The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Application Security Weekly
Application Security Weekly artwork

Scanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386

Application Security Weekly · 2026-06-09 · 1h 16m

0:00--:--

Episode notes

Most AppSec teams are working through more findings than their teams can validate. SAST surfaces thousands of potential issues. DAST generates alert volume that outpaces triage capacity. Somewhere in that output are the vulnerabilities that matter, the ones that are actually exploitable in production. This conversation explores why automated testing often stops short of the hardest part of the job: proving what is real. We dig into how business logic flaws and authorization vulnerabilities get missed by tools that scan without reasoning, what exploit validation looks like at runtime, and how security engineers are shifting toward findings that developers will actually act on. The segment is sponsored by XBOW. Visit to see how autonomous AI pentesting delivers expert-quality findings in hours with real exploit validation your team can actually act on. Visit for all the latest episodes! Show Notes:

More from Application Security Weekly

All episodes →
  • Reducing Attack Surface & Evaluating Efficiency in Agents - Itamar Apelblat, David Goldschlag - ASW #38978 / 100
  • How AI Is Reshaping Identity Security at the Infrastructure Layer - Amit Masand, Neha Duggal, Ev Kontsevoy - ASW #388
  • Why Does It Matter Who or What Created the Code? - Matias Madou - ASW #387
  • BadHost, Dead CTFs, Exploding NPMs, and the Verizon DBIR - ASW #385
  • AppSec Conversations on Agents, LLMs, and OWASP from RSAC - Merritt Maxim, Scott Clinton, Janet Worthington - ASW #384
Explore the best B2B Engineering & DevTools podcasts →
All Application Security Weekly episodes →