From Austin OWASP June 2025 Meeting
Static analysis was built for yesterday’s code. Its rule-based engines still hunt for familiar strings while AI assistants generate brand-new logic paths at record speed. The result? False positives everywhere, real vulnerabilities left open, and developers who treat security findings like background noise.
In this 40-minute session, James Wickett, CEO & Co-Founder of DryRun Security, hits “rewind” to show where traditional SAST got stuck—and fast-forwards to a context-first approach that finally keeps pace with modern development. Drawing on fresh data from the 2025 SAST Accuracy Report and real cod stories, James will:
Contrast patterns vs. context — why deterministic rules miss IDOR, broken auth, and AI-generated edge cases.
Unpack probabilistic scanning — how contextual signals cut noise without sacrificing coverage.
Contextual Security Analysis in Action — a live authorization flaw that slipped through regex nets.
Share a plan for AI readiness for AppSec — tools, projects, resources to plan for AI readiness for your appsec or product security program.
Attendees will leave with open-source resources, clear ROI talking points for leadership, and a practical roadmap to upgrade their AppSec program for the AI era—no VHS tape required."