What happened
Sonar announced GA (Aug 27, 2026) of SonarQube Hunter Agent, an AI security agent built on the Sonar Foundation Agent harness that reasons through an entire codebase like a human researcher to find broken access control, business-logic, and authentication/session-management flaws — categories traditional SAST cannot detect. Every finding is independently validated for exploitability (80-90% precision) before surfacing in existing SonarQube workflows; GA on SonarQube Cloud now, Server support coming.
Why it matters
Closes a well-documented SAST blind spot (broken access control is OWASP's #1 risk, found in 100% of tested apps in 2025) at a moment when AI-generated code (42%+ of enterprise commits) is outpacing manual review capacity — a major, widely-deployed AppSec vendor shipping this at scale is a notable shift from pattern-matching to reasoning-based code security.
Applicability
AppSec and platform engineering teams already on SonarQube Cloud should enable Hunter Agent now; broader enterprises evaluating AI-augmented pentesting/SAST complements should watch for Server GA.