Home / Companies / StackHawk / Blog / February 2026

February 2026 Summaries

8 posts from StackHawk

Filter
Month: Year:
Post Summaries Back to Blog
David, with over 20 years of experience in IT and cybersecurity sales, has joined StackHawk, drawn by the company's approach to addressing modern application security needs in the era of AI-assisted development. His career has witnessed significant platform shifts like cloud migration and DevOps, but he identifies AI development as the most transformative, posing increased challenges for application security due to the rapid expansion of the codebase and attack surfaces. StackHawk's strategy of integrating dynamic application security testing (DAST) into CI/CD pipelines aligns with the need for continuous and thorough security validation, addressing concerns of CISOs who prioritize understanding and reducing risk over acquiring new tools. Previously, David held senior roles at Uptycs, Rapid7, and DivvyCloud, and co-founded New Signature, a Microsoft cloud services provider. His leadership and contributions have been recognized through various industry accolades.
Feb 27, 2026 562 words in the original blog post.
APIs are integral to modern technology, powering applications across mobile, SaaS, AI, and IoT domains, and with API traffic comprising over 71% of web interactions, ensuring their reliability and security is crucial. API testing plays a vital role in verifying API behavior, performance, and security, catching issues early in the development lifecycle before they impact users. As of 2026, the landscape of API testing tools has evolved significantly, incorporating AI-driven capabilities such as security scans, test case generation, and vulnerability fixes. The article discusses the importance of selecting the right API testing tool, highlighting key features to consider such as ease of use, protocol support, test features, and integration with CI/CD pipelines. The tools are categorized based on their primary functions, including functional testing, load and performance testing, security testing, and contract testing, with notable examples like Postman, StackHawk, Apache JMeter, and REST Assured. The future of API testing is set to be influenced by AI and Model Context Protocol (MCP) servers, which facilitate seamless integration with developer workflows, enabling natural language commands for API interactions and promoting the evolution of testing methodologies.
Feb 25, 2026 4,068 words in the original blog post.
Rapid advancements in artificial intelligence are driving organizations to integrate AI features at unprecedented speeds, but this has introduced significant risks, such as data breaches and biased decision-making. The AI TRiSM framework, developed by Gartner, offers a comprehensive approach to managing trust, risk, and security in AI systems throughout their lifecycle. Focusing on aspects like governance, runtime inspection, information governance, and infrastructure, AI TRiSM aims to ensure that AI models are reliable, fair, and compliant with regulations. As traditional security frameworks struggle to address the unique challenges posed by AI, AI TRiSM provides the necessary tools and guidelines to safeguard AI implementations. StackHawk, for instance, supports AI TRiSM by offering runtime testing capabilities that integrate with existing development workflows, helping organizations manage AI risks effectively. With AI TRiSM, companies can innovate confidently, knowing they have robust mechanisms in place to protect against potential vulnerabilities and ensure the trustworthy deployment of AI technologies.
Feb 23, 2026 2,966 words in the original blog post.
Anthropic's announcement of Claude Code Security marks a significant disruption in code security by utilizing AI to scan codebases in a manner akin to human researchers, identifying vulnerabilities missed by traditional rule-based tools. It highlights successes like Opus 4.6's discovery of over 500 bugs in open-source software, emphasizing AI's advantage in certain vulnerability detection. However, it also points out the limitations of AI in identifying business logic flaws, which require application-specific testing at runtime. StackHawk addresses this gap by offering runtime testing in CI/CD pipelines, ensuring application behavior is validated before deployment. The development signifies a maturing of AI-powered security tools, underscoring the need for programs to incorporate both intelligent code review and runtime validation to keep pace with rapid code development and evolving attack surfaces.
Feb 20, 2026 498 words in the original blog post.
ISO 27001:2022 introduced significant changes to application security requirements, emphasizing secure software development lifecycle (SDLC) practices and continuous vulnerability scanning. Organizations are now required to demonstrate security measures throughout the entire SDLC, including development, testing, and post-deployment phases. StackHawk supports these requirements by providing CI/CD-native dynamic application security testing (DAST), which integrates vulnerability scanning directly into the SDLC, ensuring consistent and automated security validation without hindering development velocity. The standard mandates documented, repeatable processes for vulnerability management, secure coding guidelines, and developer training, alongside security testing for outsourced and third-party code. Compliance involves maintaining audit trails and evidence of systematic security processes, with StackHawk offering tools to generate the necessary documentation and metrics to prove adherence to ISO 27001 standards.
Feb 19, 2026 2,085 words in the original blog post.
The EU Cyber Resilience Act (CRA), effective from December 10, 2024, mandates cybersecurity for all products with digital elements sold in the EU, with compliance required by December 11, 2027. The CRA enforces cybersecurity throughout the product lifecycle, requiring no known exploitable vulnerabilities at market release, documented vulnerability handling, and regular security updates. Products are categorized into three classes, with varying assessment requirements, and pure SaaS offerings are typically excluded. StackHawk addresses CRA requirements by providing pre-production testing that detects vulnerabilities in runtime through CI/CD pipelines, ensuring products are secure by design. The platform discovers complete API attack surfaces, automates vulnerability management, and supports compliance documentation, integrating seamlessly into developer workflows. This comprehensive approach helps organizations maintain development velocity while meeting CRA’s security and documentation mandates, guaranteeing that security is built in from the start and continuously validated throughout the product lifecycle.
Feb 10, 2026 2,322 words in the original blog post.
The security industry heavily relies on the concept of "intelligence," particularly in the context of application security (AppSec), where the challenge lies in bridging the gap between data and actionable insights. Many AppSec programs face a "context gap," struggling to fully understand their application attack surfaces, with surveys indicating only 30% of stakeholders are very confident in their knowledge. This incomplete understanding leads to false confidence in coverage metrics and hinders the generation of meaningful intelligence. Effective AppSec intelligence requires clarity on three fronts: visibility of the attack surface, discernment of exploitable vulnerabilities, and prioritization based on business risk. Despite advances in testing tools and methodologies, many organizations still rely on outdated methods that fail to keep pace with rapid development cycles, leaving them unable to act with confidence. The emergence of actionable intelligence depends on answering these three critical questions, particularly as AI accelerates development and boards demand concrete risk assessments, emphasizing that action is the key to effective security.
Feb 05, 2026 646 words in the original blog post.
StackHawk has launched the StackHawk Alliances & Reseller Program (SHARP) to emphasize a partner-driven approach in the rapidly evolving Application Security (AppSec) market. This initiative offers partners 30%+ margins, deal registration protection, NFR licenses for hands-on experience, and extensive training to enhance expertise, aiming to position them as trusted advisors rather than mere vendors. The company addresses the challenges posed by AI-accelerated development, which has increased code production and alert volumes, by focusing on runtime application and API security testing directly integrated into developers’ workflows. This approach is designed to improve the signal-to-noise ratio by identifying exploitable vulnerabilities quickly, allowing AppSec teams to prioritize meaningful threats over unexploitable alerts. StackHawk’s strategy, which includes application attack surface discovery, is seen as a strategic necessity in the AI-driven landscape, offering visibility and assurance to customers. The program is supported by partners like Defy, GuidePoint, Myriad360, Optiv, Trace3, and WWT, with the goal of advancing AppSec teams' capabilities amidst AI-era security challenges.
Feb 04, 2026 644 words in the original blog post.