StackHawk makes it simple for developers to find, triage, and fix application security bugs. AppSec Closer to the Keyboard than Ever Before. 🦅 Kaakaww!

Denver, CO
One security engineer rolled out DAST to 40+ dev teams in two quarters. The verdict: the problem was never technical. It was a project management problem. Read the full story: lnkd.in/gXFapXtM
2
101
Bay Area AppSec, we'll be at the SF Secure Software and AppSec Summit on May 14 in Palo Alto. Learn more: clutchevents.co/events/san-f…
71
StackHawk is now a @Wiz_io Integration Partner! StackHawk’s pre-production DAST findings flow directly into the Wiz Security Graph, where they are correlated with the cloud infrastructure context Wiz maintains. Application and cloud risk in one place. stackhawk.com/blog/stackhawk…
1
146
Every DAST vendor supports OAuth2, Jira, and OWASP Top 10. That's not an evaluation. Download our new DAST RFP template with 75+ criteria, the ones that actually separate tools. 🔗 stackhawk.com/resources/dast…
1
1
59
OpenAI launched Codex Security in March. Real results. Previously unknown vulns in OpenSSH and Chromium. Most coverage stopped there.
1
41
Copilot's coding agent learned from public codebases — including the ones with SQL injection sitting in them, weak auth that nobody caught, secrets committed by accident. It doesn't apply a security lens. It applies the patterns it saw most often.
1
80
MCP servers connect to production: your DBs, internal APIs, real services. Most ship with zero security testing. StackHawk now scans remote MCP servers. Add a config block, run HawkScan, findings map to specific tools, not raw protocol calls. stackhawk.com/blog/introduci…
44
Cybersecurity stocks dropped for Claude Code Security. Rallied for Project Glasswing. Same category. Very different reactions. The difference isn't capability. It's that code analysis still doesn't send requests to your running app. Full breakdown 👇
1
330
AI pen testing isn't replacing DAST. It's replacing the $40k manual pentest you run twice a year. Different cadence, different scope, different job. Read the full breakdown of DAST vs. AI pentesting: stackhawk.com/blog/dast-vs-a…
1
62
StackHawk will be at @owasp SnowFROC '26 on April 16–17. 400 practitioners. Two days of talks and hands-on training. If you're going and want to talk about how AppSec programs actually keep up with AI development velocity, come find us🦅 snowfroc.com
40
That's a wrap on RSAC 2026. It was a packed week of dinners, workshops, and incredible conversations with the AppSec community. Big thanks to our partners, customers, and friends for making it one to remember. Check out Payton O'Neal’s full recap: stackhawk.com/blog/rsac-2026…
1
1
33
StackHawk is heading to @owasp BASC 2026 in Cambridge 🦅 April 11 at the Boston Marriott. We'll be there talking about how teams are running DAST and API security testing in CI/CD. Come find us! 🔗basconf.org
45
On the night before SnowFROC 🏔️ We're joining @semgrep, @SheHacksPurple, and OWASP for a panel on AI agents in AppSec. Register here: semgrep.dev/events/agentical…
1
35
@StackHawk's Scott Gerlach and @semgrep's Kyle Northcutt got into a room at #RSAC2026 and talked about code velocity, vibe coders, AI budgets, and why sitting on the bench isn't an option anymore. Watch the full video here: piped.video/nbsOae30PWg
30
StackHawk CSO & Co-founder Scott Gerlach is joining @semgrep at RSAC for an interactive demo. When: March 25, 10 AM PT in SF Can't make it? Catch us at Semgrep's booth #1743 on March 24 at 11 AM PT for an in-person demo on the floor. Register here: semgrep.dev/events/sast-dast…
40
The Women in Security Documentary is an award-winning film on the real stories behind women shaping the security industry. The San Francisco premiere is a red carpet event at AMC Metreon 16 on March 24 and 25 at 4 PM PT. Register here: docs.google.com/forms/d/e/1F…
45
JSON-RPC powers blockchain, IoT, MCP, and most DAST tools completely ignore it. The attack surface hides in the method namespace, not the URL. StackHawk now fuzzes every method, every parameter. REST, GraphQL, gRPC, and now JSON-RPC. We test it all. stackhawk.com/blog/json-rpc-…
1
37
Joe Sullivan (former CSO at Uber, Facebook, and Cloudflare) is leading a fireside chat at RSAC. StackHawk is co-hosting with @EndorLabs, Cyberhaven, and @brinqa . Learn more and RSVP here: endorlabs.com/events/ciso-ba…
1
76
We’re excited to welcome Regional Sales Director Suzy McClure to the team! Suzy has spent 15+ years in SaaS and cybersecurity sales, with deep channel experience at every stop. Welcome to the flock, Suzy!
54
We're a proud sponsor of PBC Connect at RSAC 2026 with ArmorCode Inc. The Purple Book Community is bringing together CISOs and security leaders for a full day of panels and networking at RSAC. Register for free here: thepurplebook.club/pbc-conne…
29
Joe Sullivan sits down with Adam LaGreca of 10KMedia to discuss how AI is reshaping application security. 🎧 Listen to the full podcast here: open.spotify.com/episode/6w0…
38
Joe Sullivan's word for 2026: runtime. He led security at Meta, Uber, and Cloudflare. His read: AI tools are solving code-level security. Runtime is what’s needed. That's exactly what StackHawk is built for. And that’s why he's joining our board. Welcome, Joe!
1
57
Copilot. Cursor. Full APIs in an afternoon. New endpoints. New attack surface. Nothing in any spec. Security testing not in the pipeline doesn't run at all. The AI-DLC changed everything → stackhawk.com/blog/what-is-t…
1
152
DAST has played second fiddle for years. Too slow. Too clunky. Too late in the development lifecycle to operationalize at scale. @latiotech's 2026 AppSec Market report confirms AppSec tool success criteria should focus on time to fix, not number of findings.
1
1
36
Where you run DAST determines what you can actually test for. No single stage catches everything. Each one tests what the others can't. That only works if your scanner can actually run at every stage. That's the architecture StackHawk was built on. stackhawk.com/blog/dast-in-s…
54
The StackHawk team is headed to San Francisco for RSAC 2026. We'll be at several events throughout the week with partners @semgrep , Armorcode, Endor Labs, and Cycode. If you're going to be there, grab 30 minutes with us. We'd love to connect. stackhawk.com/resources/even…
1
39
David Geevaratne is joining as our EVP of Sales! 20+ yrs in cloud-native and cybersecurity sales leadership. Co-founded and scaled a company to $40M+. Built teams at Uptycs, DivvyCloud, and Rapid7. Welcome to the team David!
57
ICYMI -@latiotech's 2026 AppSec Market report dropped last week, covering 50+ vendors across the full AppSec stack. Their conclusion: the real differentiators aren't scanner counts anymore. It's usability, developer experience, and how tools fit into their development lifecycle
1
44
Most teams don't fail ISO 27001 audits because they skipped security testing. They fail because they can't prove it was systematic. A pentest from last quarter isn't a process. CI/CD-native DAST is. stackhawk.com/blog/iso-27001…
39
That's a wrap on SKO 2026 🎯 Two days of real talk about why runtime AppSec testing is more critical than ever for 2026. Nothing beats getting this incredibly hard-working team in the same room. We couldn’t be more excited for the year to come. 🦅
30
Shadow APIs are about to become a serious compliance risk under EU Cyber Resilience Act. You can't document vulnerabilities in components you don't know exist. Automatic API discovery isn't optional anymore: stackhawk.com/blog/cyber-res…
35
Traditional approach: Detect APIs in production → scramble to figure out what they are Modern approach: Discover APIs from source code → connect with developers early Our CSO, Scott Gerlach breaks down why source-based discovery changes AppSec. 📺 stackhawk.com/resources/giga…
1
46
BFLA isn't about accessing someone else's data. It's about performing actions your role shouldn't allow. Your API checks authentication ✅ But forgets authorization ❌ Regular users executing DELETE requests. #5 on OWASP. stackhawk.com/blog/understan…
29
90% test coverage of 60% of your attack surface isn't coverage. It's false confidence. Only 30% of AppSec teams are "very confident" they know what exists in their environment. Intelligence = context + action. Most programs have neither. Learn more👉 sthwk.com/45TmoD8
17
StackHawk is sponsoring @GuidePointSec CKO in Orlando this week and is excited that GuidePoint is an inaugural partner for our new SHARP program. Connecting with security teams about application security testing and shift-left strategies. stackhawk.com/blog/introduci…
1
30
Authentication vs Authorization. Most developers know the difference, but BOLA vulnerabilities say otherwise. BOLA has been the #1 API risk since 2019. Not because it's complex, but because it's easy to overlook. stackhawk.com/blog/understan…
27
The problem isn't that AI writes vulnerable code. 🤖 The problem: when velocity increases 5-10x, findings increase 5-10x. 50% of AppSec teams spend 40%+ of their time just triaging. Manual processes weren't built for this. stackhawk.com/blog/ai-coding…
27
4 business days to disclose material incidents + annual proof of risk management = you need proactive prevention. Do you have complete attack surface visibility? Can you prove what was tested? Do you have metrics for board oversight? Read more: stackhawk.com/blog/sec-cyber…
42
🚨 Today 3 PM ET: API Security for the AI Era GigaOm + StackHawk break down: → API inventory for AI/LLM components → LLM-specific threats → Discover → Test → Govern framework 📅 Register now: stackhawk.com/resources/giga…
1
47
Tomorrow! Join us at @LiminalStrategy's AppSec in the Age of AI Demo Day. In just 8 minutes, we're showing how StackHawk helps security teams match the pace of AI development. 📅 Jan 28 | 10:30 AM ET Save your spot: hubs.la/Q03-FhRc0
2
39
AppSec programs haven't evolved to match AI-driven development. Yet. We're sponsoring Cycode's Product Security Summit on Jan 28 to dig into what's actually working. Register here: cycode.com/product-security-…
31
🔍 Next week: API Security for the AI Era Source-based discovery. LLM threat testing. Prevention before production. Jan 27 | 3 PM ET Don’t miss out! Register to save your spot → stackhawk.com/resources/giga…
2
39
The 2026 AppSec reality: 87% adopted AI coding assistants, but 50% spend 40%+ of their time just triaging alerts. 73% can't confidently answer board questions about risk posture. Learn more: stackhawk.com/blog/2026-stat… Download the guide: stackhawk.com/resources/guid…
245
PCI DSS v4.0.1 is mandatory. 𝗧𝗵𝗲 𝘀𝗵𝗶𝗳𝘁: annual pen tests → continuous testing StackHawk = pre-prod DAST in minutes, not hours. Runtime validation. AI-powered API discovery. Read how we help meet the requirements 👇 stackhawk.com/blog/pci-dss-a…
43
⏰ 2 weeks: API Security for the AI Era Why @gigaom recognized StackHawk: source-based discovery finds APIs before production. Jan 27 | 3 PM ET Learn the: Discover → Test → Govern framework. Register → stackhawk.com/resources/giga…
1
34
AI tools let devs generate complete APIs in minutes. Traditional security tools? Still catching up weeks later. We're demoing how StackHawk keeps pace at @LiminalStrategy's AppSec in the Age of AI Demo Day. 📅 Jan 28 | Our session starts at 10:30 AM ET liminal.co/demo-day/applicat…
1
33
DAST programs don't stall because the tech fails. They stall because teams can't prove impact. 3 questions your metrics need to answer: Are we testing what matters? Are we reducing risk? Are we scaling? Learn more about DAST metrics: stackhawk.com/blog/dast-apps…
32
AI is creating attack surfaces faster than AppSec teams can track. So how do you gain visibility and control? Join us Jan 28 at The Great Convergence—Cycode's Product Security Summit. Sign up: cycode.com/product-security-…
27
📣 Upcoming Webinar: API Security for the AI Era Jan 27 | 3 PM ET AI coding assistants + LLM components = new attack surfaces your security program wasn't built for. Join @GigaOm + StackHawk to learn what's next. Register → sthwk.com/4qkZzR2
1
36
Need AppSec help for every new app? You won’t scale. 🚦 Build the paved road: templates, workflows, docs devs can use independently. Learn how: sthwk.com/49vwP0x
15
Happy New Year from StackHawk! 🦅 2025 was a transformational year—for us and AppSec at large. As we head into 2026, we're grateful for our world-class customers, proud of what we accomplished, and energized to keep helping AppSec teams. Here's to reimagining AppSec in 2026.🥂
18