Skip to main content

StackHawk Delivers Wingman to Fix Vulnerabilities as Developers Write Code

StackHawk this week launched Wingman, an artificial intelligence (AI) tool that makes it possible for application developers to automatically fix vulnerability issues as code is being written.

Wingman is designed to install into Claude Code, Cursor, GitHub Copilot, Codex, and Antigravity. It scans the live application, interprets findings, and fixes vulnerabilities in a way that makes it simpler for application developers to maintain context as they write code. At the core of those capabilities, StackHawk’s application testing platform is made available through a set of AI skills, hooks and rules that Wingman invokes.

Once an AI coding agent finishes a feature, Wingman auto-configures and boots the running application to run a series of security tests with no manual steps required. Findings are then shared with the AI coding agent that wrote the code to fix any issues discovered. Wingman then rescans that application to confirm the fix held before reporting back to the continuous integration (CI) pipeline that the issue has been resolved. Every test is tied to a specific commit, giving security teams an attestation record of what code was securely shipped.

Priced at $10 per user, per month, Wingman includes unlimited applications that can be scanned 50 times per user, per month. StackHawk claims Wingman has already automatically fixed more than 7,000 vulnerabilities for early access customers, with 98% of those fixes remaining resolved with no regressions.

StackHawk CEO Joni Klippert said Wingman is designed to prevent vulnerabilities from ever finding their way into a build in the first place. That capability dramatically reduces the backlog of issues that DevSecOps teams need to address by eliminating tickets they would otherwise have to address at a time when the overall pace at which code is being generated has dramatically accelerated in the AI era, she added.

Mitch Ashley, vice president and practice lead for the Futurum Group, said embedding the fix and verification inside the coding session moves the security control point out of the pipeline gate and into the loop that writes the code. That is the right response to AI-generated code because verification work is accumulating faster than teams can hire reviewers, he added.

Most application developers, to one degree or another, are now relying on AI to generate code. Historically, those application developers lacked the security expertise required to prevent vulnerabilities from being inadvertently included in their code. As the pace at which code is developed in the AI era continues to accelerate, the number of issues that DevSecOps teams are expected to resolve has already dramatically increased. The goal now needs to be to resolve those issues before any ticket is ever created.

Hopefully, the quality of the code being generated in the AI era will get better sooner than later. In the meantime, however, DevSecOps teams, in the absence of any ability to automatically remediate vulnerabilities, are increasing technical security debt at a time when cybercriminals are becoming more adept at using AI to reverse engineer the code needed to exploit those vulnerabilities.



from DevOps.com https://ift.tt/vtSPeYF

Comments

Popular posts from this blog

Exadel Records Strong Year with Surge in Client Roster, Additions to Executive Team and Record-Breaking Company Growth

Success comes from growing need for digital transformation solutions and services amidst the COVID-19 pandemic WALNUT CREEK, Calif., January 12, 2021 — Exadel (www.exadel.com), a global provider of digital engineering solutions and services, announces a successful 2020 including a burgeoning client portfolio, continued growth, including new executive team members and 2020 sales projections. This year, […] The post Exadel Records Strong Year with Surge in Client Roster, Additions to Executive Team and Record-Breaking Company Growth appeared first on DevOps.com . from DevOps.com https://ift.tt/2LMO6eg

In Nepal and Across the World, Child Marriage Is Rising

In Nepal and Across the World, Child Marriage Is Rising By Bhadra Sharma and Jeffrey Gettleman from NYT World https://ift.tt/3cbjEnR Nepal, Quarantine (Life and Culture), Coronavirus (2019-nCoV), Child Marriages, Youth, Women and Girls, Teenage Pregnancy, Pregnancy and Childbirth, Third World and Developing Countries, Birth Control and Family Planning

Rochelle Walensky on the Rocky Road to Normal

Rochelle Walensky on the Rocky Road to Normal By David Wallace-Wells from NYT Opinion https://ift.tt/0A5Wx6r internal-sub-only-nl, Coronavirus (2019-nCoV), Vaccination and Immunization, Rumors and Misinformation, Centers for Disease Control and Prevention, Walensky, Rochelle