Urgent.News

What's breaking now, across thousands of outlets.

Tech

StackHawk Delivers Wingman to Fix Vulnerabilities as Developers Write Code

StackHawk this week launched Wingman, an artificial intelligence (AI) tool that makes it possible for application developers to automatically fix vulnerability issues as code is being written. Wingman is designed to install into Claude Code, Cursor, GitHub Copilot, Codex, and Antigravity. It scans the live application, interprets findings, and fixes vulnerabilities in a way that […]

StackHawk Delivers Wingman to Fix Vulnerabilities as Developers Write Code

StackHawk has announced the launch of Wingman, an artificial intelligence (AI) tool designed to automatically fix vulnerabilities as developers write code. This innovative solution integrates with popular AI coding agents such as Claude Code, Cursor, GitHub Copilot, Codex, and Antigravity. Wingman's primary function is to scan the live application, interpret findings, and rectify vulnerabilities seamlessly as the code is being written, thereby simplifying the developer's context management.

The heart of Wingman's functionality lies in StackHawk's application testing platform, which powers Wingman through a set of AI skills, hooks, and rules. Once an AI coding agent concludes a feature, Wingman automatically configures and initiates the running application to perform a series of security tests without requiring any manual intervention.

Wingman then shares the findings with the AI coding agent to address any issues detected. Following this, Wingman re-scans the application to ensure the fix was successful before reporting back to the continuous integration (CI) pipeline, confirming the resolution of the issue.

Priced at $10 per user per month, Wingman offers unlimited applications that can be scanned a maximum of 50 times per user, per month. StackHawk asserts that Wingman has already automatically fixed over 7,000 vulnerabilities for its early access customers, with 98% of these fixes remaining resolved without any regressions. Joni Klippert, CEO of StackHawk, emphasized that Wingman is designed to prevent vulnerabilities from entering the build phase, significantly reducing the backlog of issues for DevSecOps teams.

By integrating the fix and verification process directly into the coding session, Wingman shifts the security control point from the traditional pipeline gate into the code-writing loop, a crucial move in the AI era where code generation has accelerated exponentially.

Mitch Ashley, vice president and practice lead for the Futurum Group, noted that this approach moves the security control point within the coding process, which is particularly pertinent given the surge in AI-generated code. As developers increasingly rely on AI for code generation, many lack the necessary security expertise to prevent vulnerabilities from creeping into their code.

The rapid pace of AI-driven code development has consequently increased the number of issues that DevSecOps teams must resolve, with the expectation now being to address these issues before any tickets are created.

The rise of AI-generated code presents a dual challenge: enhancing the quality of code faster while managing the increasing technical security debt. While the ultimate goal is to improve AI code quality, Wingman serves as a critical interim solution to mitigate security risks in the interim. However, the persistent issue remains that DevSecOps teams are accumulating technical security debt, a situation exacerbated by cybercriminals' increasing proficiency in using AI to exploit vulnerabilities.

Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at devops.com →

More in Tech

More from Thursday 17 September →