**Andrew Ziegler** (0:04)
Welcome back to Dev Interrupted. I'm your host, Andrew Ziegler. And on the show, we've been learning how the world of autonomous agents are pushing deployment speeds to the limit with security paying the ultimate price. And we've been covering the ongoing software supply chain crisis with leaders like CEO Dan Lorinc of ChainGuard. And today, we're pushing the topic even further with a returning guest who also happens to be Owasp distinguished member and Hacker of the Year. Yes, joining me is a favorite who's proven throughout her career that security isn't a product, it's a practice, and that it can be purple too.
She's the best-selling author of Alice in Bob Learns Application Security and Alice in Bob Learns Secure Coding, which we covered on the show.
She's a former rock star and most recently, project leader for the Owasp Top 10 2025 Tanya Janca, aka SheHacksPurple, welcome back to the show.
**Tanya Janca** (1:00)
Andrew, thank you so much for having me.
**Andrew Ziegler** (1:02)
We're so excited to have you, and I just want to start by saying, it's always so impressive for me to read your list of credentials and your background. I think you've had such an amazing career and you have such a really unique perspective to bring to our listeners, especially with your passion around security. As I say constantly, we just never give enough of a spotlight to that topic, and so I'm really happy to have you here, especially with all of the work you've been doing with Owasp. I'm really excited to dig in. So you served as a project leader for the top 10 2025
What was that like? Can you maybe kind of orient some of our listeners who maybe are less familiar with that world?
**Tanya Janca** (1:42)
So Owasp is an international nonprofit where we have over 300 chapters where people meet in person every month, over 100 open source projects. We have international conferences that move around the world.
And then there's a nonprofit foundation as well. And our most popular project of old time that is over 20 years old is called the Owasp Top 10, which is supposed to be the top 10 risks to web apps. But it actually is just the top 10 risks to software in general. And this time, there's 13
**Andrew Ziegler** (2:16)
Ah! Has that ever happened before?
**Tanya Janca** (2:19)
No. So we had to decide what to put in the what's next. And we had a tie for number 10
And then there was another one that was just extremely noteworthy. And then we had to talk about vibe coding. So I was like, let's just, you know, in the what next, there's just three extra items that I was, we're not going to do another top 10 for two to three years. And I'm like, we can't just not talk about vibe coding. We can't skip that. And so the team talked about it, and they're like, well, what's the worst that can happen is the community yells at us. And no one did, so yay.
**Andrew Ziegler** (2:52)
And that's a signal in and of itself, that there's so many top of mind, critical security topics that we all need to be talking about, that we had to throw away the template and approach we used to talk about them, like the bracket. We had to expand the bracket, because now there's more threats than ever.
How did y'all approach that challenge, and you say vibe coding makes the list. So I'm curious, in this world where you're scoping out problems for web apps, but really all software, what were some of the biggest things that are standing out to you now that maybe didn't stand out years in the past when you've made this list?
**Tanya Janca** (3:31)
Absolutely. So the way that they, so I mean, the first top 10 list, let's just be really blunt, a bunch of experts just got together, had a couple balls of wine, just made the top 10 things they always found in pen tests. And then going forward, they're like, okay, so we probably need some data.
**Andrew Ziegler** (3:51)
As it goes, so then you start getting the data practice to figure out what are actually these application security problems that are plaguing developers.
**Tanya Janca** (3:58)
Yeah, but the issue is gathering data. So guess who gives us data? A couple of great pen testing companies who are so awesome to anonymize and share their data with us, which is extremely effortful. Then we have a whole ton of static analysis and dynamic analysis vendors who then just show us what they know how to find, right? But what we really care about and what data I wish we could have that no one will ever, ever give us is specifically incident response data and breach data. So I know that there's the Verizon Breach Report and there's the CrowdTrack Report and the Microsoft, whatever, right? But those are really big public breaches. I mean, the average AppSec nerd responding to attacks that are happening that make a giant mess of everything. It's like, what was that? What caused that? What hurt your company? Because that's what we actually care about the most is because this top 10 list is an awareness document. And I actually don't care about vendors are good at finding this. I care about this is what will help you move the needle on protecting your organization and your customers. And so when we got to talking about it, Andrew, you were talking about what really stood out. So what we used to have on the list was using outdated and vulnerable components. So you use a library and there's like 12 CVEs in it. And you're like, is that really a good life choice that you're making here?
38 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000773867894