The evolution of app sec: Getting off the scan-and-fix hamster wheel remains elusive
ID: 49674bc2-e2dc-5599-ac37-706afaa76849
STIX ID: report--49674bc2-e2dc-5599-ac37-706afaa76849
Feed Name: ReversingLabs Blog
Date Published: 2023-10-12
Date Updated: 2026-04-29
Author: [email protected] (John P. Mello Jr.)
This piece critiques the scan-and-fix paradigm in application security, arguing that “shift-left” alone doesn’t solve the problem and exploring alternatives like RASP/IAST, IDE-integrated checks, and AI-driven remediation. Experts debate feasibility, performance, and developer workflow impacts, with a consensus emerging around the need for prioritization, contextualization, and smarter tools to reduce noise and focus on remediation that aligns with clearly defined risk policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
