StackHawk@StackHawk
May 5United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
One security engineer rolled out DAST to 40+ dev teams in two quarters.
The verdict: the problem was never technical. It was a project management problem.
Read the full story: lnkd.in/gXFapXtM
StackHawk@StackHawk
May 4United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Bay Area AppSec, we'll be at the SF Secure Software and AppSec Summit on May 14 in Palo Alto.
Learn more: clutchevents.co/events/san-f…
StackHawk@StackHawk
Apr 30United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
StackHawk is now a @Wiz_io Integration Partner!
StackHawk’s pre-production DAST findings flow directly into the Wiz Security Graph, where they are correlated with the cloud infrastructure context Wiz maintains.
Application and cloud risk in one place.
stackhawk.com/blog/stackhawk…
StackHawk@StackHawk
Apr 29United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Every DAST vendor supports OAuth2, Jira, and OWASP Top 10.
That's not an evaluation.
Download our new DAST RFP template with 75+ criteria, the ones that actually separate tools.
🔗 stackhawk.com/resources/dast…
StackHawk@StackHawk
Apr 23United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
OpenAI launched Codex Security in March. Real results. Previously unknown vulns in OpenSSH and Chromium. Most coverage stopped there.
StackHawk@StackHawk
Apr 17United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Copilot's coding agent learned from public codebases — including the ones with SQL injection sitting in them, weak auth that nobody caught, secrets committed by accident. It doesn't apply a security lens. It applies the patterns it saw most often.
StackHawk@StackHawk
Apr 16United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
MCP servers connect to production: your DBs, internal APIs, real services. Most ship with zero security testing.
StackHawk now scans remote MCP servers. Add a config block, run HawkScan, findings map to specific tools, not raw protocol calls.
stackhawk.com/blog/introduci…
StackHawk@StackHawk
Apr 14United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Cybersecurity stocks dropped for Claude Code Security. Rallied for Project Glasswing.
Same category. Very different reactions.
The difference isn't capability. It's that code analysis still doesn't send requests to your running app.
Full breakdown 👇
StackHawk@StackHawk
Apr 8United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
AI pen testing isn't replacing DAST.
It's replacing the $40k manual pentest you run twice a year.
Different cadence, different scope, different job.
Read the full breakdown of DAST vs. AI pentesting: stackhawk.com/blog/dast-vs-a…
StackHawk@StackHawk
Apr 6United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
StackHawk will be at @owasp SnowFROC '26 on April 16–17.
400 practitioners. Two days of talks and hands-on training.
If you're going and want to talk about how AppSec programs actually keep up with AI development velocity, come find us🦅
snowfroc.com