
José Carlos Chávez - When Museums Get Hacked: OWASP Top 10 Lessons from Heists
Om avsnittet
Why do broken access control and injection still dominate the OWASP Top 10 despite years of mature tooling? Okta's José Carlos Chávez joins Chris to explain what changed in the 2025 list—and what stubbornly did not. Drawing on his path from software engineering and observability into security, José examines why ownership and root causes matter more than another scanner. They explore the rise of supply-chain and software-integrity failures, the fragile security model around downloaded AI skills and agent permissions, and the continuing need for immutable, trustworthy logging. Along the way, José uses museum heists to make the Top 10 memorable and shows how its categories connect. The result is a practical look at where AppSec teams should focus when familiar vulnerabilities persist and autonomous tools gain more access.
Connect with José Carlos Chávez:
→ José Carlos Chávez on LinkedIn
→ OWASP Coraza
Mentioned in this episode:
→ OWASP Top 10:2025
→ OWASP Coraza
→ Traceable
→ tj-actions/changed-files advisory (CVE-2025-30066)
→ Apache Kafka
→ Istio
→ Falco
→ OpenTelemetry
→ lodash
→ The left-pad incident
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet José Carlos Chávez
01:19 From software engineering to application security
04:54 Observability as a security foundation
10:32 Museums, heists, and teaching the OWASP Top 10
13:50 What changed in the OWASP Top 10 for 2025
17:31 Why broken access control is still number one
24:59 Why injection refuses to disappear
30:05 Supply chain risk vs. software integrity failures
34:11 Can you trust downloaded AI skills?
35:13 When an agent quietly controls your computer
38:29 Immutable logging and incident evidence
43:46 Root causes across the Top 10
49:08 Ownership is the key takeaway
52:07 Closing thoughts
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.