EPISODE · Aug 31, 2026 · 43 MIN
AI Pen Testing Killed Traditional DAST
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generated with context about your actual application, agents that chase findings the way a human tester would, and results a scanner was never going to produce. We get into what it costs once tokens enter the picture, who pays for them, whether a pentest on every pull request is realistic, and what stops an autonomous tester from going further than it should. Then we look further out: the future of bug bounties, what happens when cloud and model providers absorb today's security tooling, and who is accountable when an agent deletes your production database.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with James Berthoty:→ James Berthoty on LinkedIn→ Latio→ Latio PulseMentioned in this episode:→ Latio's free reports→ James on the podcast the first time: Is DAST Dead? And the future of API securityFollow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — the results speak for themselves01:01 Meet James Berthoty and the "Is DAST dead?" fallout01:31 Chickens, eggs, and getting away from screens03:46 Why we're revisiting the DAST question04:14 A working definition of AI pentesting05:47 Contextual payloads and application awareness06:47 Determinism, repeatability, and what buyers actually want07:46 Can you run an AI pentest on every code change?09:43 What it really costs10:40 Incumbents vs. AI-native vendors13:27 Who pays for the tokens?14:29 Bundling, platforms, and competitive pressure16:25 AI across the whole development workflow18:22 Agents that run all the way to deployment19:21 A pentest on every pull request21:52 What stops a pentest from going too far?23:10 Permission scoping and guardrails26:07 Where the findings actually land28:02 The future of bug bounties30:50 Why pentests command more budget than DAST31:45 Could the cloud providers absorb security tooling?34:38 What model providers could build instead36:36 The same story on the code scanning side39:24 Accountability when the tool misses something40:22 Shared responsibility when an agent deletes production41:23 The verdict on DAST42:19 Where to find Latio's free reports43:15 Closing thoughts
Embed this episode
What this episode covers
Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generated with context about your actual application, agents that chase findings the way a human tester would, and results a scanner was never going to produce. We get into what it costs once tokens enter the picture, who pays for them, whether a pentest on eve...
Ready to play
AI Pen Testing Killed Traditional DAST
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.