dast
Safeguard articles tagged "dast" — guides, analysis, and best practices for software supply chain and application security.
127 articles
A Scanner's Scope Guard Belongs in Code, Not in a Config File
The difference between a security test and an unauthorised attack is permission on the target. If that boundary is a setting, then a typo, a redirect or a merged config is all it takes to cross it.
Authenticated DAST: Getting Past the Login Without Wrecking the App
Most of an application is behind a session, so an unauthenticated scan tests the login page and the marketing footer. Getting in is the easy half — staying in, and not clicking Delete Account, is the rest.
Your DAST Scan Has Six Timeouts and No Deadline
Per-phase timeouts add up. Six phases capped at ten minutes each is a sixty-minute scan wearing a ten-minute label — and the phase that mattered gets whatever is left.
Fingerprinting AI-Built Web Apps From the Outside
A DAST scan has no repository and no commit history — only what the server sends a browser. That is enough to identify the builder that generated an app, and nowhere near enough to name the model.
AI Writes Code Faster Than You Can Review It. Which Scanner Do You Point at It?
AI-generated code arrives faster than review can absorb and fails in distinct patterns. SAST, DAST, and reachability each catch part of that — and each misses a specific, predictable slice.
Your DAST Scanner Was Built to Crawl Links. Your Application Doesn't Have Any.
Classic DAST discovers attack surface by following hyperlinks. In an estate of APIs and serverless functions there is nothing to crawl, so the scan completes, reports clean, and covers little.
Medtronic and AdaptHealth: The Third Party Was the Vulnerability
3.8 million people notified by Medtronic. PII, PHI and insurance billing credentials exfiltrated at AdaptHealth after social engineering against a third-party contractor. Neither breach needed a software vulnerability — both needed a trusted outsider with a session.
Polymarket Lost ~$3M Without a Single Smart Contract Bug
On 25–26 June 2026 attackers compromised a third-party vendor and injected malicious code into Polymarket's website frontend, manipulating users into approving fraudulent transactions. Roughly $3M in crypto drained. The smart contracts were never touched. Your client-side dependency tree is production.
A framework for consolidating SAST, DAST, and SCA tools
Enterprises run 45 security tools on average, and 50+ tool stacks detect incidents 8% worse. Here's when AppSec consolidation actually pays off.
Vulnerability Scanners and the Gartner AST Landscape: How the Tools Actually Work
When people search for a vulnerability scanner in the Gartner sense, they usually mean the AST market. Here is what that market covers, how the tool types work, and how to choose.
API security fundamentals: mapping the OWASP API Top 10 to real tests
OWASP's 2023 API Security Top 10 lists 10 risk categories — most start with a single curl request. Here's how to test and fix each one.
Black Box Fuzzing, Explained
Black box fuzzing throws malformed input at a running application with zero knowledge of its internals, and it still finds crashes and memory bugs white box testing misses — here's how it works and where it fits in a security program.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.