https://www.youtube.com/watch?v=R5Eca_H7mxA

Highlights:

- Opened with a full audit of Crocs, socks, and Birkenstock ownership across all four of us, this is a running bit now and I have accepted my fate as the guy with two Crocs and six Birkenstocks

- ASPM consolidation, Gartner smashed dashboards and scanners into one category and now every vendor is one bolted onto the other, my take is it only works when it cuts noise and gives execs one place to look without a meeting

- Risk management versus vulnerability management, we still don't agree on the vocabulary as an industry, VulnOps came up because of course it did

- Malicious packages versus vulnerable packages get treated like the same problem and they're not, one's a mistake and one's a bomb someone shipped you on purpose

- My running frustration that AppSec is quietly becoming the SOC, we're the ones getting the 2am call on a compromised npm package because the SOC has zero visibility past the OS

- New OWASP Top 10 pitches, mine is developer endpoint risk, Kurt threw out critical infrastructure and autonomous vehicles, fair, we have one for boats

- Closed on the Mythos and Fable export sanctions as the biggest AppSec story of Q2, less about the models and more about everything that spun out of it
 
 
Back to Top