TechNewsReel
Live

StackHawk Launches Wingman to Automate Security Fixes in AI Coding Workflows

The new platform integrates with AI agents to find and remediate exploitable vulnerabilities before code is committed.

TechNewsReel Newsroom · September 15, 2026

StackHawk has released Wingman, a security platform designed to integrate directly into AI-driven coding workflows to stop vulnerabilities from reaching production. The tool provides AI coding agents with the specific skills, hooks, and rules needed to automatically identify, repair, and verify exploitable flaws in running applications before a developer opens a pull request.

Wingman supports a wide array of major AI agents, including GitHub Copilot, Cursor, Claude Code, Codex, and Antigravity. The system operates on a continuous "find -> fix -> verify" loop: it utilizes runtime tests to identify exploitable vulnerabilities, remediates the flaws within the codebase using source context, and performs a rescan to confirm the fix is successful. In early-access testing prior to the official launch, Wingman fixed more than 7,000 vulnerabilities with a 98% success rate for those repairs.

The AI Velocity Gap

The launch comes as AI coding agents significantly accelerate the pace of software development. While these tools increase productivity, they also risk introducing security vulnerabilities at a faster rate than human teams can manually review. Traditionally, security triaging has led to a systemic problem where "medium" or "low" severity bugs are pushed to a backlog due to time constraints. However, these smaller flaws can often be chained together by attackers to create critical exploits.

Shifting Security Left

By automating remediation within the AI's own operational loop, Wingman shifts security "left," moving the fix to the earliest possible stage of the development lifecycle. This approach aims to eliminate the security backlog entirely by resolving issues before they are committed to a repository.

This shift changes the fundamental economics of vulnerability management. Security teams have historically triaged lower-severity issues into backlogs not because they were irrelevant, but because of a lack of time. In modern environments, attackers can chain three medium-severity flaws into a critical exploit in seconds, making automated resolution a necessity.

Future Outlook

As AI agents become more autonomous in writing and deploying code, the industry is watching whether automated security loops can keep pace with generative AI's output. The success of Wingman will likely depend on its ability to maintain high repair accuracy across increasingly complex codebases and diverse application architectures. By integrating security directly into the agent's logic, StackHawk is betting that the only way to secure AI-generated code is to use AI to fix it in real-time.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.