The security repo is a podcast that focuses on real world security issues we are all facing today. We will take deep dives into news events and have exclusive interviews with security leaders on the ground.
…
continue reading
Dwayne McDaniel Podcasts
The site for PHP professionals, Magazine, Training, Books, Conferences
…
continue reading
This week on the PHP Podcast, Eric and John talk about NativePHP Mobi…
…
continue reading

1
Dev Engagement in Security: From Content Strategy to Community Strategy with Alyssa Miles
18:44
18:44
Play later
Play later
Lists
Like
Liked
18:44In this episode of the Security Repo Podcast, we chat with Alyssa Miles, a product marketing leader at CyberArk, about building authentic developer communities in the security space. She shares her journey from agency marketing to driving developer engagement, along with insights from Hacker Summer Camp and strategies for enabling community-driven …
…
continue reading

1
Community Corner: PHP 8.5 Release Manager Daniel Scherzer
28:33
28:33
Play later
Play later
Lists
Like
Liked
28:33 In this episode, Scott talks with Daniel Scherzer about his work as a PHP contributor and PHP 8.5 release manager. Links: https://displace.tech/ Our Discord – https://discord.gg/aMTxunVx Buy our shirts – https…
…
continue reading

1
PHP Alive And Kicking: Episode 4 – Ashley Hindle
1:12:47
1:12:47
Play later
Play later
Lists
Like
Liked
1:12:47 From wannabe teen hacker to 20+ years in PHP, AI Lead at Laravel, and…
…
continue reading
By php[podcast] episodes from php[architect]
…
continue reading

1
PHP Alive and Kicking 3: Special Guest Gina Banyard
1:18:04
1:18:04
Play later
Play later
Lists
Like
Liked
1:18:04 Shownotes: https://thephp.foundation/ https://wiki.php.net/ https://wiki.php.net/rfc https://opencollective.com/phpfoundation https://gpb.moe/about.html Streams: Youtube Channel Twitch Partners This podcast is…
…
continue reading

1
Beyond Controls: Building Trust and Communication in Security – Featuring AriaDear
19:59
19:59
Play later
Play later
Lists
Like
Liked
19:59In this episode of the Security Repo Podcast, Aria Langer returns to share deep insights from her work in privileged access management and the challenges of implementing security controls without alienating coworkers. She and Dwayne dive into the often-overlooked importance of empathy in cybersecurity, exploring how human connection can make securi…
…
continue reading

1
Community Corner: PHPScore with Ed Grosvenor
28:45
28:45
Play later
Play later
Lists
Like
Liked
28:45 In this episode, Scott talks with Ed Grosvenor about technical debt and his company’s new website PHPScore.com that inspects your PHP projects for technical debt so you can bring issues back to your team for r…
…
continue reading

1
The PHP Podcast 2025.09.25 with Guest James Seconde
1:15:01
1:15:01
Play later
Play later
Lists
Like
Liked
1:15:01 This week on the PHP Podcast, Eric and John talk about Special guest James Seconde, CTO who don’t like PHP, AI, and more… Links from the show: Reddit – The heart of the internet 2025 DORA State of AI Assisted …
…
continue reading

1
Misconfigurations, Legacy Landmines, and Tier Zero Truths – Jake Hildreth on Active Directory
21:37
21:37
Play later
Play later
Lists
Like
Liked
21:37In this episode of the Security Repo Podcast, we chat with Jake Hildreth, Principal Security Consultant at Semperis, about the enduring challenges of securing Active Directory in a hybrid cloud world. Jake shares war stories from the field, including dangerously misconfigured environments and the real-world impacts of legacy systems. We also explor…
…
continue reading
This week on the PHP Podcast, Eric and John discuss NativePHP bringing everything, including the Kitchen Sink, PHP Foundation announcement of the SDK for MCP, Nuno’s Explanation of Laravel MCP, PHP 8.5 Pipe Op…
…
continue reading

1
Rebuilding OWASP St. Louis & Strengthening Security Growing The Community – Andre Van Klaveren
24:52
24:52
Play later
Play later
Lists
Like
Liked
24:52In this episode of the Security Repo Podcast, Andre Van Klaveren talks about his decades-long journey through IT, software development, and application security, culminating in the reboot of the OWASP St. Louis chapter. They discuss the history and importance of OWASP, community building in a post-pandemic world, and how risk-based thinking and str…
…
continue reading

1
PHP Alive and Kicking Episode 2: Sara Golemon
1:03:39
1:03:39
Play later
Play later
Lists
Like
Liked
1:03:39 In this episode of “PHP Alive and Kicking,” Mike and Chris engage in …
…
continue reading

1
Community Corner: Exposed Secrets with Dwayne McDaniel
26:02
26:02
Play later
Play later
Lists
Like
Liked
26:02 In this episode, we speak with Dwayne McDaniel about exposed secrets in our GitHub repositories and figuring out when we’ve been compromised using Honeytoken. Links: Dwayne’s site – https://dwayne-mcdaniel.com…
…
continue reading

1
Teaching AppSec With Scratchers: Gamified Learning For Real-World Impact - Jenn Gile
20:29
20:29
Play later
Play later
Lists
Like
Liked
20:29In this episode of the Security Repo Podcast, Jenn Gile shares insights from her hands-on security education at DEF CON's AppSec Village, where she ran a wildly successful lottery-style dependency upgrade game. She discusses the challenges developers face with remediation, the importance of empathy in AppSec, and how gamified, tangible learning exp…
…
continue reading

1
Threat Modeling OpenSSL, Lessons from a Data Breach, and Volunteering with Narayan Ram Narayanan
18:17
18:17
Play later
Play later
Lists
Like
Liked
18:17In this episode of the Security Repo Podcast, Narayan Ram Narayanan shares his journey into cybersecurity, sparked by a personal data breach and fueled by a passion for privacy and secure development. He discusses his upcoming talk on threat modeling OpenSSL applications using STRIDE and other threat models, and highlights the value of volunteering…
…
continue reading

1
From Risk Acceptance to Community Building: Inside Security With Sean Juroviesky
19:32
19:32
Play later
Play later
Lists
Like
Liked
19:32In this episode of the Security Repo Podcast, Sean Juroviesky joins us to share their journey through cybersecurity, from finding community in BurbSec to giving talks at major conferences like DEF CON and BlueTeamCon. Sean dives deep into the realities of risk management, executive sign-off processes, and the critical importance of understanding bu…
…
continue reading

1
Tackling Deepfakes - Battling Ai-Generated Faces, Scams, Detection, And Security – Sankalp Kumar
19:51
19:51
Play later
Play later
Lists
Like
Liked
19:51In this episode of the Security Repo Podcast, Dwayne McDaniel and Sankalp Kumar dive into the world of deepfakes, how they are created using transformer models and GANs, and the real-world scams they enable. They discuss current detection techniques, including physiological analysis, iris scanning, and PKI-based authentication. Sankalp also shares …
…
continue reading

1
Security Onion - From Classroom To SOC, Open Source and Education - Matt Gracie
22:32
22:32
Play later
Play later
Lists
Like
Liked
22:32In this episode of the Security Repo Podcast, we’re joined by Matt Gracie, a seasoned blue team expert and senior engineer at Security Onion Solutions. Matt dives deep into the architecture and practical deployment of Security Onion, a powerful open-source enterprise security monitoring tool. He also shares insights from his role as a cybersecurity…
…
continue reading

1
From Code to Crypto: How Learning Fundamentals Empowers Security Pros – Matt Olmsted
25:58
25:58
Play later
Play later
Lists
Like
Liked
25:58In this episode of the Security Repo Podcast, software engineer and newly minted CISSP Matt Olmsted joins us to explore cryptographic fundamentals and why understanding them matters for anyone in security. From explaining symmetric vs. asymmetric encryption to the real-world implications of side-channel attacks, Matt delivers practical insights for…
…
continue reading

1
Inside BurbSec: From Suburban InfoSec Beers to Global Discord Community – Johnny Xmas
36:04
36:04
Play later
Play later
Lists
Like
Liked
36:04In this episode of the Security Repo Podcast, Johnny Xmas shares the grassroots story and philosophy behind BurbSec, a unique InfoSec meetup network focused on genuine community and consistent in-person engagement. He dives into the evolution from IRC to Discord, detailing how digital platforms have helped expand and sustain their hyperlocal connec…
…
continue reading

1
From Car Culture to Cybersecurity: Building Community and Skills with Christian Pinkston
22:49
22:49
Play later
Play later
Lists
Like
Liked
22:49In this episode of the Security Repo Podcast, we meet Christian Pinkston, a cybersecurity student and car culture enthusiast who's become a recognizable figure in the hacker community. Christian shares his unique journey into cybersecurity—from early experiments with hacking tools to volunteering at major conferences and running mesh networks with …
…
continue reading

1
Keeping Drupal Running With Static Code Analysis & Lessons From Drupalgeddon - Matt Glaman
20:00
20:00
Play later
Play later
Lists
Like
Liked
20:00In this episode of the Security Repo Podcast, we sit down with Matt Glaman, a veteran developer in the Drupal community, to explore the role of static code analysis in maintaining secure, performant, and upgrade-ready PHP applications. We dive into tools like PHPStan and DrupalCheck, and how they help identify deprecations and prevent security risk…
…
continue reading

1
From Phishing Scam Response to Cyber Defender: A Journey into Security - Manoj Viswanathan
25:52
25:52
Play later
Play later
Lists
Like
Liked
25:52In this episode of the Security Repo Podcast, Manoj Viswanathan shares his unconventional journey into cybersecurity, from a personal phishing incident to mastering Capture The Flag (CTF) competitions and interning at Toshiba. The conversation dives deep into the community-driven value of groups like BurbSec, the practical benefits of hands-on expe…
…
continue reading

1
AI, Zero Trust, And The Future Of DevSecOps In A Cloud-First World – Nivathan Athiganoor Somasundharam
19:35
19:35
Play later
Play later
Lists
Like
Liked
19:35In this episode of the Security Repo Podcast, we dive deep into the evolving role of DevSecOps with Nivathan Athiganoor Somasundharam, a technical account manager at Teleport. He shares his journey from cloud engineering to becoming a DevSecOps practitioner, emphasizing proactive security, the elimination of secrets, and the future of identity-base…
…
continue reading

1
Reducing Developer Toil, Shifting Security Left, And Using Caution With AI – Andy Dennis
20:41
20:41
Play later
Play later
Lists
Like
Liked
20:41In this episode of the Security Repo Podcast, Andy Dennis, VP at Modus Create, joins Dwayne McDaniel to unpack what "shifting left" really means for security and engineering teams. They explore the impact of hands-on security training at B-Sides events, the concept of developer toil, and the role AI tools like GitHub Copilot AutoFix are starting to…
…
continue reading

1
Educate, Empower, Prepare: Building Inclusive Cybersecurity With Rebekah Skeete
23:26
23:26
Play later
Play later
Lists
Like
Liked
23:26In this episode of the Security Repo Podcast, we sit down with Rebekah Skeete, COO of BlackGirlsHack, to explore how her organization is increasing diversity and accessibility in cybersecurity through hands-on training, mentorship, and inclusive community building. Rebekah shares the origin story of BlackGirlsHack, their evolving programs including…
…
continue reading

1
Bridging the Gap Between Dev and Sec: Tools, Culture, and Careers - Thomas Jost
24:49
24:49
Play later
Play later
Lists
Like
Liked
24:49In this episode of the Security Repo Podcast, Thomas Jost shares his journey from software development to becoming a Senior Application Security Engineer, offering insights into the value of diverse tech backgrounds in AppSec. He discusses the real-world friction between security practices and developer workflows, especially around static analysis …
…
continue reading

1
What Tools Miss and Why Humans Matter in AppSec - Yash Shahani
18:02
18:02
Play later
Play later
Lists
Like
Liked
18:02In this episode of the Security Repo Podcast, Dwayne McDaniel sits down with Yash Shahani, a seasoned AppSec engineer and vulnerability hunter, to dive into the nuances of manual code review and the limitations of automated security tools. They explore the evolving role of AI in AppSec, its promise and pitfalls, and why human intuition still plays …
…
continue reading

1
Visualizing Data Poisoning and Rethinking Threat Detection Through Graphs – Maria Khodak
21:05
21:05
Play later
Play later
Lists
Like
Liked
21:05In this episode of the Security Repo Podcast, Maria Khodak explores how graph theory and data visualization can be used to uncover machine learning vulnerabilities like data poisoning. She explains how her work as a penetration tester intersects with research on threat detection and the importance of making abstract security concepts more human-rea…
…
continue reading

1
Building Human-Centric Security and Hacker Communities in Argentina - Ailin Castellucci
23:04
23:04
Play later
Play later
Lists
Like
Liked
23:04In this episode of the Security Repo Podcast, Ailin Castellucci shares her inspiring journey from selling shoes to building cybersecurity teams and leading human-centric education projects. She discusses the unique challenges and perspectives of cybersecurity education in Argentina, emphasizing the importance of empathy, communication, and passion …
…
continue reading

1
From SOCs to Threat Detection Engineering: Crafting Better Security Responses - Chris Kulakowski
20:03
20:03
Play later
Play later
Lists
Like
Liked
20:03In this episode of the Security Repo Podcast, Chris Kulakowski, a seasoned detection engineer from IBM, delves into the complexities of threat detection, from writing detection rules to collaborating with red teams for proactive security strategies. He shares insights on prioritizing security risks, the evolving role of AI in cybersecurity, and the…
…
continue reading

1
Quarantine Policies and Cloud Security Strategies for AWS – Bleon Proko
23:06
23:06
Play later
Play later
Lists
Like
Liked
23:06In this episode of the Security Repo Podcast, Bleon Proko dives into the intricacies of AWS security, focusing on the role and impact of quarantine policies in mitigating the risks of compromised credentials. He explains how AWS policies prioritize denial to prevent privilege escalation, lateral movement, and financial fraud, offering practical str…
…
continue reading

1
Helping Developers Use Open Source Security Tools & Improving Defense With AI - Mackenzie Jackson
24:19
24:19
Play later
Play later
Lists
Like
Liked
24:19In this episode of the Security Repo Podcast, we welcome back Mackenzie Jackson, security researcher and founder of this very show, to discuss the evolving landscape of AI in cybersecurity. Mackenzie dives deep into how AI is reshaping open-source security, revealing research that uncovered 600 unreported vulnerabilities in popular packages. We als…
…
continue reading

1
How Digital Forensics Supports Incident Response And Who Should Own IAM - Gerard Johansen
22:20
22:20
Play later
Play later
Lists
Like
Liked
22:20In this episode of the Security Repo Podcast, we sit down with cybersecurity expert Gerard Johansen to dive deep into identity and access management (IAM) challenges in the enterprise space. We explore the explosion of data and identities, the ongoing debate over who "owns" IAM in organizations, and how threat actors are evolving their tactics to e…
…
continue reading

1
Navigating And Defining The Evolving Role Of The CISO In Government Security - Josh Kuntz
22:53
22:53
Play later
Play later
Lists
Like
Liked
22:53In this episode of the Security Repo Podcast, we sit down with Josh Kuntz, Chief Information Security Officer (CISO) for the Texas Department of Licensing and Regulation, to explore the unique challenges of securing state agencies. With nearly three decades in public service, Josh shares his insights on navigating government cybersecurity, hiring t…
…
continue reading

1
The State And Future Of Cybersecurity Training and AIShaping The Role - Zach Hill
22:36
22:36
Play later
Play later
Lists
Like
Liked
22:36In this episode of the Security Repo Podcast, we sit down with Zach Hill from Antisyphon Training to discuss affordable cybersecurity education and the evolving landscape of IT training. Zach shares insights on the importance of hands-on learning, the challenges of misinformation in online education, and how AI is reshaping entry-level IT roles. We…
…
continue reading

1
Secrets Management With The OpenPao Project And Open Source Security - Alex Scheel
22:15
22:15
Play later
Play later
Lists
Like
Liked
22:15In this episode of the Security Repo Podcast, we sit down with Alex Scheel, staff back-end engineer at GitLab and chair of the OpenBao Technical Steering Committee, to discuss the origins and future of OpenBao, a fork of HashiCorp Vault. Alex explains the implications of HashiCorp's licensing change, the technical advantages OpenBao brings to the t…
…
continue reading

1
Playing (And Winning) CTFs To Advance Your Cybersecurity Career - Edna Jonssen
22:45
22:45
Play later
Play later
Lists
Like
Liked
22:45In this episode of the Security Repo Podcast, we sit down with Edna Jonnson, a cybersecurity engineer and SOC analyst, to discuss their journey from web development to security operations. Edna shares insights on the value of Capture the Flag (CTF) competitions for skill development, recounting their recent victory at Wild West Hacking Fest. We als…
…
continue reading

1
Defense In Depth Means Writing More Tests To Make Sure You Don't Regress - John Poulin
41:51
41:51
Play later
Play later
Lists
Like
Liked
41:51In this episode of the Security Repo Podcast, we dive into the concept of defense in depth with guest John Poulin, who shares insights on secure code reviews, architecture design, and threat modeling. We discuss the importance of integrating security tests into development workflows, the role of security headers in assessing a company's security po…
…
continue reading

1
What Does It Mean To Be A Security Lead - A Conversion With Kayssar Daher
42:21
42:21
Play later
Play later
Lists
Like
Liked
42:21In this episode of the Security Repo Podcast, Dwayne and Kayssar dive into Kayssar's role as a security leader at GitGuardian, exploring his responsibilities, challenges, and the balance between proactive and reactive security work. They also discuss the evolution of security tools, the importance of relationship-building in security roles, and sha…
…
continue reading

1
Understanding Security Champions and Making Human Connections - Dustin Lehr
48:29
48:29
Play later
Play later
Lists
Like
Liked
48:29In this episode of the Security Repo Podcast, Dwayne and Kayssar sit down with Dustin Lehr, co-founder and chief product and tech officer at Katilyst , to explore the power of Security Champions programs. Dustin shares insights from his journey as a software engineer turned cybersecurity leader and explains how security champions can bridge the gap…
…
continue reading

1
Leveraging Hermeneutics In Cyber Threat Intelligence at The MM-ISAC - Cherie Burgett
37:54
37:54
Play later
Play later
Lists
Like
Liked
37:54In this episode of the Security Repo Podcast, we dive into the world of ISACs (Information Sharing Analysis Centers) with Cherie Burgett. Cherie shares insights into the nuanced field of cyber threat intelligence, discussing how interpretation techniques like hermeneutics can enhance understanding of threat actor behavior. The conversation also exp…
…
continue reading

1
Observability ownership, monitoring apps at scale, and learning DevOps like a language- Josh Lee
30:59
30:59
Play later
Play later
Lists
Like
Liked
30:59In this episode of the Security Repo Podcast, we explore the intersection of observability and security with special guest Josh Lee, a developer advocate at Altinity and expert on Clickhouse and OpenTelemetry. We discuss the evolving definition of observability, how context and tagging enhance both security and observability practices, and how data…
…
continue reading

1
The Freedom Of Information Act, Ethical AI, And NerdCore Music - Stephanie Honore
36:39
36:39
Play later
Play later
Lists
Like
Liked
36:39In this episode of the Security Repo Podcast, we talk with cybersecurity expert Stephanie Honore, about her journey into security, her work with the Freedom of Information Act (FOIA), and her insights on ethical AI and chain of custody in data handling. She shares her experience building software for evidence management and her thoughts on the inte…
…
continue reading

1
Securing Workload Identities And Working On Conjure - Jody Hunt
43:31
43:31
Play later
Play later
Lists
Like
Liked
43:31In this episode of the Security Repo Podcast, we explore the fascinating and complex world of non-human identities (NHIs) with Jody Hunt from CyberArk. We discuss the challenges of authenticating machine workloads, delve into the "secret zero" problem, and consider how frameworks like SPIFFE are shaping the future of secure machine identity. Plus, …
…
continue reading

1
The Updated OWASP Top 10 for LLM Applications and the AI landscape - Talesh Seeparsan
42:37
42:37
Play later
Play later
Lists
Like
Liked
42:37In this episode of the Security Repo Podcast, the team dives into the OWASP Top 10 for Large Language Model Applications with special guest Talesh Seeparsan, an expert in cybersecurity and AI safety. Talesh shares insights into why a specialized top 10 for LLM vulnerabilities is essential, delves into unique challenges like system prompt leakage an…
…
continue reading

1
Securing Flight Simulators And Other Operational Technology - Coburn Slay
45:02
45:02
Play later
Play later
Lists
Like
Liked
45:02In this episode of the Security Repo Podcast, we delve into the intricate world of flight simulators and their unique cybersecurity challenges with guest Coburn Slay. He shares insights into managing both legacy and modern systems, the importance of compliance in operational technology, and his journey into tech starting at a young age. We also exp…
…
continue reading

1
Getting Out Of Walled Gardens By Running Your Own Email - Michael Harrison
36:03
36:03
Play later
Play later
Lists
Like
Liked
36:03In this week's episode of The Security Repo Podcast, we are joined by Michael Harrison, a tech veteran who discusses the benefits and challenges of running your own email server in a world dominated by major providers, along with insights into the surprising persistence of fax technology in industries like healthcare. Michael also reflects on his p…
…
continue reading

1
Understanding Psychological Safety And Asking Questions To Stay Relevant - Deanna Stanley
37:37
37:37
Play later
Play later
Lists
Like
Liked
37:37Got psychological safety? In this episode of the Security Repo Podcast we sit down with Deanna Stanley to learn about psychological safety and the framework she has coauthored on building the layers of trust within organizations. We also dig into a few interesting stories from her time at MITRE and end up with some very encouraging words on how to …
…
continue reading