Security News

Cybersecurity news aggregator

INFO News SC Media

Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390

  • What: Discussion on defense-in-depth strategies for securing mobile applications
  • Impact: Relevant to developers and security professionals working on mobile app security
Read Full Article →

Subscribe Share Full episode and show notes Application security , DevSecOps , DevOps Defense-in-depth strategies for securing mobile applications – Ryan Lloyd – ASW #390 Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We’ll dive into some of these defense-in-depth strategies and why they are important to mobile applications. Securing workflows goes beyond input validation and pattern matching suspicious payloads; it requires detailed attention to state machines, edge cases, and collecting signals to evaluate trust. Segment Resources: https://hubs.la/Q04jLKj70, https://mas.owasp.org/MASTG/0x04c-Tampering-and-Reverse-Engineering/, https://owasp.org/API-Security/editions/2023/en/0x00-header/. Th... July 7, 2026 This episode is sponsored by Full Segment Notes Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'll dive into some of these defense-in-depth strategies and why they are important to mobile applications. Securing workflows goes beyond input validation and pattern matching suspicious payloads; it requires detailed attention to state machines, edge cases, and collecting signals to evaluate trust. Segment Resources: https://hubs.la/Q04jLKj70 https://mas.owasp.org/MASTG/0x04c-Tampering-and-Reverse-Engineering/ https://owasp.org/API-Security/editions/2023/en/0x00-header/ This segment is sponsored by Guardsquare. Visit https://securityweekly.com/guardsquare to learn more about them! Guest Ryan Lloyd Chief Product Officer at Guardsquare Ryan has spent the past 25 years working for companies that build software tools for developer teams. Version control, issue tracking, automated testing and app security. In his current role as Chief Product Officer for Guardsquare he engages customers to help identify and solve the biggest challenges in mobile application security. Host Mike Shema https://dangerouserrors.com Announcements AppSec teams, your backlog is growing faster than you can fix it. SAST and DAST tools are flooding you with findings, developers are pushing back, and prioritizing what actually matters in code is getting harder. So how do you reduce risk without slowing releases? Join the Vulnerability Management Virtual Cybersecurity Summit to learn how teams are prioritizing real exploitable issues, reducing noise, and integrating remediation into modern development workflows. Security Weekly listeners can register for free at https://securityweekly.com/vulnmanagement using the promo code: CSS26-SW CyberRisk TV is proud to be an official media partner of Black Hat USA 2026! We'll be broadcasting live from the Black Hat LIVEWIRE Studio, where application security innovators can showcase the technologies, research, and strategies shaping the future of secure software development. Our Executive Interviews and Event Momentum Packages help you stay in front of developers and AppSec teams long after Black Hat ends. Fewer than 10 interview opportunities remain, so visit https://securityweekly.com/exec today and reserve your spot before they're gone. List of Articles Mike Shema Seven FatFs bugs, one very large blast radius AI coding agents vulnerability: GuardFall shell injeciton | Adversa AI GPT-5.5-Cyber built a zlib fuzzing lab in a day – The Trail of Bits Blog The New MCP Specification: What Security Teams Must Prepare For | Akamai Snyk VulnBench JS 1.0: LLM Bug Repeatability Show More Stay in the Know, No Smoke and Mirrors – Join Our Newsletter Get expert insights and technical breakdowns straight to your inbox. Join Now Related Segments Application security AI is Writing Your Code… And It’s Insecure | The New AppSec Reality – WC #1 Application security Reducing Attack Surface & Evaluating Efficiency in Agents – Itamar Apelblat, David Goldschlag – ASW #389 Application security How AI Is Reshaping Identity Security at the Infrastructure Layer – Ev Kontsevoy, Neha Duggal, Amit Masand – ASW #388 Related Content Vulnerability Management The context gap: Building trusted agents in the age of AI-accelerated exploitation Application security India questions WhatsApp username feature over cyberattack fears AI/ML AI adoption outpaces governance, creating risks for businesses You can skip this ad in 5 seconds

Share this article