Checkmarx is how the world’s largest enterprises can finally get ahead of application risk without slowing down development.

Worldwide
Pinned Tweet
Nearly half of all production code is now AI-generated. Traditional scanning wasn't built for today's pace, growing codebases, or the increasing complexity of modern applications. Organizations need the consistency of deterministic scanning alongside the flexibility of AI-powered analysis. Today, we're introducing Checkmarx Fusion, a new hybrid scanning architecture that combines Checkmarx's trusted AppSec engines and proprietary security context with frontier AI reasoning from Anthropic to deliver the industry's most complete vulnerability detection. With Checkmarx Fusion, organizations can: ✔️ Detect vulnerabilities across every language, every codebase, and every stage of the SDLC ✔️ Improve detection by validating and enriching findings across multiple scanning methods ✔️ Scale with an enterprise architecture designed for performance, flexibility, and compliance This isn't just another scanning engine. It's a hybrid approach to vulnerability detection designed for how software is built today. Learn more about Checkmarx Fusion: checkmarx.com/press-releases…
2
6
489
AppSec is hitting the road, and we’re bringing AI with us. 🚌 Starting next week, we’re teaming up with Anthropic and Amazon Bedrock for Securing Code in the AI Era, an event series on securing software as AI changes how it’s built. Expert perspectives, live demos, and conversations with your peers. Find your city and request an invite: partner-program.net/checkmat…
1
143
Finding a vulnerability isn’t always what slows teams down. It’s everything that comes next. Is it reachable? Exploitable? What’s the right fix? Checkmarx Triage & Remediation Assist helps move findings through those decisions and toward a review-ready fix, with people still making the final call. Rebecca Spiegel takes us inside the workflow: checkmarx.com/inside-checkma…
1
107
AI-generated code brings speed to development, but securing it takes more than AI alone. Our CEO @sandeepjohri joined Dark Reading’s Joan Goodchild to discuss why combining deterministic analysis with AI reasoning matters, from detection through remediation. Watch the conversation: darkreading.com/application-…
1
161
AI coding tools are already embedded in enterprise development. So what should the security program around them look like? Our CPO @JonathanRende joined @ResilientCyber to talk AI code security, coding agents, and why the model generating code shouldn’t be the only one validating it: resilientcyber.io/p/ai-code-…
1
1
1
191
Dario Amodei’s call to “pace the frontier” has sparked a lot of conversation, but there’s a security story in his essay worth digging into too. Our latest newsletter looks at it through an AppSec lens and what teams can learn as AI-generated code and agents become part of everyday development. Read it here: linkedin.com/pulse/appsec-re…
1
1
147
The conversation around slowing down AI development has gotten a lot louder this week, and it’s raising some important questions about how the industry moves forward responsibly. There are real risks to consider, just as there are real benefits to continued AI development. How the industry, policymakers, and individual companies navigate that balance is a much bigger conversation than any one organization can answer. From our perspective, there’s also a more immediate reality. AI is already deeply embedded in how software is being built, and whatever happens next at the frontier, organizations still need to secure the code being generated today. Our CEO @sandeepjohri has been speaking with CNBC and NBC Las Vegas about the slowdown conversation, what responsible AI adoption can look like, and why security can’t wait for the broader debate to be resolved. CNBC: cnbc.com/2026/09/15/trump-op… NBC Las Vegas: news3lv.com/news/local/ai-ar…
1
2
1
172
Blocking the front door doesn’t help much when attackers find another way in. 👀 Our @CheckmarxZero team is tracking an npm campaign that skips install scripts entirely, triggering malicious code only when the package is used. The package reached nearly 2M weekly downloads and even uses an Ethereum smart contract for command and control. Bruno Dias breaks down what’s happening, the IOCs, and why runtime behavior matters: checkmarx.com/zero-post/npm-…
1
1
1
232
“0 critical” only tells you what your tools were able to find. As previously unseen risks surface and response windows shrink, AppSec needs to see more, prioritize what matters, and fix it faster. See how Checkmarx One brings comprehensive detection, risk-based prioritization + AI-powered remediation together: checkmarx.com/product/applic…
1
112
‼️ Tomorrow: less time sorting through findings, more time fixing what actually matters.‼️ Join Checkmarx’s Emma Datny and Avi Hein, and @TechstrongGroup's @NetworkingNerd for a practical conversation on how context can help AppSec teams cut through the overload and prioritize real risk. Save your spot: webinars.techstronglearning.…
2
123
Shana Tova to everyone celebrating Rosh Hashanah. 🍎🍯 Wishing our colleagues, customers, partners, and communities around the world a sweet New Year filled with health, happiness, and peace.
138
The best way to understand what application security looks like in practice? Hear from the teams doing it every day. Across industries, our customers are tackling different challenges, but the goal is the same: reduce risk without getting in the way of building great software. We’re proud to be part of their stories. See how organizations around the world are putting Checkmarx to work: checkmarx.com/why-checkmarx/…
137
AppSec has never had more data. Somehow, developers are still spending nearly half their time figuring out what to do with it. More findings aren’t the answer. Teams need the context to know which vulnerabilities are actually reachable, exploitable, and worth fixing first. On September 15, Checkmarx’s Emma Datny and Avi Hein join @TechstrongGroup’s @NetworkingNerd to unpack how code, cloud, and runtime context can cut through the overload, and how ASPM turns scattered security signals into a clearer view of real risk. 📅 September 15 ⏰ 11:00 AM ET webinars.techstronglearning.…
1
137
The Checkmarx Partner Pulse is back. 🤝 September is packed with opportunities to connect, learn, and talk security alongside our partners around the world. Here’s where you can find us: 📍September 10 | Kuala Lumpur: Cyber Security Summit Malaysia – exito-e.com/cybersecuritysum… 📍September 15-16 | Houston: CYBR.SEC.CON. – cybrseccon.com/ 📍September 15-17 | São Paulo: Mind The Sec – mindthesec.com.br/inscreva-s… 📍September 16-18 | Dubai: GISEC Global – gisec.ae/ Different cities, different conversations, one busy month for the Checkmarx partner community. We’ll see you out there.
160
What happens when an AI agent has the right credentials, but makes the wrong call? In a recent interview on AIM Network’s Point Break, Nitin Kumar Dang, VP of APAC, Middle East & Africa at Checkmarx, discusses how AI is reshaping software development - and why application security must evolve alongside it. As organizations embrace AI-assisted and agentic development, securing software can no longer be an afterthought. Security needs to operate continuously, at the speed and scale at which software is now being created. Watch this soundbite from the conversation and catch the full interview: piped.video/watch?v=PLlHQw9B…
1
169
Today, we’re excited to announce another big step forward for Checkmarx, and for what’s possible in vulnerability detection. We’re joining @AnthropicAI’s Project Glasswing, giving us access to Claude Mythos 5 for defensive cybersecurity work. We’ll use Mythos to strengthen our vulnerability detection and explore risks that have gone undetected by conventional approaches. And just as importantly, what we learn won’t stay with us. As the work progresses, we’ll share findings and best practices with the broader security community, helping advance how the industry approaches application security workflows, triage, and disclosure. We’re excited to get to work. Learn more about Checkmarx and Project Glasswing: checkmarx.com/press-releases…
3
6
1,341
AppSec doesn’t exactly have a finding problem. It has a “what do we do with all of these findings?” problem. 🙃 Finding more only helps if teams can prioritize what matters and fix it fast enough. See how Checkmarx Fusion tackles that gap live, from high-fidelity detection and Attackability-based prioritization to a merge-ready fix for human approval. Pick your session: 📅 Sept 8 | 2 PM CET 📅 Sept 9 | 1:30 PM SGT 📅 Sept 10 | 1 PM EDT See what happens after the scan. 👇info.checkmarx.com/closing-t…
1
4
253
Could you actually list every AI model, agent, MCP server, and dataset being used across your organization? Regulators increasingly expect you to, but traditional AppSec tooling wasn’t built to see the growing AI supply chain. You can’t govern what you can’t inventory. Emma Datny breaks down how to close the visibility gap: checkmarx.com/blog/the-regul…
1
4
240