Dynamic application security testing
37
MENTIONS
14
EPISODES
13
PODCASTS
Search complete. 37 mentions across 14 episodes found for "Dynamic application security testing".
Sep 10, 2026
'Cybersecurity: Why Legacy Telnet and Zero Trust Flaws Persist' by Carlos Lozano, CEO, Rent A Hacker
L
1:34Lorena RuizNARRATOR
and although in some cases the certificates were self-signed, in others, where the applications were proprietary, the certificates were properly configured.
L
1:42Lorena RuizNARRATOR
For the integrations, this company made use of periodic SAST, DAST, and CSA scans, so the encryption algorithms were also the most recent.
L
1:52Lorena RuizNARRATOR
On top of that, breaking the certificate was not that simple.
L
1:55Lorena RuizNARRATOR
Active monitoring would surely have detected any kind of attempt to break the encryption, so it was not too viable.
Astra Is Hard to Monitor
S
18:05speaker_3NARRATOR
Figure 31 from the system card, titled Monitor Evasion Under Task-Guided Sabotage.
S
18:10speaker_3NARRATOR
Six panels plot rates against chain of thought plus tool call tokens from 1,000 to 40,000 for GPT-5.5 in DAST gray, GPT-5.6 SOL in blue, and GPT-6 Astra in pink.
S
18:24speaker_3NARRATOR
Side task success.
S
18:25speaker_3NARRATOR
Astra sits between about 83 and 100% from 5,000 tokens upward.
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475
T
62:50Tyler ShieldsHOST
We're seeing a weird overlapping dynamic now when you start to layer in AI into a continuous pen testing model, agentic AI, offensive AI.
T
63:00Tyler ShieldsHOST
pen testing is very different than the traditional DAST, which had its own isolated market for a long time.
T
63:07Tyler ShieldsHOST
It's also very different than the PTAS, which might go lower in the stack than the app layer and have a broader view of it.
T
63:15Tyler ShieldsHOST
These things are combining is what it really comes down to.
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475
A
61:27Adrian SanabriaHOST
Uh, I haven't kept up with them over the years, but, um, but yeah.
A
61:31Adrian SanabriaHOST
And then net spy is on the like DAST SAST side of things.
A
61:35Adrian SanabriaHOST
If, if I remember correctly.
A
61:37Adrian SanabriaHOST
Yeah.
T
62:45Tyler ShieldsHOST
Now, the question becomes, the market segmentation is very unique in this space.
T
62:50Tyler ShieldsHOST
We're seeing a weird overlapping dynamic now when you start to layer in AI into a continuous pen testing model, agentic AI, offensive AI.
T
63:00Tyler ShieldsHOST
pen testing is very different than the traditional DAST, which had its own isolated market for a long time.
T
63:07Tyler ShieldsHOST
It's also very different than the PTAS, which might go lower in the stack than the app layer and have a broader view of it.
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475
T
62:50Tyler ShieldsHOST
We're seeing a weird overlapping dynamic now when you start to layer in AI into a continuous pen testing model, agentic AI, offensive AI.
T
63:00Tyler ShieldsHOST
pen testing is very different than the traditional DAST, which had its own isolated market for a long time.
T
63:07Tyler ShieldsHOST
It's also very different than the PTAS, which might go lower in the stack than the app layer and have a broader view of it.
T
63:15Tyler ShieldsHOST
These things are combining is what it really comes down to.
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475
A
61:27Adrian SanabriaHOST
Uh, I haven't kept up with them over the years, but, um, but yeah.
A
61:31Adrian SanabriaHOST
And then net spy is on the like DAST SAST side of things.
A
61:35Adrian SanabriaHOST
If, if I remember correctly.
A
61:37Adrian SanabriaHOST
Yeah.
T
62:45Tyler ShieldsHOST
Now, the question becomes, the market segmentation is very unique in this space.
T
62:50Tyler ShieldsHOST
We're seeing a weird overlapping dynamic now when you start to layer in AI into a continuous pen testing model, agentic AI, offensive AI.
T
63:00Tyler ShieldsHOST
pen testing is very different than the traditional DAST, which had its own isolated market for a long time.
T
63:07Tyler ShieldsHOST
It's also very different than the PTAS, which might go lower in the stack than the app layer and have a broader view of it.
358 - What’s up, Exposure Management?
T
34:48Tobias ZimmergrenHOST
to replace the third-party code scanning tools that we're using right now.
T
34:51Tobias ZimmergrenHOST
Because we're using some well-known third-party code scanning tools that have both DAST and SAST, so Static Application Security Testing and Dynamic Application Security Testing.
T
35:02Tobias ZimmergrenHOST
And the dynamic one is like, okay, you're running here, let's do a pen test on it.
T
35:05Tobias ZimmergrenHOST
And the static one is, okay, here's your code running through a static code analyzer.
Julien-David Nitlech (IRIS): What Exotec taught IRIS about backing deep tech that lasts
J
46:18Julien-David NitlechGUEST
To their opinion, they've already pivoted twice.
J
46:20Julien-David NitlechGUEST
They started at a CI-CD tool for API security, and they moved on to penetration testing and dynamic application security testing, DAST.
J
46:30Julien-David NitlechGUEST
And now they're good.
J
46:32Julien-David NitlechGUEST
So it's a small change to the technology, but they're leaders in AI penetration testing.
Vulnerability Research, AI Slop, and Why Fundamentals Still Win with Stephen Sims
S
19:49Stephen SimsGUEST
I would say half the floor was like AI SOC.
S
19:53Stephen SimsGUEST
And so how do you define your moat or your differentiation to stand out and solve problems? So we currently support like API testing, web app testing, SAST and DAST validation, and then LLM chatbots.
S
20:08Stephen SimsGUEST
We believe strongly in like human in the loop and that, and I'll give you a good example.
S
20:14Stephen SimsGUEST
We've benchmarked against different solutions out there, both open source and commercial.
AI Pen Testing Killed Traditional DAST
C
1:05Chris RomeoHOST
And James was on the show back in May 2024.
C
1:08Chris RomeoHOST
So if you want to go back and take a look at that episode to hear his security origin story, but also the title of that episode was, Is DAST Dead? But James, we do want to welcome you to the podcast, but also my favorite question to ask people right now is, what do you like to do that takes you away from technology, screens, just gets you outside? Like, is there something that gets you away from tech? Yeah, we have
J
1:36James BerthotyGUEST
three kids and a cat and a dog and nine chickens most recently.
J
1:41James BerthotyGUEST
And so we are usually busy with a mixture of kids activities plus animal activities and those things.
C
3:34Chris RomeoHOST
Visit Korgia.com. C-O-R-G-E-A dot com.
C
3:40Chris RomeoHOST
Corgea, one security platform for the entire SDLC.
C
3:46Chris RomeoHOST
But as I said in that first episode, we talked about, is DAST dead? And that brought lots of fire from a lot of different angles.
C
3:55Chris RomeoHOST
A lot of different people had a lot of feedback and comments on that one.
4 more episodes mention Dynamic application security testing.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.