Checkmarx

16.7K posts

Checkmarx banner
Checkmarx

Checkmarx

@Checkmarx

Checkmarx is how the world’s largest enterprises can finally get ahead of application risk without slowing down development.

Worldwide Katılım Aralık 2011
2.9K Takip Edilen7.3K Takipçiler
Sabitlenmiş Tweet
Checkmarx
Checkmarx@Checkmarx·
🚀Record-breaking growth. Industry recognition. Game-changing innovation. Checkmarx One surpassed $150M ARR in less than 3 years, now securing the software of 865+ of the world’s largest enterprises.
English
2
2
7
3.1K
Checkmarx
Checkmarx@Checkmarx·
The cybersecurity conversation doesn't end when Black Hat does. If you're staying in Las Vegas for #DEFCON, stop by #AppSecVillage and connect with the @CheckmarxZero research team. 🎯 Take on our "AppSec Quiz Gauntlet: Spot the Vulnerability", test your secure code review skills, and see if you can spot what others miss. 📍AppSec Village 🗓️Aug. 7–9 appsecvillage.com
Checkmarx tweet media
English
0
0
2
141
Checkmarx retweetledi
Nikki Siapno
Nikki Siapno@NikkiSiapno·
Concepts Every Developer Should Know: CI/CD Pipelines. A CI/CD pipeline is an automated workflow that manages the building, testing, and release of code through continuous integration (CI) and continuous delivery or deployment (CD). It integrates the various stages of the software development lifecycle (SDLC) into a seamless, repeatable process. These stages include source code management, automated testing, artifact creation, deployment orchestration, and automated security scanning. The goal is simple: catch issues as early as possible, when they're cheaper and easier to fix. But that only works if developers trust the feedback the pipeline provides. If security scanners generate too many false positives, developers begin treating security checks like any other noisy build failure. As more security feedback moves directly into CI/CD, the quality of that feedback becomes just as important as the coverage. That's why scanner fidelity matters. Checkmarx's latest announcement introduces a Hybrid scanning approach that combines AI-driven analysis with traditional deterministic rules to improve the quality of security findings before they reach developers. If you want to understand how security feedback is evolving inside modern CI/CD pipelines, it's worth a read. Learn more here → lucode.co/hybrid-sast-ar… What else would you add? —— ♻️ Repost to help others learn and grow. 🙏 Thanks to @Checkmarx for sponsoring this post. ➕ Follow me ( Nikki Siapno ) + turn on notifications.
Nikki Siapno tweet media
English
5
41
186
33.7K
Checkmarx
Checkmarx@Checkmarx·
There's no better way to bring a team together than by giving back. 💙 During our Q3 QBR in Chicago, the Checkmarx AMS Leadership Team assembled 120 snack bags for Chicago HOPES for Kids, helping provide children with nutritious snacks throughout the summer. We're proud of our team for giving back to the local community and grateful for the opportunity to make a meaningful impact.
Checkmarx tweet mediaCheckmarx tweet mediaCheckmarx tweet mediaCheckmarx tweet media
English
0
0
0
132
Checkmarx
Checkmarx@Checkmarx·
Diversification isn't just smart investing; it's a smart application security strategy. As AI accelerates software development, relying on a single model to write, review, and secure code isn't enough. The strongest AppSec programs combine deterministic security with AI-powered reasoning to reduce risk, accelerate remediation, and build software with confidence. In his latest blog, @ek121268 explores why a hybrid approach is becoming essential in the age of AI: checkmarx.com/blog/investmen…
Checkmarx tweet media
English
0
1
1
98
Checkmarx
Checkmarx@Checkmarx·
Nearly half of all production code is now AI-generated. Traditional scanning wasn't built for today's pace, growing codebases, or the increasing complexity of modern applications. Organizations need the consistency of deterministic scanning alongside the flexibility of AI-powered analysis. Today, we're introducing Checkmarx Fusion, a new hybrid scanning architecture that combines Checkmarx's trusted AppSec engines and proprietary security context with frontier AI reasoning from Anthropic to deliver the industry's most complete vulnerability detection. With Checkmarx Fusion, organizations can: ✔️ Detect vulnerabilities across every language, every codebase, and every stage of the SDLC ✔️ Improve detection by validating and enriching findings across multiple scanning methods ✔️ Scale with an enterprise architecture designed for performance, flexibility, and compliance This isn't just another scanning engine. It's a hybrid approach to vulnerability detection designed for how software is built today. Learn more about Checkmarx Fusion: checkmarx.com/press-releases…
Checkmarx tweet media
English
0
1
1
126
Checkmarx
Checkmarx@Checkmarx·
Black Hat is almost here, and the Checkmarx team is gearing up for a full week of conversations, networking, and connecting with the cybersecurity community in Las Vegas. If you're heading to Vegas, don't wait until the expo floor opens to say hello. Here's where you can find us: 📍BSides Las Vegas | August 3–5 We're proud to be an All In Sponsor of BSides Las Vegas. Stop by to meet the team, exchange ideas with fellow security professionals, and join the conversations shaping the future of application security. Find more details here: bsideslv.org 🏎️Executive Networking at F1 Arcade | August 4 Join us for an exclusive evening of networking with fellow security leaders at F1 Arcade Las Vegas. Enjoy great conversations, food, drinks, and a little friendly competition. If you're interested, reach out to alison.huggins@checkmarx.com for more information. We'll see you in Las Vegas! 🎲
Checkmarx tweet mediaCheckmarx tweet media
English
0
0
0
158
Checkmarx
Checkmarx@Checkmarx·
Security leaders have a balancing act ahead. How do you embrace AI without introducing new blind spots? How do you help developers ship faster without creating more risk? In this clip, Rossana Hagg and Meg Peddada from AWS, and Frank Emery discuss why the next generation of application security isn't just about adopting AI; it's about making AI, security, and developer productivity work together. Watch the clip below, then catch the full fireside chat to hear more about how organizations are rethinking AppSec for the AI era: #better-together?utm_source=twitter&utm_medium=social&utm_campaign=aws_fireside_chat" target="_blank" rel="nofollow noopener">checkmarx.com/aws-partner/#b
English
0
0
0
99
Checkmarx
Checkmarx@Checkmarx·
What if AI isn't just introducing new vulnerabilities—but bringing back ones we've already fixed? New research from Ilya Kabanov via The Weather Report found that 65–75% of working patches generated by frontier AI coding agents resurrect vulnerabilities that had already been discovered and fixed. Additional findings include: → 83–95% functional success → Only 24–36% secure and functional → Even with threat modeling and post-hoc security reviews, roughly half of generated code remained insecure AI is getting better at writing code, but not at writing secure code. Read the full research in our latest newsletter:linkedin.com/pulse/zombie-c…
English
0
1
1
207
Checkmarx
Checkmarx@Checkmarx·
75% of organizations knowingly ship vulnerable code. That's a risk no team can afford. Patient Point took a different approach. With Checkmarx Triage Assist and Remediation Assist, the team was able to: → Prioritize the vulnerabilities that mattered most → Filter out false positives → Generate AI-assisted, merge-ready remediation → Improve developer efficiency with competitive AI token costs AI is accelerating software development. It should accelerate remediation too. Read the full story: checkmarx.com/resources/on-p…
English
0
0
1
170
Checkmarx
Checkmarx@Checkmarx·
If you're heading to Black Hat, come spend a little time with us at the Checkmarx Theater in Booth #4553. We've put together a lineup of sessions focused on some of the biggest questions AppSec teams are facing right now: 🎤Two Fronts, One Risk: Securing Yesterday's Debt and Today's AI Code | Why AI has changed the security landscape, and what it takes to tackle both legacy risk and AI-generated code. 🎤Proof, Not Promises: How Checkmarx Drives Security Testing Accuracy With Better Data | A look at why measuring security testing accuracy matters, and how to separate real results from marketing claims. 🎤Getting To High Fidelity | How to cut through the noise, reduce false positives, and help developers focus on the vulnerabilities that actually matter. Whether you're interested in AI, application security, or just want to see what's new, we'd love to see you there. 📍 Booth #4553 🗓️ August 1–6 See the full agenda and book time with our team: checkmarx.com/black-hat/?utm…
Checkmarx tweet mediaCheckmarx tweet media
English
0
0
0
108
Checkmarx
Checkmarx@Checkmarx·
96% of developers now use AI coding tools. Only 18% apply security continuously while they write code. And the challenge doesn't stop there. Recent research from The Weather Report found that frontier AI models produce code that's both secure and functional less than a third of the time. Even after a post-hoc security review, that number only rises to about half. Today, we're introducing self-healing application security, expanding the Checkmarx Assist Agent family with autonomous agents that help detect, fix, and verify vulnerabilities before code is committed, while also prioritizing and accelerating remediation across existing codebases. Developer Assist detects, fixes, and verifies vulnerabilities as developers write code before it's ever committed. Triage & Remediation Assist then takes over, autonomously prioritizing the vulnerabilities that matter most and generating merge-ready fixes to help teams reduce backlog and accelerate remediation. Because the future of AppSec isn't just finding more vulnerabilities. It's preventing them from slowing development in the first place. Learn more: checkmarx.com/press-releases…
English
1
1
2
156
Checkmarx
Checkmarx@Checkmarx·
Modern application security requires more than point solutions. We're proud to announce that Checkmarx One for Government has achieved FedRAMP® Moderate Certification and is now listed in the FedRAMP Marketplace. Federal agencies can now access a unified AppSec platform designed to reduce tool sprawl, prioritize the risks that matter most, and secure software development from code to cloud. checkmarx.com/press-releases…
Checkmarx tweet media
English
0
0
1
142
Checkmarx
Checkmarx@Checkmarx·
A recent conversation between Rossana Hagg and Meg Peddada from AWS and Frank Emery explored a reality many security teams are navigating today: the application attack surface isn't just growing—it's becoming more dynamic. As AI, cloud-native architectures, and modern toolchains reshape development, identifying and addressing risk earlier becomes even more critical. Watch the clip below, then catch the full AWS + Checkmarx fireside chat here: #better-together?utm_source=twitter&utm_medium=social&utm_campaign=aws_fireside_chat" target="_blank" rel="nofollow noopener">checkmarx.com/aws-partner/#b
English
0
0
1
103
Checkmarx
Checkmarx@Checkmarx·
The industry has spent the last two years measuring AI's ability to generate code. It's time to start measuring its ability to generate secure code. New research from Ilya Kabanov via The Weather Report evaluated today's leading AI coding models. The results highlight a growing disconnect: → AI models successfully completed 83–95% of coding tasks. → But only 24–36% of those solutions were both functional and secure. → Even with additional security interventions, the highest secure-and-functional success rate reached just 56%. As AI becomes a core part of software development, success can't be measured by functionality alone. The next generation of AI benchmarks should measure what organizations can safely deploy. Read the full report, Capability Without Security: Measuring the Functionality-Security Gap in AI-Generated Code: checkmarx.com/capability-wit…
Checkmarx tweet mediaCheckmarx tweet media
English
1
2
3
116