Talk Python - Python Web Security Owasp Top 10 With Agentic Ai Course

Started by BeMyLove, Yesterday at 12:13 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

BeMyLove


Talk Python - Python Web Security: Owasp Top 10 With Agentic Ai Course
Released 5/2026
MP4 | Video: h264, 1920x1080 | Audio: AAC, 44.1 KHz, 2 Ch
Genre: eLearning | Language: English | Duration: 126 Lessons ( 5h 28m ) | Size: 1.6 GB
When Mozilla recently ran Claude over the Firefox JavaScript runtime, the AI uncovered more than 100 bugs, 14 of them serious enough to become CVEs. ? That kind of agentic security review used to be the exclusive domain of expensive pen-testing firms. Not anymore.

This course shows you how to do the same thing for your own Python web apps. We start by working through every category of the OWASP Top 10 (2025 edition) with real vulnerable-and-fixed examples in Flask, Django, and FastAPI. Then we build the Security Lead, a custom Claude Code agent specifically tuned for Python and SaaS security, that audits any codebase in minutes for roughly the cost of a fancy coffee. We turn it loose on three popular open source apps (Apache Superset, Paperless-ngx, and Kibitzr) and find genuine issues in each one.
What students are saying
This is by far the best Python course I've done to date, clear explanations, good apps that incorporate the concepts of the particular session and a follow up on core concepts. The course is very engaging with a little humour which makes it much easier to dedicate time following along.
If you are looking for a easy to follow, enjoyable Python course - back the project now, get comfortable and enjoy! I don't often leave public feedback, but felt on this occasion I had to as now I'm hooked!
Source code and course GitHub repository
github.com/talkpython/python-web-owasp-top-10-with-agentic-ai-course
What's this course about and how is it different?
This course teaches you to find and fix the OWASP Top 10 security vulnerabilities, not as an abstract checklist, but as concrete, fixable problems in real Python web apps built with Flask, Django, and FastAPI. For every category you'll see vulnerable code, why it's dangerous, and exactly how to fix it. Then we go further and build the Security Lead, a custom Claude Code agent that brings that same OWASP-aware perspective to any Python codebase, with the discipline a pen-testing firm would apply. Think of it as pair programming with a security specialist who lives in your repo, never gets tired, and never skips a step.
Why this course is different from other Python security tutorials
The brand-new OWASP 2025 edition - Covers the freshly released 2025 list including the new "mishandling of exceptional conditions" category, so you're studying current threat priorities, not 2021's. For background, hear OWASP committee member Tanya Janca walk through the new list on Talk Python episode 545.
A reusable AI security agent you keep forever - Walk away with the Security Lead, a custom Claude Code agent definition tuned for Python and SaaS security that you can drop into any future project.
Real, named, live audits - Unscripted and unstaged. Michael picks three popular open source apps (Apache Superset, Paperless-ngx, and Kibitzr) and runs the audits live on camera, discovering the genuine issues in each one for the first time as you watch.
Vulnerable and fixed code, side by side - Every OWASP category includes the broken version, exactly why an attacker can exploit it, and the secure fix using current Python practices.
Flask, Django, and FastAPI together - Examples span all three major Python web frameworks, so you see how the same vulnerability looks (and gets fixed) across the stack you actually use.
Built for SaaS multi-tenancy concerns - Dedicated focus on user data isolation, IDOR risks, and cross-tenant data leaks, the things that keep SaaS builders up at night.
Practical AI workflow, not vibe coding - Learn how to point an agent at a real codebase, prompt it for an OWASP-aligned report, and apply fixes responsibly using careful engineering practices.
Honest costs and time spent - See exactly what a million-line audit consumes (roughly $3 to $5 in Claude Code compute) and how to keep audit spend predictable.
Modern Python security toolbox - Argon2 password hashing, MultiFernet key rotation, slowapi rate limiting, loguru audit logging, pip-audit for supply chain, Have I Been Pwned checks, and more.
Ethics built in - Closing guidance on how to apply these techniques responsibly, including why not to flood open source maintainers with low-signal AI-generated PRs.
What will you learn about OWASP Top 10 and Python security?
By the end of this course, you'll be able to
Recognize and fix all ten OWASP Top 10 2025 vulnerability categories in real Python web apps
Diagnose broken access control vulnerabilities including IDOR, path traversal, and missing function-level access checks
Configure Docker Compose, Django settings, and security headers to avoid the most common production misconfigurations
Pin Python dependencies safely with uv pip compile and exclude-newer-than to defend against fresh supply chain attacks
Run pip-audit in CI and Docker builds so a CVE never ships unnoticed
Replace weak password hashing with Argon2 and rotate encryption keys with MultiFernet without downtime
Defend against SQL, NoSQL, and stored XSS injection with parameterized queries and proper template escaping
Apply server-side validation with Pydantic field validators so client-side checks can never be the only gate
Enforce strong password policies including Have I Been Pwned breach checks and a top-10k common-passwords list
Build a secure password reset flow with hashed tokens, short expirations, and no user enumeration
Prevent mass-assignment attacks with strict serializer fields and read-only flags
Vendor third-party JavaScript and CSS into your own infrastructure instead of trusting external CDNs
Implement structured security audit logging with loguru and threshold-based alerts to Slack, PagerDuty, or Sentry
Return safe, generic error responses to users while logging full context server-side with a traceable reference ID
Use SQLAlchemy transaction context managers to prevent partial writes and money-disappearance bugs
Audit multi-tenant SaaS applications for cross-tenant data leaks and identity isolation gaps
Write a custom Claude Code agent persona definition tuned for your stack and threat model
Wire OWASP markdown sources directly into your agent so it cites canonical references instead of hallucinating
Run a complete agentic security audit on any Python codebase and turn the report into a prioritized fix list
Apply fixes with AI assistance while keeping a clear audit trail of what changed, why, and how it was tested
Estimate and control the cost of agentic security audits so they remain practical for routine use
Who is this OWASP Python security course for?
This course is perfect for
Python web developers who ship production apps in Flask, Django, or FastAPI without a dedicated security team backing them up
SaaS founders and indie hackers who run multi-tenant apps where data isolation between users is critical
Senior engineers and tech leads who want a systematic, OWASP-aligned approach to reviewing their team's Python web code
Developers facing compliance audits who need documented security practices for SOC 2, HIPAA, PCI DSS, GDPR, NIST 800-63-4, or CMMC
Developers already using AI tools daily who want a serious, security-focused application of agentic AI (if you'd like to build up the agentic-coding foundations first, Agentic AI Programming for Python is a natural prerequisite)
Anyone maintaining a legacy Python web app that hasn't had a security audit recently and wants a practical, AI-assisted way to catch up


https://rapidgator.net/file/9f7c102381789d99421813b1d776a94f/Python_Web_Security_OWASP_Top_10_with_Agentic_AI_Course.part1.rar.html
https://rapidgator.net/file/d60096d68dcdebc580f59cfde6721ae8/Python_Web_Security_OWASP_Top_10_with_Agentic_AI_Course.part2.rar.html