Skip to main content
Dynamic application security testing

Dynamic application security testing

Search complete. 37 mentions across 14 episodes found for "Dynamic application security testing".

Sep 10, 2026

Lorena RuizNARRATOR
1:34
and although in some cases the certificates were self-signed, in others, where the applications were proprietary, the certificates were properly configured.
Lorena RuizNARRATOR
1:42
For the integrations, this company made use of periodic SAST, DAST, and CSA scans, so the encryption algorithms were also the most recent.
Lorena RuizNARRATOR
1:52
On top of that, breaking the certificate was not that simple.
Lorena RuizNARRATOR
1:55
Active monitoring would surely have detected any kind of attempt to break the encryption, so it was not too viable.
speaker_3NARRATOR
18:05
Figure 31 from the system card, titled Monitor Evasion Under Task-Guided Sabotage.
speaker_3NARRATOR
18:10
Six panels plot rates against chain of thought plus tool call tokens from 1,000 to 40,000 for GPT-5.5 in DAST gray, GPT-5.6 SOL in blue, and GPT-6 Astra in pink.
speaker_3NARRATOR
18:24
Side task success.
speaker_3NARRATOR
18:25
Astra sits between about 83 and 100% from 5,000 tokens upward.
Tyler ShieldsHOST
62:50
We're seeing a weird overlapping dynamic now when you start to layer in AI into a continuous pen testing model, agentic AI, offensive AI.
Tyler ShieldsHOST
63:00
pen testing is very different than the traditional DAST, which had its own isolated market for a long time.
Tyler ShieldsHOST
63:07
It's also very different than the PTAS, which might go lower in the stack than the app layer and have a broader view of it.
Tyler ShieldsHOST
63:15
These things are combining is what it really comes down to.
Adrian SanabriaHOST
61:27
Uh, I haven't kept up with them over the years, but, um, but yeah.
Adrian SanabriaHOST
61:31
And then net spy is on the like DAST SAST side of things.
Adrian SanabriaHOST
61:35
If, if I remember correctly.
Adrian SanabriaHOST
61:37
Yeah.
Tyler ShieldsHOST
62:45
Now, the question becomes, the market segmentation is very unique in this space.
Tyler ShieldsHOST
62:50
We're seeing a weird overlapping dynamic now when you start to layer in AI into a continuous pen testing model, agentic AI, offensive AI.
Tyler ShieldsHOST
63:00
pen testing is very different than the traditional DAST, which had its own isolated market for a long time.
Tyler ShieldsHOST
63:07
It's also very different than the PTAS, which might go lower in the stack than the app layer and have a broader view of it.
Tyler ShieldsHOST
62:50
We're seeing a weird overlapping dynamic now when you start to layer in AI into a continuous pen testing model, agentic AI, offensive AI.
Tyler ShieldsHOST
63:00
pen testing is very different than the traditional DAST, which had its own isolated market for a long time.
Tyler ShieldsHOST
63:07
It's also very different than the PTAS, which might go lower in the stack than the app layer and have a broader view of it.
Tyler ShieldsHOST
63:15
These things are combining is what it really comes down to.
Adrian SanabriaHOST
61:27
Uh, I haven't kept up with them over the years, but, um, but yeah.
Adrian SanabriaHOST
61:31
And then net spy is on the like DAST SAST side of things.
Adrian SanabriaHOST
61:35
If, if I remember correctly.
Adrian SanabriaHOST
61:37
Yeah.
Tyler ShieldsHOST
62:45
Now, the question becomes, the market segmentation is very unique in this space.
Tyler ShieldsHOST
62:50
We're seeing a weird overlapping dynamic now when you start to layer in AI into a continuous pen testing model, agentic AI, offensive AI.
Tyler ShieldsHOST
63:00
pen testing is very different than the traditional DAST, which had its own isolated market for a long time.
Tyler ShieldsHOST
63:07
It's also very different than the PTAS, which might go lower in the stack than the app layer and have a broader view of it.
Tobias ZimmergrenHOST
34:48
to replace the third-party code scanning tools that we're using right now.
Tobias ZimmergrenHOST
34:51
Because we're using some well-known third-party code scanning tools that have both DAST and SAST, so Static Application Security Testing and Dynamic Application Security Testing.
Tobias ZimmergrenHOST
35:02
And the dynamic one is like, okay, you're running here, let's do a pen test on it.
Tobias ZimmergrenHOST
35:05
And the static one is, okay, here's your code running through a static code analyzer.
Julien-David NitlechGUEST
46:18
To their opinion, they've already pivoted twice.
Julien-David NitlechGUEST
46:20
They started at a CI-CD tool for API security, and they moved on to penetration testing and dynamic application security testing, DAST.
Julien-David NitlechGUEST
46:30
And now they're good.
Julien-David NitlechGUEST
46:32
So it's a small change to the technology, but they're leaders in AI penetration testing.
Stephen SimsGUEST
19:49
I would say half the floor was like AI SOC.
Stephen SimsGUEST
19:53
And so how do you define your moat or your differentiation to stand out and solve problems? So we currently support like API testing, web app testing, SAST and DAST validation, and then LLM chatbots.
Stephen SimsGUEST
20:08
We believe strongly in like human in the loop and that, and I'll give you a good example.
Stephen SimsGUEST
20:14
We've benchmarked against different solutions out there, both open source and commercial.
Chris RomeoHOST
1:05
And James was on the show back in May 2024.
Chris RomeoHOST
1:08
So if you want to go back and take a look at that episode to hear his security origin story, but also the title of that episode was, Is DAST Dead? But James, we do want to welcome you to the podcast, but also my favorite question to ask people right now is, what do you like to do that takes you away from technology, screens, just gets you outside? Like, is there something that gets you away from tech? Yeah, we have
James BerthotyGUEST
1:36
three kids and a cat and a dog and nine chickens most recently.
James BerthotyGUEST
1:41
And so we are usually busy with a mixture of kids activities plus animal activities and those things.
Chris RomeoHOST
3:34
Visit Korgia.com. C-O-R-G-E-A dot com.
Chris RomeoHOST
3:40
Corgea, one security platform for the entire SDLC.
Chris RomeoHOST
3:46
But as I said in that first episode, we talked about, is DAST dead? And that brought lots of fire from a lot of different angles.
Chris RomeoHOST
3:55
A lot of different people had a lot of feedback and comments on that one.

4 more episodes mention Dynamic application security testing.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.