Two pieces of AppSec engineering guidance highlighted how developer tooling and detection techniques are evolving alongside AI-assisted software development. A discussion on modern application security emphasized that even memory-safe languages like Go can still accumulate security risk through flawed patterns and legacy style, and argued that automated, AST-based refactoring (e.g., go fix) can improve readability and reduce mistakes—an effect that can translate into more secure and maintainable code. It also noted a practical AI-development concern: LLMs often reproduce outdated or disfavored coding styles because of their training data, potentially generating “legacy from the start” code unless teams enforce modern conventions through tooling.
Separate research on secrets scanning argued that entropy-based filtering—commonly used after regex candidate capture—struggles with generic secrets and can produce false positives because many non-secret strings (e.g., UUIDs, base64, dependency artifacts) can look similarly “random.” The post proposed reframing the problem as “rare, not random,” and explored Byte-Pair Encoding (BPE) tokenization as an alternative primary filter to better distinguish statistically unusual secret-like strings from normal human-written text, alongside additional rule-based filters (e.g., excluding known safe files such as go.sum).

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
The Aikido post says the token-efficiency approach was implemented in a Gitleaks-derived scanner called Betterleaks. Reported benchmark results show improved F1 scores on CredData compared with entropy-only configurations and with CredSweeper's published performance.
Aikido published research arguing that secrets are better identified as rare or out-of-vocabulary strings than simply random-looking ones, and proposed a Byte-Pair Encoding-based metric called token efficiency for post-regex filtering. The post reports stronger separation of secrets from non-secrets than Shannon entropy on the CredData dataset, especially for generic secrets and short passwords.
The SC Media podcast segment says Go maintainers have seen large language models generate disfavored or legacy Go patterns because models were trained on older code, creating maintainability and potential security concerns. The discussion highlights AST-based modernization tooling such as go fix as a way to improve readability and reduce human error.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.