From Code to Runtime: Why SAST + DAST Are Both Essential for Modern AppSec

Static analysis alone has never been the full picture, but in modern architectures, that gap is becoming critical. In this SafeDev Talk episode, security leaders and practitioners come together to examine why relying on isolated signals is no longer enough to understand real application risk. The conversation explores how combining code-level analysis (SAST) with runtime visibility (DAST) fundamentally changes the way teams detect, prioritize, and remediate vulnerabilities throughout the software lifecycle. Featuring ๐‚๐š๐ฆ๐ž๐ซ๐จ๐ง ๐–๐š๐ฅ๐ญ๐ž๐ซ๐ฌ (Director of AppSec & Security Engineering, @CoffeeChaosProdSec), ๐’๐š๐ฆ ๐’๐ญ๐ž๐ฉ๐š๐ง๐ฒ๐š๐ง (OWASP London Chapter Leader), ๐‘๐ข๐œ๐ค ๐Œ๐œ๐„๐ฅ๐ซ๐จ๐ฒ (CEO, NeXasure), and ๐‹๐ฎ๐ข๐ฌ ๐‘๐จ๐๐ซรญ๐ ๐ฎ๐ž๐ณ ๐๐ž๐ซ๐ณ๐จ๐ฌ๐š (CTO, Xygeni โ€“ https://xygeni.io/), this session brings together perspectives from practitioners operating across enterprise AppSec, DevSecOps, and real-world production environments. The panel breaks down why many organizations (despite heavy investment in static analysis) still face breaches in production. The discussion goes beyond tooling to focus on context: why vulnerabilities that seem low-risk in code can become critical at runtime, how fragmented signals create noise instead of clarity, and why modern AppSec requires continuous, context-aware validation rather than point-in-time scanning. Rather than framing SAST vs DAST as a trade-off, this episode explores how both approaches complement each other, and what it actually takes to connect signals across code, pipeline, and runtime to identify exploitable risk. โญ Key Takeaways โ€ข Why code-level visibility alone is insufficient in modern application environments โ€ข How SAST and DAST complement each other across the software lifecycle โ€ข What types of vulnerabilities only emerge at runtime โ€ข How to move from raw findings to prioritized, exploitable risk โ€ข Practical approaches to integrating security into CI/CD without slowing developers This episode is highly relevant for professionals working in Application Security, DevSecOps, CI/CD Security, Software Supply Chain Security, and platform engineering teams building and operating modern distributed systems. Takeaway: ๐Œ๐จ๐๐ž๐ซ๐ง ๐€๐ฉ๐ฉ๐’๐ž๐œ ๐ข๐ฌ ๐ง๐จ ๐ฅ๐จ๐ง๐ ๐ž๐ซ ๐š๐›๐จ๐ฎ๐ญ ๐ฆ๐จ๐ซ๐ž ๐ญ๐จ๐จ๐ฅ๐ฌ, ๐ข๐ญโ€™๐ฌ ๐š๐›๐จ๐ฎ๐ญ ๐›๐ž๐ญ๐ญ๐ž๐ซ ๐œ๐จ๐ง๐ญ๐ž๐ฑ๐ญ. Subscribe to SafeDev Talks and follow Xygeni ย ย /ย xygeniย ย  for more expert conversations on AppSec, DevSecOps, and securing modern software from code to runtime. #SafeDevTalks #AppSec #DevSecOps #CyberSecurity #ApplicationSecurity #DAST #SAST #SoftwareSupplyChain #CI/CD #SecurityEngineering #Xygeni

AI Is Already Inside Your SDLC. Now What?
โ–ถ๏ธŽ

AI Is Already Inside Your SDLC. Now What?

What about Software Supply Chain Security? Essential Insights & Predictions
โ–ถ๏ธŽ

What about Software Supply Chain Security? Essential Insights & Predictions

Identity, the Browser and the New Perimeter
โ–ถ๏ธŽ

Identity, the Browser and the New Perimeter

THESE Apps Are SPYING on You โ€” Shut Them Off NOW!
โ–ถ๏ธŽ

THESE Apps Are SPYING on You โ€” Shut Them Off NOW!

Trump Attends NBA Finals, Cries Election Fraud in California & Storms Out of Interview
โ–ถ๏ธŽ

Trump Attends NBA Finals, Cries Election Fraud in California & Storms Out of Interview

It's time to expect more from your accounting.
โ–ถ๏ธŽ

It's time to expect more from your accounting.

How to Pass the Audit? Building Real AppSec aligned with ISO, NIST & CRA
โ–ถ๏ธŽ

How to Pass the Audit? Building Real AppSec aligned with ISO, NIST & CRA

Something is jamming GPS over Europe. Here's what we found
โ–ถ๏ธŽ

Something is jamming GPS over Europe. Here's what we found

Open Source, AI and the New Attack Surface
โ–ถ๏ธŽ

Open Source, AI and the New Attack Surface

Attacking AI - Jason Haddix - NDC Security 2026
โ–ถ๏ธŽ

Attacking AI - Jason Haddix - NDC Security 2026

Knicks Fans Brand Elmo a Traitor & Trump Storms Out of "Meet the Press" Interview | The Daily Show
โ–ถ๏ธŽ

Knicks Fans Brand Elmo a Traitor & Trump Storms Out of "Meet the Press" Interview | The Daily Show

Cybersecurity Architecture: Networks
โ–ถ๏ธŽ

Cybersecurity Architecture: Networks

Andrej Karpathy: From Vibe Coding to Agentic Engineering w/ Stephanie Zhan
โ–ถ๏ธŽ

Andrej Karpathy: From Vibe Coding to Agentic Engineering w/ Stephanie Zhan

It finally happened
โ–ถ๏ธŽ

It finally happened

AI Bubble: How AI's push towards IPOs became a death drive | Ed Zitron
โ–ถ๏ธŽ

AI Bubble: How AI's push towards IPOs became a death drive | Ed Zitron

Your Life As Every Cybersecurity Rank
โ–ถ๏ธŽ

Your Life As Every Cybersecurity Rank

Software Supply Chains Under Pressure: What 2025 Taught Us About Malware & AI and What Comes Next
โ–ถ๏ธŽ

Software Supply Chains Under Pressure: What 2025 Taught Us About Malware & AI and What Comes Next

How AI will change software engineering โ€“ with Martin Fowler
โ–ถ๏ธŽ

How AI will change software engineering โ€“ with Martin Fowler

The New AppSec Reality: AI-Driven Development, Malware, and Modern Software Risk
โ–ถ๏ธŽ

The New AppSec Reality: AI-Driven Development, Malware, and Modern Software Risk

The Biggest Lies in Cybersecurity
โ–ถ๏ธŽ

The Biggest Lies in Cybersecurity