POPULARITY
You're competent everywhere else. Work, money, your family, the things that take discipline and follow through. Then it comes to food and your body and none of that seems to apply. This episode is about why that happens, and it isn't a willpower problem.Farshad Sarrafi is back for a third conversation. He spent years around NBA and NFL athletes and high level executives, and the thing the best ones had in common wasn't more drive. It was that they knew how to stop. We get into what your stress/binge eating is actually pointing at, where "I'm not good enough" comes from, and how to let an emotion move through you instead of eating over it.What we cover:- Why you can run a business but can't seem to run your own eating- The habit Farshad saw in the highest performers that nobody talks about- What your stress eating and 11pm snacking are actually telling you- Why the story you think is driving you usually isn't the real one- What to do when you slow down and nothing seems to change- How to feel an emotion all the way through instead of eating over itConnect with Farshad:‣ X: https://x.com/FarSarrafi‣ Instagram: https://www.instagram.com/farsarrafi/‣ Out Of Office: https://www.instagram.com/outofofficetheexperience/00:00 - "The biggest gap is the ability to do nothing"(01:05) - Who Farshad is, and why he's back on again(04:00) - Why you win everywhere except with food(08:05) - "All I do is work." So where do you even start?(11:05) - Change your story, change your life. Does that actually hold up?(16:30) - Your symptom list, and the one question to ask about it(21:00) - "I slowed down and nothing happened"(26:00) - Comparing with others (and keeping it contextual)(30:15) - What surrender actually looks like when you want to change your body(41:05) - Feel your feelings, or change your state?(48:00) - What are you actually trying to get from the food?(55:30) - Emotional capacity vs. nervous system regulation(59:10) - Where to find Farshad‣ Apply to Join Dieting From The Inside Out Here: https://inquire.hamiltontrained.com?utm_source=podcast‣ Grab the Food Noise Solution Guide Here: https://inquire.hamiltontrained.com/food-noise?utm_source=podcast
It's one thing to write secure code, it's another to release it into the wild. That code needs to be designed, built, tested, released, and maintained. Farshad Abasi and Cameron Walters explain how the OWASP Secure Pipeline Verification Standard picks up from where ASVS left off, how it complements other supply chain security efforts like SLSA, and why they updated it with explicit coverage for AI. They show what goes into making a project relevant and -- most importantly -- successful at defending how supply chains are attacked. They're also looking for more feedback and participation! If you build software packages, consume software packages, or have an interest in helping organizations stay secure, check it out! Resources https://owasp.org/www-project-spvs/ https://github.com/OWASP/www-project-spvs/blob/main/1.5/ReleaseNotesOWASPSPVS1.5-AI-Pipeline-Security.md https://youtu.be/-WoqGDdivGw?si=kK5-csbnTw8Y4g2J -- The Story Behind OWASP SPVS https://slsa.dev Zero Trust That Actually Ships: Moving From Strategy Decks to Real Security Most enterprise organizations have been working at Zero Trust for years and fail to deliver truly secure environments. Rohan Ravindranath shares insights that Zappsec has gained from guiding the global teams that are succeeding at protecting their orgs. Discover the common pitfalls so you can deploy a solution that works. This segment is sponsored by Zappsec. Visit https://securityweekly.com/zappsecrsac to learn more about them! Cloning Attacker Tradecraft: Why AI Pentesting is Becoming Essential Enterprises ship code continuously, but most security validation still happens in snapshots. Novee CEO and co-founder Ido Geffen explains what “AI penetration testing” means, why it's different from automated scanning, and why it's becoming essential as attackers adopt AI to move faster. He breaks down what separates best-in-class AI pentesting: operator-like reasoning across real environments, validated exploitability, and the ability to uncover business logic flaws and multi-step attack chains. Ido covers the technology behind Novee's AI penetration tester: a proprietary LLM model, built independently of “frontier” LLMs (like Claude, ChatGPT, Cursor, etc.), and consistently outperforming them at browser exploitation tests. Finally, he shares what buyers should demand in a live evaluation and how continuous retesting closes the loop after fixes ship. This segment is sponsored by Novee Security. See what your attackers already know at https://securityweekly.com/noveersac. Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-378
It's one thing to write secure code, it's another to release it into the wild. That code needs to be designed, built, tested, released, and maintained. Farshad Abasi and Cameron Walters explain how the OWASP Secure Pipeline Verification Standard picks up from where ASVS left off, how it complements other supply chain security efforts like SLSA, and why they updated it with explicit coverage for AI. They show what goes into making a project relevant and -- most importantly -- successful at defending how supply chains are attacked. They're also looking for more feedback and participation! If you build software packages, consume software packages, or have an interest in helping organizations stay secure, check it out! Resources https://owasp.org/www-project-spvs/ https://github.com/OWASP/www-project-spvs/blob/main/1.5/ReleaseNotesOWASPSPVS1.5-AI-Pipeline-Security.md https://youtu.be/-WoqGDdivGw?si=kK5-csbnTw8Y4g2J -- The Story Behind OWASP SPVS https://slsa.dev Zero Trust That Actually Ships: Moving From Strategy Decks to Real Security Most enterprise organizations have been working at Zero Trust for years and fail to deliver truly secure environments. Rohan Ravindranath shares insights that Zappsec has gained from guiding the global teams that are succeeding at protecting their orgs. Discover the common pitfalls so you can deploy a solution that works. This segment is sponsored by Zappsec. Visit https://securityweekly.com/zappsecrsac to learn more about them! Cloning Attacker Tradecraft: Why AI Pentesting is Becoming Essential Enterprises ship code continuously, but most security validation still happens in snapshots. Novee CEO and co-founder Ido Geffen explains what "AI penetration testing" means, why it's different from automated scanning, and why it's becoming essential as attackers adopt AI to move faster. He breaks down what separates best-in-class AI pentesting: operator-like reasoning across real environments, validated exploitability, and the ability to uncover business logic flaws and multi-step attack chains. Ido covers the technology behind Novee's AI penetration tester: a proprietary LLM model, built independently of "frontier" LLMs (like Claude, ChatGPT, Cursor, etc.), and consistently outperforming them at browser exploitation tests. Finally, he shares what buyers should demand in a live evaluation and how continuous retesting closes the loop after fixes ship. This segment is sponsored by Novee Security. See what your attackers already know at https://securityweekly.com/noveersac. Show Notes: https://securityweekly.com/asw-378
It's one thing to write secure code, it's another to release it into the wild. That code needs to be designed, built, tested, released, and maintained. Farshad Abasi and Cameron Walters explain how the OWASP Secure Pipeline Verification Standard picks up from where ASVS left off, how it complements other supply chain security efforts like SLSA, and why they updated it with explicit coverage for AI. They show what goes into making a project relevant and -- most importantly -- successful at defending how supply chains are attacked. They're also looking for more feedback and participation! If you build software packages, consume software packages, or have an interest in helping organizations stay secure, check it out! Resources https://owasp.org/www-project-spvs/ https://github.com/OWASP/www-project-spvs/blob/main/1.5/ReleaseNotesOWASPSPVS1.5-AI-Pipeline-Security.md https://youtu.be/-WoqGDdivGw?si=kK5-csbnTw8Y4g2J -- The Story Behind OWASP SPVS https://slsa.dev Zero Trust That Actually Ships: Moving From Strategy Decks to Real Security Most enterprise organizations have been working at Zero Trust for years and fail to deliver truly secure environments. Rohan Ravindranath shares insights that Zappsec has gained from guiding the global teams that are succeeding at protecting their orgs. Discover the common pitfalls so you can deploy a solution that works. This segment is sponsored by Zappsec. Visit https://securityweekly.com/zappsecrsac to learn more about them! Cloning Attacker Tradecraft: Why AI Pentesting is Becoming Essential Enterprises ship code continuously, but most security validation still happens in snapshots. Novee CEO and co-founder Ido Geffen explains what "AI penetration testing" means, why it's different from automated scanning, and why it's becoming essential as attackers adopt AI to move faster. He breaks down what separates best-in-class AI pentesting: operator-like reasoning across real environments, validated exploitability, and the ability to uncover business logic flaws and multi-step attack chains. Ido covers the technology behind Novee's AI penetration tester: a proprietary LLM model, built independently of "frontier" LLMs (like Claude, ChatGPT, Cursor, etc.), and consistently outperforming them at browser exploitation tests. Finally, he shares what buyers should demand in a live evaluation and how continuous retesting closes the loop after fixes ship. This segment is sponsored by Novee Security. See what your attackers already know at https://securityweekly.com/noveersac. Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-378
It's one thing to write secure code, it's another to release it into the wild. That code needs to be designed, built, tested, released, and maintained. Farshad Abasi and Cameron Walters explain how the OWASP Secure Pipeline Verification Standard picks up from where ASVS left off, how it complements other supply chain security efforts like SLSA, and why they updated it with explicit coverage for AI. They show what goes into making a project relevant and -- most importantly -- successful at defending how supply chains are attacked. They're also looking for more feedback and participation! If you build software packages, consume software packages, or have an interest in helping organizations stay secure, check it out! Resources https://owasp.org/www-project-spvs/ https://github.com/OWASP/www-project-spvs/blob/main/1.5/ReleaseNotesOWASPSPVS1.5-AI-Pipeline-Security.md https://youtu.be/-WoqGDdivGw?si=kK5-csbnTw8Y4g2J -- The Story Behind OWASP SPVS https://slsa.dev Zero Trust That Actually Ships: Moving From Strategy Decks to Real Security Most enterprise organizations have been working at Zero Trust for years and fail to deliver truly secure environments. Rohan Ravindranath shares insights that Zappsec has gained from guiding the global teams that are succeeding at protecting their orgs. Discover the common pitfalls so you can deploy a solution that works. This segment is sponsored by Zappsec. Visit https://securityweekly.com/zappsecrsac to learn more about them! Cloning Attacker Tradecraft: Why AI Pentesting is Becoming Essential Enterprises ship code continuously, but most security validation still happens in snapshots. Novee CEO and co-founder Ido Geffen explains what "AI penetration testing" means, why it's different from automated scanning, and why it's becoming essential as attackers adopt AI to move faster. He breaks down what separates best-in-class AI pentesting: operator-like reasoning across real environments, validated exploitability, and the ability to uncover business logic flaws and multi-step attack chains. Ido covers the technology behind Novee's AI penetration tester: a proprietary LLM model, built independently of "frontier" LLMs (like Claude, ChatGPT, Cursor, etc.), and consistently outperforming them at browser exploitation tests. Finally, he shares what buyers should demand in a live evaluation and how continuous retesting closes the loop after fixes ship. This segment is sponsored by Novee Security. See what your attackers already know at https://securityweekly.com/noveersac. Show Notes: https://securityweekly.com/asw-378
To access the full interview visit https://www.b2binterviews.com/ .Access all of our exclusive interviews and content, as well as our terms/policies/notices at https://b2binterviews.com/ and follow us on social for alerts and updates as new content goes live.Twitter: https://twitter.com/b2binterviewsLinkedIn: https://www.linkedin.com/company/b2binterviews All contents COPYRIGHT B2B Interviews, LLC (hereinafter referred to as “B2B”). All rights reserved. Reproduction of all or part of this document in any form is prohibited without express written consent of B2B. Protected by US copyright laws 17 USC 101 et seq., 18 USC 2319; violations punishable by 5 years imprisonment and/or $250,000 in fines. Copyright © 2026 B2B Interviews, LLC/ B2B. All rights reserved.
Farshad Farzankia er kunstmaler. Men sådan har det ikke altid været. Oprindeligt er han uddannet fra Den Grafiske Højskole arbejdede i en årrække som art director på Euroman. Men da han i 2016 sagde sit job op, fik et atelier og begyndte at male, gik det rigtig stærkt. At kalde det en kometkarriere vil ikke være nogen overdrivelse, og allerede fem år senere havde han en soloudstilling på Arken.I det nye afsnit af 'Arbejdstitel' er de to værter Oliver Enné og Kristoffer Dahy Ernst på besøg i Farshad Farzankias næsten 500 kvadratmeter store atelier i Søborg. Og omgivet af værker taler de om en kunstbranche, der kan være svær at få hånd om, om at forsøge at holde styr på, hvor ens værker ender, og det abstrakte i at et maleri den ene dag kan koste noget og den næste være meget dyrere.
This week on Defender Fridays, Farshad Abasi, Founder and CEO of Forward Security and Eureka DevSecOps, discusses how AI can help us set a new standard in app and cloud security. Farshad brings over 27 years of industry experience to the forefront of cybersecurity innovation. His professional journey includes key technical roles at Intel and Motorola, evolving into senior security positions as the Principal Security Architect for HSBC Global, and Head of IT Security for the Canadian division. Farshad's commitment to the field extends to his role as an instructor at BCIT, where he imparts his wealth of knowledge to the next generation of cybersecurity experts. His diverse experience, which spans startups to large enterprises, informs his approach to delivering adaptive and reliable solutions.Engaged actively in the cybersecurity community through roles in BSides Vancouver/MARS, OWASP Vancouver/AppSec PNW, and as a CISSP designate, Farshad's vision and leadership continue to drive the industry forward. Under his guidance, Forward Security is setting new standards in application and cloud security. Learn more at https://www.eurekadevsecops.com/ and https://forwardsecurity.com/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Farshad Ghodoosi, assistant professor of business law at California State University, Northridge, and Tal Kastner, associate professor of law at Rutgers University, join the Business Scholarship Podcast to discuss their article Against the Drafter: An Empirical and Theoretical Analysis of the Doctrine of Contra Proferentem. This episode is hosted by Andrew Jennings, associate professor of law at Emory University, and was edited by Alec Johnson, a law student at Emory University.
Hvordan ser egentlig hverdagen ut i 2025 – midt mellom karriere, familie, skjermtid og trening? I denne episoden tar vi turen til ATA Treningsutstyr sitt hovedkontor i Asker, hvor vi møter tre menn i sin beste alder – og med en felles visjon: å skape en sterkere generasjon
The Africa Report | Darfur - Siege of Al-Farshad Ushers in Humanitarian Catastrophe and Risk of Ethnic Atrocities by Radio Islam
Kat Gourd, Acting Deputy Editor of The Lancet Oncology, is joined by Dr Linda Bi, Dr Ruchit Patel, Dr Chloe Gui, Dr Farshad Nassiri, and Dr Matija Snuderl, from institutions in the USA and Canada, to discuss two exciting papers on TERT expression and TERT promoter mutations in meningiomas.In these two cohort studies, the authors analyse the expression of TERT and TERT promoter mutations in meningiomas, assess their association with patient outcomes, and discuss the potential implications for patient management and the classification of these tumours.You can read the two Articles here:https://www.thelancet.com/journals/lanonc/article/PIIS1470-2045(25)00267-0/fulltext?dgcid=buzzsprout_icw_podcast_September_25_lanonchttps://www.thelancet.com/journals/lanonc/article/PIIS1470-2045(25)00422-X/fulltext?dgcid=buzzsprout_icw_podcast_September_25_lanoncTell us what you thought about this episodeContinue this conversation on social!Follow us today at...https://thelancet.bsky.social/https://instagram.com/thelancetgrouphttps://facebook.com/thelancetmedicaljournalhttps://linkedIn.com/company/the-lancethttps://youtube.com/thelancettv
In deze aflevering spreken we met Farshad Poye, verantwoordelijk voor de Nederlandse markt bij EnterpriseDB, en Driss Chhayra, die binnen EDB de EMEA-markt aanstuurt. Ze nemen ons mee in de groei van PostgreSQL binnen Kubernetes, de rol van open source in hybride infrastructuur én hoe AI dichter bij je data komt te staan dan ooit.We blikken terug op de ontwikkelingen sinds hun eerdere (meest beluisterde!) aflevering, EDB's operator is nu als sandbox opgenomen in de CNCF, en biedt met CloudNativePG de mogelijkheid om PostgreSQL volledig open source in Kubernetes te draaien. Wat begon als testomgeving, groeit nu uit tot enterprise-ready – met rolling upgrades, snapshots, en failover mechanismen.Daarnaast delen Farshad en Driss hoe EDB de brug slaat naar AI. Met geïntegreerde modellen in Postgres wordt AI toegankelijker: AI-toepassingen draaien direct op het platform waar je data al staat, zonder dataverplaatsing. Denk aan MVP's bouwen in vijf stappen en verkoopdata analyseren zonder dat je zelf AI-specialist hoeft te zijn.Tot slot bespreken we de rol van open source in digitale vrijheid, en hoe organisaties met behoud van soevereiniteit hun infrastructuur toekomstbestendig maken — of je nu in de cloud werkt, on-premise of in een hybride setup.Stuur ons een bericht.ACC ICT Specialist in IT-CONTINUÏTEIT Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overalSupport the showLike and subscribe! It helps out a lot.You can also find us on:De Nederlandse Kubernetes Podcast - YouTubeNederlandse Kubernetes Podcast (@k8spodcast.nl) | TikTokDe Nederlandse Kubernetes PodcastWhere can you meet us:EventsThis Podcast is powered by:ACC ICT - IT-Continuïteit voor Bedrijfskritische Applicaties | ACC ICT
In this episode of The Higher Standard, we're joined by viral sensation turned courtroom assassin, Farshad Dehbozorgi, Esq. — or as we like to call him, “The Club-to-Courtroom Closer.” We dig into his unlikely journey from viral TikToks and bottle service to bar prep and building a boutique law firm. If you've ever wondered how roasting your wife online could land you a law license, this one's for you.➡️ Chris, Saied, Rajeil and Farshad get real about the grind of content creation, the misconceptions around being a creator, and how law, social media, and outrageous honesty can collide in one man's career. From being mistaken for a nightclub promoter to now negotiating with insurance companies and personal injury clients, Farshad proves that you really can go from “likes” to litigation — if you're bold (and delusional) enough.
What makes a threat modeling process effective? Do you need a long list of threat actors? Do you need a long list of terms? What about a short list like STRIDE? Has an effective process ever come out of a list? Farshad Abasi joins our discussion as we explain why the answer to most of those questions is No and describe the kinds of approaches that are more conducive to useful threat models. Resources: https://www.eurekadevsecops.com/agile-devops-and-the-threat-modeling-disconnect-bridging-the-gap-with-developer-insights/ https://www.threatmodelingmanifesto.org https://kellyshortridge.com/blog/posts/security-decision-trees-with-graphviz/ In the news, learning from outage postmortems, an EchoLeak image speaks a 1,000 words from Microsoft 365 Copilot, TokenBreak attack targets tokenizing techniques, Google's layered strategy against prompt injection looks like a lot like defending against XSS, learning about code security from CodeAuditor CTF, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-335
What makes a threat modeling process effective? Do you need a long list of threat actors? Do you need a long list of terms? What about a short list like STRIDE? Has an effective process ever come out of a list? Farshad Abasi joins our discussion as we explain why the answer to most of those questions is No and describe the kinds of approaches that are more conducive to useful threat models. Resources: https://www.eurekadevsecops.com/agile-devops-and-the-threat-modeling-disconnect-bridging-the-gap-with-developer-insights/ https://www.threatmodelingmanifesto.org https://kellyshortridge.com/blog/posts/security-decision-trees-with-graphviz/ In the news, learning from outage postmortems, an EchoLeak image speaks a 1,000 words from Microsoft 365 Copilot, TokenBreak attack targets tokenizing techniques, Google's layered strategy against prompt injection looks like a lot like defending against XSS, learning about code security from CodeAuditor CTF, and more! Show Notes: https://securityweekly.com/asw-335
What makes a threat modeling process effective? Do you need a long list of threat actors? Do you need a long list of terms? What about a short list like STRIDE? Has an effective process ever come out of a list? Farshad Abasi joins our discussion as we explain why the answer to most of those questions is No and describe the kinds of approaches that are more conducive to useful threat models. Resources: https://www.eurekadevsecops.com/agile-devops-and-the-threat-modeling-disconnect-bridging-the-gap-with-developer-insights/ https://www.threatmodelingmanifesto.org https://kellyshortridge.com/blog/posts/security-decision-trees-with-graphviz/ In the news, learning from outage postmortems, an EchoLeak image speaks a 1,000 words from Microsoft 365 Copilot, TokenBreak attack targets tokenizing techniques, Google's layered strategy against prompt injection looks like a lot like defending against XSS, learning about code security from CodeAuditor CTF, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-335
What makes a threat modeling process effective? Do you need a long list of threat actors? Do you need a long list of terms? What about a short list like STRIDE? Has an effective process ever come out of a list? Farshad Abasi joins our discussion as we explain why the answer to most of those questions is No and describe the kinds of approaches that are more conducive to useful threat models. Resources: https://www.eurekadevsecops.com/agile-devops-and-the-threat-modeling-disconnect-bridging-the-gap-with-developer-insights/ https://www.threatmodelingmanifesto.org https://kellyshortridge.com/blog/posts/security-decision-trees-with-graphviz/ In the news, learning from outage postmortems, an EchoLeak image speaks a 1,000 words from Microsoft 365 Copilot, TokenBreak attack targets tokenizing techniques, Google's layered strategy against prompt injection looks like a lot like defending against XSS, learning about code security from CodeAuditor CTF, and more! Show Notes: https://securityweekly.com/asw-335
Listen & Download: https://fanlink.tv/STM019
Listen & Download: https://fanlink.tv/STM019
In this episode, Jared sits down with Farshad Sarrafi to uncover why changing your identity and shifting deep-rooted beliefs is key to lasting transformation.Farshad shares how your core beliefs about who you are directly influence all your behaviors, decisions, and outcomes—whether you're an athlete, executive, or someone simply trying to improve their health. You'll learn practical strategies to clearly identify your values, navigate resistance, and distinguish between genuine self-protection and self-sabotage. If you're tired of repeating old patterns and feeling stuck, this episode reveals how to rewrite your identity and create the life you've always envisioned.In This Episode We Cover:- Why identity dictates every aspect of your life- How beliefs formed in childhood continue to influence you today- The difference between self-sabotage and healthy protection- Practical exercises to uncover your true values and align with your goals- Navigating discomfort and resistance during personal transformationCONNECT WITH FARSHAD:INSTAGRAM: https://www.instagram.com/farshadsarrafi/OUT OF OFFICE WEBSITE: https://outofofficetheexperience.com/OUT OF OFFICE YOUTUBE: https://www.youtube.com/channel/UCzAWohhoc8WPSdl8DkSUJDQMY RESOURCES & SPECIAL OFFERS:‣ Join the Dieting From The Inside Out Collective & get immediate access: bit.ly/DFIOcollective‣ Apply for 1:1 Coaching:Application for Coaching‣ Join my free Facebook group & get all my trainings:Fat Loss Simplified | Facebook‣ Get my [Free] Fat Loss Check-list Course:Never Struggle Losing Weight Ever Again Masterclass‣ Grab my 20 Pound Blueprint to lose your next 20lbs without feeling restricted:The 20 Pound BlueprintFIND ME ON:‣ Instagram:Instagram (@realjaredhamilton)‣ YouTube:Jared Hamilton‣ TikTok:Jared Hamilton on TikTok‣ Email:jared@hamiltontrained.com----© 2025 Jared Hamilton
In this engaging podcast conversation, Ryan Kassim and Farshad Sarrafi, delve into personal journeys of growth, fitness, and the exploration of human behavior. They discuss the importance of identity, values, and the impact of personal experiences on one's development.The conversation also touches on the significance of emotional responsibility and the various avenues for inner work, emphasizing the need for self-awareness and understanding in navigating life's challenges. In this conversation, the speakers delve into the importance of emotional awareness, radical accountability, and the role of curiosity in fostering meaningful connections. They explore cultural identity and personal growth, discussing how these experiences shape their perspectives. The dialogue also touches on navigating family dynamics and emotional maturity, emphasizing acceptance and understanding. Finally, they reflect on pivotal moments that catalyze change and the significance of emotional resilience in overcoming life's challenges.Podcast Links:Please leave a 5 star review wherever you listen to this podcast :)If you are interested in 1:1 online coaching, you can apply here: https://bodybyryan.com/coaching/Use my FREE Calorie Calculator: bodybyryan.com/calculatorFat Loss Made Easy Facebook Group:https://www.facebook.com/groups/1701659280174513/Follow me on Instagram: https://www.instagram.com/bodybyryanfitness/Follow me on TikTok: https://www.tiktok.com/@ryankassim?lang=engFollow me on X: https://x.com/Ryan_KassimSubscribe to my YouTube Channel:https://www.youtube.com/ryankassimlifeisgood20% off Legion Supplements - Use code: BodyByRyanhttps://legionathletics.rfrl.co/542mpChapters00:00 Introduction and Podcast Dynamics03:05 Journey into Fitness and Personal Growth06:01 Understanding Human Behavior and Identity09:05 The Impact of Personal Experiences on Growth11:57 Values, Morals, and Personal Evolution14:56 Exploring Inner Work and Emotional Responsibility25:02 Emotional Awareness and Radical Accountability30:00 Curiosity as a Tool for Connection36:04 Cultural Identity and Personal Growth40:01 Navigating Family Dynamics and Emotional Maturity44:54 Catalysts for Change and Emotional Resilience
In this episode of the Other Side Lifestyle Podcast, hosts Jim and Aram welcome Farshad Sarrafi-Nour, who shares his unique journey from studying accounting to becoming a fitness coach. The conversation delves into the disconnect between academic research and practical coaching, emphasizing the importance of understanding the human element in training. Farshad discusses the significance of context in coaching, the psychological aspects of fitness, and common misconceptions in the industry. He advocates for a performance-focused approach rather than an aesthetics-driven mindset, highlighting the need for proper movement quality and body awareness. The episode concludes with practical tips for improving movement and the importance of maintaining a balanced perspective in fitness. In this conversation, the speakers delve into innovative training methods, emphasizing the psychological aspects of fitness, the importance of flexibility in movement choices, and the significance of maintaining a long-term fitness mindset. They discuss the necessity of self-awareness and accountability in achieving fitness goals, as well as the role of simplicity in nutrition and lifestyle choices. The dialogue highlights the journey of self-discovery that comes with personal growth in fitness and health. Follow Farshad on IG: https://www.instagram.com/farshadsarrafi/ f you are a coach, sign up now for The Real Coaches Summit 2025 in Las Vegas this April, organized by yours truly - Aram Grigorian. The speaker lineup is insane, and don't forget macro friendly breakfast, lunch, and dinner is provided, as well as a top shelf open bar happy hour each evening to network and meet the speakers. No VIP - we are all equals at this event! https://www.realcoachessummit2023.com/ You can find us on Instagram: Aram: https://www.instagram.com/4weeks2thebeach/ Jim: https://www.instagram.com/jimmynutrition/ Grab some Serenity Gummies: https://www.CuredNutrition.com/ Code: OSL for 20% OFF Get some t-shirts/tanks/hoodies at: https://www.othersidelifestyle.com/shop If you'd like to reach out to Aram, you can find him at: https://www.4weeks2thebeach.com/work-with-me If you'd like to reach out to Jim, you can find him at: https://www.othersidelifestyle.com/schedule Go get some supplements: https://legionathletics.com/ use code: ARAM
This episode is sponsored by https://WE-PN.com Become your own VPN provider.To get 50% off enter promo code: kingraam50-------------------------This episode is sponsored by BetterHelp. Give online therapy a try at https://betterhelp.com/MASTYORASTY and get on your way to being your best self.-------------------------Farshad is senior director of AI/ML at Betterhelp. In this episode he talks to Raam about his journey to the United States, the different companies he has worked at, and the development of artificial intelligence and machine learning.-------------------------To learn more about psychedelic therapy go to my brother Mehran's page at: https://www.mindbodyintegration.ca/ or to https://www.legacyjourneys.ca/ for his next retreat.***Masty o Rasty is not responsible for, or condone, the views and opinions expressed by our guests ******مستی و راستی هیچگونه مسولیتی در برابر نظرها و عقاید مهمانهای برنامه ندارد.***--------Support the showhttps://paypal.me/raamemamiVenmo + Revolut: @KingRaam Hosted on Acast. See acast.com/privacy for more information.
More remote car control via web interfaces, an RCE in CUPS, Microsoft reduces attack surface, migrating to memory safety, dealing with dependency confusion, getting rid of password strength calculators, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-301
More remote car control via web interfaces, an RCE in CUPS, Microsoft reduces attack surface, migrating to memory safety, dealing with dependency confusion, getting rid of password strength calculators, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-301
Generative AI has produced impressive chatbots and content generation, but however fun or impressive those might be, they don't always translate to value for appsec. Allie brings some realistic expectations to how genAI is used by attackers and can be useful to defenders. Segment resources: https://www.forrester.com/blogs/generative-ai-will-not-fulfill-your-autonomous-soc-hopes-or-even-your-demo-dreams/ https://www.forrester.com/blogs/top-5-things-you-need-to-know-about-how-generative-ai-is-used-in-security-tools/ https://www.forrester.com/blogs/the-blob-is-poisoning-the-security-industry/ SAPwned demonstrates tenets of tenant isolation, a weak login flow puts Squarespace domains at risk, how AIs might (or might not) be useful for fixing code, getting buy-in for infosec investments, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-292
Generative AI has produced impressive chatbots and content generation, but however fun or impressive those might be, they don't always translate to value for appsec. Allie brings some realistic expectations to how genAI is used by attackers and can be useful to defenders. Segment resources: https://www.forrester.com/blogs/generative-ai-will-not-fulfill-your-autonomous-soc-hopes-or-even-your-demo-dreams/ https://www.forrester.com/blogs/top-5-things-you-need-to-know-about-how-generative-ai-is-used-in-security-tools/ https://www.forrester.com/blogs/the-blob-is-poisoning-the-security-industry/ Show Notes: https://securityweekly.com/asw-292
Generative AI has produced impressive chatbots and content generation, but however fun or impressive those might be, they don't always translate to value for appsec. Allie brings some realistic expectations to how genAI is used by attackers and can be useful to defenders. Segment resources: https://www.forrester.com/blogs/generative-ai-will-not-fulfill-your-autonomous-soc-hopes-or-even-your-demo-dreams/ https://www.forrester.com/blogs/top-5-things-you-need-to-know-about-how-generative-ai-is-used-in-security-tools/ https://www.forrester.com/blogs/the-blob-is-poisoning-the-security-industry/ SAPwned demonstrates tenets of tenant isolation, a weak login flow puts Squarespace domains at risk, how AIs might (or might not) be useful for fixing code, getting buy-in for infosec investments, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-292
Generative AI has produced impressive chatbots and content generation, but however fun or impressive those might be, they don't always translate to value for appsec. Allie brings some realistic expectations to how genAI is used by attackers and can be useful to defenders. Segment resources: https://www.forrester.com/blogs/generative-ai-will-not-fulfill-your-autonomous-soc-hopes-or-even-your-demo-dreams/ https://www.forrester.com/blogs/top-5-things-you-need-to-know-about-how-generative-ai-is-used-in-security-tools/ https://www.forrester.com/blogs/the-blob-is-poisoning-the-security-industry/ Show Notes: https://securityweekly.com/asw-292
Today, I speak with Farshad Sarrafi, who is constantly evolving through expression. He is also a lifestyle, athlete & contest prep coach. Our conversation centers around understanding who you really are outside of your profession and how you serve in life. We talk about: -identifying your values -lived values versus stated values -learning from your mistakes -beliefs versus reality -people are not rational -auditing your progress -unlearning -choosing a mentor who has what you want -be a star in your roll Time Stamps: 00:00 Introduction 3:42 seeing yourself outside of how you serve 7:44 bridging the gap to the values you want to live 13:56 taking imperfect action 16:09 we are not rational 19:43 staying focused when it gets hard 24:50 where you find meaning 31:10 building a business YOU want 40:30 perceptions on the internet 48:45 chasing money to fill a void 52:01 finding the right mentor 58:40 playing to your strengths 61:57 you cannot control how others feel about you CONNECT WITH KAIT: IG: https://www.instagram.com/kaitannmichelle/ Team LevelUp: https://www.instagram.com/team.levlup/ Email: Kait@levluptraining.com Free FB Community: : https://www.facebook.com/groups/levluptraining TikTok: https://www.tiktok.com/@kaitannmichelle Email List: First Dibs on Freebies and Tips! Twitter: https://twitter.com/kaitannmichelle SnapChat: https://snapchat.com/add/kait.callahan22 Legion Code: CoachK CONNECT WITH FARSHAD: IG: https://www.instagram.com/farshadsarrafi/ --- Support this podcast: https://podcasters.spotify.com/pod/show/kaitannmichelle/support
Links!!!!All about AILAAll about FarshadAll about KelliFarshad's AILA Annual Conference 2024 SpeechKelli's AILA Annual Conference 2024 SpeechSponsors and friends of the podcast!Kurzban Kurzban Tetzeli and Pratt P.A.Immigration, serious injury, and business lawyers serving clients in Florida, California, and all over the world for over 40 years.Docketwise"Modern immigration software & case management"Stafi"Remote staffing solutions for businesses of all sizes"Promo Code: stafi2024Get Started! Promo Code: FREEWant to become a patron?Click here to check out our Patreon Page!CONTACT INFORMATIONEmail: kgregg@kktplaw.comFacebook: @immigrationreviewInstagram: @immigrationreviewTwitter: @immreviewAbout your hostCase notesRecent criminal-immigration article (p.18)Featured in San Diego VoyagerDISCLAIMER & CREDITSSee Eps. 1-200Support the Show.
In this episode of the Dollars and Dumbbells podcast, host Justin Green interviews Farshad Sarrafi, co-founder of Beyond Built.They discuss: the impact of pricing strategies on client acquisition and retention, and the importance of building a skilled team. the necessity of understanding business fundamentals, such as market positioning and the value of a premium service. Trends in the coaching industry, including the shift towards group models and community-based services, and the critical role of building an engaged audience for success. Connect with Justin Green Schedule a 1:1 Free Intro Call Farshad Sarrafi on Instagram Time Stamps 01:36 Reflecting on Growth and Change: Coach Far's Journey 04:06 Evolving Beyond Built: Strategies and Lessons Learned 19:42 Building a Team and Cultivating Success in Online Coaching 28:52 Transitioning from Solo to Team: The Hiring Journey 29:32 Early Hiring Decisions and Mentorship Insights 30:03 Building a Profitable Coaching Business: Strategies and Challenges 31:57 Client Retention vs. Acquisition: Balancing the Business Dance 34:34 Pricing Strategies for Sustainable Growth 37:04 The Long Game: Building Skills for Business Success 38:25 Exploring Low Ticket and Group Coaching Models 40:12 Building an Engaged Audience: The Key to Success
We look into the supply chain saga of the XZ Utils backdoor. It's a wild story of a carefully planned long con to add malicious code to a commonly used package that many SSH connections rely on. It hits themes from social engineering and abuse of trust to obscuring the changes and suppressing warnings. It also has a few lessons about software development, the social and economic dynamics of open source, and strategies for patching software. It's an exciting topic partially because so much other appsec is boring. And that boring stuff is important to get right first. We also talk about what parts of this that orgs should be worried about and what types of threats they should be prioritizing instead. Segment Resources: https://tukaani.org/xz-backdoor/ https://news.risky.biz/risky-biz-news-supply-chain-attack-in-linuxland/ https://www.zdnet.com/article/this-backdoor-almost-infected-linux-everywhere-the-xz-utils-close-call/#ftag=RSSbaffb68 https://therecord.media/malicious-backdoor-code-linux-red-hat-cisa https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 https://duo.com/decipher/carefully-crafted-campaign-led-to-xz-utils-backdoor https://boehs.org/node/everything-i-know-about-the-xz-backdoor OWASP leaks resumes, defining different types of prompt injection, a secure design example in device-bound sessions, turning an ASVS requirement into practice, Ivanti has its 2000s-era Microsoft moment, HTTP/2 CONTINUATION flood, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-280
We look into the supply chain saga of the XZ Utils backdoor. It's a wild story of a carefully planned long con to add malicious code to a commonly used package that many SSH connections rely on. It hits themes from social engineering and abuse of trust to obscuring the changes and suppressing warnings. It also has a few lessons about software development, the social and economic dynamics of open source, and strategies for patching software. It's an exciting topic partially because so much other appsec is boring. And that boring stuff is important to get right first. We also talk about what parts of this that orgs should be worried about and what types of threats they should be prioritizing instead. Segment Resources: https://tukaani.org/xz-backdoor/ https://news.risky.biz/risky-biz-news-supply-chain-attack-in-linuxland/ https://www.zdnet.com/article/this-backdoor-almost-infected-linux-everywhere-the-xz-utils-close-call/#ftag=RSSbaffb68 https://therecord.media/malicious-backdoor-code-linux-red-hat-cisa https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 https://duo.com/decipher/carefully-crafted-campaign-led-to-xz-utils-backdoor https://boehs.org/node/everything-i-know-about-the-xz-backdoor Show Notes: https://securityweekly.com/asw-280
We look into the supply chain saga of the XZ Utils backdoor. It's a wild story of a carefully planned long con to add malicious code to a commonly used package that many SSH connections rely on. It hits themes from social engineering and abuse of trust to obscuring the changes and suppressing warnings. It also has a few lessons about software development, the social and economic dynamics of open source, and strategies for patching software. It's an exciting topic partially because so much other appsec is boring. And that boring stuff is important to get right first. We also talk about what parts of this that orgs should be worried about and what types of threats they should be prioritizing instead. Segment Resources: https://tukaani.org/xz-backdoor/ https://news.risky.biz/risky-biz-news-supply-chain-attack-in-linuxland/ https://www.zdnet.com/article/this-backdoor-almost-infected-linux-everywhere-the-xz-utils-close-call/#ftag=RSSbaffb68 https://therecord.media/malicious-backdoor-code-linux-red-hat-cisa https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 https://duo.com/decipher/carefully-crafted-campaign-led-to-xz-utils-backdoor https://boehs.org/node/everything-i-know-about-the-xz-backdoor OWASP leaks resumes, defining different types of prompt injection, a secure design example in device-bound sessions, turning an ASVS requirement into practice, Ivanti has its 2000s-era Microsoft moment, HTTP/2 CONTINUATION flood, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-280
We look into the supply chain saga of the XZ Utils backdoor. It's a wild story of a carefully planned long con to add malicious code to a commonly used package that many SSH connections rely on. It hits themes from social engineering and abuse of trust to obscuring the changes and suppressing warnings. It also has a few lessons about software development, the social and economic dynamics of open source, and strategies for patching software. It's an exciting topic partially because so much other appsec is boring. And that boring stuff is important to get right first. We also talk about what parts of this that orgs should be worried about and what types of threats they should be prioritizing instead. Segment Resources: https://tukaani.org/xz-backdoor/ https://news.risky.biz/risky-biz-news-supply-chain-attack-in-linuxland/ https://www.zdnet.com/article/this-backdoor-almost-infected-linux-everywhere-the-xz-utils-close-call/#ftag=RSSbaffb68 https://therecord.media/malicious-backdoor-code-linux-red-hat-cisa https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 https://duo.com/decipher/carefully-crafted-campaign-led-to-xz-utils-backdoor https://boehs.org/node/everything-i-know-about-the-xz-backdoor Show Notes: https://securityweekly.com/asw-280
Farshad Abasi joins us again to talk about creating a new OWASP project, the Secure Pipeline Verification Standard. (Bonus points for not being a top ten list!) We talk about what it takes to pitch a new project and the problems that this new project is trying to solve. For this kind of project to be successful -- as in making a positive impact to how software is built -- it's important to not only identify the right audience, but craft guidance in a way that's understandable and achievable for that audience. This is also a chance to learn more about a project in its early days and the opportunities for participating in its development! Segment resources https://github.com/OWASP/www-project-secure-pipeline-verification-standard--spvs- (coming soon!) PrintListener recreates fingerprints, iMessage updates key handling for a PQ3 rating, Silent Sabotage shows supply chain subterfuge against AI models, 2023 Rust survey results, the ways genAI might help developers, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-274
Farshad Abasi joins us again to talk about creating a new OWASP project, the Secure Pipeline Verification Standard. (Bonus points for not being a top ten list!) We talk about what it takes to pitch a new project and the problems that this new project is trying to solve. For this kind of project to be successful -- as in making a positive impact to how software is built -- it's important to not only identify the right audience, but craft guidance in a way that's understandable and achievable for that audience. This is also a chance to learn more about a project in its early days and the opportunities for participating in its development! Segment resources https://github.com/OWASP/www-project-secure-pipeline-verification-standard--spvs- (coming soon!) Show Notes: https://securityweekly.com/asw-274
Farshad Abasi joins us again to talk about creating a new OWASP project, the Secure Pipeline Verification Standard. (Bonus points for not being a top ten list!) We talk about what it takes to pitch a new project and the problems that this new project is trying to solve. For this kind of project to be successful -- as in making a positive impact to how software is built -- it's important to not only identify the right audience, but craft guidance in a way that's understandable and achievable for that audience. This is also a chance to learn more about a project in its early days and the opportunities for participating in its development! Segment resources https://github.com/OWASP/www-project-secure-pipeline-verification-standard--spvs- (coming soon!) PrintListener recreates fingerprints, iMessage updates key handling for a PQ3 rating, Silent Sabotage shows supply chain subterfuge against AI models, 2023 Rust survey results, the ways genAI might help developers, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-274
This was an amazing interview! In today's episode of Dieting From The Inside Out I interview my coaches, Chad and Far. We get into a ton of this episode... - How Chad stopped in bodybuilding without spiraling out of control - How to have results that a never leave - How to master maintenance so you aren't stressing - How to overall change your life So much more, it was a fully episode for sure. Be sure to subscribe, enjoy! - Jared Timestamps: (00:45) - Intro (04:59) - Who are Chad and Far? (08:12) - Managing your lifestyle and body building/competing (16:45) - Chad's dieting & prep mistakes (20:09) - Chad's approach to fitness and lifestyle (23:12) - When is someone ready to compete in bodybuilding? (33:43) - Should dieting for lifestyle and competition be the same? (37:23) - How to enjoy the process in your fitness journey (44:02) - Why most people can't stick to a simple plan (51:30) - Maintenance and being patient with your results (59:34) - Outro and freebies JOIN THE 180 ACADEMY FOR OVER 50% OFF (special offer ONLY for podcast listeners): https://inquire.hamiltontrained.com/180academypodcastoffer FREEBIES & SPECIAL OFFERS: ‣ Special Coaching Offer calendar link for only podcast listeners: https://link.arfunnel.io/widget/bookings/dietingfromtheinsideout ‣ #Project90 - the exact 90-day blueprint on how to lose weight & never gain it back (without giving up the rest of your life): https://bit.ly/Project90Access ‣ Join my free Facebook group & get all my trainings: https://www.facebook.com/groups/fatlosssimplified ‣ Get my [Free] Fat Loss Check-list Course: https://inquire.hamiltontrained.com/minicourse-optin ‣ The best supplements for weight loss video: https://www.youtube.com/watch?v=OfjByg4Zr_Y ‣ 1st Phorm Supplement Training (from our Facebook community): https://bit.ly/3hkBuLF ‣ Get FREE shipping on 1st Phorm Supplements: https://1stphorm.com/?a_aid=realjaredhamilton ‣ Use promo code HAMILTONTRAINED for 20% off at: https://www.flexpromeals.com FIND ME ON: ‣ Instagram: https://www.instagram.com/realjaredhamilton ‣ YouTube: https://www.youtube.com/@jaredhamilton ‣ TikTok: https://www.tiktok.com/@realjaredhamilton ‣ Email: jared@hamiltontrained.com ---- © 2023 Jared Hamilton #podcast #dietingfromtheinsideout --- Support this podcast: https://podcasters.spotify.com/pod/show/dietingfromtheinsideout/support
A new edition of Roqe featuring a lifetime interview with popular British-Iranian news anchor, producer, and presenter, Farshad Mottaghi, from Manoto TV, joining Jian from London. In his first ever long form interview in English, Farshad talks to Jian about his career, the emotional toll of covering heartbreaking news, his move to the UK and the incredible story behind it, and more. Plus, a Roqe Roundup with Pegah on current issues including the evolving - and devastating - war in the Middle East and the complicity and sponsorship of related recent atrocities by the leaders of the Islamic Republic of Iran.
Introducing "Daily Dose of Leadership: From Insight to Influence: Daily Steps to Awareness, Growth, and Leadership Mastery", authored by the visionary Farshad Asl. This groundbreaking book is infused with innovation, offering a fresh and unique approach to reading and learning. With "Daily Dose of Leadership," you will embark on a transformative journey towards becoming an exceptional leader. Each day's "daily doses" will equip you with powerful insights and practical wisdom, enabling you to unlock your leadership potential. But that's not all – we've taken learning to a whole new level! At the end of each chapter, you can access exclusive video content by simply scanning the QR Code. These videos, carefully curated to complement the topics discussed, will provide you with deeper insights and enhance your understanding. Don't let this invaluable opportunity slip away. Get your copies of "Daily Dose of Leadership" now, available on Amazon or visit our website, https://www.farshadasl.net, to learn more about this transformative book and explore Farshad Asl's remarkable leadership journey. Elevate your leadership game and lead with purpose and impact – order your copy today! Follow me: Twitter: https://twitter.com/FarshadAsl Linkedin: https://linkedin.com/in/FarshadAsl Facebook: https://facebook.com/FarshadMAsl Instagram: https://instagram.com/iFarshad #Leadership #Mindshift #NoExcuses --- Support this podcast: https://podcasters.spotify.com/pod/show/farshadasl/support
Links!!!!All about AILAAll about Jeremey All about FarshadJeremy's AILA Annual Conference 2023 SpeechFarshad's AILA Annual Conference 2023 SpeechSponsors and friends of the podcast!Kurzban Kurzban Tetzeli and Pratt P.A.Immigration, serious injury, and business lawyers serving clients in Florida, California, and all over the world for over 40 years.Docketwise"Modern immigration software & case management"Joorney Business Plans"Business-critical documents for every stage of your journey"For 30% off use code: REVJOORNEY30 Want to become a patron?Click here to check out our Patreon Page!CONTACT INFORMATIONEmail: kgregg@kktplaw.comFacebook: @immigrationreviewInstagram: @immigrationreviewTwitter: @immreviewAbout your hostMore episodesCase notesTop 15 immigration podcast in the U.S.Recent criminal-immigration article (p.18)Featured in San Diego VoyagerDISCLAIMER:Immigration Review® is a podcast made available for educational purposes only. It does not provide legal advice. Rather, it offers general information and insights from publicly available immigration cases. By accessing and listening to the podcast, you understand that there is no attorney-client relationship between you and the host. The podcast should not be used as a substitute for competent legal advice from a licensed attorney in your state.MUSIC CREDITS:"Loopster," "Bass Vibes," "Chill Wave," and "Funk Game Loop" Kevin MacLeod - Licensed under Creative Commons: By Attribution 4.0 Support the show
Farshad Abasi shares three models for deploying resources within application security teams:The Dedicated AppSec Person Model involves assigning an AppSec person to work with each team. Farshad shares his experience of working with developers and the challenges faced in getting them to understand and implement threat modeling. He also discusses the transition from waterfall to Agile and how it affected threat modeling.The Federated Model: A security consultant attends weekly standups and sprint planning sessions in this model. They work with a checklist to quickly determine if any user stories could be security sensitive. This model reduces the allocation required to 10 to 20% of an AppSec consultant.The Champion or Deputy Model: The AppSec team deputizes developers to do the bulk of the application security work, and the AppSec team becomes a resource and escalation point for more complex problems. Each DevOps team appoints a security champion, and these champions form a working group supported by an AppSec person. The champions handle day-to-day issues and threat modeling, with the AppSec team providing mentorship and support.Over several years, Farshad's journey progressed from the expert-led model to a fully-deputized, champion-driven approach to AppSec. After careful consideration, we conclude that the fully deputized model is the only path to scalability.FOLLOW OUR SOCIAL MEDIA: ➜Twitter: @AppSecPodcast➜LinkedIn: The Application Security Podcast➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast Thanks for Listening! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Check out this interview from the ASW VAULT, hand picked by main host Mike Shema! This segment was originally published on March 14, 2022. Cybersecurity is a large and often complex domain, traditionally focused on the infrastructure and general information security, with little or no attention to Application Security. Security providers usually tack-on AppSec services to their existing menu of offering without understanding the domain, and their team of professionals have little or no experience with software development or inner workings of modern application architectures. As the world turns Digital at a rapid pace accelerated by the recent pandemic, applications become common place in our lives, providing attackers more opportunities to exploit these poorly protected applications. As such, it is important to know what is actually required to build and run software securely, and how to do application security right. Segment Resources: https://forwardsecurity.com/2022/03/07/application-security-for-busy-tech-execs/ Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/vault-asw-1
Check out this interview from the ASW VAULT, hand picked by main host Mike Shema! This segment was originally published on March 14, 2022. Cybersecurity is a large and often complex domain, traditionally focused on the infrastructure and general information security, with little or no attention to Application Security. Security providers usually tack-on AppSec services to their existing menu of offering without understanding the domain, and their team of professionals have little or no experience with software development or inner workings of modern application architectures. As the world turns Digital at a rapid pace accelerated by the recent pandemic, applications become common place in our lives, providing attackers more opportunities to exploit these poorly protected applications. As such, it is important to know what is actually required to build and run software securely, and how to do application security right. Segment Resources: https://forwardsecurity.com/2022/03/07/application-security-for-busy-tech-execs/ Show notes: https://www.scmagazine.com/podcast-episode/asw-188-farshad-abasi
Check out this interview from the ASW VAULT, hand picked by main host Mike Shema! This segment was originally published on March 14, 2022. Cybersecurity is a large and often complex domain, traditionally focused on the infrastructure and general information security, with little or no attention to Application Security. Security providers usually tack-on AppSec services to their existing menu of offering without understanding the domain, and their team of professionals have little or no experience with software development or inner workings of modern application architectures. As the world turns Digital at a rapid pace accelerated by the recent pandemic, applications become common place in our lives, providing attackers more opportunities to exploit these poorly protected applications. As such, it is important to know what is actually required to build and run software securely, and how to do application security right. Segment Resources: https://forwardsecurity.com/2022/03/07/application-security-for-busy-tech-execs/ Show notes: https://www.scmagazine.com/podcast-episode/asw-188-farshad-abasi
We're taking a little break from interviewing Top Chef contestants to do a good old fashioned rewatch episode with our friend Farshad Khansari (Boogiemanja). Farshad wanted to watch and talk about Top Chef Season 06, Episode 07 "Dinner Party", so that's what we did! And we start doing it at 37:15. We share Tom's latest idea for breaking into Hollywood (we wants us to write a sitcom pilot for him), we visit the writer's room, and we name all the people in the MCCU. Check out the sketch team that Farshad is on with me - Big Apartment And check him out on Twitch - @falukun ----more---- Subscribe for new episodes every Monday. Rate us 5 stars and let us know what you had for dinner last night in the review! This episode was edited by Bryan A Jackson. The Pod Chef theme song was produced and performed by Jeff Ray. Pod Chef Links Follow us on Instagram and Twitter - @podchefpodcast Follow Bryan on Instagram - @bjacksonininaction Follow Jamal on Instagram - @hell0newman Our intro was produced and performed by Jeff Ray - https://www.instagram.com/jeffrayfilms/
This week in the AppSec News: Apple introduces Lockdown Mode, PyPI hits 2FA trouble, cataloging cloud vulns, practical attacks on ML, NIST's post-quantum algorithms, & more! Appsec starts with the premise that we need to build secure code, but it also has to be able to recommend effective practices and tools that help developers. This also means appsec teams need to work with developers to create criteria for security solutions, whether it's training or scanners, in order to make sure their investments of time and money lead to more secure apps. Segment Resources: https://forwardsecurity.com/2022/04/24/embedding-security-into-software-during-development/ https://forwardsecurity.com/2022/03/15/application-security-for-busy-tech-execs/ https://forwardsecurity.com/2022/03/09/sast-sca-dast-iast-rasp-what-they-are-and-how-you-can-automate-application-security/ Visit https://www.securityweekly.com/asw for all the latest episodes! Follow us on Twitter: https://www.twitter.com/secweekly Like us on Facebook: https://www.facebook.com/secweekly Show Notes: https://securityweekly.com/asw203