From Code to Runtime: Why SAST + DAST Are Both Essential for Modern AppSec
Static analysis alone has never been the full picture, but in modern architectures, that gap is becoming critical. In this SafeDev Talk episode, security leaders and practitioners come together to examine why relying on isolated signals is no longer enough to understand real application risk. The conversation explores how combining code-level analysis (SAST) with runtime visibility (DAST) fundamentally changes the way teams detect, prioritize, and remediate vulnerabilities throughout the software lifecycle. Featuring ๐๐๐ฆ๐๐ซ๐จ๐ง ๐๐๐ฅ๐ญ๐๐ซ๐ฌ (Director of AppSec & Security Engineering, @CoffeeChaosProdSec), ๐๐๐ฆ ๐๐ญ๐๐ฉ๐๐ง๐ฒ๐๐ง (OWASP London Chapter Leader), ๐๐ข๐๐ค ๐๐๐๐ฅ๐ซ๐จ๐ฒ (CEO, NeXasure), and ๐๐ฎ๐ข๐ฌ ๐๐จ๐๐ซรญ๐ ๐ฎ๐๐ณ ๐๐๐ซ๐ณ๐จ๐ฌ๐ (CTO, Xygeni โ https://xygeni.io/), this session brings together perspectives from practitioners operating across enterprise AppSec, DevSecOps, and real-world production environments. The panel breaks down why many organizations (despite heavy investment in static analysis) still face breaches in production. The discussion goes beyond tooling to focus on context: why vulnerabilities that seem low-risk in code can become critical at runtime, how fragmented signals create noise instead of clarity, and why modern AppSec requires continuous, context-aware validation rather than point-in-time scanning. Rather than framing SAST vs DAST as a trade-off, this episode explores how both approaches complement each other, and what it actually takes to connect signals across code, pipeline, and runtime to identify exploitable risk. โญ Key Takeaways โข Why code-level visibility alone is insufficient in modern application environments โข How SAST and DAST complement each other across the software lifecycle โข What types of vulnerabilities only emerge at runtime โข How to move from raw findings to prioritized, exploitable risk โข Practical approaches to integrating security into CI/CD without slowing developers This episode is highly relevant for professionals working in Application Security, DevSecOps, CI/CD Security, Software Supply Chain Security, and platform engineering teams building and operating modern distributed systems. Takeaway: ๐๐จ๐๐๐ซ๐ง ๐๐ฉ๐ฉ๐๐๐ ๐ข๐ฌ ๐ง๐จ ๐ฅ๐จ๐ง๐ ๐๐ซ ๐๐๐จ๐ฎ๐ญ ๐ฆ๐จ๐ซ๐ ๐ญ๐จ๐จ๐ฅ๐ฌ, ๐ข๐ญโ๐ฌ ๐๐๐จ๐ฎ๐ญ ๐๐๐ญ๐ญ๐๐ซ ๐๐จ๐ง๐ญ๐๐ฑ๐ญ. Subscribe to SafeDev Talks and follow Xygeni ย ย /ย xygeniย ย for more expert conversations on AppSec, DevSecOps, and securing modern software from code to runtime. #SafeDevTalks #AppSec #DevSecOps #CyberSecurity #ApplicationSecurity #DAST #SAST #SoftwareSupplyChain #CI/CD #SecurityEngineering #Xygeni

AI Is Already Inside Your SDLC. Now What?

What about Software Supply Chain Security? Essential Insights & Predictions

Identity, the Browser and the New Perimeter

THESE Apps Are SPYING on You โ Shut Them Off NOW!

Trump Attends NBA Finals, Cries Election Fraud in California & Storms Out of Interview

It's time to expect more from your accounting.

How to Pass the Audit? Building Real AppSec aligned with ISO, NIST & CRA

Something is jamming GPS over Europe. Here's what we found

Open Source, AI and the New Attack Surface

Attacking AI - Jason Haddix - NDC Security 2026

Knicks Fans Brand Elmo a Traitor & Trump Storms Out of "Meet the Press" Interview | The Daily Show

Cybersecurity Architecture: Networks

Andrej Karpathy: From Vibe Coding to Agentic Engineering w/ Stephanie Zhan

It finally happened

AI Bubble: How AI's push towards IPOs became a death drive | Ed Zitron

Your Life As Every Cybersecurity Rank

Software Supply Chains Under Pressure: What 2025 Taught Us About Malware & AI and What Comes Next

How AI will change software engineering โ with Martin Fowler

The New AppSec Reality: AI-Driven Development, Malware, and Modern Software Risk

