RPG miniatures on a grid

Presentations

Apr 2025BSidesSF 2025Secure Design, UX Dragons, Vuln Dungeon
Oct 2018DevSecCon London 2018Building Effective DevSecOps Teams Through Role-Playing Games (video)
Oct 2018(ISC)2 Security CongressDevOps Is Automation, DevSecOps Is People
Oct 2018STAR West Software Testing ConferenceMeasuring and Maximizing Crowdsourced Vuln Discovery
Feb 2018DevSecCon SingaporeMeasuring and Maximizing Vuln Discovery Efforts
Jan 2018OWASP AppSec Cali 2018DevOps Is Automation, DevSecOps Is People (video)
Oct 2017DevSecCon LondonThe Flaws in Hordes, the Security in Crowds
Sep 2017(ISC)2 Security CongressCrowdsourced Security: The Good, the Bad, and the Ugly
Jun 2017RVASec 2017Managing Crowdsourced Security Testing (video)
May 2017AppSec EU 2017The Flaws in Hordes, the Security in Crowds (video)
Apr 2017SOURCE Boston 2017Crowdsourced Security -- The Good, the Bad, and the Ugly
Nov 2016ISACA Silicon Valley 2016Evolving a Bug Bounty Program
Oct 2016SOURCE Seattle 2016Evolving a Bug Bounty Program (preview on Brakeing Security podcast)
Oct 2015SOURCE Seattle 2015Battling the Geologic Timescale of SAST
Jul 2014RSA APJ 2014CDS-W07 - Building and Breaking Privacy Barriers
Feb 2014RSA USA 2014DSP-R04A - Is your browser a User Agent, or a Double Agent?
Oct 2013Hack in the Box Kuala LumpurCSRF Lab & Session Origin Security
Sep 2013Hacker Halted USAUsing HTML5 to Make JavaScript (Mostly) Harmless
Jul 2013BlackHat USADissecting CSRF Attacks & Countermeasures (co-presented with Vaagn Tukharian)
May 2013RVAsec 2013JavaScript Security & HTML5 (video)
Feb 2013RSA USA 2013ASEC-F41 - Using HTML5 WebSockets Securely
Feb 2013B-Sides San Francisco 2013JavaScript Security & HTML5
Dec 2012BayThreat 2012WebSockets Unplugged (video, co-presented with Sergey Shekyan and Vaagn Tukharian)
Oct 2012RSA Europe 2012ASEC-303 - Cases of JavaScript Misuse and How to Avoid Them
Aug 2012BlackHat USA 2012Hacking With WebSockets (co-presented with Sergey Shekyan and Vaagn Tukharian)
May 2012ITWeb Security SummitHTML5 Unbound: A Security & Privacy Drama (check out the supplemental article, then parts two, three, and four)
May 2012OWASP/ISSA Bletchley ParkGraveyards & Zombies: How HTML5 Improves Security. Mostly.
Oct 2011RSA Europe 2011ASEC-201 - HTML5 Security Pitfalls
Feb 2010RSA USA 2010SPO1-203 - Does Web 2.0 Need Security 2.0?
Jan 2006IT Underground, Berlin 2006Automating SQL Injection Exploits (slides completed, but conference was canceled)

Podcasts & Webcasts

Mar 18, 2026SC MediaHard to handle: Securing AI-generated code and the AI agents that write it (sponsored)
Mar 10, 2026SC MediaAppSec in the age of AI: An RSAC Conference preview (sponsored)
Mar 4, 2026SC MediaInside monday.com’s Security Strategy: When App Growth Outpaces Identity Control (sponsored)
Dec 8, 2025SC MediaScaling secure software in the age of AI: Turning intelligence into action (sponsored)
Nov 12, 2025SC MediaEmpowering without exposing: A roadmap for security teams in a citizen developers’ world (sponsored)
Oct 21, 2025SC MediaApplication Security 2.0: AI changes everything (sponsored)
Sep 30, 2025SC MediaThe Evolution of AppSec for the AI Era (sponsored)
July 29, 2025SC MediaSecuring Vibe Coding: Addressing the Security Challenges of AI-Generated Code (sponsored)
June 17, 2025SC MediaRewriting the AppSec Playbook: Ditch the Vulnerability Backlog, Defend What Matters (sponsored)
May 15, 2025SC MediaBreaking Barriers: Solving AppSec Challenges in Financial Services (sponsored)
Mar 12, 2025Qualys Cyber Risk SeriesAppSec in 2025: Navigating Risks, Threats, and Innovation (sponsored) intro and sessions
Oct 9, 2024SC MediaA More Ironclad AppSec: Forecast and Guidance Late 2024 and Early 2025 (sponsored)
Aug 28, 2024SC Media8 ways attackers target mobile apps to steal your data (and how to stop them) (sponsored)
Aug 27, 2024SC Media Virtual ConferenceApplication security: Key trends, tools and techniques (sponsored)
Mar 26, 2019Application Security Weeklyep. 55 Wins & Challenges in Appsec
Sep 11, 2018Humans of Infosecep. 14 Tanya Janca: Hacking Purple and Defending Developers
Aug 7, 2018Humans of Infosecep. 12 Georgia Weidman: Writing books, riding horses, and starting companies
Feb 26, 2018Humans of Infosecep. 1 Mike Shema