Developer-First DAST: Fix Security Issues Before They Reach Production with Gadi Bashvitz
Categories: Podcasts , Test Guild Devops Toolchain Podcast
AI is revolutionizing application security testing, but its integration into developer workflows is challenging due to issues like authentication and access. Dynamic application security solutions are more effective than traditional methods, eliminating false positives and improving security without disrupting performance.
Test Guild Devops Toolchain Podcast
Test Guild Devops Toolchain Podcast - hosted by Joe Colantonio has a Dev Ops and Cloud focus. Each episode has a different guest. Show notes have comprehensive links and usually a full transcript. Released as audio and video.
- https://testguild.com/podcasts/performance/
- https://www.youtube.com/playlist?list=PL9AgRtJkydU3pQfcrQmDrGMbx3aNMnLnW
Episode Details
- Show Notes: https://app.testguild.com/podcast/p203-gadi/
- Published: 2026-01-22T14:29:00Z
- Duration: 34:48
- Author: Unknown
Overview
The podcast examines the increasing influence of AI on application security, particularly in the context of dynamic application security testing (DAS) within large financial institutions. It emphasizes how AI is streamlining complex security tasks, such as authentication and shadow API detection, making DAS more efficient and easier for developers to integrate into their workflows. However, it also addresses the risks associated with AI-generated code, highlighting the need for security integration early in the development process to reduce false positives and improve overall efficiency.
A major focus is on STAR, an AI-driven security tool that identifies and automatically resolves vulnerabilities during the development cycle. STAR leverages existing AI coding tools and provides validation to ensure the security of fixes, making it a valuable asset in modern development environments. The tool is described as language-agnostic, scalable, and compatible with current systems, offering features like audit logs, reporting dashboards, and enterprise system integration. While automation plays a key role, the podcast stresses the continued importance of developer engagement with security, emphasizing education and understanding over passive acceptance of automated fixes. The discussion also underscores the need for continuous scanning, adaptation to emerging threats, and a shift from compliance-based approaches to proactive risk management, with metrics like time to fix vulnerabilities and developer productivity serving as key performance indicators for security improvement.
What If
-
What if you integrated AI-powered security tools directly into your CI/CD pipeline to automate dynamic application security testing (DAS)?
- Move: Implement STAR Security Testing to run dynamic scans and auto-remediation during code commits, leveraging its integration with GitHub/GitLab.
- Why_now: With AI-generated code becoming prevalent (e.g., Copilot), vulnerabilities are rising while manual checks are inefficient. STARs auto-remediation cuts resolution time from weeks to hours.
- Expected_upside: Reduced risk exposure by 90% (as shown in the NRI model), faster deployments, and 20-40% higher developer productivity by eliminating false positives.
-
What if you adopted a developer-centric DAS workflow with AI-guided security fixes using your existing coding assistants?
- Move: Configure STAR to trigger guided AI fixes (via GitHub Copilot or Cursor) during unit testing, with context-aware vulnerability suggestions.
- Why_now: Modern developers use AI tools but lack security integration. STAR bridges this gap by aligning code generation with secure practices, reducing 60-70% false positives from static analysis.
- Expected_upside: 80% faster vulnerability resolution, fewer compliance gaps, and a 30% reduction in security debt from legacy issues in AI-generated code.
-
What if you prioritized real-time vulnerability detection with STARs dynamic scanning and iterative remediation for your AI-assisted projects?
- Move: Enable STARs dynamic proof-of-exploitation validation and iterative auto-remediation (up to 6 attempts) for every new API or shadow API in your codebase.
- Why_now: Regulatory pressures and AI-driven cyber threats demand continuous monitoring. STARs 3% false positive rate and rapid validation are unmatched compared to legacy tools.
- Expected_upside: 98% faster time-to-fix vulnerabilities, 50% reduction in audit overhead, and a secure foundation for AI-generated applications in regulated industries.
Takeaway
-
Integrate AI-Powered Dynamic Application Security (DAS) Tools into Your Workflow: Use tools like STAR or Bright Security’s SaaS to automate vulnerability detection, validation, and remediation directly within your codebase (e.g., GitHub, GitLab). This reduces manual effort and integrates seamlessly into your development environment.
- Example: Enable STAR to run in the background during coding, mapping APIs, and intelligently selecting unit tests.
-
Automate Vulnerability Remediation with Guided AI Fixes: Leverage AI tools (e.g., GitHub Copilot) for code fixes by pairing them with security tools that provide context-specific guidance. Validate fixes through dynamic scans to ensure they resolve issues effectively.
- Example: Use STAR to propose fixes, validate them via dynamic testing, and iterate up to six times for resolution.
-
Address AI-Generated Code Vulnerabilities Proactively: When using AI coding assistants (e.g., Cursor, GitHub Copilot), deploy tools like Brightstar to scan for vulnerabilities in generated code. Prioritize fixing legacy security issues in LLM outputs.
- Example: Integrate Brightstars SaaS solution to catch and remediate security risks in code generated by AI models.
-
Reduce False Positives Using Dynamic Validation: Implement tools that use dynamic proof-of-exploitation to validate vulnerabilities, aiming for <3% false positives. Actively manage false positives via customer reports, MSSP scans, or internal CISO testing.
- Example: Configure your DAS tool to discard false positives through continuous learning and contextual validation.
-
Educate Developers on Security Practices via Automation: Use automated security tools to trigger targeted training (e.g., Secure Code Warrior) based on vulnerabilities found. Provide developers with dashboards showing “hotspots” and action items for fixes.
- Example: Set up STAR to generate reports highlighting recurring issues and link them to developer training modules.
For a PDF of longer Software Testing Podcast Episode Summaries with Briefing Notes and more detailed summary notes, visit EvilTester Patreon Podcast Summaries.