Blog

Application security insights, research, and product updates from the Security Reviewer team.

False-Positive Triage: What Security Teams Can Learn from Medical AI Validation
false-positive triagesecurity alert fatigueAI validationSAST tuning

2 June 2026

False-Positive Triage: What Security Teams Can Learn from Medical AI Validation

Medical AI's struggle with false positives offers hard-won lessons for security teams drowning in noisy alerts. Here's what actually works.

Read More
HazyBeacon: Lambda Function URLs Abused as C2 Infrastructure
aws-securitymalwarelambdataint-analysis

3 June 2026

HazyBeacon: Lambda Function URLs Abused as C2 Infrastructure

HazyBeacon: Lambda Function URLs Abused as C2 Infrastructure

Read More
Miasma Supply Chain Attack: When Red Hat npm Packages Become Attack Vectors
supply-chainnpmsastred-hat

1 June 2026

Miasma Supply Chain Attack: When Red Hat npm Packages Become Attack Vectors

Traditional SAST tools scan first-party source code for known vulnerability patterns, then stop. That boundary is exactly where Miasma lives. The wiz-research-supplied threat intelligence on the…

Read More

Topics

SAST DAST MAST Supply Chain / SCA Vulnerability Research Speed & Performance OWASP DevSecOps