Will Fuzzing Replace SAST?

In many instances, the answer is becoming “when” not “if.” Static analysis scanners, like SAST (static application security testing) create more problems than solutions. In less than 6-years, advancements in fuzzing have made it the most robust application security scanning available.

David Merian
System Weakness
Published in
3 min readFeb 3, 2023

--

CARIAD and SQLite demonstrates this phenomenon perfectly. Let’s start with SQLite, the prevalent open source

--

--

Application Security Testing | Web Security | Embedded Security | DevSecOps | Fuzzing | Software Security | SaaS + OnPrem | ISO 21434 | Pentesting | #followback