# Scanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386 Page: https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755/scanner-results-are-a-starting-point-here-s-what-comes-next-federico-kirschbaum-asw-386 Text version: https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755/scanner-results-are-a-starting-point-here-s-what-comes-next-federico-kirschbaum-asw-386.md Podcast: [Security Weekly Podcast Network (Audio)](https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755) Published: 2026-06-09T09:00:00+00:00 Episode link: http://sites.libsyn.com/18678/scanner-results-are-a-starting-point-heres-what-comes-next-federico-kirschbaum-asw-386 Audio file: https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/pauldotcom/ASW_386_1--7ef42155-fea5-4ffe-ad99-83adac9da8cb--audio-converted--3e6f3d41-086f-4f25-8e99-0ae84ffa0c6c.mp3?dest-id=13427 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/security-weekly-podcast-network-audio-319755/episodes/scanner-results-are-a-starting-point-here-s-what-comes-next-federico-kirschbaum-asw-386 Duration seconds: 4583 ## Resource Most AppSec teams are working through more findings than their teams can validate. SAST surfaces thousands of potential issues. DAST generates alert volume that outpaces triage capacity. Somewhere in that output are the vulnerabilities that matter, the ones that are actually exploitable in production. This conversation explores why automated testing often stops short of the hardest part of the job: proving what is real. We dig into how business logic flaws and authorization vulnerabilities get missed by tools that scan without reasoning, what exploit validation looks like at runtime, and how security engineers are shifting toward findings that developers will actually act on. The segment is sponsored by XBOW. Visit https://securityweekly.com/xbow to see how autonomous AI pentesting delivers expert-quality findings in hours with real exploit validation your team can actually act on. Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-386 ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/security-weekly-podcast-network-audio-319755/episodes/scanner-results-are-a-starting-point-here-s-what-comes-next-federico-kirschbaum-asw-386/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755/scanner-results-are-a-starting-point-here-s-what-comes-next-federico-kirschbaum-asw-386.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.