The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
AI Pen Testing Killed Traditional DAST
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generated with context about your actual application, agents that chase findings the way a human tester would, and results a scanner was never going to produce. We get into what it costs once tokens enter the picture, who pays for them, whether a pentest on every pull request is realistic, and what stops an autonomous tester from going further than it should. Then we look further out: the future of bug bounties, what happens when cloud and model providers absorb today's security tooling, and who is accountable when an agent deletes your production database.
This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
→ Learn more about Corgea
Connect with James Berthoty:
→ James Berthoty on LinkedIn
→ Latio
→ Latio Pulse
Mentioned in this episode:
→ Latio's free reports
→ James on the podcast the first time: Is DAST Dead? And the future of API security
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
Chapters:
00:00 Cold open — the results speak for themselves
01:01 Meet James Berthoty and the "Is DAST dead?" fallout
01:31 Chickens, eggs, and getting away from screens
03:46 Why we're revisiting the DAST question
04:14 A working definition of AI pentesting
05:47 Contextual payloads and application awareness
06:47 Determinism, repeatability, and what buyers actually want
07:46 Can you run an AI pentest on every code change?
09:43 What it really costs
10:40 Incumbents vs. AI-native vendors
13:27 Who pays for the tokens?
14:29 Bundling, platforms, and competitive pressure
16:25 AI across the whole development workflow
18:22 Agents that run all the way to deployment
19:21 A pentest on every pull request
21:52 What stops a pentest from going too far?
23:10 Permission scoping and guardrails
26:07 Where the findings actually land
28:02 The future of bug bounties
30:50 Why pentests command more budget than DAST
31:45 Could the cloud providers absorb security tooling?
34:38 What model providers could build instead
36:36 The same story on the code scanning side
39:24 Accountability when the tool misses something
40:22 Shared responsibility when an agent deletes production
41:23 The verdict on DAST
42:19 Where to find Latio's free reports
43:15 Closing thoughts
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo