
AI Pen Testing Killed Traditional DAST
Om avsnittet
Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generated with context about your actual application, agents that chase findings the way a human tester would, and results a scanner was never going to produce. We get into what it costs once tokens enter the picture, who pays for them, whether a pentest on every pull request is realistic, and what stops an autonomous tester from going further than it should. Then we look further out: the future of bug bounties, what happens when cloud and model providers absorb today's security tooling, and who is accountable when an agent deletes your production database.
This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
→ Learn more about Corgea
Connect with James Berthoty:
→ James Berthoty on LinkedIn
→ Latio
→ Latio Pulse
Mentioned in this episode:
→ Latio's free reports
→ James on the podcast the first time: Is DAST Dead? And the future of API security
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
Chapters:
00:00 Cold open — the results speak for themselves
01:01 Meet James Berthoty and the "Is DAST dead?" fallout
01:31 Chickens, eggs, and getting away from screens
03:46 Why we're revisiting the DAST question
04:14 A working definition of AI pentesting
05:47 Contextual payloads and application awareness
06:47 Determinism, repeatability, and what buyers actually want
07:46 Can you run an AI pentest on every code change?
09:43 What it really costs
10:40 Incumbents vs. AI-native vendors
13:27 Who pays for the tokens?
14:29 Bundling, platforms, and competitive pressure
16:25 AI across the whole development workflow
18:22 Agents that run all the way to deployment
19:21 A pentest on every pull request
21:52 What stops a pentest from going too far?
23:10 Permission scoping and guardrails
26:07 Where the findings actually land
28:02 The future of bug bounties
30:50 Why pentests command more budget than DAST
31:45 Could the cloud providers absorb security tooling?
34:38 What model providers could build instead
36:36 The same story on the code scanning side
39:24 Accountability when the tool misses something
40:22 Shared responsibility when an agent deletes production
41:23 The verdict on DAST
42:19 Where to find Latio's free reports
43:15 Closing thoughts
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.