RL Blog

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top
ReversingLabs: The More Powerful, Cost-Effective Alternative to VirusTotalSee Why
Skip to main content
Contact UsSupportLoginBlogCommunity
reversinglabs
AppSec & Supply Chain SecurityDev & DevSecOpsSeptember 7, 2023

20 application security pros you should follow

These leading app sec experts provide a steady flow of security knowledge to keep you up to speed.

John P. Mello Jr.
John P. Mello Jr., Freelance technology writer.John P. Mello Jr.
FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us
20 App Sec Social Profiles

Keeping current with the latest developments in application security can be challenging and time-consuming. One way to make it less so is to have a go-to list of active online application security pros to follow who can keep you up to date on the latest security threats and trends, as well as best practices, through their social media, blogs, podcasts, and newsletters.

Here are 20 app sec pros that provide security practitioners and leaders with the knowledge they need to stay at the top of their game.

Want curated software supply chain security news? Subscribe to Chainmail

Sean Atkinson and Tony Sager 

Atkinson and Sager are co-hosts of the Cybersecurity Where You Are podcast, which is sponsored by the Center for Internet Security, a nonprofit organization whose mission is to make the connected world a safer place for people, businesses, and governments. In a typical podcast episode, the hosts and an expert guest or guests discuss a security topic. Recent episodes of CWYA include "Inside the 'Spidey Sense' of a Pentester," "Overcoming Pre-Audit Scaries Through Governance," and "Guiding Vendors to IoT Security by Design."

Cybersecurity Where You Are podcast
Cybersecurity Where You Are podcast

https://www.cisecurity.org/insights/podcast/episode-62-inside-the-spidey-sense-of-a-pentester

Kurt Baumgartner

Baumgartner is a principal security analyst with the global research and analysis team at the cybersecurity software company Kaspersky. He focuses on the analysis and exposure of advanced persistent threats, as well as the investigation of targeted attacks, mass exploits, and cyber-intrusions, and he talks about malware issues at international conferences  He can be found on both X, formerly Twitter, and Mastodon, although he's more active on X.

Kevin Beaumont

As a senior threat intelligence analyst at Microsoft, Beaumont is a frequent speaker at security conferences and author of the DoublePulsar blog, named for a nasty kernel-mode implant that was developed by the National Security Agency and leaked in 2017 to a hacker group called the Shadow Brokers. Recent blog entries discuss the distribution of Trojan-infected versions of a Hans Solo video role-playing game, unpatched server vulnerability at the Electoral Commission in the United Kingdom, and a backdoor discovered in a popular mobile device management product. Beaumont also tweets and posts to Mastodon.

Michael Burch

Recognizing how rapidly the world of application security is evolving, Security Journey, a maker of application security education tools to help developers and the entire software development lifecycle team recognize and understand vulnerabilities and threats and proactively mitigate them, launched the Security Champions podcast, hosted by Burch, who is the company’s applications security director. Episodes include discussions with development leaders and security experts about the latest headlines in the app sec world, as well as advice on building, maintaining, and scaling a successful security program.

Mark Curphey

Curphey writes the Crash Override blog and newsletter. He's a founder of OWASP, as well as of SourceClear, a cloud-native data security platform. SourceClear's software composition tool technology was acquired by Veracode in 2018. The blog has entries on product software certification, security tooling, and the latest developments in the company's open-source Chalk project. Chalk allows software developers, DevOps engineers, and security pros to gain visibility across development and production. Curphey also tweets at @VuduChief.

crash override blog
crash override blog

https://crashoverride.com/blog/less-appsec-assessment-and-protection-more-devsecops-observability/

Royal Hansen

As the Google vice president of privacy, safety, and security, Hansen is focused on making the Internet safer for everyone. During his term at Google, he launched OSV Scanner, a tool that allows developers to scan for vulnerabilities in open-source software dependencies, led the development of the company's security incident response plan, and worked to improve the security of its products and services, such as Chrome, Android, and Gmail. Hansen is active on both X and LinkedIn.

Troy Hunt

Best known for his invaluable Have I Been Pwned website, which allows Internet users to check whether their personal data has been compromised in a data breach, Hunt is an Australian web security consultant and educator who has written several popular security-related courses on Pluralsight, a provider of video training courses for software developers and IT pros. In addition to conducting keynotes and workshops at conferences around the world, he writes a blog and is active on X and Mastodon, and has a YouTube channel.

James Kettle

Kettle is director of research at PortSwigger, which makes Burp, a suite of programs for web security scanning and application testing. Of the 10 most popular Burp extensions, Kettle has written three of them: ActiveScan++, HTTP Request Smuggler, and Backslash Powered Scanner. He has also made presentations on HTTP desync attacks at DEF CON, and on practical web cache poisoning at BlackHat USA. In addition to maintaining a dynamic personal web page with links to PortSwigger research, he is active on X, Mastodon, and LinkedIn.

Seth Law and Ken Johnson

Law, founder of the research and security consulting firm Redpoint, and Johnson, co-founder and CTO of DryRun Security, a maker of security software for developers, are hosts of the Absolute AppSec podcast. The podcast offers discussions on a wide range of application security topics, including contextual security analysis, scans, app sec research, threat modeling, Zip TLD, PyPI 2FA, AI poisoning, watering-hole attacks, and adversarial AI. Recent guests include Brian Walter of OpenContext, Evan Johnson of RunReveal, and Brian Joe of Impart Security. Both are active on X.

Jeremy Long

Developers who use software composition tools to determine if the libraries they're using are free of known security defects are likely to be familiar with Long's work. He wrote and maintains Dependency-Check, one of the earliest software composition tools to be offered to code warriors. His day job is as a principal security engineer at ServiceNow, a cloud-based platform that automates IT service management and other business processes, but he's also active on X and GitHub.

Melinda Marks

Marks is a senior analyst at TechTarget's Enterprise Strategy Group. She writes about cloud-native application protection platforms, cloud workload protection, cloud security posture management, DevSecOps, and application security, including web application security testing such as static AST, dynamic AST, interactive AST, software composition analysis, and API security. Her latest report on APIs delves into the challenges of securing APIs and how to build an effective security strategy so developers can safely utilize the power of APIs to build better applications. She's active on both X and LinkedIn.

Better API security needed as companies modernize apps | TechTarget
Better API security needed as companies modernize apps | TechTarget

https://www.techtarget.com/searchapparchitecture/feature/Better-API-security-needed-as-companies-modernize-apps?trk=public_post_embed_feed-article-content


Katie Moussouris

Bug bounty and vulnerability disclosure programs are Moussouris' specialty, which was honed working as chief policy officer for HackerOne and helping Microsoft and the U.S. Department of Defense set up their first bug bounty programs. Valuable knowledge can be gained by reading her blog at Luta Security, the company she founded. She's also very active on X, where she's garnered more than 116,000 followers.

Luta Security blog preview
Luta Security blog preview

https://www.lutasecurity.com/post/bug-bounty-evolution-not-your-grandson-s-bug-bounty

Jack Rhysider

Hackers, breaches, shadow government activity, hacktivism, and cybercrime are the subjects covered by Rhysider in his Darknet Diaries podcast. Episodes cover a range of subjects including the history of hacking and cybercrime, types of malware and how they work, and the dark web and how it is used for illegal activities, as well as stories about real-life hackers and cybercriminals and the latest trends in cybersecurity. In addition to his podcast, Rhysider is active on X and Discord. His website also has some cool T-shirts based on edgy original art created for his podcasts.

Chris Romeo

Application security and threat modeling are Romeo's forte, but he's had many roles over his long career, including trusted product evaluator, senior security consultant, penetration tester, director of incident response, chief security advocate at Cisco, and startup CEO at Security Journey. Currently, he is managing general partner at
Kerr Ventures, a cybersecurity startup investment and advisory firm. He also hosts or shares hosting duties for the Threat Modeling podcast, the Application Security podcast, and the Security Table podcast. In addition to his podcast activity, Romeo pens the Reasonable Application Security newsletter.

application security podcast preview
application security podcast preview

https://www.linkedin.com/posts/application-security-podcast_dan-kuykendall-why-all-application-security-activity-7101923487396626432-p6pQ

Mike Shema

Shema, along with John Kinsella and Akira Brand, hosts the Application Security Weekly podcast sponsored by SC Magazine. The podcast delivers interviews and news about app sec, DevOps, DevSecOps and all the ways software flaws can be found and fixed. Recent episodes include "Security in a Cloud Native World & Mobile App Attacks,"
"Pointers and Perils for Presentations," "You’ve Got Appsec, But Do You Have Archsec?," "Identity and Verifiable Credentials in Cars," and "Navigating the Complexities of Development to Create Secure APIs."

Adam Shostack

As an active member of the security community (he's on the Black Hat review board and an emeritus member of the CVE advisory board) and an author (he's written Threat Modeling: Designing for Security and Threats: What Every Engineer Should Learn from Star Wars and co-wrote The New School of Information Security) Shostack brings some impressive credentials and valuable insights to his Shostack + Associates blog. Recent entries include "Threat Modeling and Secure by Design," "Valorizing Rule Breaking," and "Microsoft Can Fix Ransomware Tomorrow."

Shostack + Friends Blog: Threat Modeling and Secure by Design
Shostack + Friends Blog: Threat Modeling and Secure by Design

https://shostack.org/blog/cisa-secure-by-design-feedback/

smelly_vx

The mysterious smelly_vx is the guardian of vx-underground.org, the largest collection of malware source code, samples, and papers on the Internet. Smelly describes himself as in his early 30s, married, and a dog owner. Judging from his tweets at the vx-underground X account, he also has a sense of humor. The latest activity at the vx-underground website—addition of malware samples and new papers—as well as hacker news can also be found at the X account, which has more than 224,000 followers.

Sam Stepanyan

Stepanyan is an application security architect and leader of OWASP's London chapter. In addition to posting OWASP news and notices on his X and Mastodon accounts, Stepanyan riffs about data breaches, zero-day vulnerabilities, open-source licensing and other concerns of app sec practitioners.

Sam Stepanyan X post preview
Sam Stepanyan X post preview

https://infosec.exchange/@securestep9/110938854365615666/

Chris Wysopal

Cybersecurity has been in Wysopal’s blood for a long time. He was one of the original vulnerability researchers at the L0pht, a 1990s hacker think tank, where he was one of the first to publicize the risks of insecure software. He co-founded Veracode, which pioneered the concept of using automated static binary analysis to discover vulnerabilities in software, where he's now CTO. A well-known security expert, he's testified before Congress and has been interviewed by numerous publications and TV networks. He's active on LinkedIn, X, and Mastodon.

What do you have to gain?

Staying on top of the rapidly evolving field of application security requires dedication and diligent effort. Following respected leaders in the app sec community through their blogs, newsletters, podcasts, and social media is a good way to keep up with the latest threats, tools, and best practices. The diverse group of experts highlighted here represent valuable sources of insight covering a wide range of topics from software composition analysis to threat modeling to vulnerability disclosure.

Whether you're just starting out in application security or are an experienced practitioner looking to expand your knowledge, subscribing to a select set of app sec thought leaders will ensure that you have access to breaking news and innovative thinking in the field. Making an effort to regularly consume their commentary and advice will pay dividends in helping you master today's threats and prepare for tomorrow's.

Want curated software supply chain security news? Subscribe to Chainmail

Keep learning

  • Get up to speed on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar to discussing the findings.
  • Learn why binary analysis is a must-have in the Gartner® CISO Playbook for Commercial Software Supply Chain Security.
  • Take action on securing AI/ML with our report: AI Is the Supply Chain. Plus: See RL's research on nullifAI and watch how RL discovered the novel threat.
  • Get the report: Go Beyond the SBOM. Plus: See the CycloneDX xBOM webinar.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Tags:AppSec & Supply Chain SecurityDev & DevSecOps

More Blog Posts

ReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsRL at RSAC
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
Trust model flips

How agentic AI flips the trust model

As AppSec shifts focus from the components to data, your strategy needs updating. Are you on top of your trust debt?

Learn More about How agentic AI flips the trust model
How agentic AI flips the trust model
MCP attacks

MCP rug-pull attack worries mount

This new class of AI tool supply chain attack highlights how trust of agents can be exploited.

Learn More about MCP rug-pull attack worries mount
MCP rug-pull attack worries mount
AI coding racing

Can AppSec keep pace with AI coding?

AI lets software teams generate code at a rate faster than security can validate it. One way to win the race: more AI.

Learn More about Can AppSec keep pace with AI coding?
Can AppSec keep pace with AI coding?

LLMmap puts its finger on ML attacks

Researchers show how LLM fingerprinting can be used to automate generation of customized attacks.

Learn More about LLMmap puts its finger on ML attacks
LLMmap puts its finger on ML attacks
Finger on map