
Static application security testing
11
MENTIONS
7
EPISODES
7
PODCASTS
Search complete. 11 mentions across 7 episodes found for "Static application security testing".
Sep 9, 2026
Clear your calendar, it’s Patch Tuesday.
A
16:22Andy HorngoldGUEST
I think in the new environment, you're able to do things significantly quicker than you were previously.
A
16:27Andy HorngoldGUEST
Like, I remember doing pen tests back in the day where you were asked to do source code reviews or at least code-assisted pen tests, and you'd have to use one of the SAST scanners, the static code analysis tools that was out there and was available, but it was always, it was always a headache.
A
16:42Andy HorngoldGUEST
I don't think anybody...
A
16:43Andy HorngoldGUEST
Like, when I ran a pen testing team over at Context, nobody enjoyed doing that security, like, code review side of things.
358 - What’s up, Exposure Management?
T
34:48Tobias ZimmergrenHOST
to replace the third-party code scanning tools that we're using right now.
T
34:51Tobias ZimmergrenHOST
Because we're using some well-known third-party code scanning tools that have both DAST and SAST, so Static Application Security Testing and Dynamic Application Security Testing.
T
35:02Tobias ZimmergrenHOST
And the dynamic one is like, okay, you're running here, let's do a pen test on it.
T
35:05Tobias ZimmergrenHOST
And the static one is, okay, here's your code running through a static code analyzer.
Vulnerability Research, AI Slop, and Why Fundamentals Still Win with Stephen Sims
S
19:49Stephen SimsGUEST
I would say half the floor was like AI SOC.
S
19:53Stephen SimsGUEST
And so how do you define your moat or your differentiation to stand out and solve problems? So we currently support like API testing, web app testing, SAST and DAST validation, and then LLM chatbots.
S
20:08Stephen SimsGUEST
We believe strongly in like human in the loop and that, and I'll give you a good example.
S
20:14Stephen SimsGUEST
We've benchmarked against different solutions out there, both open source and commercial.
AI Pen Testing Killed Traditional DAST
J
5:25James BerthotyGUEST
And I think year over year, as within the OWASP top 10, we've seen like BOLA and IDOR move up the chart, that this is the opportunity that presents itself is really we're talking about authorization level vulnerabilities from the DAST side.
J
5:41James BerthotyGUEST
And then AI SAST to me is the same logic, but applied to like code analysis.
J
5:46James BerthotyGUEST
So it's really about getting the maximum value out of like a contextual understanding of your application.
C
5:52Chris RomeoHOST
Okay, so does AI pen testing imply agentic? Like, are these things synonymous?
28 MINS LATER
J
33:43James BerthotyGUEST
And the question, like, could...
J
33:45James BerthotyGUEST
Could OpenAI or Anthropic make a, I'll just use like sneak check marks, whoever, like could they make one of those solutions? Sure.
J
33:53James BerthotyGUEST
But I don't like AI SAST, which is what they currently have the closest version of, is still just one slice of the alphabet soup that you named.
J
34:07James BerthotyGUEST
And so I just have a hard time believing that they're going to in a timely manner, expand across that entire suite of offerings.
Securing The Build. AI, AppSec, & Exposure Management. Azi Cohen & Asaf Saar, Mend.io.
A
12:54Asaf SaarGUEST
It changes is how you are looking and defining your, your security strategy, right? How you build a plan, how you are executing at that, and you need to look at from different angle.
A
13:03Asaf SaarGUEST
We look at the AppSec, the traditional AppSec with SCA and SAST, right, infrastructure and code containers and such, and then comes the AI capabilities.
A
13:11Asaf SaarGUEST
Again, this is runtime.
A
13:13Asaf SaarGUEST
It's guardrail, it's, it's red teaming, it's, um, prompt injection and, uh, jailbreaking, right? This is a completely different angle that you need to plan and act upon.
Tearing Down Vendor Fluff: The Real State of AI Security | James Berthoty
J
6:40James BerthotyGUEST
And so I've just been shocked by the number of teams who are willing to rethink their entire security program in light of AI.
J
6:47James BerthotyGUEST
They're like, do I even need a SAST SCA scanner? Like, what does a scanner even do now that we're deploying code so quickly in an entirely different way? And it's leading them to rethink almost every aspect of their security program.
J
7:00James BerthotyGUEST
And there's such a willingness to throw out old tools, adopt new ones, and figure out the right stack that it's really been pretty crazy to see how quickly it's happened.
M
7:09Mackenzie JacksonHOST
And where are you at in that throwing out old tools kind of journey? Because it is something that I think from the vendor perspective, I put my little vendor hat on.
M
7:30Mackenzie JacksonHOST
And SaaS is still important.
M
7:31Mackenzie JacksonHOST
But I think if we just remove all of that and we had to do it...
M
7:36Mackenzie JacksonHOST
Is there still a world where SAST SCA scanning is needed? Is it more important? Is it morphed in? How does that future exist?
J
7:47James BerthotyGUEST
It's so much of the goal of Latio as a whole is to provide people tailored recommendations for their environment.
Episode 330 - w/ Jeevan Singh - Vulnerability Jail
S
29:41Seth LawHOST
Go ahead, Ken.
K
29:43Ken JohnsonHOST
Just a question around where are the vulnerabilities coming from? Are these like you're doing nightly or weekly scans and these are SCA vulnerabilities or you're doing those same scans in container vulnerabilities or is it SAST vulnerabilities, DAST vulnerabilities? What's kind of the general breakdown that we're talking about?
J
30:05Jeevan SinghGUEST
Yeah, it's everything so.
J
30:09Jeevan SinghGUEST
Our most is the detections that we have put into place, so we leverage our bug bounty to.