Nearly half of all production code is now AI-generated.
Traditional scanning wasn't built for today's pace, growing codebases, or the increasing complexity of modern applications. Organizations need the consistency of deterministic scanning alongside the flexibility of AI-powered analysis.
Today, we're introducing Checkmarx Fusion, a new hybrid scanning architecture that combines Checkmarx's trusted AppSec engines and proprietary security context with frontier AI reasoning from Anthropic to deliver the industry's most complete vulnerability detection.
With Checkmarx Fusion, organizations can:
✔️ Detect vulnerabilities across every language, every codebase, and every stage of the SDLC
✔️ Improve detection by validating and enriching findings across multiple scanning methods
✔️ Scale with an enterprise architecture designed for performance, flexibility, and compliance
This isn't just another scanning engine. It's a hybrid approach to vulnerability detection designed for how software is built today.
Learn more about Checkmarx Fusion: checkmarx.com/press-releases…
AppSec is hitting the road, and we’re bringing AI with us. 🚌
Starting next week, we’re teaming up with Anthropic and Amazon Bedrock for Securing Code in the AI Era, an event series on securing software as AI changes how it’s built.
Expert perspectives, live demos, and conversations with your peers.
Find your city and request an invite: partner-program.net/checkmat…
Finding a vulnerability isn’t always what slows teams down. It’s everything that comes next.
Is it reachable? Exploitable? What’s the right fix?
Checkmarx Triage & Remediation Assist helps move findings through those decisions and toward a review-ready fix, with people still making the final call.
Rebecca Spiegel takes us inside the workflow: checkmarx.com/inside-checkma…
AI-generated code brings speed to development, but securing it takes more than AI alone.
Our CEO @sandeepjohri joined Dark Reading’s Joan Goodchild to discuss why combining deterministic analysis with AI reasoning matters, from detection through remediation.
Watch the conversation: darkreading.com/application-…
AI coding tools are already embedded in enterprise development. So what should the security program around them look like?
Our CPO @JonathanRende joined @ResilientCyber to talk AI code security, coding agents, and why the model generating code shouldn’t be the only one validating it: resilientcyber.io/p/ai-code-…
Dario Amodei’s call to “pace the frontier” has sparked a lot of conversation, but there’s a security story in his essay worth digging into too.
Our latest newsletter looks at it through an AppSec lens and what teams can learn as AI-generated code and agents become part of everyday development.
Read it here: linkedin.com/pulse/appsec-re…
The conversation around slowing down AI development has gotten a lot louder this week, and it’s raising some important questions about how the industry moves forward responsibly.
There are real risks to consider, just as there are real benefits to continued AI development. How the industry, policymakers, and individual companies navigate that balance is a much bigger conversation than any one organization can answer.
From our perspective, there’s also a more immediate reality. AI is already deeply embedded in how software is being built, and whatever happens next at the frontier, organizations still need to secure the code being generated today.
Our CEO @sandeepjohri has been speaking with CNBC and NBC Las Vegas about the slowdown conversation, what responsible AI adoption can look like, and why security can’t wait for the broader debate to be resolved.
CNBC: cnbc.com/2026/09/15/trump-op…
NBC Las Vegas: news3lv.com/news/local/ai-ar…
Blocking the front door doesn’t help much when attackers find another way in. 👀
Our @CheckmarxZero team is tracking an npm campaign that skips install scripts entirely, triggering malicious code only when the package is used. The package reached nearly 2M weekly downloads and even uses an Ethereum smart contract for command and control.
Bruno Dias breaks down what’s happening, the IOCs, and why runtime behavior matters: checkmarx.com/zero-post/npm-…
“0 critical” only tells you what your tools were able to find.
As previously unseen risks surface and response windows shrink, AppSec needs to see more, prioritize what matters, and fix it faster.
See how Checkmarx One brings comprehensive detection, risk-based prioritization + AI-powered remediation together: checkmarx.com/product/applic…
‼️ Tomorrow: less time sorting through findings, more time fixing what actually matters.‼️
Join Checkmarx’s Emma Datny and Avi Hein, and @TechstrongGroup's @NetworkingNerd for a practical conversation on how context can help AppSec teams cut through the overload and prioritize real risk.
Save your spot: webinars.techstronglearning.…
Shana Tova to everyone celebrating Rosh Hashanah. 🍎🍯
Wishing our colleagues, customers, partners, and communities around the world a sweet New Year filled with health, happiness, and peace.
The best way to understand what application security looks like in practice? Hear from the teams doing it every day.
Across industries, our customers are tackling different challenges, but the goal is the same: reduce risk without getting in the way of building great software.
We’re proud to be part of their stories.
See how organizations around the world are putting Checkmarx to work: checkmarx.com/why-checkmarx/…
AppSec has never had more data. Somehow, developers are still spending nearly half their time figuring out what to do with it.
More findings aren’t the answer. Teams need the context to know which vulnerabilities are actually reachable, exploitable, and worth fixing first.
On September 15, Checkmarx’s Emma Datny and Avi Hein join @TechstrongGroup’s @NetworkingNerd to unpack how code, cloud, and runtime context can cut through the overload, and how ASPM turns scattered security signals into a clearer view of real risk.
📅 September 15
⏰ 11:00 AM ET
webinars.techstronglearning.…
The Checkmarx Partner Pulse is back. 🤝
September is packed with opportunities to connect, learn, and talk security alongside our partners around the world.
Here’s where you can find us:
📍September 10 | Kuala Lumpur: Cyber Security Summit Malaysia – exito-e.com/cybersecuritysum…
📍September 15-16 | Houston: CYBR.SEC.CON. – cybrseccon.com/
📍September 15-17 | São Paulo: Mind The Sec – mindthesec.com.br/inscreva-s…
📍September 16-18 | Dubai: GISEC Global – gisec.ae/
Different cities, different conversations, one busy month for the Checkmarx partner community. We’ll see you out there.
What happens when an AI agent has the right credentials, but makes the wrong call?
In a recent interview on AIM Network’s Point Break, Nitin Kumar Dang, VP of APAC, Middle East & Africa at Checkmarx, discusses how AI is reshaping software development - and why application security must evolve alongside it.
As organizations embrace AI-assisted and agentic development, securing software can no longer be an afterthought. Security needs to operate continuously, at the speed and scale at which software is now being created.
Watch this soundbite from the conversation and catch the full interview: piped.video/watch?v=PLlHQw9B…
Today, we’re excited to announce another big step forward for Checkmarx, and for what’s possible in vulnerability detection.
We’re joining @AnthropicAI’s Project Glasswing, giving us access to Claude Mythos 5 for defensive cybersecurity work.
We’ll use Mythos to strengthen our vulnerability detection and explore risks that have gone undetected by conventional approaches. And just as importantly, what we learn won’t stay with us.
As the work progresses, we’ll share findings and best practices with the broader security community, helping advance how the industry approaches application security workflows, triage, and disclosure.
We’re excited to get to work. Learn more about Checkmarx and Project Glasswing: checkmarx.com/press-releases…
AppSec doesn’t exactly have a finding problem. It has a “what do we do with all of these findings?” problem. 🙃 Finding more only helps if teams can prioritize what matters and fix it fast enough.
See how Checkmarx Fusion tackles that gap live, from high-fidelity detection and Attackability-based prioritization to a merge-ready fix for human approval.
Pick your session:
📅 Sept 8 | 2 PM CET
📅 Sept 9 | 1:30 PM SGT
📅 Sept 10 | 1 PM EDT
See what happens after the scan. 👇info.checkmarx.com/closing-t…
Could you actually list every AI model, agent, MCP server, and dataset being used across your organization?
Regulators increasingly expect you to, but traditional AppSec tooling wasn’t built to see the growing AI supply chain.
You can’t govern what you can’t inventory.
Emma Datny breaks down how to close the visibility gap: checkmarx.com/blog/the-regul…