The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Omer Gil and Daniel Krivelevich -- Top 10 CI/CD Security Risks
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
CI/CD systems hold code, credentials, and production access, yet many organizations still treat them as internal plumbing rather than a critical attack surface. Omer Gil and Daniel Krivelevich join Chris and Robert to explain the research behind the Top 10 CI/CD Security Risks. They trace lessons from SolarWinds and Codecov, show why pipeline security often falls between AppSec and infrastructure teams, and describe how the list was built with community input. The discussion turns the risks into practical guidance for threat modeling pipelines, reducing exposure, assigning ownership, and using the intentionally vulnerable CI/CD Goat project to learn safely by doing.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Omer Gil and Daniel Krivelevich:
→ Omer Gil on LinkedIn
→ Daniel Krivelevich on LinkedIn
→ Top 10 CI/CD Security Risks
Mentioned in this episode:
→ Top 10 CI/CD Security Risks
→ Threat Modeling Manifesto
→ CI/CD Goat
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 The hidden attack surface in CI/CD
02:03 Why create a CI/CD security top ten
04:30 How the project began
11:17 Making the risks useful to developers
14:49 Lessons from SolarWinds and Codecov
21:26 Why CI/CD security falls through the cracks
27:17 Research and community collaboration
30:38 Building and ranking the risk list
35:20 Mitigations teams can apply
39:33 When internal build systems are exposed
44:18 Threat modeling the software pipeline
48:44 Learning with CI/CD Goat
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo