
Frustration with 'Revolutionary' AppSec Tools Repackaging Old SAST
CybersecurityAppSecSASTFalsePositives
The author expresses frustration with application security (AppSec) tools that are marketed as "revolutionary" and "AI-powered" but are actually just repackaged versions of existing Static Application Security Testing (SAST) tools with improved user interfaces. They criticize a recent demonstration that showcased basic features like static code analysis, configuration file checking, and generic threat intelligence feeds. The author highlights that their team is overwhelmed by critical alerts that are often false positives and lacks visibility into what is really happening in their runtime environments.