For those who want to follow the course without access to the warzones (until the course is over), or just practice the material, you could play with some of the other warzones out there.
A lot of these security auditors(but not all!) are just running automated tools and generating automated reports.
Woah... A professional security auditor actually knows what to look for and would be flexible enough to understand (and manipulate) what your software is doing. If you are paying someone to run a script, you're not getting your money's worth.
Even a dedicated security guy at a large company can't be everywhere and doesn't know everything(or even understand, say, hypervisor security).
True, that's why ideally you'd want a team of people on this, not just one security guy to carry the globe.
I agree though, security needs to be thought out from the beginning and throughout the development process. The later you catch something, the harder it is to fix. But you need a fair amount of experience as a developer to see security issues thoroughly (because you often need to understand the platforms you are building on, not just your domain). So if you don't have that knowledge you can either teach yourself or if you don't have the time, let someone else do it.
Having a thorough understanding of what you are actually doing does take care of most of that. I doubt that's where a startup's priorities are, sadly. For most, speed > solid code
No. You are saying that anyone who creates software with a security bug in it should be condemned. Komodia built their software with a very serious security hole, intentionally, to sell a product with HTTPS sniffing abilities.
Just because Lenovo didn't build the software, doesn't mean they are not guilty of overlooking a serious security vulnerability by including software which provides no benefit to its customers. It's an insult to customers.
The bugs you find in openSSL and Bash are not insults, they are mistakes made by people who don't get money out of their work (and who don't go out of their way to sell / track information). Security is hard to build correctly, easy to break.
There is https://exploit-exercises.com/ and http://overthewire.org/wargames/, the former is somewhat more pedagogical, but both are really good.