Season 4, Episode 5 of Application Paranoia—your ultimate guide to application security, DevSecOps, and the HCL AppScan family. Let's embark on this transformative journey together!

View Details

Brace yourselves as we embark on a ground breaking adventure, joined by our esteemed guests, the remarkable Julie Reed our Product Manager for AppScan on Cloud and the insightful Urmi Chatterjee our Static Engine Lead Engineer. Julie and Urmi will take us on a thrilling journey as they introduce the highly anticipated launch of AppScan 360. Get ready to hear about the cutting-edge technology, unparalleled insights, and revolutionary 

So join us as we dive headfirst into Season 4, Episode 4 of Application Paranoia—your ultimate guide to application security, DevSecOps, and the awe-inspiring launch of AppScan 360. Let's embark on this transformative journey together!

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another insightful application paranoia session.

In this  episode our team cover the following;

  • Kris's second winter
  • May the 4th festival in Malin Head

Guest:  Soloman Barghouthi fromCAST Software 

We are thrilled to have Solomon as our guest on this episode. With over 15 years of progressive leadership experience, Solomon is a highly credible, customer-centric, and decisive leader who is deeply committed to ensuring customer satisfaction. As a strategic thinker and resourceful problem solver, Solomon has an innate ability to see the big picture and guide clients through their digital transformation journey. He is particularly skilled at building skilled technical Sales teams, and has a proven track record of success in this area.

Solomon is also a trusted advisor and an exceptional communicator with outstanding presentation skills. He has a natural talent for building relationships with both technical and non-technical audiences, even in diverse global environments. His expertise and dedication to customer satisfaction make him an invaluable asset to any team, and we're thrilled to have him as our guest .

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another insightful application paranoia session.

In this  episode our team cover the following;

  • March Maddness review
  • Fever treatment experiments
  • Worst April Fool of 2023

Rob talks to Stephanie Sylvestre on How to advocate for women in IT

The team talk to John Dickson on all things appsec including;

  • SBOM's are not enough
  • Supply Chain requirements
  • The Pantry problem and how it relates to supply chain
  • The impact of developer turnover
  • The future of supply chain and CISO influence
  • Security Champions
  • San Antonio Airport
  • What factors are important for students wanting to get into app security

Ref : The State of CISO Influence survey 

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another insightful application paranoia session.

For our first episode this season we hosted a live session at the Agile Internation Conference in Miami Florida on 9th and 10th March.

Our Panel included  both
James Grenning  (Coach and Agile technical trainer for Wingman software) and
David Ralph (Director of Software Engineering form Allview).

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another insightful application paranoia session.

In this weeks episode our special guest is Quantum Computing expert André König

André is a published author, speaker and expert on DeepTech with 25 years of Fortune 500, investing and startup experience. He is the CEO of Interference Advisors, the premier BI provider in Quantum Tech,  Chairman of OneQuantum, the leading Quantum Tech community globally with 35K+ members, and Managing Partner of Entanglement Capital, a Quantum Tech investment fund and startup accelerator.

He studied Quantum Computing at MIT (certificates) and holds a MBA in Economics from the University of Chicago Booth School of Business as well as a Masters in Business from ICN School of Management.

Learn more at https://www.andrémkönig.com/ and join the quantum computing community at https://onequantum.org/

His site is: https://www.andrémkönig.com/

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application paranoia session.

In this weeks episode the team meet with special guest  Charlotte Chang

Charlotte is a Technology Product Strategist with nearly 20 years of experience. She enjoys working with executives, managers, and teams to create Systems of Compassion that provide a sustainable, humane, inclusive experience for all contributors throughout product development. 

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application paranoia session.

In this weeks episode the team meet with special guest  Rick Regueira.  Rick is a seasoned Enterprise & Executive Agile Coach & Trainer, Consultant, Project Manager, and IT professional. He is vastly experienced in leading and mentoring successful Organizational Agile transformations of several fortune 500 companies.

If you would like to personally connect with Rick, you can find him on LinkedIn at https://www.linkedin.com/in/rickregueira/.

If you are interested in connecting with other agile professionals or learning more about agile, visit Transformation Experts at https://www.teculture.com/ and see their events section. Finally, if you would like to attend the next Agile International Conference March 16-17 2023, visit https://www.agileinternational.org/aic-2023

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application paranoia session.

In this weeks episode the team meet with special guest  Cody Travis who is a senior application security specialist at HCL Software.  In this Episode the team discuss the post pandemic virtues of hybrid working,  Penetration Testing practices, blockchain and cyrpto investments.

Also find out why it is not good to be considered Cordless.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application paranoia session.

In this weeks episode the team meet with special guest  Zoe Braiterman who is an Information Security Leader, Consultant / Researcher who is passionate about data, startups, blockchain, technology, and of course, cybersecurity.

https://owasp.org/www-committee-wia/

Remember don't be a Lantern !!

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application paranoia session.

In this weeks episode the team meet with special guest  Al Wagner who is a senior security architect at HCL Software. Al helps to highlight the benefits of Value Stream mapping  and HCL Accelerate.

The unlikely meeting of Bono, Yoko Ono, and Brian Eno was also discussed
For reference...

https://twitter.com/yokoono/status/1347524447205531648/photo/2

View Details

Back for another season Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application security interview special. 

In this weeks episode the team meet with special guest  Hector Monsegur. Hector is a industry professional with decades of experience, mostly on the offensive side. 

He is currently  Director of Research for Alacrinet where he spends his days working with clients to improve their overall security posture while he works on offensive research and engagements. 

Join us as Hector helps discuss Log4j, Pen testing  evolution and how to get more folks involved in application security.

For reference...
Meat Loaf, a flying wheelchair, and the greatest story ever told | Louder (loudersound.com)

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion on Application Security, DevSecOps and AppScan. This episode is the season finale for 2021 and the team look back on the many fabulous guests, the  insightful discussions, statistics and of course the best fun facts of the year.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application security interview special. 

In this Episode the team discuss the recent 'Rug Pull' with a fake Squid Game Crypto Currency and they also talk to Philippe Humeau the founder of CrowdSec.

Phillippe is a true Entrepreneur and  CrowdSec is his latest startup founded in 2020. It is a company editing an eponymous open-source massively multiplayer firewall, leveraging both IP behaviour & reputation to create a community and tackle the mass scale hacking problem. 

Find out more about CrowdSec here.... https://crowdsec.net/

View Details

Colin Bell, Rob Cuddy and Kris Duer bring you another Application Paranoia episode. This episode has guest Panellist Julie Reed outlining all the more greatness with AppScan on Cloud (ASoC).  The team also address the topic of  William Shatner in Space and Rickrolling a school district.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application security interview special. 

In this Episode the team talk to Dr. Michael Owens who is the BISO at Equifax.

Michael is an innovative, collaborative, and distinguished leader with over 25 years of experience in startup, corporate, government, and military organizations. A transformation leader and sought-after speaker, Michael frequently keynotes on topics related to cybersecurity, cyberwarfare, and national security matters. 

Michael is  also the president and CEO of the U.S. Global Center of Cyber Policy, where he leads the organization in providing federal, state, and local governments with non-partisan thought leadership and expert information and analysis on cybersecurity, cybercrime, and cyberwarfare trends, strategies, and policies from a domestic and international perspective.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode has guest Panellist Florin Coada discussing  the new technology preview for AppScan Source and what folks can expect going forward  The team also discuss cows in drive throughs,  PSL season, Cats jumping in stadiums and the best bits from the latest GDS Security Summit.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application security interview special. 

In this episode the team talk to Randy Abernethy

Randy  is a Managing Partner at RX-M who are a cloud native advisory and training firm. He is a tech entrepreneur, startup advisor and author with a passion for large scale distributed systems and all things cloud native. He Interacts with hundreds of technology professionals each year, and stays highly connected with the latest software and platform trends and developments. 

Find out more about RX-M here 
https://rx-m.com/

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode has guest Panellist Matt Murphy discussing  advances in AppScan CodeSweep, intersections with GitHub and the potential of automatic quick fixes of code..  The team also discuss crypto currencies and recent security breaches.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application security interview special. 

In this episode the team talk to Sebastian Dan Naste from Cullen International.  Sebastian is a Privacy and Data Protection Analyst and specializes in International Law, EU regulations and legislative developments around the digital economy. He is a cyber world enthusiast, and his passion is to connect the legal environment with technology. 

The team also discuss virtual Disney queues and how running to New York from Florida is best done on land.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode has guest Panellist Eitan Worcel discussing the latest 10.0.5 release and the future.  The team also discuss better approaches to penalty shootouts in the Euros and Kris breaks down container security.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application security interview special. 

In this episode the team talk to Naomi Buckwalter, the vCISO and Director of IT for Beam Technologies.  Naomi has been a part of several great events recently including the CISO Series Podcast with David Spark and the EvolveSec Meetup on cyber talent.  She is a fantastic contributor to LinkedIn and has had a number of eye-opening and thought-provoking posts recently. Naomi discusses her passion for cyber and how we need to lower the barriers to getting people into the space.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode has guest Panellist Ran Klein bringing us up to speed with IAST and  correlation prospects.  The team also discuss AppScan news, ransomware updates and growing babies in pods.

View Details

Colin Bell from HCL Software brings you another application security interview special. 

In this episode we have a European panel comprising of  Radu Stanescu who is the Founder of Sandline, Arnaud Bourlier who is the CEO and founder of ABLogix and Guy Paquet who is a security consultant and lecturer.  

The team cover topics on Bee Keeping, Being a Gartner MQ Leader,  Irish Health Ransomware, DevSecOps and Security education.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode has guest Panellist Chris Nowak helping us break down the recent Colonial Ransomware attack and giving us insight into DevOps at HCL Software.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application security interview special. 

In this episode the team talk to Altaz Valani  who is the Research Director at Security Compass. Altaz provides insight into managing  cybre threats and the current best practices of threat modelling.

View Details

Colin Bell, Rob Cuddy and Kris Duer bring you another Application Paranoia episode. This episode has guest Panellist Julie Reed outlining all the new greatness with AppScan on Cloud (ASoC).  Kris outlines how to address the Elephant in a vacuum and we also have fun topics retating to home construction, volcanoes and Oxymorons.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application security interview special. 

In this episode the team talk to Matt Crouse  who is the CISO for Taco Bell where he leads his company's efforts to design, deliver and operate an effective security program to over 7,000 restaurants worldwide. 

View Details

Colin Bell, Rob Cuddy and Kris Duer bring you another Application Paranoia episode. This episode has guest Panellist Billy Weber helping to navigate through discussions about a bunch of exciting new AppScan features in the recent 10.0.4 release.  There are also discussions about St. Patricks day being cancelled in Ireland, Why SQL Injection is still a thing, zero day vulnrabilities in Accellion's file transfer appliance (FTA), MS Exchange email exploits and that Golf is bad for the planet. So basically something for everyone...

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application security interview special. 

In this episode the team talk to Vandana Verma who is the Vice-Chairman of the OWASP Global Board of Directors.  Vandana discusses  how OWASP continued to interact during the pandemic, her InfosecGirls and  InfosecKids intiatives, the OWASP top 10 and future cyber security trends. 

View Details

Colin Bell, Rob Cuddy and Kris Duer bring you another Application Paranoia episode. This episode has guest Panellist Kathleen Brady helping to navigate through discussions about a bunch of exciting new AppScan on Cloud features, the recent Florida  Water  hack and the reemergence of "the Mullet". Join us for another informative episode.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another application security interview special.

In this episode the team talk to Kavya Pearlman and Tamas Henning from the XR Safety Initiative. They provide a fascinating insight into the privacy, security, and ethics within immersive environments (virtual reality, mixed reality, and augmented reality).

How to get involved with XRSI

Well, the answer is that it depends on who you are!

  • For government and regulators, they undertake government grants and projects requests; They also advise regulators on pragmatic policy decisions
  • Private Entities can contribute and donate to XRSI mission, efforts and research
  • XR Stakeholders: safety and awareness campaigns for various XR stakeholders
  • Universities: Get funded for research pertaining VR Safety
  • Students can Sign Up for Newsletters, updates and new developments

In general, anyone who’s interested can contact them at info@xrsi.org, or visiting our website, and/or volunteer and Donate: https://xrsi.org/donate

Below are some additional resources for those wanting more information about XRSI:

  • Simple Online Safety tips for parents :https://em360tech.com/business_agility/tech-news/opinion-piece/safer-internet-day-2020/
  • XRSI Privacy and Safety Framework : https://xrsi.org/publication/the-xrsi-privacy-framework
  • XRSI Media Platform (Rh1) www.readyhackerone.com
  • XR Safety Awareness Week Knowledge base : www.gettingintoxr.com

View Details

Colin Bell, Rob Cuddy and Kris Duer return with a new season of Application Paranoia. A podcast dedicated to Application Security, DevSecOps and AppScan. This episode has guest Panellist Florin Coada helping to navigate through discussions about IaC scanning, Java 11 support, the latest from Codesweep, the Solarwinds hack and the discovery of booze fairies. Join us for the first episode from season 2... 

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion on Application Security, DevSecOps and AppScan. This episode is the season finale for 2020 and is hosted by our special guest Mikala Vidal.  In this special episode the team look back on many of the insightful discussions, application security trends and of course fun facts.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode includes all the latest AppScan news, tips around avoiding Skimmy Dipping and how to be keep your credit cards secure. Our guest this week is our Product Manager Eitan Worcel who helps us highlight our 2020 achievements and also frames where we will go in 2021...

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode includes all the latest AppScan news, tips around Data Security,  the advantages of being a data steward and having a big head for big change. Our guest this week is Darius Bennett who is a Certified Master of Data Privacy,  a Legal Consultant, and a Licensed Attorney.  He provides great insight into the world of Data Privacy.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode includes all the latest AppScan news, tips around Mobile cryptography,  early Snow in the north ,  Close wild fires in the south and Irish Samhain (Sawin) traditions. Our guest this week is Dr Larry Ponemon from the Ponemon Institute who recently publish a report of Application Security in Devops. He talks to us about the report and some of the fascinating findings.

For a free copy of the Ponemon report that we discussed in this episode, please visit: https://www.hcltechsw.com/wps/portal/products/appscan/ponemon-report

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode includes all the latest AppScan news, tips around Open Source scanning, Solas running,  and the wonders of leaf peeping. Our guest this week is Jeff Turnham who provides insight into HCL Softwares Solution Factory (SoFy), Kubernetes security and best practices.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode includes the latest AppScan news, tips around OS Injections and a discussion about DevSecOps with HCL Softwares Chris Nowak.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode includes an outline of collective nouns for vulnerabilities, the latest from the AppScan 10.0.2 release and an insightful interview with sports, radio and TV personality Steve Mason.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode includes an exciting discussion about all things purple with Tanya Janca from "WeHackPurple" fame.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode brings a Security Directors perspective with an interview with Dragan Pleskonjic.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This episode includes an interview with our HCL AppScan Chief Architect Shahar Sperling talking all things DAST.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL Software bring you another discussion Application Security, DevSecOps and AppScan. This includes an interview with HCL Software's Vice President for Product Management Raj Iyer.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL AppScan bring you another discussion Application Security, DevSecOps and AppScan. This includes an interview with HCL Software's Security and Research Analyst Lev Aronsky about the work his team conduct. 

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL AppScan bring you another discussion around AppScan and the latest Application Security trends. This includes an interview with HCL Software's CISO Joe Rubino about his security vision. 

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL AppScan bring you another insightful discussion around AppScan and the latest Application Security trends. This includes an interview with HCL Software's Digital Solutions CTO Jason Gary about embedding security practices into large and diverse engineering teams. 

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL AppScan bring you another insightful discussion around AppScan and the latest Application Security trends. Includes an interview with Gal Ben-Yair about AppScan's recently launched Interactive Application Security Testing (IAST) solution. 

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL AppScan bring you another insightful discussion around AppScan and the latest Application Security trends. Includes an interview with Matt Murphy about AppScan Code Sweep for Visual Studio.

View Details

Colin Bell, Rob Cuddy and Kris Duer from HCL AppScan bring you an insightful discussion around the AppScan version 10 release and the latest Application Security trends. Includes an interview with Urmi Chatterjee about AppScan's common scan engine.