Blog

Insights on application security, IAST, RASP, and securing AI-generated code from the Waratek team.

More Stories

  1. Blog

    Mythos Doesn’t Need CVEs: Defending against AI Zero-Days

    How Anthropic's Claude Mythos collapses exploit development from weeks to minutes, and why Waratek …

  2. Blog

    Runtime Reality vs AI Hallucinations in AppSec

    AI-driven static analysis hallucinates vulnerabilities that don't exist, fueling developer fatigue. …

  3. Blog

    Is Your Security Blind to the Party Inside Your App?

    Using a ballroom analogy to explain why SAST and DAST only see the outside of your application, and …

  4. Blog

    Why Your Security Team Needs to Move at AI Speed

    New vulnerabilities and zero-days now emerge faster than human teams can manually patch them. …

  5. Blog

    Oracle Releases April 2026 Critical Patch Update

    Oracle Communications, Fusion Middleware, MySQL, E-Business Suite and Financial Services lead 483 …

  6. Blog

    Moving at the Speed of Thought & No Security Debt

    AI-assisted 'vibe coding' introduces security flaws in nearly 45% of generated code. Waratek IAST …

  7. Blog

    Goldilocks Security: The “Just Right” AppSec Tool 

    Why SAST is too noisy, DAST is too shallow, and IAST is finally hitting the sweet spot for modern …

  8. Blog

    Trust, but Verify: AI Code Supply Chain Security

    AI-generated code and sprawling software supply chains create a false sense of security. Waratek …