StackHawk
banner
stackhawk.bsky.social
StackHawk
@stackhawk.bsky.social
StackHawk makes it simple for developers to find, triage, and fix application security bugs. AppSec Closer to the Keyboard than Ever Before.
Big thanks to everyone who joined StackHawk, Arnica, Eve Security, Prime Security, & Phoenix Security at our OWASP DC social!

It was great connecting with the AppSec community and talking all things shift-left and secure software.

#AppSec #ShiftLeft #OWASP #DevOps
November 7, 2025 at 7:09 PM
What a great night after #DayOne of #SecureWorld Seattle! 🌐

Big thanks to everyone who joined the AppSec dinner we co-hosted with @semgrep.com and EVOTEK last night.

Amazing food, even better conversations. 🥂

#SecureWorld #AppSec #DevSecOps
November 6, 2025 at 4:37 PM
Same vulnerability. Two tools. Double the effort.

The hidden cost of AppSec tool sprawl is duplication, not risk.

Correlating SAST + DAST cuts triage time, clarifies priorities, and accelerates fixes.

🔍 Learn more: www.stackhawk.com/blog/sast-da...

#AppSec #DevOps #SAST #DAST
October 29, 2025 at 3:09 PM
Security tools fail because of setup friction, not capability gaps.

New @github.com Copilot agent: analyzes your repo for attack surface, generates complete StackHawk config + GitHub Actions workflow.

Security testing goes from "someday" to "merged."

www.stackhawk.com/blog/github-...
#DAST
October 28, 2025 at 9:01 PM
Joni Klippert, CEO & Co-Founder of @StackHawk, will be speaking at the @forrester #SecurityAndRisk Forum in the Women’s Leadership Program:

Thrive in Chaos.

Agenda 👉 www.forrester.com/event/securi...
www.forrester.com/event/securi...

#WomenInLeadership #Forrester #SecurityAndRisk #ThriveInChaos
October 27, 2025 at 4:03 PM
🍦 The Flavors of DAST: Which one are you running?

Legacy DAST. Shift-Left. Business Logic. AI Pen Testing.
Not all deliver what’s on the label.

We break down when they run, what they catch, who owns them, and the real talk behind the buzzwords.

👉 www.stackhawk.com/blog/ai-pene...

#AppSec #DAST
October 24, 2025 at 8:45 PM
@semgrep.com 🔗 @stackhawk.bsky.social

Correlated findings. Real risk clarity.

Connect code-level issues with runtime exploitability to:
✅ Cut duplicate alerts
✅ Reduce false positives
✅ Prioritize what’s truly exploitable

Learn more: www.stackhawk.com/blog/stackha...

#SAST #DAST
October 22, 2025 at 4:09 PM
57% of orgs had API breaches in the last 2 years.

The common cause: incomplete API visibility and missing and outdated API documentation

Manual docs can’t scale.

AI-powered OpenAPI Specs = complete coverage and proactive testing.

📖 Read more: www.stackhawk.com/blog/openapi...

#AppSec
October 21, 2025 at 8:14 PM
Claude Code + StackHawk = secure AI coding 🛡️🤖

Run scans, catch vulns, & fix issues without leaving Claude Code.

Our new blog can show you how 👉 stackhawk.com/blog/develop...

#ClaudeCode #DevSecOps #AppSec
October 21, 2025 at 8:13 PM
Your scanner isn’t broken. It just doesn’t understand your business.

Traditional tools find technical flaws like SQLi or XSS.
But business logic bugs live in how your app is supposed to work, not where it breaks.

Learn more: www.stackhawk.com/blog/testing...

#APISecurity #ShiftLeft
October 17, 2025 at 7:49 PM
Windsurf = faster coding.
Windsurf + StackHawk = faster & secure coding.

See how the new MCP Server integration makes vulnerability scanning and remediation part of your workflow, without slowing you down.

🔗 Read it here: www.stackhawk.com/blog/a-devel...

#AppSec #Windsurf #AIcoding
October 14, 2025 at 4:35 PM
A global airline scaled security without slowing dev.

Here’s what changed:
➡️GitHub Actions + Jira integration
➡️ Complex auth support
➡️ Shift-left security testing

✅ Faster releases
✅ Reduced backlog
✅ Developer ownership

Full story 👉 stackhawk.com/customers/gl...

#AppSec #DevOps #APISecurity
October 10, 2025 at 3:08 PM
AI coding is powerful, but is it secure?

With the StackHawk MCP Server in Cursor, you can scan and fix vulnerabilities as you code, without context switching.

🔗 Read the blog to learn more: www.stackhawk.com/blog/secure-...

#AppSec #DevOps #Cursor #AICoding #APISecurity
October 8, 2025 at 4:36 PM
🎲 StackHawk is in Las Vegas for Trace3 Evolve 2025!

We’re sponsoring this year’s event as leaders explore what’s next in innovation, AI, and security.

If you’re here, let’s connect 👋

#Trace3Evolve #ProactiveAPISecurity #DevOps #AppSec
October 2, 2025 at 9:09 PM
🦖 Day 1 at #GRRCon 2025 is here!

Find StackHawk at Booth 64 and let’s talk proactive API security.

Don’t forget 👉 we’re co-hosting a Happy Hour with GuidePoint Security tonight!

🔗 Register here: go.guidepointsecurity.com/2025_10_02_N...

#AppSec #DevOps #APISecurity
October 2, 2025 at 8:16 PM
StackHawk + GuidePoint Security are hosting a Happy Hour at #GRRCon 2025!

📅 Thursday, Oct 2nd

👉 Save your spot: go.guidepointsecurity.com/2025_10_02_N...

Come for the drinks, stay for the API security talk. 🦖
#AppSec #APISecurity #DevOps
October 1, 2025 at 2:48 PM
StackHawk is going to #GRRCon 2025!🦖

Stop by Booth 64 to see how we help teams:
⚡Shift left
🔒Secure APIs in CI/CD
🌐Gain API attack surface visibility

We’re also teaming up with GuidePoint Security to co-host a Happy Hour on October 2 at 5 PM ET
RSVP: go.guidepointsecurity.com/2025_10_02_N...
September 26, 2025 at 5:17 PM
StackHawk and Semgrep teamed up at the Giants game last night! ⚾️

Great night with the security community, good conversations, and some solid baseball.

Big thanks to everyone who joined us!

#AppSec #DevOps #AppSecCommunity #APISecurity
September 25, 2025 at 8:22 PM
APIs power modern software, and we help teams secure them from code to runtime.

📢 StackHawk is featured in Cyber Security News’ list of the Top 10 Best Solutions for API Security Testing in 2025.

Read the full article:
🔗 cybersecuritynews.com/best-api-sec...

#AppSec #DevOps
September 24, 2025 at 6:20 PM
StackHawk has landed at BSides Columbus 🦅

The booth’s up, the swag’s out, and we’re ready to talk about modern API security that actually keeps up with dev speed.

If you’re at BSides Columbus, swing by and say hey 👋

#AppSec #DevOps #BSidesColumbus #AppSecCommunity
September 19, 2025 at 5:05 PM
StackHawk will be at #BSidesColumbus Sept 19 🦅 (presented by GuidePoint Security).

Stop by the StackHawk table to see how modern API security testing fits directly into developer workflows.

👋 See you in Columbus!

Learn more: www.bsidescolumbus.com

#APISecurity #AppSec #DevOps
September 16, 2025 at 4:06 PM
Manual ⏳ → Automated security ⚡

A LATAM financial giant shifted left with real-time feedback, securing infrastructure at scale and keeping compliance on track.

Full story 👉 t.co/KAWGmx2M92

#AppSec #DevOps #ShiftLeft
September 12, 2025 at 8:46 PM
Your APIs are multiplying faster than your AppSec team can track.

This new guide shows you:
→ Top API risks you can’t ignore
→ Dev + AppSec best practices
→ How to secure APIs without slowing down development

Read now 👉 t.co/nqqW7ZdwJA

#APISecurity #AppSec #DevOps
September 10, 2025 at 3:30 PM
StackHawk made the invisible, visible.
Legacy, shadow, internal APIs, now discoverable and testable.

See how OpenAPI Spec Generation can benefit your API security program. Learn more: www.stackhawk.com/blog/openapi...

#AI #OpenAPISpec #AppSec #DevOps
September 4, 2025 at 2:41 PM
APIs with no specs = APIs with no testing.

Join StackHawk’s Office Hours (Sept 3) to learn how our AI generates OpenAPI specs directly from source code.

✅ Instant visibility
✅ Complete coverage

Register 👉 www.stackhawk.com/resources/of...

#OpenAPISpecs #AIPowered #AI #APIDiscovery
August 25, 2025 at 3:17 PM