﻿<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[All Things AppSec]]></title><description><![CDATA[Learn the ins and outs of application security brought to you by the team at Beagle Security.]]></description><link>https://beaglesecurity.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!pByK!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34635baa-dc56-4128-bff9-f23f5b63e4f5_388x388.png</url><title>All Things AppSec</title><link>https://beaglesecurity.substack.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 07 Aug 2026 09:04:54 GMT</lastBuildDate><atom:link href="https://beaglesecurity.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Beagle Security]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[beaglesecurity@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[beaglesecurity@substack.com]]></itunes:email><itunes:name><![CDATA[Rejah Rehim]]></itunes:name></itunes:owner><itunes:author><![CDATA[Rejah Rehim]]></itunes:author><googleplay:owner><![CDATA[beaglesecurity@substack.com]]></googleplay:owner><googleplay:email><![CDATA[beaglesecurity@substack.com]]></googleplay:email><googleplay:author><![CDATA[Rejah Rehim]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Do you need an AppSec engineer?]]></title><description><![CDATA[There&#8217;s a version of this question that gets asked in every engineering firm at some point. Let's try to figure out the answer.]]></description><link>https://beaglesecurity.substack.com/p/do-you-need-an-appsec-engineer</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/do-you-need-an-appsec-engineer</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Wed, 29 Jul 2026 13:30:18 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/ebc98916-3e6a-4b11-8950-886ce189bb2c_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>There&#8217;s a version of this question that gets asked in every engineering firm at some point. It&#8217;s usually right after a security incident, or right before a big compliance push, or when someone forwards a scary CVE and nobody in the room knows what to do with it.</span></p><p><span>Do we need one?</span></p><p><span>And honestly, it&#8217;s not a simple yes or no. Because &#8216;AppSec engineer&#8217; means very different things depending on where your company is, what you&#8217;re building, and how much security debt you&#8217;ve already accumulated without realizing it.</span></p><p><span>What&#8217;s interesting though is that more people are asking it. Search interest for &#8216;application security engineer&#8217; is up 400% compared to the preceding five years, with a sharp spike starting in late 2025 that&#8217;s still climbing. Something shifted. Whether that&#8217;s AI making attack surfaces bigger, compliance pressure catching up, or companies finally waking up to security debt they&#8217;d been ignoring, whatever it may be, the question is now more urgent than it used to be.</span></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eUov!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa30e51c3-b73f-4fe0-985a-3a0db8c14950_2048x434.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eUov!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa30e51c3-b73f-4fe0-985a-3a0db8c14950_2048x434.png 424w, https://substackcdn.com/image/fetch/$s_!eUov!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa30e51c3-b73f-4fe0-985a-3a0db8c14950_2048x434.png 848w, https://substackcdn.com/image/fetch/$s_!eUov!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa30e51c3-b73f-4fe0-985a-3a0db8c14950_2048x434.png 1272w, https://substackcdn.com/image/fetch/$s_!eUov!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa30e51c3-b73f-4fe0-985a-3a0db8c14950_2048x434.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eUov!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa30e51c3-b73f-4fe0-985a-3a0db8c14950_2048x434.png" width="1456" height="309" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a30e51c3-b73f-4fe0-985a-3a0db8c14950_2048x434.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:309,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eUov!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa30e51c3-b73f-4fe0-985a-3a0db8c14950_2048x434.png 424w, https://substackcdn.com/image/fetch/$s_!eUov!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa30e51c3-b73f-4fe0-985a-3a0db8c14950_2048x434.png 848w, https://substackcdn.com/image/fetch/$s_!eUov!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa30e51c3-b73f-4fe0-985a-3a0db8c14950_2048x434.png 1272w, https://substackcdn.com/image/fetch/$s_!eUov!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa30e51c3-b73f-4fe0-985a-3a0db8c14950_2048x434.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><span>So here&#8217;s an honest breakdown, along with a graph of AppSec engineers currently working, related to the company size.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HIsg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff250a1-7bfe-4b7b-ad70-a77948b3bb63_2048x1468.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HIsg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff250a1-7bfe-4b7b-ad70-a77948b3bb63_2048x1468.png 424w, https://substackcdn.com/image/fetch/$s_!HIsg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff250a1-7bfe-4b7b-ad70-a77948b3bb63_2048x1468.png 848w, https://substackcdn.com/image/fetch/$s_!HIsg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff250a1-7bfe-4b7b-ad70-a77948b3bb63_2048x1468.png 1272w, https://substackcdn.com/image/fetch/$s_!HIsg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff250a1-7bfe-4b7b-ad70-a77948b3bb63_2048x1468.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HIsg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff250a1-7bfe-4b7b-ad70-a77948b3bb63_2048x1468.png" width="1456" height="1044" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bff250a1-7bfe-4b7b-ad70-a77948b3bb63_2048x1468.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1044,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HIsg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff250a1-7bfe-4b7b-ad70-a77948b3bb63_2048x1468.png 424w, https://substackcdn.com/image/fetch/$s_!HIsg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff250a1-7bfe-4b7b-ad70-a77948b3bb63_2048x1468.png 848w, https://substackcdn.com/image/fetch/$s_!HIsg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff250a1-7bfe-4b7b-ad70-a77948b3bb63_2048x1468.png 1272w, https://substackcdn.com/image/fetch/$s_!HIsg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbff250a1-7bfe-4b7b-ad70-a77948b3bb63_2048x1468.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><span>If you&#8217;re at an early stage, you probably don&#8217;t need one yet.</span></strong></p><p><span>Not because security doesn&#8217;t matter, it genuinely does. But an AppSec engineer at a 15 person start up is expensive, often underutilized, and solving problems that don&#8217;t fully exist yet.</span></p><p><span>The numbers actually back this up. Companies under 50 employees account for a combined 443 AppSec engineers on LinkedIn. That&#8217;s the bottom three tiers combined, which tells you most early stage companies aren&#8217;t hiring for this yet, and for the most part they&#8217;re probably right not to.</span></p><p><span>What you actually need at this stage is security awareness baked into the engineers you already have. Basic practices, dependency scanning, not storing secrets in your repo, these are some basic fundamentals that an AppSec engineer would tell you to do anyway, but that don&#8217;t require a full time hire to implement.</span></p><p><span>The exception is if you&#8217;re building in a regulated space like fintech or healthcare, or anything that touches sensitive data at scale. Then you need someone earlier than you think.</span></p><p><strong><span>If you&#8217;re growing and starting to feel the gaps, that&#8217;s the signal.</span></strong></p><p><span>Now this is where things get real. You&#8217;ve got a product that&#8217;s getting traction, maybe some enterprise customers starting to ask about security questionnaires, a pentest report sitting somewhere that nobody&#8217;s fully actioned. Your engineers care about security but it&#8217;s nobody&#8217;s actual job.</span></p><p><span>That&#8217;s when an AppSec engineer starts making sense. Their job is not to own security entirely, but to sit inside the engineering team, catch things earlier, and make security part of how the team already works rather than a separate audit that happens twice a year.</span></p><p><span>Here&#8217;s where the data gets interesting though. Hiring actually peaks at the 51 to 200 headcount range with 358 AppSec engineers, then dips slightly for companies between 201 and 1000. That dip is worth paying attention to. Those are companies big enough to have real security exposure but apparently still deciding whether the hire is justified. That&#8217;s exactly where the mistake gets made. By the time security is on fire, you&#8217;re not hiring thoughtfully, you&#8217;re panic hiring.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!p3ZH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245300d4-8936-42f2-822b-3c79709c3839_2048x1468.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!p3ZH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245300d4-8936-42f2-822b-3c79709c3839_2048x1468.png 424w, https://substackcdn.com/image/fetch/$s_!p3ZH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245300d4-8936-42f2-822b-3c79709c3839_2048x1468.png 848w, https://substackcdn.com/image/fetch/$s_!p3ZH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245300d4-8936-42f2-822b-3c79709c3839_2048x1468.png 1272w, https://substackcdn.com/image/fetch/$s_!p3ZH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245300d4-8936-42f2-822b-3c79709c3839_2048x1468.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!p3ZH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245300d4-8936-42f2-822b-3c79709c3839_2048x1468.png" width="1456" height="1044" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/245300d4-8936-42f2-822b-3c79709c3839_2048x1468.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1044,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!p3ZH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245300d4-8936-42f2-822b-3c79709c3839_2048x1468.png 424w, https://substackcdn.com/image/fetch/$s_!p3ZH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245300d4-8936-42f2-822b-3c79709c3839_2048x1468.png 848w, https://substackcdn.com/image/fetch/$s_!p3ZH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245300d4-8936-42f2-822b-3c79709c3839_2048x1468.png 1272w, https://substackcdn.com/image/fetch/$s_!p3ZH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245300d4-8936-42f2-822b-3c79709c3839_2048x1468.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><span>If you&#8217;re at scale, one isn&#8217;t enough.</span></strong></p><p><span>A single AppSec engineer at a company with dozens of engineers and multiple products is stretched thin almost immediately. They become a bottleneck, since they are the person every team needs to sign off on things, which slows everyone down and burns them out fast.</span></p><p><span>The enterprise numbers make this obvious. Companies with over 10,000 employees account for 1000+ AppSec engineers alone, and companies between 1001 and 5000 aren&#8217;t far behind with 981. At that scale it stopped being a &#8216;should we hire one&#8217; conversation a long time ago. The question is how many, and how they&#8217;re structured.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3cs6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3cs6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png 424w, https://substackcdn.com/image/fetch/$s_!3cs6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png 848w, https://substackcdn.com/image/fetch/$s_!3cs6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!3cs6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3cs6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png" width="1456" height="1044" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1044,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:177152,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://beaglesecurity.substack.com/i/208956906?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3cs6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png 424w, https://substackcdn.com/image/fetch/$s_!3cs6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png 848w, https://substackcdn.com/image/fetch/$s_!3cs6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!3cs6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bec6a11-2d35-4947-9d10-eed2bce8b409_2790x2000.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>At this stage the question shifts from &#8216;do we need one&#8217; to &#8216;how do we build a security function that scales.&#8217; Which usually means a mix of dedicated AppSec engineers, tooling that automates the repetitive stuff, and security champions embedded in each product team who aren&#8217;t specialists but know enough to catch the obvious things.</span></p><p><span>The honest answer to &#8216;do you need an AppSec engineer&#8217; is probably yes, just maybe not as soon as you think, and definitely not as a substitute for building security into how your team works from the start.</span></p><p><span>A single person owning security is always going to be a weaker position than security being part of how the whole team works.</span></p><p><span>Where are you on this? Have you made the hire, or are you still figuring out if it&#8217;s the right moment? Drop it in the comments.</span></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[What level of AI fluency does your AppSec team actually have?]]></title><description><![CDATA[This edition of All Things AppSec is a short read, but it&#8217;s about something that has been on my mind for a while.]]></description><link>https://beaglesecurity.substack.com/p/what-level-of-ai-fluency-does-your</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/what-level-of-ai-fluency-does-your</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Thu, 25 Jun 2026 13:46:08 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/dea363d6-9dad-4cb0-b8da-beffd7e1d97c_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This edition of All Things AppSec is a short read, but it&#8217;s about something that has been on my mind for a while. You probably have had this cross your mind too, and hopefully, reading this would make it a small bit clearer.</p><p>Everybody&#8217;s using AI for security work now, but almost nobody can exactly say how.</p><p>Ask a team if they&#8217;re &#8216;doing AI&#8217; in AppSec and most will say yes, but ask what that actually looks like day to day and the answers get vague fast. It could be a tool here, a script there or maybe, someone&#8217;s just using AI to draft pentest reports faster. It&#8217;s adoption without much sense of where the team actually stands.</p><p>The problem isn&#8217;t that teams aren&#8217;t trying. It&#8217;s that there&#8217;s no shared language for what &#8216;good&#8217; looks like at each stage, so every team just assumes they&#8217;re doing fine. Fine compared to what, though?</p><p>So here&#8217;s a rubric. Three levels, describing what AI fluency actually looks like in practice rather than in theory.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q7sa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q7sa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png 424w, https://substackcdn.com/image/fetch/$s_!q7sa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png 848w, https://substackcdn.com/image/fetch/$s_!q7sa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!q7sa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q7sa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png" width="1456" height="1044" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1044,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:569763,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://beaglesecurity.substack.com/i/203547408?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!q7sa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png 424w, https://substackcdn.com/image/fetch/$s_!q7sa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png 848w, https://substackcdn.com/image/fetch/$s_!q7sa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!q7sa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88045c1f-c4cc-42f1-9d97-e03b1b49ad27_2790x2000.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most teams reading this will land somewhere between <strong>Capable</strong> and <strong>Adoptive</strong>, and that&#8217;s honestly fine. The point of a rubric isn&#8217;t to make you feel behind, it&#8217;s to give you language for where you are and what the next level actually requires instead of guessing.</p><p>At <strong>Capable</strong>, this usually looks like a security engineer feeding scan output into an AI tool to summarise what&#8217;s critical and what&#8217;s noise. It&#8217;s useful and it genuinely saves time. But it&#8217;s still the same workflow underneath. A human still reviews every finding, just with a faster first pass.</p><p>At <strong>Adoptive</strong>, the team asks a different question. Should a human be looking at every finding in the first place? So instead of speeding up the old workflow, they rebuild it. AI clusters duplicate findings, cross-references each one against known exploitability data, and only what survives both filters reaches a human reviewer. The review still happens, there&#8217;s just far less of it, and what&#8217;s left actually matters.</p><p><strong>Transformative</strong> is rarer, and not something worth rushing toward for its own sake. This is where the review step itself starts disappearing for entire categories of findings. Continuous pentesting runs as a permanent layer instead of a quarterly event and AppSec stops being a list of tasks someone works through and becomes something that scales with the product instead of headcount.</p><p>It&#8217;s also the level a lot of the automation we build at Beagle Security is aimed at, even if most teams using it today sit comfortably at <strong>Capable</strong> or <strong>Adoptive</strong>.</p><p>Where does your team actually land? Be honest, not aspirational.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Shift left was the right idea. Here’s why it’s still not working]]></title><description><![CDATA[Shift left was the right call. The execution just never caught up.
This edition breaks down why the habit never formed, and what it actually takes to make it work.]]></description><link>https://beaglesecurity.substack.com/p/shift-left-was-the-right-idea-heres</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/shift-left-was-the-right-idea-heres</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Wed, 03 Jun 2026 13:30:26 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/dad49147-342b-47b9-bdef-f59b8ffd6540_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Somewhere in the mid 2010s, the entire security industry collectively decided that waiting until production to solve vulnerabilities was a problem. So the fix? Move security earlier, test during development and catch it before it ships.</p><p>Smart idea honestly, hard to argue with. Everyone bought into this.</p><p>And yet, critical vulnerabilities are still showing up in production. Teams are still having those &#8216;how did this make it through&#8217; conversations weeks after shipping. The mantra spread but the habit didn&#8217;t.</p><p>So the question is, what happened?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ffv-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ffv-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png 424w, https://substackcdn.com/image/fetch/$s_!Ffv-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png 848w, https://substackcdn.com/image/fetch/$s_!Ffv-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!Ffv-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ffv-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png" width="1456" height="1044" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1044,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:750701,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://beaglesecurity.substack.com/i/200429059?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ffv-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png 424w, https://substackcdn.com/image/fetch/$s_!Ffv-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png 848w, https://substackcdn.com/image/fetch/$s_!Ffv-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!Ffv-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe86f6a6e-f18d-45f4-acc2-2f84b255afff_2790x2000.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The tools showed up. Developers didn&#8217;t.</strong></h2><p>Shift left got treated as a tooling problem. Buy the right scanner, plug it into the pipeline and call it a day. Security shifted, apparently.</p><p>Except developers started drowning in alerts. Hundreds of findings per scan and most of them were noise. Misconfigurations that don&#8217;t even apply, libraries nobody&#8217;s actually using, stuff flagged as critical that really isn&#8217;t. False positives aren&#8217;t just annoying though, they also kill trust. Once a developer figures out that most alerts are garbage, they start treating all alerts like garbage. And then the one real thing sits ignored in a queue for three weeks.</p><h2><strong>Nobody thought about how developers actually work.</strong></h2><p>Developers work in sprints, two weeks, ship something, move on. Security testing was built around a completely different rhythm, one with long engagements, big reports and findings dropped at the end of a cycle that nobody really asked for in the first place.</p><p>Those two things just don&#8217;t fit.</p><p>If a security test takes longer than a sprint, developers are already three features ahead by the time results come back. Fixing a vulnerability in code you wrote six weeks ago, in a feature that&#8217;s already been built on top of, that&#8217;s not &#8216;shift left&#8217;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M3Qc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M3Qc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png 424w, https://substackcdn.com/image/fetch/$s_!M3Qc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png 848w, https://substackcdn.com/image/fetch/$s_!M3Qc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!M3Qc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M3Qc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png" width="1456" height="1044" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1044,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:616224,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://beaglesecurity.substack.com/i/200429059?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!M3Qc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png 424w, https://substackcdn.com/image/fetch/$s_!M3Qc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png 848w, https://substackcdn.com/image/fetch/$s_!M3Qc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!M3Qc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F818c4950-ae48-422a-b36b-61e4ba9414cf_2790x2000.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>The friction nobody talks about.</strong></h2><p>Even when the tooling works and the timing is fine, there&#8217;s something subtler going on. Security is asking developers to care about something they were never really trained for. It&#8217;s not because they&#8217;re careless, but because their job is to ship. Every hour spent on a security finding is an hour off a feature due Friday. Security and speed feel like opposites, and until that&#8217;s sorted at a structural level, shift left just becomes something you say in standups and ignore.</p><h2><strong>So what makes it actually stick?</strong></h2><p>A few things, and none of them are revolutionary.</p><p>Testing needs to run automatically as part of how developers already work, not as a separate step someone schedules and forgets about until the next sprint review.</p><p>The results need to be usable on the same day too. Not a 200 page PDF that lands in someone&#8217;s inbox on a Friday but something that shows what&#8217;s broken, where it is, how serious it is and what to do about it before the next standup.</p><p>The coverage needs to go deeper than surface scans. Authenticated flows, business logic, the stuff that only shows up once you&#8217;re actually inside the app rather than knocking on the door.</p><p>Most teams have one or two of these. Getting all of them in the same place is where shift left actually starts working and honestly that&#8217;s the part the industry has been slow to figure out.</p><p>It&#8217;s also the part that we&#8217;ve always cared most about getting right at Beagle Security. Not another scanner throwing noise into the void, but something that actually fits into how dev teams already move. Automatic testing on every build, findings developers can actually act on, and coverage that goes deeper than a surface scan.</p><p>Shift left was always the right call. The execution just needed to catch up.</p><p>Is shift left actually working on your team, or is it just another thing that lives in a doc nobody reads? We&#8217;re genuinely curious.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The things only a manual pentester could do. Until now. ]]></title><description><![CDATA[There was a time, not too long ago, when the best security testing money could buy came down to one thing: a really smart human, sitting in front of your app, poking around like they had something to prove.]]></description><link>https://beaglesecurity.substack.com/p/the-things-only-a-manual-pentester</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/the-things-only-a-manual-pentester</guid><dc:creator><![CDATA[Rejah Rehim]]></dc:creator><pubDate>Wed, 20 May 2026 14:02:17 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/f3119ab0-2508-46e0-87d9-f7111b585800_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There was a time, not too long ago, when the best security testing money could buy came down to one thing: a really smart human, sitting in front of your app, poking around like they had something to prove.</p><p>No playbooks, no checklists, just someone who&#8217;d seen enough broken systems to know exactly where to look.</p><p>And these guys did things no automated tools could touch. Not because the tools were bad, but because what these people were doing wasn&#8217;t really scanning. They were thinking.</p><h2><strong>Business logic intuition</strong></h2><p>Let&#8217;s consider a discount coupon that is applicable on an e-commerce company.</p><p>A manual pentester looks at your &#8216;apply coupon&#8217; flow and doesn&#8217;t just test if the coupon works. They think - what if I apply it twice? What if I apply it after checkout? What if I intercept the request halfway?</p><p>No script covers that. That&#8217;s someone who&#8217;s genuinely curious about how things can fall apart, armed with too much coffee and a very specific type of thinking. That is inherently human, someone who can think in ways automated tools can&#8217;t.</p><p>It&#8217;s quite simple, automated tools test what they&#8217;re told to test while humans ask the questions nobody thought to write down.</p><h2><strong>Chained exploits</strong></h2><p>Automated scanners are bad at connecting dots, like genuinely bad.</p><p>One misconfiguration leads to a slightly bigger one, which further leads to a &#8220;wait, how did they even get here&#8221; moment. Tools flag the misconfiguration and move on. Humans go a step further, as in &#8220;okay, but what could someone do with this&#8221;. And the next thing. And the next. In other words, humans think.</p><p>Often it&#8217;s the pathways that are the problem, not the individual findings.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YukA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F505fe48e-245a-44a0-b1bf-70c756fea29f_2048x1197.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YukA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F505fe48e-245a-44a0-b1bf-70c756fea29f_2048x1197.png 424w, https://substackcdn.com/image/fetch/$s_!YukA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F505fe48e-245a-44a0-b1bf-70c756fea29f_2048x1197.png 848w, https://substackcdn.com/image/fetch/$s_!YukA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F505fe48e-245a-44a0-b1bf-70c756fea29f_2048x1197.png 1272w, https://substackcdn.com/image/fetch/$s_!YukA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F505fe48e-245a-44a0-b1bf-70c756fea29f_2048x1197.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YukA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F505fe48e-245a-44a0-b1bf-70c756fea29f_2048x1197.png" width="1456" height="851" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/505fe48e-245a-44a0-b1bf-70c756fea29f_2048x1197.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:851,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YukA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F505fe48e-245a-44a0-b1bf-70c756fea29f_2048x1197.png 424w, https://substackcdn.com/image/fetch/$s_!YukA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F505fe48e-245a-44a0-b1bf-70c756fea29f_2048x1197.png 848w, https://substackcdn.com/image/fetch/$s_!YukA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F505fe48e-245a-44a0-b1bf-70c756fea29f_2048x1197.png 1272w, https://substackcdn.com/image/fetch/$s_!YukA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F505fe48e-245a-44a0-b1bf-70c756fea29f_2048x1197.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Creative attack paths</strong></h2><p>This is the weird stuff, the &#8220;nobody would ever try this&#8221; stuff.</p><p>Except, someone would. When you&#8217;re paid to break into something, the &#8220;nobody would ever try this&#8221; stuff is basically an invitation to try exactly that.</p><p>Manual testers bring this energy naturally - the obvious attack paths could be boring, but this boredom is a useful feature for a pentester. It pushes them to corners, edge cases and those weird stuff or pathways that a creative attacker could target.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j527!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f996928-6590-4a24-aa93-bc0b8680a2ac_2048x1197.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j527!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f996928-6590-4a24-aa93-bc0b8680a2ac_2048x1197.png 424w, https://substackcdn.com/image/fetch/$s_!j527!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f996928-6590-4a24-aa93-bc0b8680a2ac_2048x1197.png 848w, https://substackcdn.com/image/fetch/$s_!j527!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f996928-6590-4a24-aa93-bc0b8680a2ac_2048x1197.png 1272w, https://substackcdn.com/image/fetch/$s_!j527!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f996928-6590-4a24-aa93-bc0b8680a2ac_2048x1197.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j527!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f996928-6590-4a24-aa93-bc0b8680a2ac_2048x1197.png" width="1456" height="851" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f996928-6590-4a24-aa93-bc0b8680a2ac_2048x1197.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:851,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j527!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f996928-6590-4a24-aa93-bc0b8680a2ac_2048x1197.png 424w, https://substackcdn.com/image/fetch/$s_!j527!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f996928-6590-4a24-aa93-bc0b8680a2ac_2048x1197.png 848w, https://substackcdn.com/image/fetch/$s_!j527!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f996928-6590-4a24-aa93-bc0b8680a2ac_2048x1197.png 1272w, https://substackcdn.com/image/fetch/$s_!j527!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f996928-6590-4a24-aa93-bc0b8680a2ac_2048x1197.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Authenticated flow testing</strong></h2><p>Now here&#8217;s the secret.</p><p>Most automated scanners don&#8217;t actually log in. They knock on the door, rattle the handle, check if it is locked and then write you a nice PDF about the door. Manual testers on the other hand actually go inside. They switch roles, do things in the wrong order, press the wrong link, basically acting just like a real hacker trying to attack your application.</p><p>A huge chunk of vulnerabilities live behind authentication. And for a long time, the only way to find them was to send a human.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KYV9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b49aac-ec1f-4256-8fc4-9867b0b3cdd1_2048x1197.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KYV9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b49aac-ec1f-4256-8fc4-9867b0b3cdd1_2048x1197.png 424w, https://substackcdn.com/image/fetch/$s_!KYV9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b49aac-ec1f-4256-8fc4-9867b0b3cdd1_2048x1197.png 848w, https://substackcdn.com/image/fetch/$s_!KYV9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b49aac-ec1f-4256-8fc4-9867b0b3cdd1_2048x1197.png 1272w, https://substackcdn.com/image/fetch/$s_!KYV9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b49aac-ec1f-4256-8fc4-9867b0b3cdd1_2048x1197.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KYV9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b49aac-ec1f-4256-8fc4-9867b0b3cdd1_2048x1197.png" width="1456" height="851" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08b49aac-ec1f-4256-8fc4-9867b0b3cdd1_2048x1197.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:851,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KYV9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b49aac-ec1f-4256-8fc4-9867b0b3cdd1_2048x1197.png 424w, https://substackcdn.com/image/fetch/$s_!KYV9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b49aac-ec1f-4256-8fc4-9867b0b3cdd1_2048x1197.png 848w, https://substackcdn.com/image/fetch/$s_!KYV9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b49aac-ec1f-4256-8fc4-9867b0b3cdd1_2048x1197.png 1272w, https://substackcdn.com/image/fetch/$s_!KYV9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b49aac-ec1f-4256-8fc4-9867b0b3cdd1_2048x1197.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>So, what&#8217;s changing?</strong></h2><p>So, here&#8217;s the thing.</p><p>Agentic AI has started doing all this. Not from a checklist - it reasons, it adapts, it chains findings together, it gets past that login page. It is not a smarter scanner, but something closer to that human method. Like the way of thinking, minus the person.</p><p>And that&#8217;s the part worth sitting with. It&#8217;s not that AI showed up and said &#8220;move over, humans&#8221;. It&#8217;s that AI watched what made manual testing valuable - the innate curiosity, those weird creative detours - and learnt to replicate exactly that.</p><p>The gap isn&#8217;t closed because the human was replaced. It closed because what made the human irreplaceable turned out to be teachable.</p><p>Which, depending on how you look at it, is either the most reassuring thing about AI - or the most quietly interesting.</p><p>So, what do you think - is manual pentesting still the norm at your work? And has agentic AI actually closed the gap or is there something a human brings that machines just can&#8217;t replicate yet?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Most security teams still shouldn't be building their own tools]]></title><description><![CDATA[There&#8217;s a version of the AI moment in security that looks like this: your team spins up Claude, builds a custom threat detection pipeline, ships a SOAR integration, and suddenly you have capabilities that would have taken a year and three engineers to build before.]]></description><link>https://beaglesecurity.substack.com/p/most-security-teams-still-shouldnt</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/most-security-teams-still-shouldnt</guid><dc:creator><![CDATA[Rejah Rehim]]></dc:creator><pubDate>Fri, 08 May 2026 13:46:01 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8d803424-1e30-4e47-9537-1580935337f3_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There&#8217;s a version of the AI moment in security that looks like this: your team spins up Claude, builds a custom threat detection pipeline, ships a SOAR integration, and suddenly you have capabilities that would have taken a year and three engineers to build before.</p><p>That version exists. But it applies to maybe 5% of security teams. For everyone else, AI is a force multiplier. But only if you had force to multiply in the first place.</p><h1>The companies that can build</h1><p>If you work at a company where engineering is the DNA (i.e. product-led, high-growth, with a team that was already building internal security tooling before AI arrived) then yes, things change significantly.</p><p>Prototyping is faster. Internal tools ship in days, not weeks. Workflows that previously required a dedicated engineer can now be handled by a security analyst who knows how to prompt well and validate the output. If that&#8217;s your team, you should be building far more now than you ever were before.</p><p>Companies like OpenAI, Anthropic, Figma, Notion, Discord; places where engineering isn&#8217;t a department. It&#8217;s the product. AI amplifies what they already had.</p><h1>The companies that can&#8217;t</h1><p>If building security products in-house wasn&#8217;t realistic for your team yesterday, AI won&#8217;t make it realistic tomorrow.</p><p>The constraint was never &#8220;we don&#8217;t have the tools to write code.&#8221; It was talent, time, infrastructure, and the organizational appetite for maintaining what gets built. Those constraints haven&#8217;t gone away.</p><p>A team of three SOC analysts with access to Claude is still a team of three SOC analysts. They can do more. But they&#8217;re not suddenly a product engineering team. Companies that were under regulatory pressure yesterday are still under that pressure today. Companies that couldn&#8217;t afford to hire senior security engineers still can&#8217;t.</p><h1>Where the line actually sits</h1><p>The distinction isn&#8217;t about willingness; it&#8217;s about what you&#8217;re building. There&#8217;s a clear line between AI-assisted task automation and building actual security infrastructure.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MRnm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a38fd74-9b9c-40ea-85a3-16b9fe4277a5_901x526.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MRnm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a38fd74-9b9c-40ea-85a3-16b9fe4277a5_901x526.png 424w, https://substackcdn.com/image/fetch/$s_!MRnm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a38fd74-9b9c-40ea-85a3-16b9fe4277a5_901x526.png 848w, https://substackcdn.com/image/fetch/$s_!MRnm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a38fd74-9b9c-40ea-85a3-16b9fe4277a5_901x526.png 1272w, https://substackcdn.com/image/fetch/$s_!MRnm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a38fd74-9b9c-40ea-85a3-16b9fe4277a5_901x526.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MRnm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a38fd74-9b9c-40ea-85a3-16b9fe4277a5_901x526.png" width="901" height="526" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1a38fd74-9b9c-40ea-85a3-16b9fe4277a5_901x526.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:526,&quot;width&quot;:901,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MRnm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a38fd74-9b9c-40ea-85a3-16b9fe4277a5_901x526.png 424w, https://substackcdn.com/image/fetch/$s_!MRnm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a38fd74-9b9c-40ea-85a3-16b9fe4277a5_901x526.png 848w, https://substackcdn.com/image/fetch/$s_!MRnm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a38fd74-9b9c-40ea-85a3-16b9fe4277a5_901x526.png 1272w, https://substackcdn.com/image/fetch/$s_!MRnm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a38fd74-9b9c-40ea-85a3-16b9fe4277a5_901x526.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Before you decide to build, ask these five questions</h1><p>Most teams skip this step. They see what AI can generate and assume that capability equals capacity. It doesn&#8217;t. Run through these before committing to building anything serious.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Rviz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc705e83-3c73-4ae9-9b6b-a20b3ee0bcc5_901x526.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Rviz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc705e83-3c73-4ae9-9b6b-a20b3ee0bcc5_901x526.png 424w, https://substackcdn.com/image/fetch/$s_!Rviz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc705e83-3c73-4ae9-9b6b-a20b3ee0bcc5_901x526.png 848w, https://substackcdn.com/image/fetch/$s_!Rviz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc705e83-3c73-4ae9-9b6b-a20b3ee0bcc5_901x526.png 1272w, https://substackcdn.com/image/fetch/$s_!Rviz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc705e83-3c73-4ae9-9b6b-a20b3ee0bcc5_901x526.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Rviz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc705e83-3c73-4ae9-9b6b-a20b3ee0bcc5_901x526.png" width="901" height="526" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc705e83-3c73-4ae9-9b6b-a20b3ee0bcc5_901x526.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:526,&quot;width&quot;:901,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Rviz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc705e83-3c73-4ae9-9b6b-a20b3ee0bcc5_901x526.png 424w, https://substackcdn.com/image/fetch/$s_!Rviz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc705e83-3c73-4ae9-9b6b-a20b3ee0bcc5_901x526.png 848w, https://substackcdn.com/image/fetch/$s_!Rviz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc705e83-3c73-4ae9-9b6b-a20b3ee0bcc5_901x526.png 1272w, https://substackcdn.com/image/fetch/$s_!Rviz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc705e83-3c73-4ae9-9b6b-a20b3ee0bcc5_901x526.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>What this means in practice</h1><p>If you&#8217;re evaluating whether to build or buy a security capability, the question isn&#8217;t &#8220;can AI help us build this?&#8221; It almost certainly can. The question is: do you have the team to maintain, iterate, and improve what you build over time?</p><p>Use AI for what it&#8217;s actually good at in your context. Automate the repeatable work. Generate the boilerplate. Speed up the analysis. But stay honest about where your team&#8217;s depth ends and choose vendors who fill the gap well, rather than tools that tempt you into filling it yourself.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Why pentest pricing feels like a scam (And what you should actually be paying for)]]></title><description><![CDATA[Pentest quotes ranging from $1,500 to $15,000 for the "same" thing? You're not comparing the same thing. New edition breaks it down + a checklist to evaluate any vendor.]]></description><link>https://beaglesecurity.substack.com/p/why-pentest-pricing-feels-like-a</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/why-pentest-pricing-feels-like-a</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Thu, 26 Feb 2026 13:45:22 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5523cdca-a3e7-4e55-b311-4d47f40ac240_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A quick search through any security forum will tell you that penetration testing pricing is all over the place. One vendor quotes $1,500. Another quotes $15,000. A third sends a proposal so vague you can&#8217;t tell what you&#8217;re actually getting. Meanwhile, someone says their MSSP does it for free as part of a bundle, and another person is paying $250 an hour for a consultant who bills by time, not scope.</p><p>This is genuinely confusing. And the confusion isn&#8217;t accidental.</p><h2>The real reason pricing varies so much</h2><p>Pentest pricing isn&#8217;t all over the place because vendors are making up numbers. It&#8217;s because &#8220;penetration testing&#8221; is being used to describe three fundamentally different things, and most buyers don&#8217;t know all three exist.</p><h3><strong>Vulnerability scanners</strong></h3><p>These run automated checks against known vulnerability signatures. They&#8217;re fast, cheap, and useful for catching obvious issues on the surface. But they don&#8217;t simulate how an attacker actually moves through your application. They find what they&#8217;re programmed to look for, not what a motivated attacker would find.</p><h3><strong>Automated penetration testing</strong></h3><p>This sits between scanners and manual testing. Platforms in this category go beyond pattern matching to simulate real-world attack scenarios across your web app, APIs, authenticated flows, and business logic. They produce structured reports with risk scoring and remediation guidance, integrate into your CI/CD pipeline, and can run continuously rather than as a one-time exercise. The output looks and functions like a pentest, not just a scan.</p><h3><strong>Manual penetration testing</strong></h3><p>Experienced security consultants spending days inside your application, manually tracing attack paths, chaining vulnerabilities, and writing findings by hand. This is the most thorough option and the most expensive. It&#8217;s also point-in-time: once the engagement ends, the clock starts ticking on how current those findings are.</p><p>All three get called &#8220;penetration testing.&#8221; None of them cost the same. And the difference in what they actually catch is significant.</p><h2>What buyers are actually comparing</h2><p>Most of the pricing confusion comes from buyers comparing a scanner to a manual engagement and wondering why the gap is so large. The missing piece is that there&#8217;s a third category that closes most of that gap at a fraction of the cost.</p><p>Automated penetration testing handles the majority of what most teams actually need: continuous coverage across their attack surface, tested against real attack scenarios, with reports that map to compliance requirements. Manual testing still has a role, particularly for complex business logic, custom authentication flows, or compliance mandates that specifically require human-led assessments. But for most teams running web applications and APIs, automated pentesting covers the ground they need covered.</p><p>The problem is that both a $1,500 scanner and a $15,000 manual engagement can produce a PDF report. From the outside, a PDF report is a PDF report. Automated pentesting also produces a report, but what&#8217;s behind it is meaningfully different from either end of the spectrum.</p><h2>The &#8220;good enough&#8221; trap</h2><p>Compliance deadlines, budget pressure, and impatient stakeholders push teams toward the cheapest option that produces a deliverable. The report gets filed. The checkbox gets ticked. And nobody asks whether the testing actually covered anything that matters until something breaks.</p><p>The risk with scanners isn&#8217;t just that they miss things. It&#8217;s that they give teams false confidence. A clean scanner report doesn&#8217;t mean your application is secure. It means nothing in the vulnerability database matched what was visible on the surface.</p><p>The risk with defaulting straight to manual testing is a different kind of problem: it&#8217;s expensive, infrequent, and doesn&#8217;t scale. If you&#8217;re shipping code every week, a manual engagement once a year leaves a lot of ground uncovered.</p><p>Automated pentesting addresses both problems. It runs continuously, covers your actual attack surface, and produces findings that are actionable rather than decorative.</p><h2>What scope actually means</h2><p>Scope is where most pricing conversations fall apart.</p><p>&#8220;Web application pentest&#8221; means different things to different vendors. Does it include authenticated flows? Does it cover your APIs, or just the frontend? What about your GraphQL endpoint? Your internal staging environment? The login page that sits behind a different subdomain?</p><p>If scope isn&#8217;t defined clearly upfront, pricing can&#8217;t be accurate, and coverage will almost certainly have gaps. The cheap quote often reflects a narrower scope, not a better deal.</p><p>A well-scoped automated pentest should cover your web application, API endpoints, authenticated user flows, and any internal apps that are part of your environment. If a vendor can&#8217;t tell you specifically what&#8217;s in and what&#8217;s out, that&#8217;s a problem regardless of the price or the delivery model.</p><h2>What the report should actually tell you</h2><p>A pentest report is only useful if it&#8217;s actionable.</p><p>A good report maps findings to risk. It tells you what was tested, what was found, how severe each finding is, and what to do about it. It includes enough context that a developer can reproduce and fix the issue. And if you&#8217;re working toward compliance, it maps to the frameworks you care about: OWASP, PCI DSS, HIPAA, SOC 2.</p><p>A bad report is a list of CVEs with severity scores copy-pasted from a scanner. It looks thorough. It isn&#8217;t.</p><p><em><strong>One practical test:</strong></em> ask to see a sample report before you buy. If it doesn&#8217;t include clear remediation guidance, risk context, and evidence of what was actually tested, you&#8217;re buying a document, not a security assessment. This applies equally whether the vendor is running manual tests or automated ones.</p><h2>A more useful question</h2><p>Instead of asking &#8220;why is this so expensive?&#8221;, the better question is: what does this actually cover, and what evidence will I have that it was done properly?</p><p>A follow-on question worth asking: do I need manual testing for this engagement, or does automated pentesting cover what I need? For most web applications and APIs, the answer is automated. For highly custom systems, complex privilege escalation scenarios, or compliance requirements that specifically mandate human-led testing, manual still has a place.</p><p>Knowing the difference makes it easier to compare vendors fairly, allocate budget correctly, and stop treating every pentest quote as if it&#8217;s measuring the same thing.</p><p>Penetration testing pricing will always vary. But the difference between a $2,000 engagement and a $20,000 one isn&#8217;t just budget. It&#8217;s scope, methodology, delivery model, and what you walk away with. Understanding that distinction is what separates teams that check a compliance box from teams that actually know what their attack surface looks like.</p><h2>Vendor evaluation checklist</h2><p>16 things to confirm before you sign with a penetration testing vendor, whether they&#8217;re offering automated pentesting, manual testing, or a combination of both.</p><p><strong>Scope clarity</strong></p><p>&#9744; Vendor specifies exactly which assets are included (web app, APIs, GraphQL, CMS, internal tools)</p><p>&#9744; Authenticated testing is included, not just unauthenticated surface scanning</p><p>&#9744; Business logic testing is part of the methodology</p><p>&#9744; Internal or staging environments can be tested if needed</p><p><strong>Methodology</strong></p><p>&#9744; Testing simulates real-world attack scenarios, not just pattern matching</p><p>&#9744; API endpoints are individually tested, not just discovered</p><p>&#9744; CI/CD or DevSecOps integration is available for continuous testing</p><p>&#9744; Retesting is included or available after fixes are applied</p><p><strong>Report quality</strong></p><p>&#9744; Sample report is available before purchase</p><p>&#9744; Findings include clear remediation guidance, not just severity scores</p><p>&#9744; Risk scoring is contextual, not just raw CVSS</p><p>&#9744; Report maps to compliance frameworks you need (OWASP, PCI DSS, HIPAA, SOC 2)</p><p><strong>Ongoing value</strong></p><p>&#9744; Findings are trackable over time, not just a one-time snapshot</p><p>&#9744; Risk score changes are visible between test cycles</p><p>&#9744; Testing can scale as your application grows</p><p>&#9744; Pricing is scope-based, not purely time-based</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The burden of proof problem in AppSec ]]></title><description><![CDATA[There&#8217;s a conversation happening in security teams right now, and it&#8217;s uncomfortable.]]></description><link>https://beaglesecurity.substack.com/p/the-burden-of-proof-problem-in-appsec</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/the-burden-of-proof-problem-in-appsec</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Fri, 20 Feb 2026 13:45:28 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/cd40f70a-7336-4269-ae2d-02a31d3675ce_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There&#8217;s a conversation happening in security teams right now, and it&#8217;s uncomfortable.</p><p>A CFO pulls up a tab showing Claude or Cursor. An engineering lead mentions that AWS has a free scanning option. Someone in a meeting says, half-joking, &#8220;can&#8217;t we just vibe code our way through this?&#8221; And suddenly, the AppSec team isn&#8217;t talking about vulnerabilities anymore. They&#8217;re talking about their own relevance.</p><p>This is the burden of proof problem. And it&#8217;s quietly becoming one of the more draining parts of working in application security.</p><h2><strong>How we got here</strong></h2><p>AI coding assistants got good fast. Not &#8220;good enough to replace a senior engineer&#8221; good, but good enough to make a CFO ask questions. When you can prompt a model to review code for security issues, the natural follow-up is: why are we paying for a dedicated tool?</p><p>The question is fair. It&#8217;s the wrong question, but it&#8217;s fair.</p><p>Cloud providers have made it worse. Most major platforms now bundle some form of security scanning into their offering. Free, or close to it. Procurement-friendly. Easy to demo in a slide. For someone trying to cut costs, it looks like a reasonable trade.</p><p>So AppSec teams walk into budget conversations with a harder job than they had two years ago. They&#8217;re not just defending their tools. They&#8217;re defending the category.</p><h2><strong>The real cost of &#8220;good enough&#8221;</strong></h2><p>Here&#8217;s what gets lost in these conversations.</p><p>General-purpose AI tools can spot obvious patterns. They&#8217;ve seen enough code to flag a SQL injection or a hardcoded secret. But application security isn&#8217;t just about pattern recognition. It&#8217;s about understanding how your application behaves under attack, across authenticated flows, across API endpoints, across the specific way your team has wired things together.</p><p>A model that&#8217;s good at writing code is not the same thing as a tool built to simulate how an attacker moves through your application. These are different problems.</p><p>The same is true for bundled cloud scanners. Coverage sounds good in a pitch. But coverage without context, without authenticated testing, without business logic awareness, leaves gaps that only show up after something goes wrong.</p><p>The cost of &#8220;good enough&#8221; isn&#8217;t visible until it isn&#8217;t good enough. By then, the conversation has moved from budget meetings to incident reports.</p><h2><strong>The wrong battle</strong></h2><p>The frustrating part is that AppSec teams shouldn&#8217;t have to fight this battle at all.</p><p>When a general-purpose tool gets positioned as a security solution, the burden of proof lands on the people who actually understand the problem space. They have to explain why breadth isn&#8217;t depth. Why free isn&#8217;t free if it misses the vulnerabilities that matter. Why a tool that wasn&#8217;t built for security testing probably shouldn&#8217;t be trusted with it.</p><p>This takes time and energy that could go toward, you know, security.</p><p>There&#8217;s also a political dimension. Some teams will take the path of least resistance: accept the demoware, keep the peace, deal with the gaps quietly. Others will push back and spend cycles proving something that should be self-evident. Neither option is great.</p><h2><strong>A better framing</strong></h2><p>The conversation shifts when you stop arguing about tools and start talking about evidence.</p><p>What does your security program actually need to demonstrate? Coverage across your attack surface. Accountability when something is found. Audit-ready reporting for compliance. A consistent process that doesn&#8217;t depend on who&#8217;s on the team this quarter.</p><p>General-purpose AI tools don&#8217;t produce pentest reports. They don&#8217;t map to OWASP or PCI DSS. They don&#8217;t tell you your risk score changed between last sprint and this one. They don&#8217;t integrate into your CI/CD pipeline so that security is part of the build, not a checkpoint after it.</p><p>When you frame it that way, the question stops being &#8220;why not use Claude?&#8221; and starts being &#8220;what does a defensible, scalable security program actually look like?&#8221; That&#8217;s a question AppSec teams are well-positioned to answer.</p><h2><strong>The takeaway</strong></h2><p>The pressure isn&#8217;t going away. AI tools will keep getting better, and the questions from leadership will keep coming.</p><p>But the answer isn&#8217;t to get defensive. It&#8217;s to get specific. Know what your tools cover that others don&#8217;t. Know what evidence your program produces. Know what &#8220;good enough&#8221; actually costs when it fails.</p><p>The burden of proof is frustrating. But it&#8217;s also an opportunity to make the case clearly, once, and move on.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[More tools, less security]]></title><description><![CDATA[If your security team spends more time switching tools than fixing issues, something&#8217;s broken. This week&#8217;s newsletter explores AppSec tool fatigue and the hidden risk it creates.]]></description><link>https://beaglesecurity.substack.com/p/more-tools-less-security</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/more-tools-less-security</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Fri, 16 Jan 2026 14:03:15 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e227d6c3-32b6-4107-a1c0-58b5dd29b040_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On paper, today&#8217;s security stacks look impressive. They cover code, cloud, containers, APIs, runtime, identity, and more. But in practice, they often leave teams with a fundamental gap:</p><p>They tell you what exists, but not what actually matters.</p><p>One tool flags a vulnerable library.<br>Another shows the workload is internet-facing.<br>Another says it&#8217;s exploitable.<br>Another says it isn&#8217;t.</p><p>None of them tell you the story.</p><p>Security teams are forced to become human correlation engines, stitching together findings across platforms to answer one simple question: &#8220;Is this a real risk we should fix now?&#8221;</p><p>That manual stitching is where most of the time (and mistakes) happen.</p><div><hr></div><h2>Why correlation is the real bottleneck</h2><p>Modern attacks don&#8217;t live in a single layer. They move across identity, APIs, infrastructure, and business logic. But most tools still think in silos.</p><p>A vulnerability scanner doesn&#8217;t know whether an endpoint is authenticated.<br>A cloud tool doesn&#8217;t know whether an API route is actually used.<br>A code scanner doesn&#8217;t know whether the flaw is reachable.</p><p>So teams are left with thousands of findings that may be technically correct but practically irrelevant. Or worse, they miss the few that really matter.</p><p>This is why so many teams feel busy but still exposed.</p><div><hr></div><h2>The cost of switching contexts</h2><p>There&#8217;s another layer to this problem that&#8217;s rarely talked about: <strong>mental overhead</strong>.</p><p>Every time a security engineer jumps from one tool to another, they lose context. Every dashboard has a different model of risk, a different way of describing assets, and a different way of scoring severity. Over time, that fragmentation creates fatigue, hesitation, and delay.</p><p>Instead of saying &#8220;this is exploitable and urgent,&#8221; teams say &#8220;it depends.&#8221;</p><p>That uncertainty is what attackers thrive on.</p><div><hr></div><h2>Why SREs and developers push back</h2><p>Security teams aren&#8217;t the only ones frustrated. SREs don&#8217;t like agents. Developers don&#8217;t like failing builds. Platform teams don&#8217;t want ten different tools touching production.</p><p>When security stacks become bloated, every new scanner feels like another piece of friction. Even when a finding is valid, it arrives wrapped in distrust.</p><p>This is how real risk gets deprioritized: not because teams don&#8217;t care, but because the signal is buried.</p><div><hr></div><h2>What modern AppSec actually needs</h2><p>The future of application security isn&#8217;t more coverage. It&#8217;s <strong>more context</strong>.</p><p>Security tools need to:</p><ul><li><p>Show exploitability, not just vulnerabilities</p></li><li><p>Understand application flows, not just endpoints</p></li><li><p>Correlate identity, cloud exposure, and business logic</p></li><li><p>Reduce noise instead of adding to it</p></li></ul><p>Most importantly, they need to answer this:</p><blockquote><p>&#8220;Can this actually be used to break something meaningful?&#8221;</p></blockquote><p>If a vulnerability can&#8217;t be reached, abused, or chained, it&#8217;s not the same as one that can drain data or take over accounts. Treating them equally is what creates alert fatigue.</p><div><hr></div><h2>Where automation should help &amp; not hurt</h2><p>Automation is supposed to remove manual work. But in many security programs, it has done the opposite by flooding teams with unprioritized output.</p><p>The goal isn&#8217;t to scan more.<br>It&#8217;s to understand more.</p><p>That means tools need to simulate attacker behavior, not just list weaknesses. They need to see what happens when a flaw meets real authentication, real APIs, real users, and real infrastructure.</p><p>Without that, teams are stuck guessing.</p><div><hr></div><h2>Where Beagle Security fits into this picture</h2><p>Beagle Security was built around a simple idea: <strong>security findings should come with context</strong>.</p><p>Rather than operating as yet another isolated scanner, Beagle focuses on how vulnerabilities behave in real applications, especially across APIs, authentication, and business logic. It combines dynamic testing, API discovery, and exploit simulation to help teams see which issues are actually reachable and dangerous.</p><p>That doesn&#8217;t replace every tool in your stack. But it does reduce one of the biggest pain points: the gap between detection and decision-making.</p><p>When teams can see how an issue can be exploited, they don&#8217;t need to jump between three dashboards to justify fixing it. They can act.</p><div><hr></div><h2>The real win: fewer tools, clearer truth</h2><p>The problem with AppSec today isn&#8217;t that teams lack data. It&#8217;s that they lack confidence in it.</p><p>When security tools disagree, humans stall. When humans stall, risk grows.</p><p>The way forward isn&#8217;t another scanner. It&#8217;s a better way of connecting what you already know (vulnerabilities, access, exposure, and behavior) into something that looks like reality instead of noise.</p><p>Because at the end of the day, security isn&#8217;t about how many tools you own.</p><p>It&#8217;s about how clearly you can see what&#8217;s actually trying to break you.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Cybersecurity round-up 2025: What last year’s biggest incidents taught us]]></title><description><![CDATA[This week&#8217;s All Things AppSec dives into the biggest cybersecurity incidents of 2025 and the hard lessons behind them.]]></description><link>https://beaglesecurity.substack.com/p/cybersecurity-round-up-2025-what</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/cybersecurity-round-up-2025-what</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Wed, 07 Jan 2026 14:00:24 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/51ada621-d23a-4cc5-ac48-060d83420c87_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Every year in cybersecurity has its share of breaches, headlines, and postmortems. But 2025 stood out; not because attacks were louder, but because they were broader, faster, and more systemic.</p><p>From record-breaking credential exposure to AI-orchestrated cyber operations, this year&#8217;s incidents revealed a hard truth: security failures are no longer isolated technical issues. They ripple across ecosystems, supply chains, and even national infrastructure.</p><p>In this edition of <em>All Things AppSec</em>, we look back at the five most significant cybersecurity incidents of 2025 and more importantly, what they tell us about where security is failing and how teams need to adapt.</p><div><hr></div><h2>1. The 16 billion credential &#8220;mega leak&#8221;</h2><p>The largest password exposure in recorded history surfaced in June 2025: <strong>16 billion login credentials</strong> compiled from infostealer malware campaigns and historical breaches spanning several years.</p><p>What made this incident unprecedented wasn&#8217;t a single breach, but aggregation at industrial scale. Credentials linked to Google, Apple, Facebook, GitHub, Telegram, VPNs, email services, and government portals were all exposed in one dataset.</p><p>This wasn&#8217;t targeted compromise. It was <strong>universal exposure</strong>.</p><h3>What we learned</h3><p>Credential security is no longer about whether <em>your</em> platform was breached&#8212;it&#8217;s about how often reused credentials resurface elsewhere. Traditional breach-response thinking doesn&#8217;t work when attackers can launch credential-stuffing attacks across every sector simultaneously.</p><p><strong>Key takeaway:</strong> Password-based security is fundamentally brittle at scale. Without strong MFA, credential rotation, and anomaly detection, account takeover becomes inevitable.</p><div><hr></div><h2>2. The Salesforce / Salesloft&#8211;Drift OAuth supply chain breach</h2><p>In September 2025, what would later be described as the <strong>largest SaaS supply chain breach in history</strong> came to light. Approximately 1.5 billion CRM records across 760+ organizations were exposed after OAuth tokens were compromised through Salesloft&#8217;s breached GitHub repositories.</p><p>The affected list was sobering: Google, Cloudflare, Palo Alto Networks, CyberArk, Proofpoint, Chanel, Pandora, and many others. A second breach via Gainsight&#8217;s Salesforce connector expanded the impact further.</p><p>This incident became a SolarWinds moment, but for SaaS integrations.</p><h3>What we learned</h3><p>OAuth tokens are often treated as low-risk plumbing. In reality, they represent <strong>persistent, privileged access</strong> that bypasses traditional authentication controls.</p><p><strong>Key takeaway:</strong> Third-party integrations expand your attack surface far beyond your own code. If OAuth permissions are over-scoped or poorly monitored, a single vendor breach can cascade across hundreds of customers.</p><div><hr></div><h2>3. The Change Healthcare ransomware attack</h2><p>Disclosed in 2025 but originating earlier, the Change Healthcare ransomware incident became the <strong>largest healthcare data breach ever reported</strong>, affecting <strong>192.7 million individuals</strong> i.e. roughly two-thirds of the U.S. population.</p><p>But data exposure was only part of the story. The operational fallout was severe: nationwide pharmacy claims processing failed, billing systems went offline, clinical workflows stalled, and manual workarounds were forced across thousands of providers. Federal agencies had to intervene.</p><p>It was critical infrastructure failure.</p><h3>What we learned</h3><p>When cybersecurity fails in core digital infrastructure, the impact extends far beyond IT systems. Healthcare delivery, patient care, and public trust all suffer.</p><p><strong>Key takeaway:</strong> Ransomware resilience must include operational continuity planning. Security teams need to assume compromise and design systems that degrade safely rather than collapse entirely.</p><div><hr></div><h2>4. The Jaguar Land Rover cyber attack</h2><p>Between August and September 2025, Jaguar Land Rover experienced the <strong>costliest cyberattack in UK history</strong>, with an estimated <strong>&#163;1.9 billion economic loss</strong>.</p><p>The incident forced a five-week halt in production at key manufacturing facilities and disrupted over 5,000 downstream organizations across the automotive supply chain. Revenue dropped 24% year-on-year in Q3 2025.</p><p>The UK Cyber Monitoring Centre classified it as a systemic cyber event, highlighting national-level economic impact.</p><h3>What we learned</h3><p>Modern manufacturing is deeply interconnected. A single compromised node can trigger widespread operational and financial disruption.</p><p><strong>Key takeaway:</strong> Cyber risk is supply-chain risk. Organizations need visibility not just into their own systems, but into the resilience of the vendors and platforms they depend on.</p><div><hr></div><h2>5. The GTG-1002 AI-orchestrated cyber espionage campaign</h2><p>In September 2025 (disclosed publicly in November), researchers revealed the first known <strong>large-scale AI-orchestrated cyberattack</strong>. The Chinese state-sponsored GTG-1002 campaign used AI to autonomously execute 80&#8211;90% of the attack lifecycle, from reconnaissance to data exfiltration.</p><p>Human operators intervened only a handful of times per campaign. Targets included government agencies, financial institutions, technology firms, and chemical manufacturers. The disclosure prompted Congressional hearings and industry-wide reassessment.</p><p>This wasn&#8217;t about scale; it was about speed and autonomy.</p><h3>What we learned</h3><p>Attackers are no longer constrained by human bandwidth. Defensive strategies built around manual response timelines are increasingly outmatched.</p><p><strong>Key takeaway:</strong> Security must evolve toward automation, behavioral detection, and continuous testing. Machine-speed attacks require machine-speed defenses.</p><div><hr></div><h2>The bigger picture: patterns across 2025</h2><p>Looking across all five incidents, several themes emerge:</p><ul><li><p>Identity remains the weakest link</p></li><li><p>Third-party access is a force multiplier for attackers</p></li><li><p>Operational resilience matters as much as data protection</p></li><li><p>Supply chains amplify cyber risk</p></li><li><p>AI is changing both offense and defense</p></li></ul><p>These weren&#8217;t failures of individual controls. They were failures of assumptions: about trust, isolation, and human-paced security.</p><div><hr></div><h2>Looking ahead</h2><p>If 2025 taught us anything, it&#8217;s that cybersecurity is no longer just about preventing breaches. It&#8217;s about limiting blast radius, maintaining continuity, and adapting faster than attackers.</p><p>The question isn&#8217;t whether incidents will happen. It&#8217;s whether organizations are prepared for the scale, speed, and complexity of the next one.</p><p>As we move into 2026, security strategies must be built for ecosystems, not silos, and for continuous change, not static defenses.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Right-sized AppSec (Security strategies that match your startup’s stage)]]></title><description><![CDATA[Most startups don&#8217;t get AppSec wrong because they ignore security. They get it wrong by copying playbooks from companies at a completely different stage.

This edition of All Things AppSec breaks down what right-sized application security actually looks like for a 10-person startup vs a 200-person startup and how to avoid slowing yourself down while staying secure.]]></description><link>https://beaglesecurity.substack.com/p/right-sized-appsec-security-strategies</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/right-sized-appsec-security-strategies</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Fri, 19 Dec 2025 14:03:13 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/a10fb864-3685-4366-863a-8fb877693454_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Most founders don&#8217;t get AppSec wrong because they ignore security. They get it wrong because they borrow security playbooks from companies operating at a completely different stage.</p><p>A 10-person startup trying to behave like a 200-person company ends up slowing itself down.<br>A 200-person startup still treating security like an early-stage afterthought quietly accumulates risk it can&#8217;t unwind later.</p><p>Good application security isn&#8217;t about maturity checklists or tool counts. It&#8217;s about <strong>matching security decisions to your team size, velocity, and attack surface</strong>.</p><p>Let&#8217;s look at what that actually means.</p><div><hr></div><h2>The real mistake: Treating AppSec as a universal template</h2><p>Security advice often sounds absolute:</p><ul><li><p>&#8220;You need a security team&#8221;</p></li><li><p>&#8220;You need manual reviews&#8221;</p></li><li><p>&#8220;You need formal approvals&#8221;</p></li></ul><p>None of that is universally true.</p><p>What <em>is</em> true is that AppSec must reduce risk <strong>without fighting the way your team works</strong>. If security creates friction at your current stage, it will be bypassed, intentionally or not.</p><p>Right-sized AppSec starts with acknowledging one simple fact:</p><p><strong>Your threats change as you scale.</strong></p><div><hr></div><h2>The 10-person startup: Speed first, basics always</h2><p>At this stage, your biggest risk isn&#8217;t advanced attackers. It&#8217;s shipping fast and accidentally exposing something you didn&#8217;t mean to.</p><p>Most early-stage security incidents come from:</p><ul><li><p>Hardcoded credentials</p></li><li><p>Unpatched dependencies</p></li><li><p>Misconfigured authentication</p></li><li><p>Insecure defaults</p></li><li><p>Overexposed APIs</p></li></ul><p>These aren&#8217;t sophisticated attacks; they&#8217;re preventable mistakes.</p><h3>What actually works here</h3><p>You don&#8217;t need a security team. You need:</p><ul><li><p>Automated security checks in your pipeline</p></li><li><p>One engineer who genuinely cares about security</p></li><li><p>Clear ownership of fixing issues when they appear</p></li></ul><p>Anything that relies on manual processes or long reports won&#8217;t survive contact with reality at this stage.</p><h3>What to focus on</h3><ul><li><p>Proper authentication and authorization</p></li><li><p>Input validation and basic API hygiene</p></li><li><p>Dependency and tech stack hygiene</p></li><li><p>Catching obvious vulnerabilities before production</p></li></ul><p>Security should be <strong>quiet and automatic</strong>. If developers have to remember to run something, it won&#8217;t happen consistently.</p><div><hr></div><h2>The 200-person startup: scaling without becoming the bottleneck</h2><p>This is where AppSec usually breaks.</p><p>The team is larger. The product surface is wider. Releases are frequent. And suddenly, security becomes visible. Often in the worst way.</p><p>Many companies respond by hiring security engineers and placing them directly in the deployment path.</p><p>That usually creates friction instead of security.</p><h3>The common failure mode</h3><ul><li><p>Security teams act as gatekeepers</p></li><li><p>Manual reviews block releases</p></li><li><p>Findings arrive late in the cycle</p></li><li><p>Developers see security as &#8220;the team that says no&#8221;</p></li></ul><p>The result is slower delivery without meaningful risk reduction.</p><h3>What works instead</h3><p>At this stage, security must shift from control to enablement.</p><p>That means:</p><ul><li><p>Building self-service security workflows</p></li><li><p>Automating detection instead of relying on manual review</p></li><li><p>Providing guardrails developers can follow on their own</p></li><li><p>Embedding security into engineering processes, not on top of them</p></li></ul><p>Security should help teams move faster <em>safely</em>, not slower.</p><h3>What to prioritize</h3><ul><li><p>Continuous security testing that runs alongside development</p></li><li><p>Visibility into regressions, not just new vulnerabilities</p></li><li><p>Accurate findings that developers trust</p></li><li><p>Consistent security standards across teams and services</p></li></ul><p>At this stage, security succeeds when developers can fix issues without waiting for security approval.</p><div><hr></div><h2>Why automation matters at both stages</h2><p>The biggest difference between the 10-person and 200-person startup isn&#8217;t intent; it&#8217;s scale.</p><p>Humans don&#8217;t scale well at repetitive tasks. Automation does.</p><p>Across both stages, automation helps you:</p><ul><li><p>Catch issues earlier</p></li><li><p>Reduce dependency on individual vigilance</p></li><li><p>Maintain consistency as teams grow</p></li><li><p>Free security expertise for higher-impact work</p></li></ul><p>This is especially true for dynamic application security testing, which continuously evaluates running applications as they change.</p><div><hr></div><h2>Where Beagle Security fits</h2><p>Beagle Security is built around the idea that AppSec should adapt to your stage and not force you into heavyweight processes too early.</p><p>For smaller teams, Beagle Security provides:</p><ul><li><p>Automated testing that runs without manual effort</p></li><li><p>Clear, actionable findings without noise</p></li><li><p>Coverage for web apps, APIs, and logic flaws</p></li></ul><p>For growing teams, Beagle Security supports:</p><ul><li><p>Continuous testing aligned with CI/CD</p></li><li><p>Reduced false positives so developers trust the results</p></li><li><p>Visibility into regressions and evolving attack surfaces</p></li></ul><p>The intent isn&#8217;t to replace people or slow teams down, but to <strong>make security sustainable as velocity increases</strong>.</p><div><hr></div><h2>The real takeaway</h2><p>There&#8217;s no single &#8220;correct&#8221; AppSec strategy.</p><p>A 10-person startup needs security that protects against obvious mistakes without slowing development. A 200-person startup needs security that scales without turning into a bottleneck.</p><p>Both need automation. Both need clarity. Both need security that works <em>with</em> the team. Not against it.</p><p>Right-sized AppSec isn&#8217;t about copying what worked for someone else. It&#8217;s about building what works for <em>where you are right now</em>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Evaluation criteria for your AppSec platform]]></title><description><![CDATA[&#8220;Is my AppSec platform actually doing the job I think it&#8217;s doing?&#8221;]]></description><link>https://beaglesecurity.substack.com/p/evaluation-criteria-for-your-appsec</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/evaluation-criteria-for-your-appsec</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Fri, 05 Dec 2025 14:03:19 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/11463c5f-39d1-4954-8684-165088fbe01a_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>&#8220;Is my AppSec platform actually doing the job I think it&#8217;s doing?&#8221;</strong></p><p>Modern application security has evolved far beyond simple vulnerability scanning. Organizations now run distributed microservices, multi-stack applications, complex integrations, and frequently changing code. Yet many teams still rely on AppSec tools with slow development cycles, monolithic apps, and predictable attack surfaces; essentially that were built for a very different era.</p><p>The result is false confidence. Blind spots. And security debt that grows silently until it becomes a crisis.</p><p>Choosing the right AppSec platform is no longer a procurement task. It&#8217;s a strategic decision that shapes your organization&#8217;s risk posture, developer velocity, and long-term resilience. In this edition of <em>All Things AppSec</em>, we break down the essential evaluation criteria that every modern AppSec platform must meet and why ignoring them leaves your organization exposed.</p><div><hr></div><h2><strong>1. Coverage across web, API, and business logic</strong></h2><p>Most security tools do a great job at one thing. But applications today are a combination of front-end interfaces, backend services, third-party integrations, and API-driven workflows. If your AppSec tool only tests part of that system, you&#8217;re not testing your real risk surface.</p><p>Ask your vendor:</p><ul><li><p>Does the platform detect vulnerabilities across both web apps and APIs?</p></li><li><p>Can it uncover business logic flaws, not just technical issues?</p></li><li><p>Can it follow multi-step workflows, session transitions, and user states?</p></li></ul><p>Attackers aren&#8217;t exploiting flaws in isolation. They&#8217;re exploiting application behavior. Platforms that can&#8217;t understand context will always miss high-severity weaknesses.</p><div><hr></div><h2><strong>2. Accuracy over noise</strong></h2><p>A tool that generates findings is useful.<br>A tool that generates <em>hundreds of false positives</em> is a liability.</p><p>When evaluating noise levels, look for:</p><ul><li><p>Real-world exploit validation</p></li><li><p>Evidence-based reporting</p></li><li><p>Low false-positive rates</p></li><li><p>Prioritized, actionable output</p></li></ul><p>A security platform should be a partner and not another inbox you have to manage.</p><div><hr></div><h2><strong>3. Ability to integrate into modern development cycles</strong></h2><p>AppSec tooling is not just for security teams anymore. It must embed itself into DevOps workflows without friction.</p><p>Your platform should integrate with:</p><ul><li><p>CI/CD pipelines</p></li><li><p>Issue tracking tools (Jira, Linear, ClickUp)</p></li><li><p>Version control (GitHub, GitLab, Bitbucket)</p></li><li><p>Communication tools (Slack, Teams)</p></li></ul><p>Teams should be able to run automated tests on every deployment, or at least on critical ones, without slowing down development.</p><div><hr></div><h2><strong>4. Support for authenticated, contextual testing</strong></h2><p>Most real vulnerabilities don&#8217;t appear on the login page, rather after authentication.</p><p>If your AppSec platform can&#8217;t handle:</p><ul><li><p>Complex login flows</p></li><li><p>Multi-factor authentication</p></li><li><p>Token refresh and authorization flows</p></li><li><p>Role-specific testing</p></li><li><p>User-context switching</p></li></ul><p>&#8230;then it&#8217;s missing 80% of the attack surface.</p><div><hr></div><h2><strong>5. Tech stack visibility</strong></h2><p>This is one of the most underrated evaluation criteria.</p><p>An AppSec platform should help you understand:</p><ul><li><p>What technologies your application uses</p></li><li><p>Which versions are outdated or vulnerable</p></li><li><p>Which components add hidden risk</p></li><li><p>Whether any stack drift has occurred during development</p></li></ul><p>Many breaches happen not because an app is vulnerable, but because something in the stack is.</p><div><hr></div><h2><strong>6. Depth of API security testing</strong></h2><p>APIs have become the top attack vector in modern applications, yet most tools still treat them as secondary.</p><p>Your AppSec platform must:</p><ul><li><p>Discover undocumented endpoints (shadow APIs)</p></li><li><p>Perform BOLA, BFLA, and authentication abuse testing</p></li><li><p>Support schema-based testing (OpenAPI, Postman Collections)</p></li><li><p>Evaluate rate limits, authorization, and workflow logic</p></li></ul><div><hr></div><h2><strong>7. Continuous rather than point-in-time security</strong></h2><p>Security today cannot rely on annual pen tests or quarterly reviews.</p><p>Your platform should support:</p><ul><li><p>Scheduled automated testing</p></li><li><p>Continuous monitoring</p></li><li><p>Regression testing after every code change</p></li><li><p>Alerting when new vulnerabilities appear in dependencies or stacks</p></li></ul><p>A &#8220;test once and forget&#8221; model no longer works.</p><div><hr></div><h2><strong>8. Clear, developer-friendly remediation guidance</strong></h2><p>The value of an AppSec tool lies not in what it finds, but how quickly your team can fix it.</p><p>Look for:</p><ul><li><p>Clear explanations (not generic CVE text)</p></li><li><p>Steps to reproduce</p></li><li><p>Code-level insights</p></li><li><p>Technology-specific fixes</p></li><li><p>Prioritization based on real exploitability</p></li></ul><div><hr></div><h2><strong>9. Scalability across your evolving application footprint</strong></h2><p>Modern organizations aren&#8217;t running one app. They&#8217;re running dozens.</p><p>Your AppSec platform must scale with:</p><ul><li><p>Multi-app environments</p></li><li><p>Microservices</p></li><li><p>Frequent deployments</p></li><li><p>Rapid product iteration</p></li><li><p>Globally distributed teams</p></li></ul><div><hr></div><h1><strong>How Beagle Security meets these evaluation criteria</strong></h1><p>While many AppSec platforms excel in one or two areas, Beagle Security is designed to cover the <em>full breadth</em> of modern application security needs. Here&#8217;s how it aligns with the evaluation criteria above, without overwhelming teams or slowing development.</p><h3><strong>Deep coverage across web, APIs, and business logic</strong></h3><p>Beagle uses intelligent workflow mapping and multi-user simulation to uncover vulnerabilities that traditional scanners miss&#8212;especially business logic flaws and authorization weaknesses.</p><h3><strong>Accurate, validated results</strong></h3><p>Every vulnerability Beagle Security reports is backed by proof-of-exploit conditions, drastically reducing false positives and helping teams focus on what really matters.</p><h3><strong>Seamless integration into DevOps</strong></h3><p>CI/CD integrations allow teams to trigger automated pen tests on deployments, commit merges, or schedules, bringing security into the development pipeline without friction.</p><h3><strong>Advanced authenticated testing</strong></h3><p>Beagle&#8217;s AI-driven authentication handling can navigate:</p><ul><li><p>Multi-step logins</p></li><li><p>Conditional MFA</p></li><li><p>Dynamic token environments</p></li><li><p>Role-based workflows</p></li></ul><p>This ensures deep coverage across authenticated user paths.</p><h3><strong>Tech stack risk insights</strong></h3><p>Beagle&#8217;s Tech stack risk module automatically identifies technologies used in your application and surfaces version-specific vulnerabilities, something many AppSec tools overlook entirely.</p><h3><strong>Strong API protection</strong></h3><p>Beagle&#8217;s API Discovery feature uncovers shadow APIs, undocumented endpoints, and orphaned routes&#8212;bridging one of the biggest security gaps in modern architectures.</p><h3><strong>Continuous, automated testing</strong></h3><p>Scheduled tests, regression validation, and continuous monitoring help security teams stay ahead of evolving threats instead of reacting to them.</p><h3><strong>Actionable guidance built for developers</strong></h3><p>Beagle reports include:</p><ul><li><p>Clear technical details</p></li><li><p>Business impact summaries</p></li><li><p>Reproduction steps</p></li><li><p>Code-level remediation insights</p></li></ul><p>This shortens fix cycles and improves collaboration across teams.</p><div><hr></div><h2><strong>Final thoughts</strong></h2><p>Choosing an AppSec platform is choosing the kind of security culture your organization wants to build.</p><p>Do you want a tool that checks boxes, or one that actually helps you understand and reduce your real-world risk? A scanner that spits out CVEs, or a platform that works alongside engineering teams? A point-in-time snapshot, or continuous assurance?</p><p>The criteria above are not features; they&#8217;re fundamentals.<br>They define whether the platform you choose will be a surface-level scanner or a partner in building secure software.</p><p>And while no single tool can replace human judgment or good engineering practices, the right AppSec platform can dramatically reduce risk, simplify workflows, and empower teams to stay ahead of threats, <em>not behind them</em>.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The risks you don't see (Addressing your tech stack)]]></title><description><![CDATA[Every application is built on a foundation: its technology stack.]]></description><link>https://beaglesecurity.substack.com/p/the-risks-you-dont-see-addressing</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/the-risks-you-dont-see-addressing</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Fri, 28 Nov 2025 13:45:24 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/2bef6438-05ae-416f-a8ac-87400316cd4b_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Every application is built on a foundation: its technology stack. Frameworks, runtimes, libraries, databases, servers, authentication layers, and third-party integrations all come together to form the backbone of your application.</p><p>But here&#8217;s the uncomfortable truth most teams learn only after something breaks:</p><p>You can secure your code, your APIs, your cloud&#8230; and still be vulnerable because of your tech stack.</p><p>A single outdated library, unsupported framework, or misconfigured runtime is sometimes all an attacker needs. And the irony? </p><p>Teams rarely have full visibility into the technologies actually running under the hood.</p><p>This is where modern AppSec often breaks down. Your tech stack evolves silently, but your security assumptions remain stuck in time.</p><p>Let&#8217;s unpack why this matters, where teams unknowingly expose themselves, and how you can stay ahead.</p><div><hr></div><h2><strong>Why tech stack vulnerabilities are more dangerous than they seem</strong></h2><p>When a vulnerability hits the news, it&#8217;s rarely the application logic that breaks first.<br>It&#8217;s usually something deeper.</p><p>They&#8217;d look something like:</p><ul><li><p>A forgotten version of Log4j powering a background module</p></li><li><p>A deprecated PHP or Python version still running on a legacy subsystem</p></li><li><p>A misconfigured Nginx or Apache server exposing sensitive info</p></li><li><p>A vulnerable SSO library leaking tokens</p></li><li><p>An outdated ORM silently allowing SQL injection payloads</p></li><li><p>A Node.js runtime multiple versions behind with known RCE vulnerabilities</p></li></ul><p>These aren&#8217;t rare incidents. They happen <em>every day</em> in companies of every size.</p><p>And the biggest reason isn&#8217;t negligence. It&#8217;s <strong>invisibility</strong>.</p><p>Most teams <em>think</em> they know their tech stack. Very few actually do.</p><div><hr></div><h2><strong>The invisible drift in your application&#8217;s foundation</strong></h2><p>Technology drift happens quietly.</p><p>A developer updates one library, breaking another. A framework dependency auto-updates to an unstable version. A new module is deployed with a different runtime.</p><p>Your tech stack does not stay static, especially in modern CI/CD pipelines.</p><p>And when you don&#8217;t know exactly what&#8217;s running, you can&#8217;t secure it.</p><p>Attackers, however, excel at detecting this drift.</p><div><hr></div><h2><strong>The cost of ignoring tech stack weaknesses</strong></h2><p>A vulnerable tech stack rarely breaks visibly. It breaks silently, until one day it becomes the entry point for:</p><ul><li><p>Remote code execution</p></li><li><p>Supply chain attacks</p></li><li><p>API takeover</p></li><li><p>Authentication bypasses</p></li><li><p>Server compromise</p></li><li><p>Data exfiltration</p></li><li><p>Undetected privilege escalation</p></li></ul><p>And for organizations with certified processes (PCI, SOC 2, ISO 27001), outdated components can even land you out of compliance.</p><p>The common saying goes:</p><blockquote><p>&#8220;We don&#8217;t know what we don&#8217;t know.&#8221;</p></blockquote><p>Tech stack risk is exactly that.</p><div><hr></div><h2><strong>Where teams struggle most (and why)</strong></h2><h3><strong>1. Manual tracking is unrealistic</strong></h3><p>Expecting teams to manually track:</p><ul><li><p>framework versions</p></li><li><p>package updates</p></li><li><p>server configurations</p></li><li><p>runtime dependencies</p></li><li><p>database engines</p></li><li><p>supporting libraries</p></li></ul><p>&#8230;across every environment is simply not feasible.</p><h3><strong>2. Dependency chains are enormous</strong></h3><p>One library brings in five more. A framework brings in dozens. A container image hides hundreds.</p><p>You rarely see the full picture.</p><h3><strong>3. CI/CD velocity accelerates risk</strong></h3><p>The faster you ship, the easier it is for vulnerabilities to slip in unnoticed.</p><p>Small changes become big liabilities.</p><h3><strong>4. Security teams often lack deep engineering context</strong></h3><p>They know what&#8217;s risky, but they don&#8217;t always know what&#8217;s running. Which is why AppSec often lags behind DevOps.</p><div><hr></div><h2><strong>How to regain control of your tech stack&#8217;s security</strong></h2><p>If you want to harden your foundation, start with these steps:</p><h3><strong>1. Maintain continuous visibility</strong></h3><p>Yearly audits won&#8217;t cut it. Your application changes far more often.</p><p>You need automatic, recurring discovery of:</p><ul><li><p>technologies</p></li><li><p>versions</p></li><li><p>dependencies</p></li><li><p>runtime details</p></li></ul><h3><strong>2. Prioritize component risks by exploitability</strong></h3><p>Not every outdated library is a crisis. Focus on high-impact risks:</p><ul><li><p>Known RCE vulnerabilities</p></li><li><p>Components with public exploit kits</p></li><li><p>Libraries no longer maintained</p></li><li><p>Frameworks out of long-term support</p></li><li><p>Versions with active KEV (Known Exploited Vulnerabilities) entries</p></li></ul><h3><strong>3. Fix foundational weaknesses first</strong></h3><p>A secure application can sit on top of an insecure stack and still get breached.</p><p>Patch from the bottom up.</p><h3><strong>4. Reduce tech sprawl</strong></h3><p>Standardize runtimes, frameworks, and languages where possible.</p><p>Consistency reduces risk.</p><h3><strong>5. Create a tight feedback loop between engineering and security</strong></h3><p>Security needs visibility. Engineering needs prioritization. The tech stack sits between them.</p><p>Bridging this gap is essential.</p><div><hr></div><h2><strong>How Beagle Security helps you secure your tech stack</strong></h2><p>Your application&#8217;s technology landscape shouldn&#8217;t be a mystery. With Beagle Security&#8217;s new <strong>Tech Stack Risk Insights</strong>, you now get:</p><h3><strong>Automatic tech stack detection after every test run</strong></h3><p>Beagle Security identifies:</p><ul><li><p>frameworks</p></li><li><p>libraries</p></li><li><p>databases</p></li><li><p>servers</p></li><li><p>languages</p></li><li><p>versions</p></li></ul><p>&#8230;for every application you test.</p><h3><strong>Manual configuration for maximum accuracy</strong></h3><p>If you know certain components that Beagle Security should track explicitly, you can customize the tech stack in your dashboard.</p><h3><strong>Risk scoring for every detected component</strong></h3><p>Each technology is evaluated for:</p><ul><li><p>known vulnerabilities</p></li><li><p>version age</p></li><li><p>stability</p></li><li><p>exploitability</p></li><li><p>security advisories</p></li><li><p>exposure risk</p></li></ul><p>You immediately see which parts of your tech stack may undermine your security posture.</p><h3><strong>A unified place to monitor tech stack risks</strong></h3><p>Inside the Results section, you&#8217;ll find the new <strong>Tech stack risk insights</strong> panel; your single source of truth for foundation-level risks.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M7rP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M7rP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png 424w, https://substackcdn.com/image/fetch/$s_!M7rP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png 848w, https://substackcdn.com/image/fetch/$s_!M7rP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png 1272w, https://substackcdn.com/image/fetch/$s_!M7rP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M7rP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png" width="1233" height="840" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:840,&quot;width&quot;:1233,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:155530,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://beaglesecurity.substack.com/i/180157029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!M7rP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png 424w, https://substackcdn.com/image/fetch/$s_!M7rP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png 848w, https://substackcdn.com/image/fetch/$s_!M7rP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png 1272w, https://substackcdn.com/image/fetch/$s_!M7rP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F509fe057-e2e7-4543-bbea-945415dc5dd2_1233x840.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Stronger remediation and prioritization</strong></h3><p>Instead of waiting for a pentest or a breach, you now get continuous, automated insights into risks hidden in your infrastructure.</p><p>The benefit?</p><p>You can finally see the vulnerabilities that live below your code; the ones that matter most.</p><div><hr></div><h2><strong>Wrapping up</strong></h2><p>Applications don&#8217;t get breached only because of bad code. They get breached because of fragile foundations.</p><p>Outdated frameworks. Unsupported runtimes. Vulnerable libraries. Misconfigured servers.</p><p>These are the vulnerabilities that slip past the eye, the sprint, and the pentest; until someone on the outside finds them first.</p><p>Understanding your tech stack and keeping it in check can help you drastically reduce your attack surface and strengthen every layer above it.</p><p>Security starts from the bottom.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Positioning DAST as an ally to pentesting]]></title><description><![CDATA[A lot of teams still depend almost entirely on traditional penetration testing to judge whether their application is secure.]]></description><link>https://beaglesecurity.substack.com/p/positioning-dast-as-an-ally-to-pentesting</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/positioning-dast-as-an-ally-to-pentesting</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Wed, 19 Nov 2025 14:02:59 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/db5d81d4-a896-4734-8b4a-a349f470d55a_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A lot of teams still depend almost entirely on traditional penetration testing to judge whether their application is secure. </p><p>And honestly? There&#8217;s nothing wrong with that. Pentesting has earned its reputation. It works, it&#8217;s deep, and it uncovers the kinds of problems no automated tool can dream of finding.</p><p>But there&#8217;s a quickly growing gap.</p><p>Modern applications change every week. The attack surface expands faster than anyone can manually track. APIs get added. Auth logic shifts. New configurations appear. And by the time the next pentest rolls around, your application is not the same app that was tested.</p><p>This is where Dynamic Application Security Testing (DAST) becomes surprisingly valuable, <strong>not as a replacement for pentesting, but as an ally for teams that rely heavily on it.</strong> <br> This isn&#8217;t about switching strategies. It&#8217;s about strengthening the one you already trust.</p><h2><strong>For pentest-first teams &#8211; The reality</strong></h2><p>Pentesting gives you depth, but only at a point in time.</p><p>Between two pentests, everything changes:</p><ul><li><p>new features ship</p></li></ul><ul><li><p>old features are deprecated</p></li></ul><ul><li><p>APIs morph</p></li></ul><ul><li><p>access control logic evolves</p></li></ul><ul><li><p>third-party integrations adjust behavior</p></li></ul><ul><li><p>misconfigurations slip in quietly</p></li></ul><p>Your last pentest may have been excellent&#8230;.but it&#8217;s no longer current<strong>.</strong></p><p>This isn&#8217;t a criticism of pentesting. It&#8217;s simply a reflection of how fast modern engineering teams move.</p><p>DAST steps in not as a challenger, but as a <strong>bridge</strong> between these snapshots.</p><h2><strong>Where DAST complement what pentesters already do well</strong></h2><h3><strong>1. Discovering what exists </strong><em><strong>today</strong></em><strong>, not six months ago</strong></h3><p>Pentesters often spend a chunk of their engagement figuring out:</p><ul><li><p>what endpoints actually exist</p></li></ul><ul><li><p>which routes are active</p></li></ul><ul><li><p>how the auth system currently behaves</p></li></ul><ul><li><p>whether new APIs have been added without documentation</p></li></ul><p>DAST can keep a running inventory of:</p><ul><li><p>shadow APIs</p></li></ul><ul><li><p>forgotten endpoints</p></li></ul><ul><li><p>parameter variations</p></li></ul><ul><li><p>behavior changes</p></li></ul><p>So when the next pentest starts, you don&#8217;t waste time rediscovering the application &#8212; you <strong>begin where the real risks are</strong>.</p><h3><strong>2. Handling &#8220;security hygiene&#8221; so pentesters focus on impact</strong></h3><p>You don&#8217;t need a human to confirm missing headers, outdated TLS configs, or reflected errors. <br> You <em>do</em> need a human to explore:</p><ul><li><p>workflow flaws</p></li></ul><ul><li><p>authentication loopholes</p></li></ul><ul><li><p>multi-step business logic issues</p></li></ul><ul><li><p>privilege escalation chains</p></li></ul><p>DAST lets pentesters skip the repetitive checks and focus on the high-value work you hired them for.</p><h3><strong>3. Preserving the value of pentest findings through continuous retesting</strong></h3><p>A common problem with relying solely on pentesting is regression:</p><ul><li><p>You fix an auth bug</p></li></ul><ul><li><p>A future refactor silently reintroduces it</p></li></ul><ul><li><p>Nobody notices until the next pentest</p></li></ul><ul><li><p>Or until an attacker does</p></li></ul><p>DAST catches regressions weeks, sometimes months, before they become real incidents.</p><p>This doesn&#8217;t replace pentesting. It <strong>protects</strong> it.</p><h3><strong>4. Giving pentesters telemetry they can use for deeper exploitation</strong></h3><p>During scans, DAST naturally records things like:</p><ul><li><p>unusual response patterns</p></li></ul><ul><li><p>odd state transitions</p></li></ul><ul><li><p>permission anomalies</p></li></ul><ul><li><p>workflows that behave differently under different user contexts</p></li></ul><p>This creates a map of &#8220;interesting behaviors&#8221; that pentesters can dig into.</p><p>It doesn&#8217;t tell them <em>how</em> to exploit something. <br> It tells them <em>where</em> the interesting stuff might be hiding.</p><h2><strong>What this hybrid mindset looks like in practice</strong></h2><p>Teams that rely on pentesting but add DAST often shift to this model:</p><ul><li><p><strong>Pentest &#8594; Fix &#8594; Continuous DAST &#8594; Pentest again</strong></p></li></ul><ul><li><p>Pentesters arrive with a clear, updated map of the system</p></li></ul><ul><li><p>Developers get faster feedback between engagements</p></li></ul><ul><li><p>Regressions never stay hidden</p></li></ul><ul><li><p>New API exposure doesn&#8217;t go unnoticed</p></li></ul><ul><li><p>Security posture becomes consistent, not episodic</p></li></ul><p>This ultimately makes pentesting <em>more valuable</em>, not less.</p><h2><strong>Where Beagle Security fits naturally </strong></h2><p><a href="http://beaglesecurity.com">Beagle Security</a> was built for organizations that want more visibility without abandoning what already works.</p><p>Relevant pieces for a pentest-first workflow:</p><ul><li><p><strong>API discovery</strong> so pentesters always test the real attack surface</p></li></ul><ul><li><p><strong>Context-aware DAST</strong> that behaves like different user roles</p></li></ul><ul><li><p><strong>API detection</strong> for endpoints developers may have missed</p></li></ul><ul><li><p><strong>Business logic awareness</strong> that hints at deeper flaws</p></li></ul><p>It doesn&#8217;t replace human pentesting, but rather, it supports it with clarity, context, and consistency.</p><h2><strong>If you rely on pentesting, keep doing it. But give it the support it deserves.</strong></h2><p>Pentesting is still the deepest, most human layer of security testing we have.</p><p>But modern applications no longer stay still long enough for a snapshot to tell the whole story.</p><p>DAST fills that gap; quietly, continuously, and without altering your fundamental strategy.</p><p>If pentesting is your main security engine, DAST is the fuel-monitoring system that makes sure you never run dry between checkpoints.</p><p>Not a replacement. Not a rival. Just an ally you didn&#8217;t realize you needed.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[How do we keep security on par with vibe coding? Answer: vibe pentesting. ]]></title><description><![CDATA[Developers today don&#8217;t always &#8220;write&#8221; code the old way.]]></description><link>https://beaglesecurity.substack.com/p/how-do-we-keep-security-on-par-with</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/how-do-we-keep-security-on-par-with</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Thu, 13 Nov 2025 14:02:54 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5df93f26-d877-45b5-ba0e-0a655f97e7fc_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Developers today don&#8217;t always &#8220;write&#8221; code the old way. They prompt, iterate, and refine with AI copilots. They prototype at the speed of conversation. That&#8217;s vibe coding: a workflow where a developer&#8217;s role shifts from typing every line to prompting, validating, and iterating AI-generated code.</p><p>Vibe coding is powerful. It lowers barriers, accelerates prototypes, and lets teams try more ideas faster. But speed without guardrails introduces new risks. So, if developers now &#8220;vibe,&#8221; security needs to evolve too. </p><p>My food for thought phrase is <strong>vibe pentesting:</strong> a testing approach designed to match the tempo, unpredictability, and context-driven outputs of vibe coding.</p><p>In this edition, I&#8217;ll try to break down both concepts.</p><h2>What is vibe coding?</h2><p>Vibe coding is shorthand for prompt-first, AI-assisted development. Instead of building starting from scaffolding and hand-written modules, a developer asks an AI to scaffold a feature, generate handlers, or write tests. The developer reviews, adjusts, and iterates.</p><p>Where it works best: prototyping UIs, generating boilerplate, experimenting with integrations, or quickly standing up internal tools. Where it&#8217;s riskier: business logic, auth flows, payment processing, or any code that touches sensitive data.</p><p>The core benefit is speed. The core risk is <em>drift:</em> the gap between working prototypes and secure, maintainable production code.</p><h2>Why traditional pentesting struggles with vibe coding</h2><p>Pentesting historically assumes relatively stable code and repeatable control flows. Tests are crafted against known endpoints, expected payloads, and documented flows.</p><p>Vibe coding changes that model in three ways:</p><ul><li><p><strong>Rapid churn:</strong> Code can change multiple times a day, with AI introducing unfamiliar patterns.</p></li></ul><ul><li><p><strong>Non-deterministic outputs:</strong> The same prompt may produce slightly different code between iterations.</p></li></ul><ul><li><p><strong>Context-driven logic:</strong> AI-generated functions may rely on inferred assumptions that aren&#8217;t documented and are hard to test with canned scripts.</p></li></ul><p>The result: static, periodic pentests miss the velocity and variability of modern development. That&#8217;s why a new testing mindset is needed.</p><h2>Introducing vibe pentesting</h2><p>Vibe pentesting is a testing philosophy and set of practices that align security testing with the vibe coding workflow. It&#8217;s not a single tool but rather a set of capabilities and processes designed to keep pace with prompt-driven development.</p><h2>Core principles of vibe pentesting (as I see it now):</h2><ul><li><p><strong>Continuous, adaptive testing:</strong> Tests run continuously and adapt to new code patterns. When the app changes, the tests evolve automatically.</p></li></ul><ul><li><p><strong>Context-aware scenarios:</strong> Rather than only generic checks, vibe pentesting understands business flows produced by AI and tests misuse cases relevant to those flows.</p></li></ul><ul><li><p><strong>Prompt and output validation:</strong> It treats AI prompts and their outputs as first-class inputs, validating generated code against security guardrails and safe coding standards.</p></li></ul><ul><li><p><strong>Workflow integration:</strong> Vibe pentesting hooks into the same prompts, repos, and CI pipelines developers use, so testing is part of the vibe, not an external checkpoint.</p></li></ul><h2>How vibe pentesting ideally works in practice</h2><ol><li><p><strong>Detect generated changes</strong> <br>The system monitors commits, merge events, or even prompt histories to detect when AI-generated code enters a branch.</p></li></ol><ol start="2"><li><p><strong>Auto-generate tailored tests</strong> <br>Using the generated code and runtime traces, the platform creates test cases that exercise the unique paths and assumptions the AI introduced. E.g., odd parameter handling, inferred defaults, or implicit authorization checks.</p></li></ol><ol start="3"><li><p><strong>Run continuous simulations</strong> <br>Tests run in ephemeral environments or against staging instances to validate behavior and catch logic gaps, race conditions, and insecure defaults.</p></li></ol><ol start="4"><li><p><strong>Simulate misuse and chaining</strong> <br>Vibe pentesting aims to recreate realistic attack chains that abuse multiple small issues together; the same way an attacker might chain AI-generated gaps into a bigger breach.</p></li></ol><ol start="5"><li><p><strong>Prioritize and close the loop</strong> <br>Findings are prioritized by business impact and automatically pushed to the developer workflow with clear remediation steps. Once fixed, tests rerun to verify closure.</p></li></ol><h2><strong>Guardrails and best practices for teams</strong></h2><p>If you&#8217;re adopting vibe coding and want vibe pentesting to protect you, start here:</p><ul><li><p><strong>Log and version prompts.</strong> Keeping a history of prompts and model outputs helps reproduce and test generated code later.</p></li></ul><ul><li><p><strong>Add security linting to the prompt pipeline.</strong> Integrate static checks and secure templates so the AI&#8217;s output must pass basic hygiene before merging.</p></li></ul><ul><li><p><strong>Run tests on every commit and pull request.</strong> Short feedback loops reduce drift and preserve velocity.</p></li></ul><ul><li><p><strong>Prioritize business-impact tests.</strong> Test the flows that matter: login, payments, data exports. Not only the shiny new pages.</p></li></ul><ul><li><p><strong>Invest in training.</strong> Teach developers to prompt securely: include guardrails in prompts (e.g., &#8220;never output credentials&#8221; or &#8220;validate inputs using these rules&#8221;).</p></li></ul><h2>Why this matters for AppSec</h2><p>Vibe coding will not go away. It&#8217;s accelerating how software is created. But unguarded, it can create a new class of fragile production issues: inconsistent auth, hidden assumptions, and subtle logic errors.</p><p>Vibe pentesting is a practical bridge. It brings testing speed and contextual intelligence to match AI-driven development. It focuses on <em>how code behaves</em> in your app, not only <em>what the code looks like</em>.</p><h2>How Beagle Security is evolving into it</h2><p>At Beagle Security we&#8217;re building capabilities that map naturally into vibe pentesting:</p><ul><li><p><strong>Contextual crawling and discovery</strong> that tracks newly generated endpoints and hidden routes.</p></li></ul><ul><li><p><strong>Adaptive test generation</strong> that creates tests based on code changes and runtime behavior rather than a static checklist.</p></li></ul><ul><li><p><strong>Business-logic simulations</strong> to find abuse scenarios born from AI-generated workflows.</p></li></ul><ul><li><p><strong>CI/CD integration</strong> so tests are part of every build and merge, not an afterthought.</p></li></ul><ul><li><p><strong>Actionable remediation guidance</strong> that gives developers clear, minimal-impact steps to fix problems fast.</p></li></ul><p>The goal: keep your speed, preserve your safety.</p><h2>Wrapping up</h2><p>Vibe coding is a step change in how we build software. It unlocks creativity and velocity, but speed without structure can be dangerous. Vibe pentesting doesn&#8217;t try to slow the developer down. It moves with them.</p><p>If you&#8217;re vibing your next feature, make sure your pentesting vibes with you.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Cybersecurity awareness month 2025: Reflections, realities, and the road ahead]]></title><description><![CDATA[October may be over, but the conversation it sparked continues.]]></description><link>https://beaglesecurity.substack.com/p/cybersecurity-awareness-month-2025</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/cybersecurity-awareness-month-2025</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Fri, 07 Nov 2025 14:03:55 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/f2dcee8a-73bb-4c35-bdfb-2b73225fe91f_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>October may be over, but the conversation it sparked continues.</p><p>Cybersecurity Awareness Month has always been a global reminder to <strong>pause, reflect, and re-evaluate</strong> how we protect our digital world. And this year with AI reshaping everything from attack surfaces to defense strategies, that reminder feels more urgent than ever.</p><p><strong>&#8220;Stay Safe Online.&#8221;</strong><br>That&#8217;s the theme for this year&#8217;s Cybersecurity Awareness Month, and perhaps the most relevant one yet.</p><p>In a world where our personal data, businesses, and even national infrastructure live online, the phrase &#8220;staying safe&#8221; now means far more than avoiding suspicious emails. It&#8217;s about <strong>rethinking how we use technology</strong>, understanding the risks that come with convenience, and building habits that keep us resilient.</p><p>At <em>Beagle Security</em>, we spent this year&#8217;s Awareness Month listening to developers, defenders, and decision-makers; and at <strong>c0c0n 2025</strong>, we interacted with some of the brightest minds in cybersecurity.</p><p>Here&#8217;s what they told us.</p><div><hr></div><h2><strong>AI: The double-edged sword</strong></h2><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;c4f453e0-96d0-402e-8bca-5689937bc5be&quot;,&quot;duration&quot;:null}"></div><blockquote><p>&#8220;<em>AI in cybersecurity is a double-edged sword</em>,&#8221; said <strong>Sunil Varkey</strong>, a veteran security leader. &#8220;<em>While adversaries are already leveraging AI, we have no choice but to keep up. The real danger lies in over-reliance &#8212; if we blindly trust AI, our workforce loses the ability to validate, adapt, and think critically.</em>&#8221;</p></blockquote><p>He warned that as companies build playbooks and response strategies generated by the same AI tools, the world risks becoming &#8220;homogeneous&#8221; i.e. defenders thinking and responding in the same predictable ways.</p><blockquote><p>&#8220;<em>AI is needed, but I&#8217;m skeptical,</em>&#8221; he concluded. &#8220;<em>The experienced security professional who can think beyond what AI suggests will be the most valuable asset in the years to come.</em>&#8221;</p></blockquote><div><hr></div><h2><strong>AI in AppSec: Opportunity meets responsibility</strong></h2><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;c3abfea1-f4a3-4e1b-8bb1-c0b458d06c72&quot;,&quot;duration&quot;:null}"></div><blockquote><p>&#8220;<em>It&#8217;s high time we start leveraging AI to its fullest potential,</em>&#8221; said <strong>Sapan Harish Talwar</strong>, cybersecurity leader. &#8220;<em>Threat actors are already using AI to exploit vulnerabilities in infrastructure and applications &#8212; it&#8217;s only fair that we use it to defend better.</em>&#8221;</p></blockquote><p>He emphasized how <strong>AI-driven continuous monitoring and remediation</strong> can revolutionize application security, still one of the most under-protected layers in many organizations.</p><blockquote><p>&#8220;<em>AI can help us detect and fix vulnerabilities instantly,</em>&#8221; he added, &#8220;<em>but only if we adopt security by design and continuous validation from the ground up.</em>&#8221;</p></blockquote><div><hr></div><h2><strong>Finding the balance: promise vs. pitfalls</strong></h2><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;e105f458-7e70-4f6f-a764-2718335110db&quot;,&quot;duration&quot;:null}"></div><blockquote><p>&#8220;<em>AI has the potential to give cybersecurity a major advantage &#8212; particularly when it comes to finding vulnerabilities in code,</em>&#8221; said <strong>Nathan Hamiel</strong>.</p></blockquote><p>AI can indeed accelerate code scanning, static analysis, and vulnerability discovery. But Nathan pointed out that we still haven&#8217;t solved one of AI&#8217;s most critical weaknesses: <strong>prompt injection</strong>.</p><blockquote><p>&#8220;<em>Even the security tools we deploy can be manipulated or misled,</em>&#8221; he warned. &#8220;<em>We need to apply secure design principles to these systems &#8212; making them resilient, robust, and trustworthy.</em>&#8221;</p></blockquote><p>The takeaway: AI can augment security, but it can&#8217;t replace design thinking and rigorous engineering.</p><div><hr></div><h2><strong>Cybersecurity as an inspiration story</strong></h2><p>Amid the technical discussions and deep dives, <strong>Jairam Ramesh</strong> brought a refreshing human perspective.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;475e1d66-8a14-4ea5-9c86-3eba99cb9eda&quot;,&quot;duration&quot;:null}"></div><blockquote><p>&#8220;<em>If cybersecurity were a movie genre right now, I&#8217;d call it an inspirational movie,</em>&#8221; he said with a smile. &#8220;<em>We&#8217;re in a time when organizations and nations are preparing for cyberattacks &#8212; but behind the scenes are countless professionals working tirelessly to defend and protect.</em>&#8221;</p></blockquote><p>He added,</p><blockquote><p>&#8220;<em>It&#8217;s a story where the good guys still triumph over the bad &#8212; not because the challenges are small, but because of the people, passion, and persistence driving cybersecurity forward.</em>&#8221;</p></blockquote><p>His words were a fitting reminder: behind every firewall, AI model, or line of defense, there are real people doing real work that matters.</p><div><hr></div><h2><strong>The permanence of data</strong></h2><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;abacb42a-797a-4a55-bfda-651df06e4449&quot;,&quot;duration&quot;:null}"></div><blockquote><p>&#8220;<em>If you put an image online or share it online, it will be there forever,</em>&#8221; said <strong>Derek Ray Hill</strong>, when asked about a lesson that has stayed with him.</p></blockquote><p>A simple statement, yet one that captures the <strong>essence of modern digital risk</strong>. Whether it&#8217;s an exposed credential, a misconfigured database, or a careless upload, what reaches the internet tends to stay there.</p><p>In an era of deepfakes, data leaks, and endless sharing, this truth underscores the need for vigilance at every level from individuals to enterprises.</p><div><hr></div><h2><strong>The awareness we still need</strong></h2><p>The messages from these leaders converge on a common truth:<br>Cybersecurity should always be about <em>awareness, adaptability, and accountability</em>.</p><p>Awareness that tools alone won&#8217;t save us.<br>Adaptability to use AI intelligently, not blindly.<br>And accountability to build systems that prioritize security from design to deployment.</p><p>This Cybersecurity Awareness Month may have ended, but the mission continues.<br>Every login, every API call, every line of code still holds the power to protect or expose.</p><div><hr></div><h2><strong>Looking ahead: Building continuous awareness</strong></h2><p>As security threats evolve, so must the way we test and defend. Platforms like <strong>Beagle Security</strong> are designed to keep organizations one step ahead with AI-driven, continuous penetration testing that uncovers vulnerabilities before attackers do.</p><p>In a world where breaches happen at machine speed, automation is the only way to stay resilient.</p><p>So, as we move beyond October, let&#8217;s carry forward the spirit of awareness, not just as a yearly campaign, but as an everyday mindset. </p><p>Security isn&#8217;t a checkbox. It&#8217;s a culture.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[IT security audit: Let's learn more]]></title><description><![CDATA[You&#8217;ve pulled together the reports.]]></description><link>https://beaglesecurity.substack.com/p/it-security-audit-lets-learn-more</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/it-security-audit-lets-learn-more</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Fri, 24 Oct 2025 07:14:38 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/cb4558ae-13d8-4c3c-bcf6-46f2e0071266_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>You&#8217;ve pulled together the reports. You&#8217;ve checked the boxes. But now comes the big question: <strong>Did you really understand what all that meant?</strong></p><p>An IT security audit can feel like a grand ceremony with multiple teams, thick binders, checklists galore. But if it ends there, you&#8217;ve missed the point. An audit isn&#8217;t a trophy; it&#8217;s a tool. One that, when wielded right, gives you clarity on your risk, your controls, and your next moves.</p><p>If you&#8217;re ready to move beyond the surface and into the meat of what an audit can truly deliver, this edition of All Things AppSec is for you.</p><div><hr></div><h2>What is an IT security audit (really)?</h2><p>An audit is not just a &#8220;find-and-fix&#8221; exercise. At its core, an IT security audit is a <strong>comprehensive and periodic evaluation</strong> of your policies, infrastructure, processes and controls. </p><p>How it shows up:</p><ul><li><p>Reviewing how your firewall rules are set up</p></li><li><p>Validating user access policies (who can do what, and is that still valid?)</p></li><li><p>Checking patching and configurations across your systems</p></li><li><p>Confirming data is classified, encrypted, handled, and disposed properly</p></li><li><p>Making sure security is baked into everything from dev workflows to disaster recovery</p></li></ul><p>When done right, an audit gives you a map: where you are, where you should be, and how far you have to go.</p><div><hr></div><h2>Why regular audits are non-negotiable</h2><p>It&#8217;s easy to treat audits like annual chores. But what do you actually get when you do them well?</p><ul><li><p><strong>Proactive risk reduction</strong> &#8211; The best time to find a gap is <em>before</em> it&#8217;s exploited.</p></li><li><p><strong>Regulatory alignment</strong> &#8211; Whether you&#8217;re under GDPR, HIPAA, PCI-DSS or ISO-27001, audits help you demonstrate compliance and avoid fines.</p></li><li><p><strong>Business resilience</strong> &#8211; Audits evaluate your incident response, backup, disaster recovery. So, when something goes wrong, you don&#8217;t lose everything.</p></li><li><p><strong>Trust &amp; reputation</strong> &#8211; Showing partners, customers and stakeholders you take security seriously matters now more than ever.</p></li></ul><div><hr></div><h2>Types of audits: Picking what fits you</h2><p>Not all audits are created equal. Here are the major types you&#8217;d want to be familiar with:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hYcO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hYcO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png 424w, https://substackcdn.com/image/fetch/$s_!hYcO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png 848w, https://substackcdn.com/image/fetch/$s_!hYcO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!hYcO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hYcO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png" width="1200" height="1200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:171635,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://beaglesecurity.substack.com/i/176989165?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hYcO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png 424w, https://substackcdn.com/image/fetch/$s_!hYcO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png 848w, https://substackcdn.com/image/fetch/$s_!hYcO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!hYcO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96aa381b-6a1a-4bca-b7f9-2a360c37959d_1200x1200.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Choosing the right type (or combination) matters because it helps you spend wisely and target what matters most.</p><div><hr></div><h2>When and how often should you audit?</h2><p>There&#8217;s no one-size-fits-all answer, but guidelines help set expectations.</p><ul><li><p><strong>At least annually</strong> for full assessments.</p></li><li><p><strong>Continuous monitoring and interim reviews</strong> for high-risk systems or changing environments.</p></li><li><p><strong>Trigger-based audits</strong> should happen after major events: new system deployments, major architecture changes, mergers/acquisitions, or after a breach.</p></li><li><p><strong>More frequent audits</strong> may be required in sectors like healthcare, finance or government.</p></li></ul><p>Your goal: align frequency with your risk profile and environment changes.</p><div><hr></div><h2>Best practices for smarter audits</h2><p>A checklist helps, but the mindset behind it counts more. Here&#8217;s how to elevate your audit game:</p><ol><li><p><strong>Define clear objectives &amp; scope</strong> &#8211; Before you start, know <em>what</em> you&#8217;re auditing and <em>why</em>.</p></li><li><p><strong>Follow recognised frameworks</strong> &#8211; Use NIST, ISO 27001, CIS Controls as your foundation.</p></li><li><p><strong>Build continuous visibility</strong> &#8211; Audits shouldn&#8217;t be once-a-year surprises. Use monitoring, automation, dashboards.</p></li><li><p><strong>Stay ahead of threats</strong> &#8211; Threat actors evolve; your audit methods should too. Training, red-teaming, fresh expertise matter.</p></li><li><p><strong>Collaborate across teams</strong> &#8211; Security isn&#8217;t just an IT problem. Get business, legal, operations involved.</p></li><li><p><strong>Report with clarity &amp; priority</strong> &#8211; Findings should have business impact context, clear next actions, and a prioritization strategy.</p></li><li><p><strong>Test incident response via exercises</strong> &#8211; Table-top drills help ensure procedures work under pressure.</p></li><li><p><strong>Focus on risk, not just vulnerabilities</strong> &#8211; Identify what <em>matters most</em> to your organisation and protect accordingly.</p></li></ol><div><hr></div><h2>IT security audit checklist &#8211; Key areas</h2><p>Here are high-value controls to include in your audit:</p><ul><li><p><strong>Governance &amp; policy</strong>: Security strategy, training, documentation align with business goals.</p></li><li><p><strong>Risk management</strong>: Risk identification, treatment plans, vendor assessments.</p></li><li><p><strong>Access control &amp; identity management</strong>: MFA, role separation, session controls.</p></li><li><p><strong>Network security</strong>: Architecture, segmentation, remote access protections.</p></li><li><p><strong>Applications &amp; systems</strong>: Patch management, secure development practices, vulnerability management.</p></li><li><p><strong>Data protection</strong>: Encryption in transit and at rest, backups, data retention.</p></li><li><p><strong>Physical security</strong>: Facility access controls, media disposal, environmental safeguards.</p></li><li><p><strong>Incident management</strong>: Response plans, escalation procedures, lessons-learned integration.</p></li><li><p><strong>Compliance &amp; third-party risk</strong>: Regulations, contractual requirements, vendor security practices.</p></li></ul><p>Use this as your starting toolkit. Adapt and expand it based on what&#8217;s unique to your business.</p><div><hr></div><h2>Why this matters for AppSec teams</h2><p>Your application security efforts (pentests, code reviews, CI/CD scanning) live inside this bigger ecosystem. A robust audit helps you:</p><ul><li><p>See how your app fits into bigger infrastructure and controls</p></li><li><p>Prioritize tests based on real risk (not just CVSS)</p></li><li><p>Align development, operations, and security around the same goals</p></li><li><p>Demonstrate value and security maturity to stakeholders</p></li></ul><p>When your AppSec program aligns with audit insights, you move from reactive to strategic.</p><div><hr></div><h2>Final thoughts</h2><p>Audits should <em>feel</em> uncomfortable. If you walk away nodding and don&#8217;t question anything, you&#8217;re doing it wrong. The best audits surface unexpected truths, challenge assumptions, and push real action.</p><p>So, set goals. Define scope. Get visibility. Use this checklist. And treat your audit as more than a one-time event. </p><p>After all, you&#8217;re not just checking boxes. You&#8217;re protecting real assets, real users, and real trust.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The small company security dilemma ]]></title><description><![CDATA[When I hear &#8220;this is the perfect security solution for your startup&#8221;, I cringe just a little.]]></description><link>https://beaglesecurity.substack.com/p/the-small-company-security-dilemma</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/the-small-company-security-dilemma</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Fri, 26 Sep 2025 14:01:35 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/769f7198-c72f-4894-b6e0-7c89b94259ee_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When I hear <strong>&#8220;this is the perfect security solution for your startup&#8221;</strong>, I cringe just a little.</p><p>&#8220;Perfect security&#8221; is a unicorn; beautiful in theory, heartbreaking in practice. Trying to build it often means you spend months locking down edge cases while someone steals the crown jewels right out from the front door.</p><p>Here&#8217;s the real truth: small businesses <em>don&#8217;t</em> need perfect security. They need smart, context-aware, resilient security. Ones that scale with them, doesn&#8217;t cost the earth, and adapts as threats evolve.</p><p>In this edition of All Things AppSec, we&#8217;ll talk about what &#8220;good enough&#8221; really means for small and growing businesses and how to make tradeoffs wisely.</p><h1>The myth of &#8220;perfect security&#8221;</h1><p>When we&#8217;re starting a business or building a minimal viable product (MVP), time and resources are tight. You might imagine security as a checklist:</p><p>&#8220;XSS? Check.&#8221; <br> &#8220;SQLi? Check.&#8221; <br> &#8220;HTTPS? Check.&#8221;</p><p>But zero vulnerabilities in a static scan doesn&#8217;t mean no risk. What matters more is whether your defenses prevent or contain real attacks in <em>your </em>actual environment. That&#8217;s where &#8220;perfect security&#8221; fails as a notion.</p><p>Trying to patch every possible weakness before shipping often leads to:</p><ul><li><p>Launch delays</p></li></ul><ul><li><p>Burnout for small teams</p></li></ul><ul><li><p>Security feature bloat that users never see</p></li></ul><ul><li><p>Blind spots where the &#8220;obvious&#8221; exposures get ignored</p></li></ul><p>Instead, small businesses should lean into <strong>purpose-built security</strong>, not perfection.</p><h1>What &#8220;good enough&#8221; looks like in practice</h1><p>Here are characteristics of security that&#8217;s practical, not perfect:</p><ol><li><p><strong>Risk-based priorities</strong> <br> Focus first on what an attacker will likely target (authentication, access control, data exfiltration, the usual supects) instead of chasing every theoretical flaw.</p></li></ol><blockquote></blockquote><ol start="2"><li><p><strong>Layered defenses</strong> <br>A single control failing shouldn&#8217;t lead to catastrophe. Use defense in depth: network rules, API gates, rate limiting, input validation.</p></li></ol><blockquote></blockquote><ol start="3"><li><p><strong>Detect + respond over prevent only</strong> <br>Security failures happen. The ability to detect anomalies and respond quickly is often more valuable than trying to block every single threat.</p></li></ol><blockquote></blockquote><ol start="4"><li><p><strong>Automation where possible</strong> <br>Tools for scanning, alerting, and auto-remediation reduce human overhead and scale better than manual controls.</p></li></ol><blockquote></blockquote><ol start="5"><li><p><strong>Continuous improvement</strong> <br>Start small, measure, learn, and incrementally enhance security as you grow. Don&#8217;t over architect too soon.</p></li></ol><h1>Common tradeoffs (and when they&#8217;re acceptable)</h1><p>To grow, small teams often must choose which fight to fight. Some tradeoffs are okay, but only if made thoughtfully.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oXh4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oXh4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png 424w, https://substackcdn.com/image/fetch/$s_!oXh4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png 848w, https://substackcdn.com/image/fetch/$s_!oXh4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png 1272w, https://substackcdn.com/image/fetch/$s_!oXh4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oXh4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png" width="1200" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:900,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108347,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://beaglesecurity.substack.com/i/174612071?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oXh4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png 424w, https://substackcdn.com/image/fetch/$s_!oXh4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png 848w, https://substackcdn.com/image/fetch/$s_!oXh4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png 1272w, https://substackcdn.com/image/fetch/$s_!oXh4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ca1af30-820d-4f54-9945-14d980565c60_1200x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>How Beagle Security can help small businesses build security wisely</h1><p>We&#8217;ve designed Beagle Security to support lean, growth-stage teams; not just enterprise security teams.</p><ul><li><p><strong>Contextual scanning, not just generic scans</strong> <br>Beagle Security understands your stack (frontend, backend, APIs) and focuses on what matters in your environment, not just generic vulnerabilities.</p></li></ul><blockquote></blockquote><ul><li><p><strong>Business logic aware tests</strong> <br>We simulate real-world misuse, not just technical flaws like abuse of discount systems, IDORs, or role escalations.</p></li></ul><blockquote></blockquote><ul><li><p><strong>Actionable reports, not noise</strong> <br>Every issue comes with business impact context and clear remediation steps suited for small teams.</p></li></ul><blockquote></blockquote><ul><li><p><strong>Continuous security integration</strong> <br>Beagle Security integrates into CI/CD pipelines so you&#8217;re always testing, even as you ship fast.</p></li></ul><h1>Final thoughts: Aim for resilient, not perfect</h1><p>&#8220;Perfect security&#8221; is a mirage. But <strong>resilient security, </strong>the kind that recovers, resists impact, and evolves, is real and achievable.</p><p>Small businesses don&#8217;t need to be invincible (who is?). They just need to be prepared enough to repel common attacks and recover when they&#8217;re struck.</p><p>Start with strong layers, focus on real threats, automate what you can, and continuously improve. That&#8217;s security that works in the real world.</p><p>Want help evaluating your &#8220;good enough&#8221;? Leave a message. Let&#8217;s talk about what your security should look like right<em> now</em>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Context is everything ]]></title><description><![CDATA[When most people think of penetration testing, they picture a fairly standard process: scan the application, flag vulnerabilities, assign a severity score, and ship a report.]]></description><link>https://beaglesecurity.substack.com/p/context-is-everything</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/context-is-everything</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Fri, 19 Sep 2025 14:03:04 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/223ea0e5-ec88-490a-9da4-7f27b57542dd_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When most people think of penetration testing, they picture a fairly standard process: scan the application, flag vulnerabilities, assign a severity score, and ship a report.</p><p>It&#8217;s neat. It&#8217;s structured. It looks good in an audit.</p><p>But here&#8217;s the problem: <strong>attackers don&#8217;t think that way.</strong></p><p>They don&#8217;t care about a severity score in isolation. They care about how different flaws in <em>your</em> environment can be chained together, abused in <em>your</em> workflows, and leveraged against <em>your</em> users.</p><p>And that&#8217;s where many pentests fall short. They miss the <strong>context.</strong></p><h1>Why generic pentesting isn&#8217;t enough</h1><p>Let&#8217;s break down why a one-size-fits-all pentest can leave major blind spots:</p><ol><li><p><strong>Business logic risks are overlooked</strong> <br> Traditional scanners and checklists are great at spotting technical issues like SQL injections or open ports. But they rarely catch business logic flaws. The subtle gaps in how features behave when pushed outside normal use are never paid attention to.</p></li></ol><blockquote></blockquote><ol start="2"><li><p><strong>Severity doesn&#8217;t always match real-world risk</strong> <br> Many reports use CVSS scores as the north star. But a &#8220;Medium&#8221; vulnerability in an authentication flow could be far more damaging than a &#8220;High&#8221; in a low-privilege API endpoint. Without context, teams often waste time fixing the wrong things.</p></li></ol><blockquote></blockquote><ol start="3"><li><p><strong>Tech stack differences matter</strong> <br> A microservices-based SaaS with GraphQL APIs has different risks than a legacy PHP monolith. Yet many pentests run the same set of canned tests across both. That&#8217;s like securing a bank vault and a coffee shop with the same lock.</p></li></ol><blockquote></blockquote><ol start="4"><li><p><strong>Compliance &#8800; security</strong> <br> Passing PCI-DSS, SOC2, or ISO audits doesn&#8217;t guarantee safety. Compliance ensures you&#8217;ve met a baseline, but attackers exploit gaps outside those baselines. A report that focuses only on compliance misses the bigger picture.</p></li></ol><h1>How context makes pentesting stronger</h1><p>If attackers think in terms of context, defenders should too. How exactly do we do this?</p><h2>1. Business-centric threat modeling</h2><p>Instead of starting with a checklist, testers should start with questions:</p><ul><li><p>What&#8217;s the most valuable data in this app?</p></li></ul><ul><li><p>Who would want it and why?</p></li></ul><ul><li><p>What workflows, if abused, could cause financial or reputational damage?</p></li></ul><p>This lens changes everything. For instance:</p><ul><li><p>A fintech app&#8217;s refund workflow is a goldmine for fraud.</p></li></ul><ul><li><p>A healthcare app&#8217;s file upload function is a potential privacy nightmare.</p></li></ul><ul><li><p>A SaaS app&#8217;s invitation link system could be abused for privilege escalation.</p></li></ul><p>When pentesters know <em>your</em> crown jewels, they can focus efforts where it matters most.</p><h2>2. Attack chain thinking</h2><p>Real attackers rarely rely on a single bug. They chain smaller issues to create a breach. Context-aware testing simulates this.</p><ul><li><p>Weak authentication &#8594; exposed API &#8594; lateral movement &#8594; sensitive data leak. <br> Individually, each issue might look minor. In context, it&#8217;s a disaster.</p></li></ul><h2>3. Impact-driven prioritization</h2><p>Not all vulnerabilities deserve the same attention.</p><ul><li><p>Example: A &#8220;Medium&#8221; issue that allows brute-force attempts on an admin login page is far more urgent than a &#8220;High&#8221; reflected XSS in a low-traffic marketing subdomain. <br> Context turns raw findings into actionable priorities.</p></li></ul><h2>4. Environment-specific testing</h2><p>The same vulnerability can look very different across environments:</p><ul><li><p>A misconfigured S3 bucket storing test data = nuisance.</p></li></ul><ul><li><p>A misconfigured S3 bucket storing production PII = regulatory nightmare. <br> Context ensures tests reflect what&#8217;s truly at stake.</p></li></ul><h1>Beagle Security&#8217;s approach</h1><p>At <a href="https://beaglesecurity.com/">Beagle Security</a>, we&#8217;ve built <strong>AI-driven automated pentesting</strong> that adapts to each application instead of forcing everything into a template. Here&#8217;s how we put context at the core:</p><ul><li><p><strong>Tech-stack aware test case selection</strong> <br> Instead of running the same scans everywhere, our engine tailors tests based on your architecture, frameworks, and integrations. A Node.js API is tested differently than a WordPress app.</p></li></ul><blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CUOk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab51f88d-8e8b-4337-a1c2-c2655aaf48ed_936x936.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CUOk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab51f88d-8e8b-4337-a1c2-c2655aaf48ed_936x936.png 424w, https://substackcdn.com/image/fetch/$s_!CUOk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab51f88d-8e8b-4337-a1c2-c2655aaf48ed_936x936.png 848w, https://substackcdn.com/image/fetch/$s_!CUOk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab51f88d-8e8b-4337-a1c2-c2655aaf48ed_936x936.png 1272w, https://substackcdn.com/image/fetch/$s_!CUOk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab51f88d-8e8b-4337-a1c2-c2655aaf48ed_936x936.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CUOk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab51f88d-8e8b-4337-a1c2-c2655aaf48ed_936x936.png" width="936" height="936" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab51f88d-8e8b-4337-a1c2-c2655aaf48ed_936x936.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:936,&quot;width&quot;:936,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CUOk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab51f88d-8e8b-4337-a1c2-c2655aaf48ed_936x936.png 424w, https://substackcdn.com/image/fetch/$s_!CUOk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab51f88d-8e8b-4337-a1c2-c2655aaf48ed_936x936.png 848w, https://substackcdn.com/image/fetch/$s_!CUOk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab51f88d-8e8b-4337-a1c2-c2655aaf48ed_936x936.png 1272w, https://substackcdn.com/image/fetch/$s_!CUOk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab51f88d-8e8b-4337-a1c2-c2655aaf48ed_936x936.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></blockquote><ul><li><p><strong>Business logic testing</strong> <br>Using AI, Beagle Security simulates complex workflows and misuse cases that often slip past scanners. Users can also upload recordings of complex flows within their app that'll help Beagle Security's AI engine double down on vulnerabilities that may arise here.</p></li></ul><blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XUrz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a3c0dc5-a484-4f13-a8cc-fb8ae20c1ed1_936x936.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XUrz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a3c0dc5-a484-4f13-a8cc-fb8ae20c1ed1_936x936.png 424w, https://substackcdn.com/image/fetch/$s_!XUrz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a3c0dc5-a484-4f13-a8cc-fb8ae20c1ed1_936x936.png 848w, https://substackcdn.com/image/fetch/$s_!XUrz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a3c0dc5-a484-4f13-a8cc-fb8ae20c1ed1_936x936.png 1272w, https://substackcdn.com/image/fetch/$s_!XUrz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a3c0dc5-a484-4f13-a8cc-fb8ae20c1ed1_936x936.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XUrz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a3c0dc5-a484-4f13-a8cc-fb8ae20c1ed1_936x936.png" width="936" height="936" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6a3c0dc5-a484-4f13-a8cc-fb8ae20c1ed1_936x936.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:936,&quot;width&quot;:936,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XUrz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a3c0dc5-a484-4f13-a8cc-fb8ae20c1ed1_936x936.png 424w, https://substackcdn.com/image/fetch/$s_!XUrz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a3c0dc5-a484-4f13-a8cc-fb8ae20c1ed1_936x936.png 848w, https://substackcdn.com/image/fetch/$s_!XUrz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a3c0dc5-a484-4f13-a8cc-fb8ae20c1ed1_936x936.png 1272w, https://substackcdn.com/image/fetch/$s_!XUrz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a3c0dc5-a484-4f13-a8cc-fb8ae20c1ed1_936x936.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></blockquote><ul><li><p><strong>Contextual reporting</strong> <br>Our reports highlight not just the &#8220;what&#8221; but the &#8220;so what.&#8221; You see which vulnerabilities could realistically compromise <em>your</em> data, <em>your</em> workflows, and <em>your</em> compliance posture.</p></li></ul><p>The goal: security testing that reflects your real-world risks, not a generic checklist.</p><h1>What you can do today</h1><p>Even if you&#8217;re not using Beagle Secuity yet, here are practical steps to bring more context into your pentesting program:</p><ol><li><p><strong>Integrate threat modeling into every pentest</strong> <br> Make it a standard to start with your business processes and data flows.</p></li></ol><ol start="2"><li><p><strong>Prioritize based on business impact, not just severity</strong> <br> Ask: &#8220;If exploited, what would this mean for us?&#8221;</p></li></ol><ol start="3"><li><p><strong>Collaborate across teams</strong> <br> Involve product managers, developers, and security teams in scoping. They know where the sensitive flows are.</p></li></ol><ol start="4"><li><p><strong>Revisit findings in your own environment</strong> <br> Don&#8217;t just rely on the pentest report. Map each issue to your assets and usage patterns.</p></li></ol><h1>Wrapping up</h1><p>Attackers don&#8217;t care about CVSS scores or compliance checkboxes. They care about impact. And unless your pentests reflect that, you&#8217;ll always be playing catch-up.</p><p><strong>The future of pentesting isn&#8217;t more scans. It&#8217;s smarter, context-driven security.</strong></p><p>Because in AppSec, as in everything else: <strong>context is everything.</strong></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The first AI-powered ransomware is here ]]></title><description><![CDATA[For years, ransomware has been one of the biggest nightmares for organizations.]]></description><link>https://beaglesecurity.substack.com/p/the-first-ai-powered-ransomware-is</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/the-first-ai-powered-ransomware-is</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Fri, 12 Sep 2025 14:00:59 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/892f09e3-d54b-4cd3-90d5-69f34cbc9ddb_2912x2096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>For years, ransomware has been one of the biggest nightmares for organizations. Traditional strains relied on pre-written malicious code, spreading through phishing campaigns, exploiting vulnerabilities, or brute-forcing credentials. Defenders learned their tricks and built detection patterns.</p><p>But now, with <strong>PromptLock</strong>, we&#8217;re entering uncharted territory: ransomware built with the help of <strong>generative AI</strong>.</p><p>ESET Research recently uncovered PromptLock, a proof-of-concept malware that demonstrates how attackers can integrate large language models (LLMs) into ransomware to make it <strong>smarter, adaptive, and cross-platform</strong>.</p><p>This is the first documented case of AI being used in active ransomware code&#8212;and it won&#8217;t be the last.</p><h1>How PromptLock works</h1><p>At its core, PromptLock is powered by <strong>OpenAI&#8217;s gpt-oss:20b model</strong> running locally through the <strong>Ollama API</strong>. Instead of hardcoding every action, the ransomware relies on AI prompts to generate <strong>Lua scripts dynamically</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TbWJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d76a843-88a6-43ad-b2e9-84c1ee193c75_894x258.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TbWJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d76a843-88a6-43ad-b2e9-84c1ee193c75_894x258.png 424w, https://substackcdn.com/image/fetch/$s_!TbWJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d76a843-88a6-43ad-b2e9-84c1ee193c75_894x258.png 848w, https://substackcdn.com/image/fetch/$s_!TbWJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d76a843-88a6-43ad-b2e9-84c1ee193c75_894x258.png 1272w, https://substackcdn.com/image/fetch/$s_!TbWJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d76a843-88a6-43ad-b2e9-84c1ee193c75_894x258.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TbWJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d76a843-88a6-43ad-b2e9-84c1ee193c75_894x258.png" width="894" height="258" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d76a843-88a6-43ad-b2e9-84c1ee193c75_894x258.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:258,&quot;width&quot;:894,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TbWJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d76a843-88a6-43ad-b2e9-84c1ee193c75_894x258.png 424w, https://substackcdn.com/image/fetch/$s_!TbWJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d76a843-88a6-43ad-b2e9-84c1ee193c75_894x258.png 848w, https://substackcdn.com/image/fetch/$s_!TbWJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d76a843-88a6-43ad-b2e9-84c1ee193c75_894x258.png 1272w, https://substackcdn.com/image/fetch/$s_!TbWJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d76a843-88a6-43ad-b2e9-84c1ee193c75_894x258.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That means:</p><ul><li><p>The code it executes can <strong>change on the fly</strong>, making it harder to detect through static analysis.</p></li></ul><ul><li><p>The attacker doesn&#8217;t need to manually write every malicious function&#8212;the AI helps produce them.</p></li></ul><ul><li><p>Defensive signatures based on known malware behaviors may not work as effectively.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z9VW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2102d1ae-2994-42c0-a6b9-f96d48815cb7_936x456.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z9VW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2102d1ae-2994-42c0-a6b9-f96d48815cb7_936x456.png 424w, https://substackcdn.com/image/fetch/$s_!z9VW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2102d1ae-2994-42c0-a6b9-f96d48815cb7_936x456.png 848w, https://substackcdn.com/image/fetch/$s_!z9VW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2102d1ae-2994-42c0-a6b9-f96d48815cb7_936x456.png 1272w, https://substackcdn.com/image/fetch/$s_!z9VW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2102d1ae-2994-42c0-a6b9-f96d48815cb7_936x456.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z9VW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2102d1ae-2994-42c0-a6b9-f96d48815cb7_936x456.png" width="936" height="456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2102d1ae-2994-42c0-a6b9-f96d48815cb7_936x456.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:456,&quot;width&quot;:936,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z9VW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2102d1ae-2994-42c0-a6b9-f96d48815cb7_936x456.png 424w, https://substackcdn.com/image/fetch/$s_!z9VW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2102d1ae-2994-42c0-a6b9-f96d48815cb7_936x456.png 848w, https://substackcdn.com/image/fetch/$s_!z9VW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2102d1ae-2994-42c0-a6b9-f96d48815cb7_936x456.png 1272w, https://substackcdn.com/image/fetch/$s_!z9VW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2102d1ae-2994-42c0-a6b9-f96d48815cb7_936x456.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Once installed on a victim&#8217;s system, PromptLock uses these generated scripts to:</p><ul><li><p>Enumerate files and directories</p></li></ul><ul><li><p>Encrypt user data</p></li></ul><ul><li><p>Potentially exfiltrate sensitive information</p></li></ul><p>And it works on <strong>Windows, Linux, and macOS</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hgGb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf726ac3-a82b-489f-a7d5-821728d5c3a8_889x175.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hgGb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf726ac3-a82b-489f-a7d5-821728d5c3a8_889x175.png 424w, https://substackcdn.com/image/fetch/$s_!hgGb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf726ac3-a82b-489f-a7d5-821728d5c3a8_889x175.png 848w, https://substackcdn.com/image/fetch/$s_!hgGb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf726ac3-a82b-489f-a7d5-821728d5c3a8_889x175.png 1272w, https://substackcdn.com/image/fetch/$s_!hgGb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf726ac3-a82b-489f-a7d5-821728d5c3a8_889x175.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hgGb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf726ac3-a82b-489f-a7d5-821728d5c3a8_889x175.png" width="889" height="175" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf726ac3-a82b-489f-a7d5-821728d5c3a8_889x175.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:175,&quot;width&quot;:889,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hgGb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf726ac3-a82b-489f-a7d5-821728d5c3a8_889x175.png 424w, https://substackcdn.com/image/fetch/$s_!hgGb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf726ac3-a82b-489f-a7d5-821728d5c3a8_889x175.png 848w, https://substackcdn.com/image/fetch/$s_!hgGb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf726ac3-a82b-489f-a7d5-821728d5c3a8_889x175.png 1272w, https://substackcdn.com/image/fetch/$s_!hgGb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf726ac3-a82b-489f-a7d5-821728d5c3a8_889x175.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h1>The anatomy of PromptLock</h1><p>What makes this malware unique?</p><ol><li><p><strong>Cross-platform reach</strong></p></li></ol><p>Written in <strong>Golang</strong>, PromptLock can compile and run natively on Windows and Linux. ESET also observed macOS prompts, indicating macOS support is possible. <br></p><blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Wiwv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be6e26e-10ad-4c7d-b274-4ba32b4739b5_907x363.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Wiwv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be6e26e-10ad-4c7d-b274-4ba32b4739b5_907x363.png 424w, https://substackcdn.com/image/fetch/$s_!Wiwv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be6e26e-10ad-4c7d-b274-4ba32b4739b5_907x363.png 848w, https://substackcdn.com/image/fetch/$s_!Wiwv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be6e26e-10ad-4c7d-b274-4ba32b4739b5_907x363.png 1272w, https://substackcdn.com/image/fetch/$s_!Wiwv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be6e26e-10ad-4c7d-b274-4ba32b4739b5_907x363.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Wiwv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be6e26e-10ad-4c7d-b274-4ba32b4739b5_907x363.png" width="907" height="363" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4be6e26e-10ad-4c7d-b274-4ba32b4739b5_907x363.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:363,&quot;width&quot;:907,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Wiwv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be6e26e-10ad-4c7d-b274-4ba32b4739b5_907x363.png 424w, https://substackcdn.com/image/fetch/$s_!Wiwv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be6e26e-10ad-4c7d-b274-4ba32b4739b5_907x363.png 848w, https://substackcdn.com/image/fetch/$s_!Wiwv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be6e26e-10ad-4c7d-b274-4ba32b4739b5_907x363.png 1272w, https://substackcdn.com/image/fetch/$s_!Wiwv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be6e26e-10ad-4c7d-b274-4ba32b4739b5_907x363.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></blockquote><ol start="2"><li><p><strong>AI-driven adaptability</strong></p></li></ol><p>Instead of a rigid payload, PromptLock leverages AI prompts to generate malicious Lua scripts dynamically. These include functions for file exfiltration, encryption, and (in theory) even destruction. <br></p><ol start="3"><li><p><strong>Encryption mechanism</strong></p></li></ol><p>It uses the <strong>SPECK 128-bit encryption algorithm</strong>, a lightweight cipher originally designed by the NSA, for encrypting victim files. <br></p><blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VMcZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb608341-d77c-453e-a74c-369c209486e7_895x565.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VMcZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb608341-d77c-453e-a74c-369c209486e7_895x565.png 424w, https://substackcdn.com/image/fetch/$s_!VMcZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb608341-d77c-453e-a74c-369c209486e7_895x565.png 848w, https://substackcdn.com/image/fetch/$s_!VMcZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb608341-d77c-453e-a74c-369c209486e7_895x565.png 1272w, https://substackcdn.com/image/fetch/$s_!VMcZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb608341-d77c-453e-a74c-369c209486e7_895x565.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VMcZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb608341-d77c-453e-a74c-369c209486e7_895x565.png" width="895" height="565" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cb608341-d77c-453e-a74c-369c209486e7_895x565.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:565,&quot;width&quot;:895,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VMcZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb608341-d77c-453e-a74c-369c209486e7_895x565.png 424w, https://substackcdn.com/image/fetch/$s_!VMcZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb608341-d77c-453e-a74c-369c209486e7_895x565.png 848w, https://substackcdn.com/image/fetch/$s_!VMcZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb608341-d77c-453e-a74c-369c209486e7_895x565.png 1272w, https://substackcdn.com/image/fetch/$s_!VMcZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb608341-d77c-453e-a74c-369c209486e7_895x565.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></blockquote><ol start="4"><li><p><strong>Proof-of-concept status</strong></p></li></ol><p>At present, PromptLock appears to be an <strong>unfinished or experimental project</strong>. ESET classifies it as a <strong>work-in-progress</strong> rather than a fully deployed ransomware campaign. <br></p><blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jBgm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbde97385-4840-45ba-b45a-5ce3117879df_900x235.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jBgm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbde97385-4840-45ba-b45a-5ce3117879df_900x235.png 424w, https://substackcdn.com/image/fetch/$s_!jBgm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbde97385-4840-45ba-b45a-5ce3117879df_900x235.png 848w, https://substackcdn.com/image/fetch/$s_!jBgm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbde97385-4840-45ba-b45a-5ce3117879df_900x235.png 1272w, https://substackcdn.com/image/fetch/$s_!jBgm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbde97385-4840-45ba-b45a-5ce3117879df_900x235.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jBgm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbde97385-4840-45ba-b45a-5ce3117879df_900x235.png" width="900" height="235" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bde97385-4840-45ba-b45a-5ce3117879df_900x235.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:235,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jBgm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbde97385-4840-45ba-b45a-5ce3117879df_900x235.png 424w, https://substackcdn.com/image/fetch/$s_!jBgm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbde97385-4840-45ba-b45a-5ce3117879df_900x235.png 848w, https://substackcdn.com/image/fetch/$s_!jBgm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbde97385-4840-45ba-b45a-5ce3117879df_900x235.png 1272w, https://substackcdn.com/image/fetch/$s_!jBgm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbde97385-4840-45ba-b45a-5ce3117879df_900x235.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></blockquote><h1>Why this matters</h1><p>So far, PromptLock may not be a major threat in itself. But the implications are huge.</p><p>Traditional ransomware had predictable lifecycles: attackers coded it, packaged it, distributed it, and defenders built detections against it. AI breaks this cycle.</p><ul><li><p><strong>Malware can evolve in real time</strong>: If ransomware dynamically generates parts of its logic, defenders can&#8217;t rely on static signatures or known IoCs (Indicators of Compromise).</p></li></ul><ul><li><p><strong>Barrier to entry is lowered</strong>: With GenAI assistance, attackers don&#8217;t need advanced coding skills. Even novice hackers could build functional ransomware by leaning on AI prompts.</p></li></ul><ul><li><p><strong>Cross-platform attacks become easier</strong>: Golang plus AI-driven adaptability means one ransomware family could hit multiple operating systems without major rewrites.</p></li></ul><ul><li><p><strong>Detection and response must evolve</strong>: Security teams will need to focus more on <strong>behavioral analysis</strong> and <strong>AI red-teaming</strong>, rather than chasing signatures.</p></li></ul><p>PromptLock is less about the here-and-now threat, and more about what it signals: the future of ransomware development.</p><h1>What you as a defender can do next</h1><ol><li><p><strong>Invest in behavioral monitoring</strong> <br>Static detection won&#8217;t cut it anymore. Monitoring how processes behave (like unusual use of scripting engines or encryption at scale) will be more reliable than looking for a known binary.</p></li></ol><ol start="2"><li><p><strong>Prepare for polymorphic malware</strong> <br>AI can make malware shape-shift. Security tools must adapt to handle variants generated in real time.</p></li></ol><ol start="3"><li><p><strong>Secure development pipelines</strong> <br>Just as attackers leverage AI, defenders can too. Integrating AI-powered code analysis tools in the SDLC can help catch weaknesses early.</p></li></ol><ol start="4"><li><p><strong>Adopt chaos-style testing</strong> <br>Just as Chaos Engineering exposed weaknesses in distributed systems, &#8220;chaos security testing&#8221; for AI-driven threats could reveal how your defenses hold up against unpredictable malware.</p></li></ol><h1>Closing thought</h1><p>PromptLock may only be a proof-of-concept today. But it shows us a glimpse of tomorrow: <strong>where AI makes ransomware more intelligent, more evasive, and harder to stop</strong>.</p><p>The evolution of threats means our defenses must evolve, too. Staying ahead of the curve requires a proactive, adaptive, and behavior-based approach to security.</p><p><em>**Images sourced from ESET Research&#8217;s X handle.</em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Why “We found it” doesn’t mean “It’s fixed” ]]></title><description><![CDATA[Ever finish a deep security scan and send off the report, feeling like you&#8217;ve just handed a gift?]]></description><link>https://beaglesecurity.substack.com/p/why-we-found-it-doesnt-mean-its-fixed</link><guid isPermaLink="false">https://beaglesecurity.substack.com/p/why-we-found-it-doesnt-mean-its-fixed</guid><dc:creator><![CDATA[Nandagopal S]]></dc:creator><pubDate>Fri, 22 Aug 2025 14:02:52 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/74fd2501-0caf-418b-9970-aa2275309fc3_2548x1834.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Ever finish a deep security scan and send off the report, feeling like you&#8217;ve just handed a gift? You&#8217;re done. Or so you think.</p><p>But most of the time? That gift lands quietly in someone&#8217;s backlog. Forgotten, deprioritized, sometimes even ignored. And that&#8217;s not because people don&#8217;t care.</p><p>Often, they just don&#8217;t know what to do next.</p><p>In this edition of All Things AppSec, we unpack the <em>real</em> reason vulnerability remediation stalls.</p><p>The good news? It&#8217;s fixable. With communication, clarity, and process.</p><h1>The invisible crux behind unpatched vulnerabilities</h1><p>Presenting the frustrating truth: Finding vulnerabilities is the easy part. Getting them fixed takes negotiation, translation, and teamwork.</p><p>As I've seen across dozens of builds and dashboards:</p><ul><li><p>Security teams write reports that scream &#8220;Urgent!&#8221;</p></li></ul><ul><li><p>Dev teams skate past them because they <em>sound</em> like feature requests</p></li></ul><ul><li><p>Management hasn&#8217;t weighed in, so critical issues drift without ownership</p></li></ul><p>It&#8217;s not malice. It's misalignment.</p><h1>&#8220;Who&#8217;s responsible now?&#8221;, and why that matters most</h1><p>Let me walk you through a scenario:</p><p>You flag a &#8220;critical&#8221; auth bypass. You label it CVSS 8. You even suggest a patch. Then&#8230; crickets.</p><p>Why? Because no one knows whose card that task should go on. When ownership isn&#8217;t formally assigned, security issues become orphaned work. And if nobody claims it, nothing happens.</p><h1>Building a remediation pipeline that gets real fixes done</h1><p>Security isn&#8217;t a report. It&#8217;s a process.</p><p>Here&#8217;s a simple framework you can try:</p><ol><li><p><strong>Tag each finding with a clear owner:</strong> Security fields it, Developers own the fix.</p></li></ol><ol start="2"><li><p><strong>Add deadline-driven SLAs:</strong> &#8220;This is critical. Fix within X days or escalate.&#8221;</p></li></ol><ol start="3"><li><p><strong>Wrap context around every finding:</strong> Explain <em>why</em> it matters, <em>how</em> to exploit it, and <em>what</em> it impacts.</p></li></ol><ol start="4"><li><p><strong>Use dashboards to track progress:</strong> Allow visibility for security, dev, and leadership.</p></li></ol><p>These small shifts turn &#8220;find it &#8594; report it &#8594; forget it&#8221; into &#8220;find it &#8594; own it &#8594; fix it.&#8221; That is real progress.</p><h1>Beagle Security&#8217;s role in bridging the gap</h1><p>Most teams don&#8217;t struggle because they can&#8217;t <em>find</em> vulnerabilities. They struggle because they can&#8217;t keep up with the noise, prioritize what actually matters, and connect security findings with business impact. That&#8217;s exactly the gap Beagle Security fills.</p><p>Beagle Security automates penetration testing in a way that adapts to your applications. Instead of just flagging issues, it understands your app&#8217;s context &#8212; the login flows, the tech stack, the way your product behaves in the real world &#8212; and then maps vulnerabilities to real risk.</p><p>That means fewer false positives, smarter test case selection, and results that developers can actually act on. It&#8217;s not just about producing a report, but about bridging the gap between security and engineering so fixes don&#8217;t stall in the backlog.</p><h1>Wrapping up</h1><p>At the end of the day, finding vulnerabilities is only half the job. What really matters is getting them fixed before they turn into real problems.</p><p>That&#8217;s why the right tools and workflows are so important. They make the difference between security reports that gather dust and security practices that actually protect your business.</p><p>Beagle Security helps teams close that gap, turning testing into action, and vulnerabilities into fixes.</p><p>Because security should move as fast as you do.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://beaglesecurity.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading All Things AppSec! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item></channel></rss>