SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
StackHawk launches Wingman to fix flaws in AI coding

StackHawk launches Wingman to fix flaws in AI coding

Thu, 1st Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

StackHawk has launched Wingman, a tool designed to fix software vulnerabilities during AI-assisted coding sessions. It is aimed at engineers using coding agents such as Claude Code, Cursor and GitHub Copilot.

Wingman works inside existing agentic development workflows and sends security findings back to the same AI agent that wrote the code, allowing issues to be corrected and checked before a pull request is opened.

The launch comes as software companies grapple with a growing imbalance between faster code generation and slower security review. StackHawk argues that coding agents are becoming regular contributors to software projects, while security teams still rely heavily on manual remediation and ticket queues.

Wingman costs USD $10 per user per month and includes unlimited applications and 50 scans per user each month. It can be used by individual developers and teams, and automatically tests running applications when a feature is marked complete.

Early rollout

Early-access customers used Wingman with more than five AI coding agents, and the product automatically fixed more than 7,500 vulnerabilities during the initial rollout, according to StackHawk. The company said 98% of those fixes remained resolved without regressions.

Those issues included high-severity flaws such as remote code execution, SQL injection and cross-site scripting, categories that have featured prominently in real-world cyber attacks, StackHawk said.

The process centres on a "find-fix-verify" loop. Once an AI agent completes a feature, Wingman starts the application, scans it in a way intended to mimic an attacker, returns the results to the coding agent, and then rescans after the code has been amended.

That sequence is meant to happen before code reaches the security team's backlog or enters the wider review process. Each test is also tied to a specific commit, creating a record of what was scanned and verified before release.

Joni Klippert, Chief Executive Officer of StackHawk, linked the launch to the shrinking time between the discovery of a flaw and its exploitation.

"The window between vulnerability disclosure and exploitation used to be measured in years. Today, that window can be negative 15 hours, as attackers often exploit vulnerabilities before they're even publicly disclosed," said Joni Klippert, Chief Executive Officer of StackHawk.

"Meanwhile, engineering teams are shipping faster than ever because of AI coding agents, but security hasn't kept pace. That mismatch is exactly what's putting most organizations at risk today," Klippert said.

Security workflow

Wingman has been built to work with Claude Code, Cursor, GitHub Copilot, Codex and Antigravity, according to StackHawk. Rather than requiring a separate security step in another tool, it is intended to stay within the coding session and the continuous integration pipeline.

The company's pitch reflects a broader shift in software development, where generative AI tools are changing the speed and structure of engineering work. One forecast cited by StackHawk says that by 2027, more than 65% of engineering teams using agentic coding will treat traditional integrated development environments as optional.

That shift creates an opening for suppliers adapting security tools to AI-assisted development, rather than asking developers to return to separate testing environments. It also puts pressure on established application security vendors to show their products can fit automated workflows instead of adding more alerts for already stretched teams.

CertiPath, an early user of the product, said it adopted Wingman as part of a broader effort to bring AI into the software development lifecycle.

"We started this year with a deliberate plan to bring AI into every stage of the software development lifecycle, from requirements through release. Application security is a critical piece in this puzzle, and we wanted a partner who could help us build an agentic security program, not just hand us another scanner," said George Baker, Chief Information Security Officer of CertiPath.

"With StackHawk's Wingman, our engineers can find and fix vulnerabilities in the same agentic session where the code is written, with human review 'over the loop' and a verified record of what shipped clean. This is an enabler for scaling security and working down backlogs without slowing the delivery pipeline," Baker said.

StackHawk, founded by Klippert and Chief Security Officer Scott Gerlach, said it serves more than 200 organisations with application and API security tools. With Wingman, it is extending its testing engine into AI coding workflows as software teams look for ways to keep security checks closer to where code is produced.

"Every other security tool finds a code vulnerability and stops at the finding - a recommendation, a ticket, a pull request waiting on an engineer. Wingman fixes it," Klippert said.

"Finding was never the hard part. Fixing and verifying it fast enough to match how engineering teams ship today, at machine speed, inside the workflow, as the code is written, is what security teams have never had the staff or the hours to do. Every unfixed vulnerability sitting in a backlog is a secret door left open. Wingman was built to close it before anyone finds it," he said.