StackHawk makes it simple for developers to find, triage, and fix application security bugs. AppSec Closer to the Keyboard than Ever Before. 🦅 Kaakaww!

Denver, CO
Joined July 2019
StackHawk
@StackHawk
May 5
One security engineer rolled out DAST to 40+ dev teams in two quarters. The verdict: the problem was never technical. It was a project management problem. Read the full story: lnkd.in/gXFapXtM
2
101
StackHawk
@StackHawk
May 4
Bay Area AppSec, we'll be at the SF Secure Software and AppSec Summit on May 14 in Palo Alto. Learn more: clutchevents.co/events/san-f…
71
StackHawk
@StackHawk
Apr 30
StackHawk is now a @Wiz_io Integration Partner! StackHawk’s pre-production DAST findings flow directly into the Wiz Security Graph, where they are correlated with the cloud infrastructure context Wiz maintains. Application and cloud risk in one place. stackhawk.com/blog/stackhawk…
1
1
146
StackHawk
@StackHawk
Apr 29
Every DAST vendor supports OAuth2, Jira, and OWASP Top 10. That's not an evaluation. Download our new DAST RFP template with 75+ criteria, the ones that actually separate tools. 🔗 stackhawk.com/resources/dast…
1
1
59
StackHawk
@StackHawk
Apr 23
OpenAI launched Codex Security in March. Real results. Previously unknown vulns in OpenSSH and Chromium. Most coverage stopped there.
1
41
StackHawk
@StackHawk
Apr 17
Copilot's coding agent learned from public codebases — including the ones with SQL injection sitting in them, weak auth that nobody caught, secrets committed by accident. It doesn't apply a security lens. It applies the patterns it saw most often.
1
80
StackHawk
@StackHawk
Apr 16
MCP servers connect to production: your DBs, internal APIs, real services. Most ship with zero security testing. StackHawk now scans remote MCP servers. Add a config block, run HawkScan, findings map to specific tools, not raw protocol calls. stackhawk.com/blog/introduci…
44
StackHawk
@StackHawk
Apr 14
Cybersecurity stocks dropped for Claude Code Security. Rallied for Project Glasswing. Same category. Very different reactions. The difference isn't capability. It's that code analysis still doesn't send requests to your running app. Full breakdown 👇
1
1
330
StackHawk
@StackHawk
Apr 8
AI pen testing isn't replacing DAST. It's replacing the $40k manual pentest you run twice a year. Different cadence, different scope, different job. Read the full breakdown of DAST vs. AI pentesting: stackhawk.com/blog/dast-vs-a…
1
62
StackHawk
@StackHawk
Apr 6
StackHawk will be at @owasp SnowFROC '26 on April 16–17. 400 practitioners. Two days of talks and hands-on training. If you're going and want to talk about how AppSec programs actually keep up with AI development velocity, come find us🦅 snowfroc.com
40