SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
StackHawk launches Wingman to fix AI coding flaws

StackHawk launches Wingman to fix AI coding flaws

Tue, 29th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

StackHawk has launched Wingman, an application security platform that fixes software vulnerabilities during AI-assisted coding sessions. The product is aimed at software engineers using AI coding tools.

Wingman integrates with development environments including Claude Code, Cursor, and GitHub Copilot, and also works with Codex and Antigravity. It is designed to identify, remediate, and verify security flaws before code reaches a pull request or enters a security team's backlog.

The launch reflects a broader shift in software development as engineering teams adopt AI coding assistants and security teams try to keep pace with faster release cycles. StackHawk argues that the gap between rapid code generation and slower manual remediation has left many organisations more exposed to known classes of software flaws.

"The window between vulnerability disclosure and exploitation used to be measured in years. Today, that window can be negative 15 hours as attackers often exploit vulnerabilities before they're even publicly disclosed," said Joni Klippert, Chief Executive Officer of StackHawk.

He linked that trend to the speed of AI-assisted software delivery.

"Meanwhile, engineering teams are shipping faster than ever because of AI coding agents, but security hasn't kept pace. That mismatch is exactly what's putting most organizations at risk today," Klippert said.

Early use

Wingman has already fixed more than 7,500 vulnerabilities for early-access customers across more than five AI coding agents, according to StackHawk. The company said 98% of those fixes remained resolved without regressions.

The issues addressed included remote code execution, SQL injection, and cross-site scripting, all categories that have long featured in major software breaches. StackHawk said the tool feeds findings back into the same agent that wrote the code, allowing it to apply a fix and then rescan the application to confirm the issue has been resolved.

Wingman is priced at USD $10 per user per month. The offer includes unlimited applications and 50 scans per user each month.

Workflow focus

The product is built around existing developer workflows rather than a separate security review process. Wingman can trigger automatically when a feature is marked complete, launch the running application, test it from an attacker's perspective, and report the result back to the continuous integration pipeline before a pull request is opened.

Each test is tied to a specific commit to create an auditable record of what code was checked and what issues were cleared before release. That record is intended for security teams that need evidence of remediation without manually reviewing every change.

George Baker, Chief Information Security Officer of CertiPath, said the product had been used as part of a broader effort to introduce AI throughout the software development lifecycle.

"We started this year with a deliberate plan to bring AI into every stage of the software development lifecycle, from requirements through release. Application security is a critical piece in this puzzle, and we wanted a partner who could help us build an agentic security program, not just hand us another scanner," Baker said.

"With StackHawk's Wingman, our engineers can find and fix vulnerabilities in the same agentic session where the code is written, with human review 'over the loop' and a verified record of what shipped clean. This is an enabler for scaling security and working down backlogs without slowing the delivery pipeline," he added.

Security backlog

StackHawk, based in Denver, sells application and API security testing tools and says its products are used by more than 200 enterprise organisations worldwide. Wingman extends that testing model into AI-assisted coding sessions, where the company sees an opportunity to address flaws before they become tickets for later review.

Klippert said that approach differs from tools that stop once a vulnerability has been identified.

"Every other security tool finds a code vulnerability and stops at the finding - a recommendation, a ticket, a pull request waiting on an engineer. Wingman fixes it," Klippert said.

"Finding was never the hard part. Fixing and verifying it fast enough to match how engineering teams ship today, at machine speed, inside the workflow, as the code is written, is what security teams have never had the staff or the hours to do. Every unfixed vulnerability sitting in a backlog is a secret door left open. Wingman was built to close it before anyone finds it," he said.