StackHawk @stackhawk.bsky.social · 05/05/2026One security engineer rolled out DAST to 40+ dev teams in two quarters. The verdict: the problem was never technical. It was a project management problem. Read the full story: lnkd.in/gXFapXtM 110
StackHawk @stackhawk.bsky.social · 04/05/2026Bay Area AppSec, we'll be at the SF Secure Software and AppSec Summit on May 14 in Palo Alto. Learn more: www.clutchevents.co/events/san-f... 100
StackHawk @stackhawk.bsky.social · 30/04/2026StackHawk is now a Wiz Integration Partner! StackHawk’s pre-production DAST findings flow directly into the Wiz Security Graph, where they are correlated with the cloud infrastructure context Wiz maintains. Application and cloud risk in one place. www.stackhawk.com/blog/stackha... 000
StackHawk @stackhawk.bsky.social · 29/04/2026Every DAST vendor supports OAuth2, Jira, and OWASP Top 10. That's not an evaluation. Download our new DAST RFP template with 75+ criteria, the ones that actually separate tools. 🔗 www.stackhawk.com/resources/da... 000
StackHawk @stackhawk.bsky.social · 23/04/2026OpenAI launched Codex Security in March. Real results. Previously unknown vulns in OpenSSH and Chromium. Most coverage stopped there.stackhawk.comCodex Security: What It Does Well and Where DAST Still MattersOpenAI's Codex Security finds code-level vulnerabilities with AI. Here's what it catches, what it misses, and why runtime testing with DAST still matters. 100
StackHawk @stackhawk.bsky.social · 17/04/2026Copilot's coding agent learned from public codebases. It applies the patterns it saw most often. Runtime testing closes the gap. StackHawk scans the running app in CI, feeds findings back to the agent as prompts, and you rescan to confirm the fix. www.stackhawk.com/blog/github-... 000
StackHawk @stackhawk.bsky.social · 16/04/2026MCP servers connect to production: your DBs, internal APIs, real services. Most ship with zero security testing. StackHawk now scans remote MCP servers. Add a config block, run HawkScan, findings map to specific tools, not raw protocol calls. www.stackhawk.com/blog/introdu...stackhawk.comStackHawk Now Tests MCP Servers for Security VulnerabilitiesStackHawk now tests remote MCP servers for security risks, enabling AppSec teams to continuously find vulnerabilities like injection attacks and data exposure before they reach prod. 000
StackHawk @stackhawk.bsky.social · 14/04/2026Cybersecurity stocks dropped for Claude Code Security. Rallied for Project Glasswing. Same category. Very different reactions. The difference isn't capability. It's that code analysis still doesn't send requests to your running app. Full breakdown 👇 www.stackhawk.com/blog/claude-... 000
StackHawk @stackhawk.bsky.social · 08/04/2026AI pen testing isn't replacing DAST. It's replacing the $40k manual pentest you run twice a year. Different cadence, different scope, different job. Read the full breakdown of DAST vs. AI pentesting: www.stackhawk.com/blog/dast-vs... 000
StackHawk @stackhawk.bsky.social · 06/04/2026StackHawk will be at @owasp.org SnowFROC '26 on April 16–17. 400 practitioners. Two days of talks and hands-on training. If you're going and want to talk about how AppSec programs actually keep up with AI development velocity, come find us🦅 snowfroc.com 000
StackHawk @stackhawk.bsky.social · 03/04/2026That's a wrap on RSAC 2026. It was a packed week of dinners, workshops, and incredible conversations with the AppSec community. Big thanks to our partners, customers, and friends for making it one to remember. Check out Payton O'Neal’s full recap: www.stackhawk.com/blog/rsac-20... 000
StackHawk @stackhawk.bsky.social · 03/04/2026StackHawk is heading to @owasp.org BASC 2026 in Cambridge 🦅 April 11 at the Boston Marriott. We'll be there talking about how teams are running DAST and API security testing in CI/CD. Come find us! 🔗basconf.org 000
StackHawk @stackhawk.bsky.social · 31/03/2026On the night before SnowFROC 🏔️ We're joining Semgrep , SheHacksPurple, and OWASP for a panel on AI agents in AppSec. Register here: semgrep.dev/events/agent... 000
StackHawk @stackhawk.bsky.social · 20/03/2026StackHawk CSO & Co-founder Scott Gerlach is joining Semgrep at RSAC for an interactive demo. When: March 25, 10 AM PT in SF Can't make it? Catch us at Semgrep's booth #1743 on March 24 at 11 AM PT for an in-person demo on the floor. Register here: semgrep.dev/events/sast-... 001
StackHawk @stackhawk.bsky.social · 19/03/2026The Women in Security Documentary is an award-winning film on the real stories behind women shaping the security industry. The San Francisco premiere is a red carpet event at AMC Metreon 16 on March 24 and 25 at 4 PM PT. Register here: docs.google.com/forms/d/e/1F... 000
StackHawk @stackhawk.bsky.social · 18/03/2026JSON-RPC powers blockchain, IoT, MCP, and most DAST tools completely ignore it. The attack surface hides in the method namespace, not the URL. StackHawk now fuzzes every method, every parameter. REST, GraphQL, gRPC, and now JSON-RPC. We test it all. stackhawk.com/blog/json-rp... 000
StackHawk @stackhawk.bsky.social · 17/03/2026Joe Sullivan (former CSO at Uber, Facebook, and Cloudflare) is leading a fireside chat at RSAC. StackHawk is co-hosting with @endorlabs.bsky.social, Cyberhaven, and Brinqa. Learn more and RSVP here: www.endorlabs.com/events/ciso-... 002
StackHawk @stackhawk.bsky.social · 16/03/2026We’re excited to welcome Regional Sales Director Suzy McClure to the team! Suzy has spent 15+ years in SaaS and cybersecurity sales, with deep channel experience at every stop. Welcome to the flock, Suzy! 000
StackHawk @stackhawk.bsky.social · 13/03/2026We're a proud sponsor of PBC Connect at RSAC 2026 with ArmorCode Inc. The Purple Book Community is bringing together CISOs and security leaders for a full day of panels and networking at RSAC. Register for free here: thepurplebook.club/pbc-connect-... 010
StackHawk @stackhawk.bsky.social · 12/03/2026Joe Sullivan's word for 2026: runtime. He led security at Meta, Uber, and Cloudflare. His read: AI tools are solving code-level security. Runtime is what’s needed. That's exactly what StackHawk is built for. And that’s why he's joining our board. Welcome, Joe! 100
StackHawk @stackhawk.bsky.social · 11/03/2026Copilot. Cursor. Full APIs in an afternoon. New endpoints. New attack surface. Nothing in any spec. Security testing not in the pipeline doesn't run at all. The AI-DLC changed everything → www.stackhawk.com/blog/what-is... 000
StackHawk @stackhawk.bsky.social · 09/03/2026Where you run DAST determines what you can actually test for. No single stage catches everything. Each one tests what the others can't. That only works if your scanner can actually run at every stage. That's the architecture StackHawk was built on. www.stackhawk.com/blog/dast-in... 000
StackHawk @stackhawk.bsky.social · 27/02/2026ICYMI, AppSec is in a full-blown hype cycle. Everyone has a hot take. But at the end of the day, AppSec testing tools are here to stay. In this Q&A with @helpnetsecurity.com, StackHawk’s CEO Joni Klippert breaks down the nuances of using AI when it comes to DAST. Learn more 👇 010
StackHawk @stackhawk.bsky.social · 23/02/2026 Most teams don't fail ISO 27001 audits because they skipped security testing. They fail because they can't prove it was systematic. A pentest from last quarter isn't a process. CI/CD-native DAST is. stackhawk.com/blog/iso-270... 000
StackHawk @stackhawk.bsky.social · 12/02/2026AI is breaking AppSec testing. Alerts multiply, static analysis gets automated—but is a vuln exploitable in YOUR environment? That requires runtime. Business logic, broken auth, prompt injection live only at runtime. DAST's moment is here. www.cybersecuritydive.com/spons/the-fu...cybersecuritydive.comThe Future of DAST in an AI-First World: Why Runtime Security Testing Remains CriticalRuntime validation is where the gap is widening—and where this shift creates the biggest leap forward. 000
StackHawk @stackhawk.bsky.social · 06/02/2026BFLA isn't about accessing someone else's data. It's about performing actions your role shouldn't allow. Your API checks authentication ✅ But forgets authorization ❌ Regular users executing DELETE requests. #5 on OWASP. www.stackhawk.com/blog/underst... 000
StackHawk @stackhawk.bsky.social · 05/02/202690% test coverage of 60% of your attack surface isn't coverage. It's false confidence. Only 30% of AppSec teams are "very confident" they know what exists in their environment. Intelligence = context + action. Most programs have neither. Learn more👉 www.stackhawk.com/blog/appsec-... 000
StackHawk @stackhawk.bsky.social · 04/02/2026StackHawk is sponsoring GuidePoint CKO in Orlando this week and is excited that GuidePoint is an inaugural partner for our new SHARP program. Connecting with security teams about application security testing and shift-left strategies. www.stackhawk.com/blog/introdu... 000
StackHawk @stackhawk.bsky.social · 30/01/2026Authentication vs Authorization. Most developers know the difference, but BOLA vulnerabilities say otherwise. BOLA has been the #1 API risk since 2019. Not because it's complex, but because it's easy to overlook. www.stackhawk.com/blog/underst... 000
StackHawk @stackhawk.bsky.social · 28/01/2026The problem isn't that AI writes vulnerable code. 🤖 The problem: when velocity increases 5-10x, findings increase 5-10x. 50% of AppSec teams spend 40%+ of their time just triaging. Manual processes weren't built for this. www.stackhawk.com/blog/ai-codi... 000
StackHawk @stackhawk.bsky.social · 27/01/20264 business days to disclose material incidents + annual proof of risk management = you need proactive prevention. Do you have complete attack surface visibility? Can you prove what was tested? Do you have metrics for board oversight? Read more: stackhawk.com/blog/sec-cyb... 000
StackHawk @stackhawk.bsky.social · 26/01/2026AppSec programs haven't evolved to match AI-driven development. Yet. We're sponsoring Cycode's Product Security Summit on Jan 28 to dig into what's actually working. Register here: cycode.com/product-secu... 000
StackHawk @stackhawk.bsky.social · 23/01/2026🔍 Next week: API Security for the AI Era Source-based discovery. LLM threat testing. Prevention before production. Jan 27 | 3 PM ET Don’t miss out! Register to save your spot → www.stackhawk.com/resources/gi... 000
StackHawk @stackhawk.bsky.social · 22/01/2026The 2026 AppSec reality: 87% adopted AI coding assistants, but 50% spend 40%+ of their time just triaging alerts. 73% can't confidently answer board questions about risk posture. Learn more: stackhawk.com/blog/2026-st... Download the guide: stackhawk.com/resources/gu... 000
StackHawk @stackhawk.bsky.social · 20/01/2026PCI DSS v4.0.1 is mandatory. 𝗧𝗵𝗲 𝘀𝗵𝗶𝗳𝘁: annual pen tests → continuous testing StackHawk = pre-prod DAST in minutes, not hours. Runtime validation. AI-powered API discovery. Read how we help meet the requirements 👇 www.stackhawk.com/blog/pci-dss... 000
StackHawk @stackhawk.bsky.social · 16/01/2026⏰ 2 weeks: API Security for the AI Era Why GigaOm recognized StackHawk: source-based discovery finds APIs before production. Jan 27 | 3 PM ET Learn the Discover → Test → Govern framework. Register → www.stackhawk.com/resources/gi... 000
StackHawk @stackhawk.bsky.social · 15/01/2026AI tools let devs generate complete APIs in minutes. Traditional security tools? Still catching up weeks later. We're demoing how StackHawk keeps pace at Liminal's AppSec in the Age of AI Demo Day. 📅 Jan 28 | Our session starts at 10:30 AM ET liminal.co/demo-day/app... 000
StackHawk @stackhawk.bsky.social · 14/01/2026DAST programs don't stall because the tech fails. They stall because teams can't prove impact. 3 questions your metrics need to answer: Are we testing what matters? Are we reducing risk? Are we scaling? Don't report scans. Report what matters. www.stackhawk.com/blog/dast-ap... 000
StackHawk @stackhawk.bsky.social · 13/01/2026AI is creating attack surfaces faster than AppSec teams can track. So how do you gain visibility and control? Join us Jan 28 at The Great Convergence—Cycode's Product Security Summit. Sign up: cycode.com/product-secu... 000
StackHawk @stackhawk.bsky.social · 08/01/2026Need AppSec help for every new app? You won’t scale. 🚦 Build the paved road: templates, workflows, docs devs can use independently. Learn how: sthwk.com/49vwP0x 000
StackHawk @stackhawk.bsky.social · 01/12/2025📣Just Dropped 📣 StackHawk founders Joni Klippert and Scott Gerlach are featured in @usatoday.com’s Innovation Leaders Docuseries, sharing our vision for reimagining AppSec. Watch the full feature ➡️ stackhawk.com/resources/ac... 000
StackHawk @stackhawk.bsky.social · 26/11/2025Are LLM risks like prompt injection in scope for your AppSec program? Should they be? Read to learn about the root causes of prompt injection vulnerabilities, real-world examples, and a guide to protecting your applications against them. 🔗 www.stackhawk.com/blog/owasp-l... 000
StackHawk @stackhawk.bsky.social · 25/11/2025Runtime testing meets ASPM. 🤜🤛 StackHawk finds exploitable vulns at runtime before code ships. Cycode adds code context, automates remediation, and validates fixes. Together, issues are fixed in hours, not weeks, with full visibility across risk. Read the blog: hubs.ly/Q03VP-S70 000
StackHawk @stackhawk.bsky.social · 20/11/2025The @endorlabs.bsky.social + @stackhawk.bsky.social integration connects SAST + DAST for one correlated finding. Less noise. Real context. Faster fixes. 🔗 www.stackhawk.com/blog/endor-l... 001
StackHawk @stackhawk.bsky.social · 19/11/2025🛡️136% increase in API security coverage. 0 manual setup. APIs discovered and tested in under 15 minutes. ITV scaled API security with StackHawk’s AI-powered OpenAPI Spec Generation, automating onboarding & testing across hundreds of apps. Read how → www.stackhawk.com/customers/it... 000
StackHawk @stackhawk.bsky.social · 13/11/2025AI isn’t just building apps faster. It’s building new attack surfaces. StackHawk now finds prompt injections, leaky prompts, and LLM risks before production, all inside CI/CD. Read the full blog to learn more: www.stackhawk.com/blog/llm-sec... 000
StackHawk @stackhawk.bsky.social · 11/11/2025Most DAST programs don’t fail on testing, they fail on visibility. StackHawk’s API Discovery finds every API right from your source code so you know what to test first. Visibility first. Security follows. 🔗 Read the full blog: www.stackhawk.com/blog/source-... 000
StackHawk @stackhawk.bsky.social · 07/11/2025Big thanks to everyone who joined StackHawk, Arnica, Eve Security, Prime Security, & Phoenix Security at our OWASP DC social! It was great connecting with the AppSec community and talking all things shift-left and secure software. #AppSec #ShiftLeft #OWASP #DevOps 010
StackHawk @stackhawk.bsky.social · 06/11/2025What a great night after #DayOne of #SecureWorld Seattle! 🌐 Big thanks to everyone who joined the AppSec dinner we co-hosted with @semgrep.com and EVOTEK last night. Amazing food, even better conversations. 🥂 #SecureWorld #AppSec #DevSecOps 011
StackHawk @stackhawk.bsky.social · 05/11/2025Join StackHawk, Arnica, Phoenix Security, Prime Security, and EVE Security, for an exclusive post-Day 1 after party at OWASP Global AppSec DC. 🗓️ Tomorrow at 6:30 PM ET Don't miss out, RSVP here→ luma.com/jhyynqjq #AppSecluma.comOwasp DC After Party! · LumaJoin us at our annual OWASP DC Global happy hour for some food, drinks, and general good time! 000