<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Checkmarx</title>
	<atom:link href="https://checkmarx.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://checkmarx.com/</link>
	<description>The world runs on code. We secure it.</description>
	<lastBuildDate>Tue, 11 Aug 2026 14:09:06 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://checkmarx.com/wp-content/uploads/2026/06/favicon_spring-150x150.webp</url>
	<title>Checkmarx</title>
	<link>https://checkmarx.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>What Is Checkmarx Fusion?</title>
		<link>https://checkmarx.com/blog/what-is-checkmarx-fusion/</link>
		
		<dc:creator><![CDATA[Jonathan Rende]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 18:40:36 +0000</pubDate>
				<category><![CDATA[AI & LLM Tools in Application Security]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Checkmarx One]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI generated code]]></category>
		<category><![CDATA[AI in Cybersecurity]]></category>
		<category><![CDATA[Checkmarx One Assist]]></category>
		<category><![CDATA[SAST]]></category>
		<guid isPermaLink="false">https://staging.checkmarx.com/?p=115391</guid>

					<description><![CDATA[Now available in Early Access for SAST within Checkmarx One, Checkmarx Fusion adds a new detection layer that advances vulnerability-finding accuracy beyond what rules-based scanning or an AI model can achieve alone.   ]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">AppSec teams have always faced a tradeoff – one that feels impossible to solve. Rules-based scanners are precise and consistent, but they only catch what they’ve been explicitly told to look for. AI-based scanners reason more broadly and catch things rules miss – but ask the same question twice and you can get two different answers.</p>



<p class="wp-block-paragraph">Checkmarx’s hybrid model removes that tradeoff.</p>



<p class="wp-block-paragraph">A deterministic detection engine and an AI reasoning engine analyze the code in parallel, and a third engine, the Findings Analysis Engine (FAE), reconciles their output into one verified result. It is precise, broad, and repeatable every time.</p>



<p class="wp-block-paragraph">But the hybrid model is only the start.</p>



<p class="wp-block-paragraph">Checkmarx Fusion, now in Early Access for SAST within Checkmarx One, adds a new layer on top of that hybrid foundation. Its Multi-Model AI Engine runs several curated frontier AI models on top of the FAE&#8217;s already-reconciled results, surfacing vulnerabilities with no known rule, CVE, or signature to catch them.</p>



<p class="wp-block-paragraph">Here&#8217;s how it works – and how this model finds what other scanners were never built to see.</p>



<h2 class="wp-block-heading article-anchor" id="why-a-new-model-is-needed">Why a New Model Is Needed</h2>



<p class="wp-block-paragraph">The limitations of traditional detection are becoming more consequential as AI changes both how software is built and how quickly it can be attacked.</p>



<p class="wp-block-paragraph">AI assistants are generating more code, across more languages, faster than security teams can review it. Checkmarx’s latest <a href="/foa-report/">Future of Application Security report</a> found that organizations where AI generates 81–100% of production code ship known vulnerabilities at 3.4 times the rate of organizations that generate only 1–20% of code.</p>



<p class="wp-block-paragraph">At the same time, attackers are moving faster. <a href="https://anthropic.com/research/n-days">Anthropic research</a> found that a working exploit could be generated within an hour of a patch being released. A vulnerability that goes undetected may become an active risk before security teams have time to respond.</p>



<p class="wp-block-paragraph">But simply adding more AI is not enough. Standalone AI scanning can be inconsistent from one run to the next, while operating frontier models at enterprise scale can create high, unpredictable token costs.</p>



<p class="wp-block-paragraph">Organizations need detection that can keep pace with AI-generated code without sacrificing precision, repeatability, or operational control.</p>



<h2 class="wp-block-heading article-anchor" id="how-the-hybrid-model-works">How the Hybrid Model Works</h2>



<p class="wp-block-paragraph">The hybrid model provides that foundation. It is made up of three engines, each serving a distinct role:</p>



<p class="wp-block-paragraph"><strong>Deterministic Engine</strong>: Rules-based analysis of known vulnerability classes. Precise, explainable, and consistent from scan to scan.</p>



<p class="wp-block-paragraph"><strong>AI-Based Engine</strong>: Extends coverage to languages and patterns that rules alone cannot reach, including novel logic and AI-generated code.</p>



<p class="wp-block-paragraph"><strong>Findings Analysis Engine (FAE)</strong>: Reconciles the output of both engines into one clean result set. False positives removed, true positives kept.</p>



<p class="wp-block-paragraph">This foundation transforms what a security scan can deliver – and it’s currently powering our Next Generation SAST. <strong><em>But Fusion takes it even further.</em></strong></p>



<p class="wp-block-paragraph"><strong>Fusion’s Multi-Model AI Engine</strong> applies several curated frontier models to the hybrid model’s verified findings. Each analyzes the code from a different perspective, allowing Fusion to uncover vulnerabilities that no single rule, signature, or AI model would be likely to identify alone – including issues with no known rule, prior CVE, or existing signature.</p>



<p class="wp-block-paragraph">The advanced AI models are selected and validated by Checkmarx research, and customers can choose higher- or lower-cost options based on the needs of each project. This extends AI-driven coverage while keeping scan costs predictable.</p>



<p class="wp-block-paragraph">Together, the hybrid model and Fusion deliver:</p>



<ul class="wp-block-list">
<li>
<strong>Precision without sacrificing coverage</strong>: deterministic precision and AI coverage together, not a compromise between them.</li>



<li>
<strong>Consistent, repeatable results</strong>: scan it twice, get the same result, on any scan type running the hybrid model. Standalone AI scanning can&#8217;t promise that.</li>



<li>
<strong>Less noise for teams</strong>: the Findings Analysis Engine, part of the hybrid model, strips noise before it reaches your team. Every finding traces to a rule or a verifiable signal, the same standard across every scan type.</li>



<li>
<strong>One unified risk view</strong>: every scan’s findings land in Checkmarx One ASPM (Risk Orchestration) next to each other, scored against the same risk model, instead of a fragmented view across separate tools.</li>
</ul>



<p class="wp-block-paragraph"><a href="https://checkmarx.com/press-releases/checkmarx-fusion-delivers-most-complete-vulnerability-detection-available/">As Erik Brown</a>, Business Information Security Officer and AppSec Leader at Nelnet, put it: “With AI generating unprecedented amounts of code, security has to be an enabler, not a bottleneck.” He added: “The industry finally has an approach built for what AI demands.”</p>



<h2 class="wp-block-heading article-anchor" id="the-data-backs-it-up">The Data Backs It Up</h2>



<p class="wp-block-paragraph">The numbers show just how much this model changes security outcomes.</p>



<p class="wp-block-paragraph">The F1 score measures both precision – how many reported findings are real – and recall – how many real vulnerabilities are found. A higher score means stronger detection – that is, finding more real vulnerabilities &#8211; without burying teams in false positives.</p>



<p class="wp-block-paragraph">Traditional, query-based SAST averages roughly 0.20. Next-Gen SAST, run on the hybrid model, raises that score to 0.64, more than triples the baseline. Add a Fusion scan, and it reaches 0.74 – nearly four times the industry average – with 60–70% fewer false positives than standalone AI scanning.</p>



<p class="wp-block-paragraph">Teams get broader coverage with a result set they can realistically manage. Fusion improves precision and recall even more, extending that coverage into novel vulnerabilities, unseen patterns, and flaws unique to AI-generated code.</p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout">
<thead><tr>
<th class="has-text-align-left" data-align="left">Approach</th>
<th class="has-text-align-left" data-align="left">F1 Score</th>
</tr></thead>
<tbody>
<tr>
<td class="has-text-align-left" data-align="left">Query-based SAST (industry average)&nbsp;</td>
<td class="has-text-align-left" data-align="left">0.20</td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">Hybrid model alone (Next-Gen&nbsp;SAST)&nbsp;</td>
<td class="has-text-align-left" data-align="left">0.64</td>
</tr>
<tr>
<td class="has-text-align-left" data-align="left">Hybrid model + Fusion&nbsp;</td>
<td class="has-text-align-left" data-align="left">0.74</td>
</tr>
</tbody>
</table></figure>



<p class="wp-block-paragraph">Mustapha Kebbeh, Chief Security Officer at UKG, <a href="https://itbrief.co.uk/story/checkmarx-launches-fusion-hybrid-scanning-tool-for-ai-code">put it this way</a>: “The question I hear every day is no longer whether we have vulnerabilities, it’s whether we’ve discovered the ones that matter most and whether we&#8217;re fixing them fast enough. That&#8217;s exactly what Checkmarx Fusion is built to address.”</p>



<h2 class="wp-block-heading article-anchor" id="efficient-at-scale">Efficient at Scale</h2>



<p class="wp-block-paragraph">That level of coverage only matters if it can be delivered efficiently, predictably, and securely at enterprise scale. Fusion uses a bounded, curated set of research-validated models rather than relying on open-ended frontier API calls. In practice that means:</p>



<ul class="wp-block-list">
<li>
<strong>Predictable Cost</strong>: Higher- or lower-cost models, your choice, with no token bill that compounds across every commit.</li>



<li>
<strong>Model Optionality</strong>: Choose high- or low-cost models per project, without being locked to any single provider.</li>



<li>
<strong>Cost Optimization</strong>: Prompt, context, and harness tuning, combined with incremental scans, keep performance high and spend controlled as usage grows.</li>



<li>
<strong>Enterprise Scale</strong>: Incremental scanning re-scans only new and changed code, so performance improves as your codebase grows.</li>



<li>
<strong>Built-In Data Protection</strong>: Source code and customer data remain within your own cloud environment or tenant using Amazon Bedrock.</li>
</ul>



<p class="wp-block-paragraph">The hybrid model – now offered within Next-Gen SAST – remains part of standard Checkmarx licensing, while Fusion is offered as an optional, usage-based add-on that draws on Checkmarx credits.</p>



<h2 class="wp-block-heading article-anchor" id="how-to-use-fusion">How to Use Fusion</h2>



<p class="wp-block-paragraph">Here’s what running Fusion looks like inside Checkmarx One, start to finish.</p>



<p class="wp-block-paragraph"><strong>1. Turn it on</strong>. Enable Checkmarx Fusion under Account Settings → AI Capabilities. From here, teams control the account-level switch, see which curated models are active, and track remaining token budget in real time.</p>



<ol class="wp-block-list">
<li>
</li>
</ol>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="2560" height="721" src="https://checkmarx.com/wp-content/uploads/2026/08/Account_Settings_-_Turn_on_Fusion_sharpened-scaled.png" alt="" class="wp-image-115401" srcset="https://checkmarx.com/wp-content/uploads/2026/08/Account_Settings_-_Turn_on_Fusion_sharpened-scaled.png 2560w, https://checkmarx.com/wp-content/uploads/2026/08/Account_Settings_-_Turn_on_Fusion_sharpened-300x85.png 300w, https://checkmarx.com/wp-content/uploads/2026/08/Account_Settings_-_Turn_on_Fusion_sharpened-1024x288.png 1024w, https://checkmarx.com/wp-content/uploads/2026/08/Account_Settings_-_Turn_on_Fusion_sharpened-768x216.png 768w, https://checkmarx.com/wp-content/uploads/2026/08/Account_Settings_-_Turn_on_Fusion_sharpened-1536x433.png 1536w, https://checkmarx.com/wp-content/uploads/2026/08/Account_Settings_-_Turn_on_Fusion_sharpened-2048x577.png 2048w, https://checkmarx.com/wp-content/uploads/2026/08/Account_Settings_-_Turn_on_Fusion_sharpened-400x113.png 400w" sizes="(max-width: 2560px) 100vw, 2560px" /><figcaption class="wp-element-caption"><em>Checkmarx&nbsp;Fusion AI Capabilities settings screen showing the account-level toggle, active models, and&nbsp;remaining&nbsp;token budget&nbsp;</em></figcaption></figure>



<p class="wp-block-paragraph">A note on the numbers in this screenshot: the token and per-model figures are illustrative. Treat any dollar or token figure here as a preview, not a rate card.</p>



<p class="wp-block-paragraph"><strong>2. Start a scan and select Checkmarx Fusion</strong>. Point Checkmarx One at a repository, file, or SBOM, then choose which scanners run. Fusion sits alongside SAST, SCA, IaC, API Security, and the rest, so enabling it is a checkbox in the same flow, not a separate tool.</p>



<ol class="wp-block-list">
<li>
</li>
</ol>



<figure class="wp-block-image size-full is-resized"><img decoding="async" width="603" height="357" src="https://checkmarx.com/wp-content/uploads/2026/08/image-1.png" alt="" class="wp-image-115393" style="width:581px;height:auto" srcset="https://checkmarx.com/wp-content/uploads/2026/08/image-1.png 603w, https://checkmarx.com/wp-content/uploads/2026/08/image-1-300x178.png 300w, https://checkmarx.com/wp-content/uploads/2026/08/image-1-400x237.png 400w" sizes="(max-width: 603px) 100vw, 603px" /><figcaption class="wp-element-caption"><em>Kicking off a new scan: point&nbsp;Checkmarx&nbsp;One at a repository, file, or SBOM.</em>&nbsp;</figcaption></figure>



<figure class="wp-block-image size-full"><img decoding="async" width="642" height="477" src="https://checkmarx.com/wp-content/uploads/2026/08/image-2.png" alt="" class="wp-image-115394" srcset="https://checkmarx.com/wp-content/uploads/2026/08/image-2.png 642w, https://checkmarx.com/wp-content/uploads/2026/08/image-2-300x223.png 300w, https://checkmarx.com/wp-content/uploads/2026/08/image-2-400x297.png 400w" sizes="(max-width: 642px) 100vw, 642px" /><figcaption class="wp-element-caption"><em>Checkmarx&nbsp;Fusion sits alongside standard scanner&nbsp;selection&nbsp;(SAST, SCA, and more) in the same scan setup. Enable it for the scan types and projects that need the highest fidelity.</em>&nbsp;</figcaption></figure>



<p class="wp-block-paragraph"><strong>3. Review results at the portfolio level</strong>. Once scans complete, risk level and total vulnerabilities roll up per project. Scanner badges show which engines contributed to each result.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="436" src="https://checkmarx.com/wp-content/uploads/2026/08/image-3-1024x436.png" alt="" class="wp-image-115395" srcset="https://checkmarx.com/wp-content/uploads/2026/08/image-3-1024x436.png 1024w, https://checkmarx.com/wp-content/uploads/2026/08/image-3-300x128.png 300w, https://checkmarx.com/wp-content/uploads/2026/08/image-3-768x327.png 768w, https://checkmarx.com/wp-content/uploads/2026/08/image-3-400x170.png 400w, https://checkmarx.com/wp-content/uploads/2026/08/image-3.png 1120w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Checkmarx Fusion results roll up at the portfolio&nbsp;level too: risk level and total vulnerabilities per project, with scanner badges showing which engines contributed to each result.</em></figcaption></figure>



<p class="wp-block-paragraph"><strong>4. Drill into Risk Orchestration.</strong> Every finding lands in the same Risk Orchestration view, regardless of which engine produced it. Teams can filter for Checkmarx Fusion’s LLM-based results alongside every other scanner.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="453" height="617" src="https://checkmarx.com/wp-content/uploads/2026/08/image-4.png" alt="" class="wp-image-115396" srcset="https://checkmarx.com/wp-content/uploads/2026/08/image-4.png 453w, https://checkmarx.com/wp-content/uploads/2026/08/image-4-220x300.png 220w, https://checkmarx.com/wp-content/uploads/2026/08/image-4-430x585.png 430w" sizes="(max-width: 453px) 100vw, 453px" /><figcaption class="wp-element-caption"><em>Fusion findings land directly in&nbsp;Checkmarx&nbsp;One Risk Orchestration, filterable alongside every other scanner. Teams can isolate results specifically: scored, prioritized, and ready to act on, not a separate report to reconcile.</em>&nbsp;</figcaption></figure>



<figure class="wp-block-image size-full"><img decoding="async" width="936" height="490" src="https://checkmarx.com/wp-content/uploads/2026/08/image-5.png" alt="" class="wp-image-115397" srcset="https://checkmarx.com/wp-content/uploads/2026/08/image-5.png 936w, https://checkmarx.com/wp-content/uploads/2026/08/image-5-300x157.png 300w, https://checkmarx.com/wp-content/uploads/2026/08/image-5-768x402.png 768w, https://checkmarx.com/wp-content/uploads/2026/08/image-5-400x209.png 400w" sizes="(max-width: 936px) 100vw, 936px" /><figcaption class="wp-element-caption"><em>A live&nbsp;scan’s&nbsp;results in Risk Orchestration, grouped by severity.</em>&nbsp;</figcaption></figure>



<p class="wp-block-paragraph"><strong>5. Know what’s AI-generated.</strong> The results table labels findings as “LLM Generated Result” when AI-based analysis produced them, so nothing is a black box.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="624" height="804" src="https://checkmarx.com/wp-content/uploads/2026/08/image-6.png" alt="" class="wp-image-115398" srcset="https://checkmarx.com/wp-content/uploads/2026/08/image-6.png 624w, https://checkmarx.com/wp-content/uploads/2026/08/image-6-233x300.png 233w, https://checkmarx.com/wp-content/uploads/2026/08/image-6-454x585.png 454w" sizes="(max-width: 624px) 100vw, 624px" /><figcaption class="wp-element-caption"><em>Checkmarx&nbsp;One results table showing the LLM Generated Result label and link to the SAST Results Viewer&nbsp;</em></figcaption></figure>



<p class="wp-block-paragraph">From here, findings flow into <a href="https://checkmarx.com/product/triage-and-remediation/">Triage Assist and Remediation Assist</a>.</p>



<h2 class="wp-block-heading article-anchor" id="from-finding-to-fix-all-within-checkmarx-one">From Finding to Fix, All Within Checkmarx One</h2>



<p class="wp-block-paragraph">Fusion findings don’t land in a separate tool, queue, or workflow. They’re part of the unified risk picture in Checkmarx One’s Risk Orchestration, where they can be prioritized and acted on alongside findings from the rest of the platform. Fusion focuses on discovery, delivering a clean, high-fidelity finding on top of what our hybrid engines already found.</p>



<p class="wp-block-paragraph">Triage and Remediation Assist takes from there. It carries eligible findings forward – from determining whether it presents a real application risk to preparing a fix. Together, this interconnected workflow can deliver:</p>



<p class="wp-block-paragraph"><strong>Up to 95% faster MTTR</strong>: Attackability-based decisions and review-ready guidance cut the time from finding to fix.</p>



<p class="wp-block-paragraph"><strong>65%+ fixed on the first attempt</strong>: context-aware remediation guidance gets it right without repeated back-and-forth.</p>



<p class="wp-block-paragraph"><strong>Up to 60% lower operational cost</strong>: fewer handoffs and less rework between AppSec and development teams.</p>



<p class="wp-block-paragraph"><strong>Governed, not autonomous</strong>: scoped rollout, eligibility criteria, and action-mode controls (diffs vs. PR) mean the agent proposes, and the developer disposes.</p>



<p class="wp-block-paragraph">This is where Checkmarx Fusion’s higher fidelity pays off. Cleaner, more trustworthy findings give downstream prioritization and remediation a stronger foundation, reducing manual validation and helping teams move more risk toward resolution faster.</p>



<p class="wp-block-paragraph">Zoom out and see that this handoff is part of a bigger picture of the connected security lifecycle within Checkmarx One:</p>



<ul class="wp-block-list">
<li>
<strong>Prevent</strong> with the Assist family of agents – from Developer Assist, Triage Assist, and Remediation Assist. Developer Assist catches issues before code is even generated for a developer.</li>



<li>
<strong>Discover</strong> with Fusion and Next-Gen SAST, which find what got through, including zero-day and unknown-pattern vulnerabilities no rule or signature could catch alone.</li>



<li>
<strong>Remediate</strong> with Triage &amp; Remediation Assist, which clears the backlog and resolves the exploitable risk that discovery surfaces, including the zero-day findings Fusion turns up.</li>
</ul>



<p class="wp-block-paragraph">Fusion makes sure that what gets handed off is real, so the resolution stage isn’t wasting time on noise.</p>



<h2 class="wp-block-heading article-anchor" id="see-it-in-your-application">See It in Your Application</h2>



<p class="wp-block-paragraph">Checkmarx Fusion is in Early Access, available within Checkmarx One for teams using credits. <a href="https://checkmarx.com/request-a-demo/">Schedule a demo</a> to see how it works in your own environment or visit the <a href="https://checkmarx.com/platform/checkmarx-fusion/">Checkmarx Fusion solution page</a> for more details.</p>]]></content:encoded>
					
		
		
		
		<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/08/Account_Settings_-_Turn_on_Fusion_sharpened-150x150.png" />
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/08/Account_Settings_-_Turn_on_Fusion_sharpened-scaled.png" medium="image">
			<media:title type="html">Account_Settings_-_Turn_on_Fusion_sharpened</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/08/Account_Settings_-_Turn_on_Fusion_sharpened-150x150.png" />
		</media:content>
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/08/image-1.png" medium="image">
			<media:title type="html">image</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/08/image-1-150x150.png" />
		</media:content>
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/08/image-2.png" medium="image">
			<media:title type="html">image</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/08/image-2-150x150.png" />
		</media:content>
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/08/image-3.png" medium="image">
			<media:title type="html">image</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/08/image-3-150x150.png" />
		</media:content>
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/08/image-4.png" medium="image">
			<media:title type="html">image</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/08/image-4-150x150.png" />
		</media:content>
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/08/image-5.png" medium="image">
			<media:title type="html">image</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/08/image-5-150x150.png" />
		</media:content>
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/08/image-6.png" medium="image">
			<media:title type="html">image</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/08/image-6-150x150.png" />
		</media:content>
	</item>
		<item>
		<title>We Now Build Code Faster Than We Can Understand It: The New Risk of AI Speed</title>
		<link>https://checkmarx.com/application-security-trends/the-new-risk-of-ai-speed/</link>
		
		<dc:creator><![CDATA[Avi Hein]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 12:48:16 +0000</pubDate>
				<category><![CDATA[AI & LLM Tools in Application Security]]></category>
		<category><![CDATA[Application Security Trends & Insights]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AppSec]]></category>
		<category><![CDATA[Article]]></category>
		<category><![CDATA[Developer]]></category>
		<guid isPermaLink="false">https://staging.checkmarx.com/?p=114955</guid>

					<description><![CDATA[AI is generating code faster than teams can review it. Learn how hybrid SAST and Checkmarx Fusion help detect AI-era software security risks.]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">There&#8217;s&nbsp;an old story about an apprentice who enchants a broom to fetch water, then&nbsp;can&#8217;t&nbsp;stop it. He panics and hacks it in half, only to end up with two brooms working just as fast, then more, then a flood, because the process he set loose was never going to slow down just because he wanted to stop it. Software in 2026 has the same problem. It&nbsp;doesn&#8217;t&nbsp;need more automation.&nbsp;It needs something that can actually keep up with what&#8217;s already been set loose.&nbsp;</p>



<p class="wp-block-paragraph">Securing enterprise codebases was already challenging because most&nbsp;contain&nbsp;code written in multiple languages. AI assistants are now adding to that challenge by generating code in whichever language they&nbsp;determine&nbsp;is best for the task,&nbsp;whether or not&nbsp;your scanner can read it.&nbsp;<a href="https://tiobe.com/tiobe-index/" target="_blank" rel="noreferrer noopener">TIOBE&#8217;s index</a>&nbsp;now tracks more than fifty languages in active use&nbsp;– and they&nbsp;aren’t&nbsp;the languages you might expect. For&nbsp;example,&nbsp;Go&nbsp;and Haskell now rank alongside Python on some of today’s most visited sites.&nbsp;</p>



<p class="wp-block-paragraph">Those&nbsp;AI&nbsp;assistants write faster than people do, too.&nbsp;<a href="https://microsoft.com/en-us/research/publication/the-impact-of-ai-on-developer-productivity-evidence-from-github-copilot" target="_blank" rel="noreferrer noopener">Microsoft Research</a>&nbsp;clocked developers using GitHub Copilot at 55.8% faster on an identical task than developers without it.&nbsp;Checkmarx&#8217;s&nbsp;2026&nbsp;<a href="https://checkmarx.com/foa-report/" target="_blank" rel="noreferrer noopener">Future of Application Security survey</a>&nbsp;names what that speed has done to the job: developers have moved from authoring code to editing it, supervising output instead of producing&nbsp;it.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">That combination – more code, written faster, across more languages – creates a security challenge most teams don’t understand and were not built to handle. This is where vulnerabilities live. </p>



<p class="wp-block-paragraph">The more production code AI generates, the more risk can slip through at scale. According to the same report, organizations where 81-100% of production code is AI-generated ship known vulnerabilities at 3.4x&nbsp;the rate of organizations where AI writes just 1-20%.&nbsp;&nbsp;The issue is not just speed. AI-generated code can look correct while still carrying insecure patterns from the code it learned from, making vulnerabilities easier to miss and harder to trace.&nbsp;</p>



<p class="wp-block-paragraph">And, in addition, attackers are not waiting for security to catch up. Anthropic&#8217;s research on N-day exploits found that WannaCry took 59 days to weaponize after its 2017 patch, and that 16 of 25 historical vulnerabilities studied by Mandiant took a month or more to exploit. That timeline is already history. In the same research, Anthropic&#8217;s own model, Claude Mythos Preview, had a working Firefox exploit ready <strong>within an hour</strong> of Mozilla shipping the patch, 18 days before the patched browser itself even went out.  </p>



<p class="wp-block-paragraph">The imbalance is clear: attackers can now move in hours, while defenders are still trying to understand code generated at AI speed, across more languages than ever. Closing that gap needs to start before the code ships. </p>



<h2 class="wp-block-heading article-anchor" id="one-scan-two-lenses">One Scan, Two Lenses </h2>



<p class="wp-block-paragraph">Scanning code has always meant choosing a lens. A deterministic scanner&nbsp;looks through the lens of known rules, signatures, and patterns. It&nbsp;is consistent: run it twice on the same code,&nbsp;and&nbsp;you’ll&nbsp;get the same&nbsp;result. This repeatability is&nbsp;why auditors and compliance teams trust it. An AI-based scanner&nbsp;uses a different lens.&nbsp;It&nbsp;reasons&nbsp;through&nbsp;code&nbsp;more like a human reviewer, which&nbsp;helps it catch risks that do not match a&nbsp;known&nbsp;rule or&nbsp;signature.&nbsp;But that flexibility comes with less predictability: ask it the same question twice, and the answer might change.&nbsp;</p>



<p class="wp-block-paragraph">Neither one was ever going to be enough by itself. That is the&nbsp;compromise&nbsp;Checkmarx&#8217;s&nbsp;hybrid&nbsp;architecture refuses to make: depending on the language, either a deterministic, rules-based engine or an AI-based reasoning engine runs, and a Findings Analysis Engine (FAE) reconciles the output into one validated list. That pairing is Next-Gen SAST, built for known, N-day vulnerabilities at the highest fidelity a scanner reaches without going further. On its own, it reaches an F1 score of 0.64, up from 0.20 for basic query-based scanning,&nbsp;the&nbsp;standard&nbsp;approach&nbsp;used by&nbsp;traditional SAST solutions.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="one-step-further">One Step Further </h2>



<p class="wp-block-paragraph">But known and N-day vulnerabilities are only part of the picture. The harder challenge is finding risks with no CVE, signature, or established pattern to match.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">That is where&nbsp;Checkmarx Fusion,&nbsp;currently in Early Access,&nbsp;adds another layer. Built&nbsp;on top&nbsp;of&nbsp;Checkmarx’s&nbsp;next generation&nbsp;hybrid&nbsp;SAST&nbsp;scanner,&nbsp;Checkmarx&nbsp;Fusion&nbsp;runs several frontier AI models, hunting for zero-day and unknown-pattern findings with no CVE or signature yet to match. Checkmarx reconciles that&nbsp;broader&nbsp;set of results&nbsp;back&nbsp;through the same rigorous validation process, producing one trusted output.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Run together,&nbsp;Checkmarx&nbsp;SAST with&nbsp;Checkmarx&nbsp;Fusion&nbsp;achieves an F1 score of 0.74.&nbsp;The point&nbsp;is&nbsp;not to add&nbsp;AI just for the sake of it. The point is to give developers scan results that they can&nbsp;trust:&nbsp;precise enough to avoid false-positive noise, and broad enough to catch critical vulnerabilities that simpler scanners might miss.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">&nbsp;Frontier AI models give&nbsp;Checkmarx&nbsp;Fusion&nbsp;a broader detection lens, surfacing complex or novel vulnerabilities that static rules and signatures alone would miss. And because AI models evolve rapidly, Checkmarx&nbsp;isn&#8217;t&nbsp;locked to any single one. The best model today may not be the best model tomorrow. So as models improve,&nbsp;Checkmarx&nbsp;swaps in whichever performs best – while the deterministic backbone, code context, and validation process remain fixed.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="inside-checkmarx-one">Inside Checkmarx One </h2>



<p class="wp-block-paragraph">A clean finding is&nbsp;not the same as&nbsp;a fixed one.&nbsp;Checkmarx&nbsp;Fusion&nbsp;sits&nbsp;as the final layer of&nbsp;Checkmarx&nbsp;SAST, and the same model is coming to other scan types, extending&nbsp;coverage&nbsp;across&nbsp;the full application development&nbsp;lifecycle&nbsp;so security&nbsp;doesn’t&nbsp;stop at detection. It is not the layer every&nbsp;team starts with. It is the layer teams reach for once&nbsp;standard scanner coverage is no longer enough,&nbsp;when&nbsp;getting a finding&nbsp;right matters as much as&nbsp;finding&nbsp;it fast.&nbsp;</p>



<p class="wp-block-paragraph">That need is only growing. New models keep arriving faster than security roadmaps can account for, and each one can change what attackers are able to find and exploit. Claude Mythos Preview&#8217;s hour-long path from patch to exploit showed what that looks like in practice: a working exploit within an hour of a patch being released.</p>



<p class="wp-block-paragraph">A scanner built only to catch what it already knows will always be one step behind. Checkmarx Fusion exists to close that gap for teams that need deeper validation and greater confidence in what they are shipping.  </p>



<p class="wp-block-paragraph">The apprentice&#8217;s mistake wasn&#8217;t casting the spell. It was assuming he could still control however many brooms showed up. Checkmarx Fusion is built for the version of that story where the brooms keep coming faster than anyone planned for, and someone still has to know which ones matter. </p>



<p class="wp-block-paragraph">Visit the <a href="https://checkmarx.com/platform/checkmarx-fusion/?utm_source=httpscheckmarx.comblog&amp;utm_medium=blog&amp;utm_campaign=checkmarx_fusion_blog_series" target="_blank" rel="noreferrer noopener">Checkmarx Fusion landing page</a>. Read more on the <a href="https://checkmarx.com/blog/your-scanners-accuracy-claims-are-only-half-the-story/" target="_blank" rel="noreferrer noopener">Checkmarx blog</a> or in the <a href="https://docs.checkmarx.com/" target="_blank" rel="noreferrer noopener">documentation</a>. </p>]]></content:encoded>
					
		
		
		
	</item>
		<item>
		<title>Risk, Return, and Remediation: An Investment Strategy for Application Security</title>
		<link>https://checkmarx.com/blog/investment-strategy-application-security/</link>
		
		<dc:creator><![CDATA[Eran Kinsbruner]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 20:05:00 +0000</pubDate>
				<category><![CDATA[AI & LLM Tools in Application Security]]></category>
		<category><![CDATA[Application Security Trends & Insights]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[Application Security Testing]]></category>
		<category><![CDATA[AppSec]]></category>
		<guid isPermaLink="false">https://staging.checkmarx.com/?p=114901</guid>

					<description><![CDATA[Learn why a hybrid application security strategy combining deterministic tools and AI delivers better protection, lower costs, and faster remediation for AI-generated code.]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph"><em>Don’t Put All Your Code in One Basket</em>.</p>



<p class="wp-block-paragraph">Every seasoned investor knows to&nbsp;never put&nbsp;your&nbsp;money&nbsp;behind a single asset.&nbsp;&nbsp;&nbsp;<br>A successful investment strategy is diverse.&nbsp;&nbsp;<br>&nbsp;<br>No&nbsp;one&nbsp;puts&nbsp;all their money&nbsp;in stocks: markets&nbsp;correct.&nbsp;Real estate&nbsp;goes through&nbsp;cycles&nbsp;of&nbsp;boom&nbsp;and&nbsp;bust.&nbsp;Cash may&nbsp;feel&nbsp;safe, but&nbsp;inflation&nbsp;erodes&nbsp;its&nbsp;value&nbsp;over time.&nbsp;Having&nbsp;different&nbsp;investment&nbsp;assets&nbsp;helps&nbsp;offset volatility, so&nbsp;your&nbsp;portfolio&nbsp;as a whole stays&nbsp;resilient,&nbsp;even&nbsp;if that meme coin you bought on a whim takes a nosedive.&nbsp;&nbsp;<br>&nbsp;<br>The same principle&nbsp;of diversification applies to our work&nbsp;in&nbsp;application security.&nbsp;Staying ahead of emerging threats&nbsp;and bad actors&nbsp;in&nbsp;the&nbsp;era of AI-generated code&nbsp;demands&nbsp;more than a&nbsp;single&nbsp;line of defense.&nbsp;It&nbsp;requires&nbsp;a layered,&nbsp;deterministic, and&nbsp;probabilistic&nbsp;approach.&nbsp;Each approach has limits on its own. Together, they&nbsp;work like a diversified portfolio.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="the-growing-gap-between-functional-and-secure">The&nbsp;Growing&nbsp;Gap Between Functional and Secure&nbsp;</h2>



<p class="wp-block-paragraph">This is the essence of our Checkmarx strategy, and&nbsp;we&#8217;re&nbsp;thrilled to see our vision backed by independent, hard data. We sponsored recent research published in&nbsp;<a href="https://theweatherreport.ai/posts/capability-without-security/" target="_blank" rel="noreferrer noopener">The Weather Report</a>, a non-profit AI security and safety lab led&nbsp;by&nbsp;<a href="https://linkedin.com/in/ilyakabanov/" target="_blank" rel="noreferrer noopener">Dr. Ilya&nbsp;Kabanov</a>,&nbsp;former founder of AI Safety &amp; Security at Google and a research affiliate at MIT Sloan Cybersecurity.&nbsp;While Checkmarx funded the study, Kabanov and his team&nbsp;retained&nbsp;full control over design,&nbsp;methodology, evaluation, and conclusions.<br><br>In&nbsp;his research, Kabanov re-ran two established security benchmarks: a&nbsp;snippet-level test, and&nbsp;a&nbsp;broader&nbsp;agentic test built around real open-source repositories. He tested both against frontier models&nbsp;in their native CLIs: Claude Opus&nbsp;4.8, GPT-5.5, Gemini 3.1 Pro, and Gemini 3.5 Flash.<br><br>The results? These models now produce working code 83–95% of the time, but secure-&nbsp;<br>and-functional code, or output that both works and passes security tests, still reaches only&nbsp;24–36%.<br><br>That finding alone&nbsp;should give any&nbsp;AppSec manager&nbsp;pause.&nbsp;But&nbsp;Kabanov’s research went even further. Adding inference-time security&nbsp;steps, or&nbsp;threat modeling&nbsp;before coding, security review after,&nbsp;raises&nbsp;the secure-and-functional&nbsp;rate from a baseline of 24-36% to 47-56%.<br><br>But this&nbsp;improvement&nbsp;comes at a steep cost. Running&nbsp;a task through the full intervention ladder&nbsp;uses&nbsp;roughly four&nbsp;to five times the&nbsp;tokens&nbsp;required&nbsp;to write&nbsp;the code alone, while still leaving&nbsp;roughly half&nbsp;of all tasks insecure.<br><br>That’s&nbsp;like&nbsp;paying a premium for a guess dressed up as a guarantee.&nbsp;But&nbsp;even then, Kabanov&nbsp;isn&#8217;t&nbsp;convinced that better code generation leads to more secure code, noting that&nbsp;&#8220;functional capability is a weak predictor of security.&#8221;&nbsp;In his findings,&nbsp;one&nbsp;of the&nbsp;top-ranked coders&nbsp;actually&nbsp;<a href="https://theweatherreport.ai/posts/capability-without-security/capability-without-security.pdf?utm_source=chatgpt.com" target="_blank" rel="noreferrer noopener">finished last on security</a>.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="llms-alone-cant-keep-the-codebase-secure">LLMs Alone&nbsp;Can’t&nbsp;Keep the Codebase Secure</h2>



<p class="wp-block-paragraph">These are the reasons we built the Checkmarx One unified platform as the most efficient, cost-effective way to deliver security at the speed of frontier LLMs. It’s a deterministic floor for ground truth and auditability, offering AI-augmented reasoning for context and novel patterns, with security context (reachability and business risk) layered on top.<br><br>Because while the leading LLMs are exceptionally good at code generation, when it comes to protecting that code, an &#8220;LLM-only&#8221; approach isn&#8217;t enough. The smart investor never bets on a single asset. The smart AppSec team doesn&#8217;t bet on a single model. <br> <br>Our deterministic tools apply consistent rules and proven detection logic, producing repeatable results that teams can trust and verify. That&#8217;s the core of our Checkmarx vision: a hybrid platform that we call <strong><a href="https://checkmarx.com/platform/checkmarx-fusion/" type="link" id="https://checkmarx.com/platform/checkmarx-fusion/">Fusion</a></strong> that pairs certainty (deterministic ground truth) with possibility (probabilistic AI reasoning). </p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="683" src="https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-hybrid-approach-600x400-1-1024x683.webp" alt="" class="wp-image-114903" srcset="https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-hybrid-approach-600x400-1-1024x683.webp 1024w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-hybrid-approach-600x400-1-300x200.webp 300w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-hybrid-approach-600x400-1-768x512.webp 768w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-hybrid-approach-600x400-1-1536x1024.webp 1536w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-hybrid-approach-600x400-1-878x585.webp 878w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-hybrid-approach-600x400-1-400x267.webp 400w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-hybrid-approach-600x400-1.webp 1800w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">Relying on the same model to check the code that it writes is an inherent conflict of interest.&nbsp;The Chief Financial Officer&nbsp;doesn’t&nbsp;audit her company’s financials.&nbsp;We champion independent verification in AppSec: a system of checks and balances to keep any single point of failure from compromising the stack.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="tokenization-savings-is-only-the-start">Tokenization Savings&nbsp;Is Only the Start</h2>



<p class="wp-block-paragraph">Not only are there cost savings to be realized by&nbsp;leveraging&nbsp;a hybrid AppSec strategy, but when issues are addressed earlier in the development lifecycle, the cost&nbsp;to fix them goes down. Way down.&nbsp;&nbsp;<br>&nbsp;<br>In&nbsp;a recent talk I gave,&nbsp;&#8220;<a href="https://checkmarx.com/blog/99-unpatched-what-mythos-gartner-and-a-nine-second-disaster-tell-us-about-the-future-of-appsec/" target="_blank" rel="noreferrer noopener">When Code Secures Itself: The Rise of Agentic AI in Application Security</a>,&#8221; I outlined four control points across the AI development lifecycle and a simple, uncomfortable truth: the cost of fixing a vulnerability rises&nbsp;roughly&nbsp;10x&nbsp;at every stage you wait.&nbsp;<br>&nbsp;<br>Fixing a vulnerability in the IDE is&nbsp;roughly 10x&nbsp;cheaper than in the build pipeline, 100x cheaper than in the AI supply chain, and 1,000x cheaper than in runtime.&nbsp;&nbsp;<br>&nbsp;<br>Yet only one in five developers embed security at the point of code creation, according to the 2,350 AppSec professionals&nbsp;we&nbsp;surveyed for&nbsp;our&nbsp;Future of Application Security Report.&nbsp;<br>&nbsp;<br>More than 80% of AppSec is conducted at defined stages after the code already exists, or worse, reactively once incidents surface.&nbsp;And the later a flaw is found, the more it costs&nbsp;in time, money, and exposure.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="show-me-the-metrics">Show Me the Metrics</h2>



<p class="wp-block-paragraph">An F1 score&nbsp;measures a&nbsp;scanning&nbsp;engine&#8217;s fidelity,&nbsp;how well it&nbsp;finds&nbsp;real vulnerabilities without burying teams in false positives.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="683" src="https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-f1-balanced-600x400-1-1024x683.webp" alt="" class="wp-image-114904" srcset="https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-f1-balanced-600x400-1-1024x683.webp 1024w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-f1-balanced-600x400-1-300x200.webp 300w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-f1-balanced-600x400-1-768x512.webp 768w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-f1-balanced-600x400-1-1536x1024.webp 1536w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-f1-balanced-600x400-1-878x585.webp 878w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-f1-balanced-600x400-1-400x267.webp 400w, https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-f1-balanced-600x400-1.webp 1800w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">In head-to-head testing across seven real production codebases, Checkmarx One’s hybrid engine&nbsp;<a href="https://checkmarx.com/press-releases/checkmarx-one-achieves-industrys-highest-scanning-fidelity-outperforming-both-legacy-tools-and-ai-models/" target="_blank" rel="noreferrer noopener">achieved an F1 score of 0.64</a>&nbsp;– more than three times the&nbsp;industry average of&nbsp;0.20&nbsp;–&nbsp;across competing&nbsp;approaches that Checkmarx evaluated.<br><br>We are building on this momentum by helping AppSec teams address the new challenge of AI-generated code: shifting the focus from discovery and “mass-detection” to “mass remediation” to fix vulnerabilities quickly and consistently, whether&nbsp;newly-created&nbsp;or languishing in the backlog.&nbsp;<br>&nbsp;<br>Our&nbsp;newly-launched&nbsp;agentic experiences&nbsp;–&nbsp;<a href="https://checkmarx.com/product/triage-and-remediation/" target="_blank" rel="noreferrer noopener">Triage Assist,&nbsp;Remediation Assist</a>, and&nbsp;<a href="https://checkmarx.com/product/developer-assist/" target="_blank" rel="noreferrer noopener">Developer Assist</a>&nbsp;–&nbsp;are&nbsp;purpose-built&nbsp;for this moment.<br><br>Triage Assist cuts through vulnerability noise using reachability, exploitability, policy context, and application risk to surface what deserves attention first. Remediation Assist then generates contextual, merge-ready fix recommendations that fit how developers already work.&nbsp;Developer Assist 2.0 is&nbsp;a fully autonomous&nbsp;virtual assistant working&nbsp;alongside&nbsp;developers in the IDE,&nbsp;detecting issues, generating fixes, and iterating until&nbsp;code is clean.<br><br>The result: fewer hours lost to manual analysis, fewer handoffs between AppSec and development, and faster remediation across the ADLC.&nbsp;This&nbsp;drives better&nbsp;credibility for AppSec teams, and more time for developers to do what they do best: build.&nbsp;<br>&nbsp;<br>But knowing how to&nbsp;find and&nbsp;fix vulnerabilities faster only matters if you know what&nbsp;you&#8217;re&nbsp;securing in the first place.&nbsp;That&#8217;s&nbsp;the gap our&nbsp;newly-launched&nbsp;<a href="https://checkmarx.com/press-releases/checkmarx-delivers-complete-ai-asset-visibility-governance-software-supply-chain-closing-shadow-ai-gap/" target="_blank" rel="noreferrer noopener">Checkmarx AI Inventory</a>&nbsp;closes.&nbsp;&nbsp;<br>&nbsp;<br>AI Inventory gives teams continuous, deterministic visibility into every AI&nbsp;component&nbsp;running in their code (like models, agents, MCP servers, SDKs,) and generates an AI-BOM&nbsp;(AI Bill of Materials.)&nbsp;This provides policy controls and audit-ready documentation for every AI&nbsp;component&nbsp;discovered, helping teams manage assets,&nbsp;monitor&nbsp;risk, and stay ahead of emerging compliance&nbsp;requirements.</p>



<h2 class="wp-block-heading article-anchor" id="the-portfolio-approach-to-application-security">The Portfolio Approach to Application Security</h2>



<p class="wp-block-paragraph">The best portfolios&nbsp;don&#8217;t&nbsp;win by picking one great asset. They win by pairing complementary strengths to deliver returns no single position could achieve alone.<br><br>In application security, that means combining the fluency of frontier AI with the certainty of deterministic enforcement.<br><br>Working in balance. Proven by the numbers. Built to scale with whatever comes next.&nbsp;<br><br>That&#8217;s the Checkmarx strategy. Built for today&#8217;s threats. Ready for whatever comes next. <a href="https://checkmarx.com/request-a-demo/?utm_source=httpscheckmarx.comblog&amp;utm_medium=httpscheckmarx.comblog&amp;utm_campaign=composite_scanning" target="_blank" rel="noreferrer noopener">Get a personalized AppSec demo from Checkmarx</a> today.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="learn-more-about-whats-new-from-checkmarx">Learn More About&nbsp;What’s&nbsp;New from&nbsp;Checkmarx</h2>



<p class="wp-block-paragraph"><a href="https://checkmarx.com/product/triage-and-remediation/?utm_source=httpscheckmarx.comblog&amp;utm_medium=httpscheckmarx.comblog&amp;utm_campaign=composite_scanning" target="_blank" rel="noreferrer noopener">Checkmarx Triage Assist</a>&nbsp;&nbsp;<br><a href="https://checkmarx.com/product/triage-and-remediation/?utm_source=httpscheckmarx.comblog&amp;utm_medium=httpscheckmarx.comblog&amp;utm_campaign=composite_scanning" target="_blank" rel="noreferrer noopener">Checkmarx Remediation Assist</a>&nbsp;&nbsp;<br><a href="https://checkmarx.com/product/developer-assist/?utm_source=httpscheckmarx.comblog&amp;utm_medium=httpscheckmarx.comblog&amp;utm_campaign=composite_scanning" target="_blank" rel="noreferrer noopener">Checkmarx Developer Assist</a>&nbsp;<br><a href="https://checkmarx.com/press-releases/checkmarx-delivers-complete-ai-asset-visibility-governance-software-supply-chain-closing-shadow-ai-gap/?utm_source=httpscheckmarx.comblog&amp;utm_medium=httpscheckmarx.comblog&amp;utm_campaign=composite_scanning" target="_blank" rel="noreferrer noopener">Checkmarx AI Inventory</a>&nbsp;<br>&nbsp;<br>Download the&nbsp;<a href="https://checkmarx.com/foa-report/?utm_source=httpscheckmarx.comblog&amp;utm_medium=httpscheckmarx.comblog&amp;utm_campaign=composite_scanning" target="_blank" rel="noreferrer noopener">2026 Checkmarx Future of Application Security Report</a></p>]]></content:encoded>
					
		
		
		
		<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-hybrid-approach-600x400-1-150x150.webp" />
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-hybrid-approach-600x400-1.webp" medium="image">
			<media:title type="html">checkmarx-hybrid-approach-600&#215;400</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-hybrid-approach-600x400-1-150x150.webp" />
		</media:content>
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-f1-balanced-600x400-1.webp" medium="image">
			<media:title type="html">checkmarx-f1-balanced-600&#215;400</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/07/checkmarx-f1-balanced-600x400-1-150x150.webp" />
		</media:content>
	</item>
		<item>
		<title>Zombie CVEs: Put to Rest by Humans, Dug Back Up by AI Agents </title>
		<link>https://checkmarx.com/blog/zombie-cves-put-to-rest-by-humans-dug-back-up-by-ai-agents/</link>
		
		<dc:creator><![CDATA[Eran Kinsbruner]]></dc:creator>
		<pubDate>Sun, 26 Jul 2026 11:47:28 +0000</pubDate>
				<category><![CDATA[AI & LLM Tools in Application Security]]></category>
		<category><![CDATA[Application Security Trends & Insights]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[ADLC]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[security research]]></category>
		<category><![CDATA[vibe coding]]></category>
		<guid isPermaLink="false">https://staging.checkmarx.com/?p=114817</guid>

					<description><![CDATA[New research: 65–75% of frontier AI agents&#8217; working patches resurrect vulnerabilities that were already found, fixed, and buried.&#160; In 2023, a path traversal vulnerability in Starlette,&#160;one of Python&#8217;s most popular web frameworks&#160;&#160;&#8211;&#160;was found,&#160;disclosed&#160;as CVE-2023-29159, and fixed. Case closed. The bug was dead and buried, like hundreds of thousands of CVEs before it: discovered by researchers, [&#8230;]]]></description>
										<content:encoded><![CDATA[<h2 class="wp-block-heading article-anchor" id="new-research-65-75-of-frontier-ai-agents-working-patches-resurrect-vulnerabilities-that-were-already-found-fixed-and-buried">New research: 65–75% of frontier AI agents&#8217; working patches resurrect vulnerabilities that were already found, fixed, and buried.&nbsp;</h2>



<p class="wp-block-paragraph">In 2023, a path traversal vulnerability in Starlette,&nbsp;one of Python&#8217;s most popular web frameworks&nbsp;&nbsp;&#8211;&nbsp;was found,&nbsp;disclosed&nbsp;as CVE-2023-29159, and fixed. Case closed. The bug was dead and buried, like hundreds of thousands of CVEs before it: discovered by researchers, patched by maintainers, laid to rest by the security community&#8217;s accumulated, painstaking work.&nbsp;</p>



<p class="wp-block-paragraph">In 2026, a frontier AI coding agent rebuilt that same feature. The vulnerability walked right back out of the ground.&nbsp;And it&nbsp;wasn&#8217;t&nbsp;a one-off.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">That is&nbsp;the&nbsp;one of the&nbsp;central findings&nbsp;of new independent research&nbsp;Checkmarx&nbsp;commissioned from&nbsp;<a href="https://linkedin.com/in/ilyakabanov/" target="_blank" rel="noreferrer noopener">Ilya Kabanov</a>, CEO of The Weather Report — the first study to measure, generation over generation, whether AI code is getting&nbsp;<em>safer</em>&nbsp;as it gets&nbsp;<em>better</em>.&nbsp;</p>



<p class="wp-block-paragraph">The answer&nbsp;is not. In fact, ironically,&nbsp;it&#8217;s&nbsp;quite the opposite.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Security, it seems, is simply not a benchmark in the AI agents&#8217; arms&nbsp;race&nbsp;toward ever-greater capability. And the result is AI output that, in the way that matters, is getting&nbsp;<strong><em>unsafer</em></strong>: a generation ago, most insecure attempts&nbsp;didn&#8217;t&nbsp;even work, so they never shipped. Now&nbsp;nearly everything&nbsp;works, everything ships, and according to the research, 65–75% of it trips over the same old CVEs the industry already resolved, dragging them back into production.&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://checkmarx.com/capability-without-security-measuring-functionality-security-gap-ai-generated-code/?utm_source=ln_email&amp;utm_medium=linkedin&amp;utm_campaign=linkedin_newsletter"><em>Read the Full Research</em></a></p>



<h2 class="wp-block-heading article-anchor" id="the-graveyard-test">The graveyard test&nbsp;</h2>



<p class="wp-block-paragraph">Rather than invent yet another benchmark, the study re-ran two established ones on today&#8217;s frontier models: Claude Opus 4.8, GPT-5.5, Gemini 3.1 Pro, and Gemini 3.5 Flash, each in its own native agent CLI.&nbsp;</p>



<p class="wp-block-paragraph">The tougher of the two,&nbsp;SusViBes, is effectively a graveyard: 200 real feature tasks inside large open-source repositories, each one built around a real vulnerability that a human already found,&nbsp;disclosed, and fixed. The agent is asked to build the feature. The question is whether it independently arrives at the protection the human fix contained,&nbsp;or digs the old bug back up.&nbsp;</p>



<p class="wp-block-paragraph">The results:&nbsp;</p>



<ul class="wp-block-list">
<li>
<strong>Functional success surged to 83–95%</strong> across the cohort — up from 44–61% a single model generation ago. Writing working code is nearly solved. </li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Secure-and-functional success reached only 24–36%.</strong> Across models, <strong>65–75% of working patches resurrected the vulnerability</strong> the humans had put to rest. </li>
</ul>



<ul class="wp-block-list">
<li>The functional–security gap <strong>widened</strong> — in the Claude lineage, from 38 points to 63 points in one generation. <br><br>
</li>
</ul>



<figure class="wp-block-image size-full"><img decoding="async" width="901" height="783" src="https://checkmarx.com/wp-content/uploads/2026/07/image-1.webp" alt="" class="wp-image-114819" srcset="https://checkmarx.com/wp-content/uploads/2026/07/image-1.webp 901w, https://checkmarx.com/wp-content/uploads/2026/07/image-1-300x261.webp 300w, https://checkmarx.com/wp-content/uploads/2026/07/image-1-768x667.webp 768w, https://checkmarx.com/wp-content/uploads/2026/07/image-1-673x585.webp 673w, https://checkmarx.com/wp-content/uploads/2026/07/image-1-345x300.webp 345w" sizes="(max-width: 901px) 100vw, 901px" /></figure>



<h2 class="wp-block-heading article-anchor" id="the-models-know-but-still-ignore">The&nbsp;models&nbsp;know, but still ignore&nbsp;</h2>



<p class="wp-block-paragraph">Here&#8217;s&nbsp;what makes this more&nbsp;concerning&nbsp;than a knowledge gap. These CVEs are public. Their advisories, their fix commits, their write-ups are all over the training data. The models have, in all likelihood,&nbsp;<em>seen the fixes,&nbsp;</em>and they resurrect the bugs anyway.&nbsp;</p>



<p class="wp-block-paragraph">The study&#8217;s failure audit makes this concrete. In the analyzed failures, agents named the exact required defense&nbsp;<strong>in their own threat model,&nbsp;</strong>then shipped the vulnerable code&nbsp;anyway.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="just-prompt-it-to-be-secure-doesnt-work">&#8220;Just prompt it to be secure&#8221; doesn&#8217;t work&nbsp;</h2>



<p class="wp-block-paragraph">The study tested a ladder of increasingly expensive interventions:&nbsp;</p>



<ul class="wp-block-list">
<li>A one-line <strong>&#8220;follow best security practices&#8221; reminder</strong> added just 1–8 points of security, depending on the model. </li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Maxing out reasoning effort</strong> added zero security in a targeted spot-check — and halved the number of working patches. </li>
</ul>



<ul class="wp-block-list">
<li>A dedicated <strong>threat-modeling step</strong> before coding lifted cumulative secure-and-functional success to 43–49%, at roughly 2x the token cost of writing the code alone. </li>
</ul>



<ul class="wp-block-list">
<li>Adding a <strong>post-hoc security review</strong> reached 47–56% — at roughly 2.5x the token cost. </li>
</ul>



<p class="wp-block-paragraph">Even&nbsp;paying&nbsp;the model multiples of the original task to secure its own output,&nbsp;roughly half&nbsp;the tasks still shipped insecure.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="what-this-means-for-your-pipeline">What this means for your pipeline&nbsp;</h2>



<p class="wp-block-paragraph">One scoping note the researchers are careful about, and so are we: these benchmark tasks were selected because the vulnerability is the&nbsp;<em>natural</em>&nbsp;way to build the feature. On generic everyday code, the resurrection rate is&nbsp;likely lower. But that scoping is cold comfort:&nbsp;real codebases are full of exactly these features, because that&#8217;s where the CVEs came from in the first place.&nbsp;</p>



<p class="wp-block-paragraph">And this isn&#8217;t confined to the lab. Checkmarx&#8217;s own<a href="https://checkmarx.com/foa-report/"> 2026 Future of AppSec report</a> &#8211; a survey of 2,350 CISOs, AppSec managers, and developers across 14 countries – supports these findings:  </p>



<ul class="wp-block-list">
<li> 70% of developers say AI code generation created more vulnerabilities in their code in 2025.  </li>
</ul>



<ul class="wp-block-list">
<li>AI-generated code already contributed to 25% of breaches, making it a top-four breach vector in its first year of tracking.  </li>
</ul>



<ul class="wp-block-list">
<li>And the dose-response curve is unmistakable: organizations where 81–100% of code is AI-generated ship vulnerable code at 3.4x the rate of those at 1–20%.  </li>
</ul>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">With nearly half (49%) of production code now AI-generated, this isn&#8217;t one zombie wandering out of a grave – it’s a horde of them. </p>



<h3 class="wp-block-heading">
<strong>Read the full research</strong>&nbsp;</h3>



<p class="wp-block-paragraph">The complete paper,&nbsp;including the per-CWE breakdown, the intervention cost analysis, and the full failure-mode taxonomy,&nbsp;is available here:&nbsp;</p>



<p class="wp-block-paragraph"><a href="https://checkmarx.com/capability-without-security-measuring-functionality-security-gap-ai-generated-code/" target="_blank" rel="noreferrer noopener"><em>Read the Full Research</em></a> </p>



<p class="wp-block-paragraph"></p>]]></content:encoded>
					
		
		
		
		<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/07/image-1-150x150.webp" />
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/07/image-1.webp" medium="image">
			<media:title type="html">image (1)</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/07/image-1-150x150.webp" />
		</media:content>
	</item>
		<item>
		<title>Checkmarx One for Government Achieves FedRAMP Moderate Certification</title>
		<link>https://checkmarx.com/blog/checkmarx-one-for-government-achieves-fedramp-moderate-certification/</link>
		
		<dc:creator><![CDATA[Kevin Hayes]]></dc:creator>
		<pubDate>Sun, 26 Jul 2026 06:24:46 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Checkmarx Product News, Use Cases & Guides]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI generated code]]></category>
		<category><![CDATA[AppSec]]></category>
		<category><![CDATA[Federal Government]]></category>
		<category><![CDATA[US Government]]></category>
		<guid isPermaLink="false">https://staging.checkmarx.com/?p=114808</guid>

					<description><![CDATA[A new standard for secure-by-design in the public sector.]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Federal agencies have a new option for securing the software behind their most critical systems.</p>



<p class="wp-block-paragraph"><a href="https://checkmarx.com/resources/checkmarx-one-for-government/">Checkmarx One for Government (CxG)</a> has officially achieved <strong><a href="https://checkmarx.com/press-releases/checkmarx-one-for-government-application-security-platform-achieves-fedramp-ready-status-at-the-high-impact-level/">FedRAMP Certified status at the Moderate Impact Level</a> </strong>(Class C, Rev5), a milestone that gives U.S. government agencies streamlined, compliant access to the industry&#8217;s most comprehensive application security platform.</p>



<p class="wp-block-paragraph">The certification comes as agencies face growing pressure to modernize their systems, secure increasingly complex software supply chains, adopt AI responsibly, and meet evolving federal requirements without adding operational burden.</p>



<h2 class="wp-block-heading article-anchor" id="federal-systems-demand-a-higher-standard">Federal Systems Demand a Higher Standard</h2>



<p class="wp-block-paragraph">Federal information systems carry an outsized burden. They hold Controlled Unclassified Information, power services that citizens depend on, and increasingly serve as the connective tissue between agencies, contractors, and critical infrastructure.</p>



<p class="wp-block-paragraph">A vulnerability introduced at the code level doesn&#8217;t stay contained; it propagates into production systems that the public relies on every day.</p>



<p class="wp-block-paragraph">FedRAMP exists precisely because of that reality. The Moderate baseline requires roughly 323 security controls across 17 control families, covering everything from access control to system and communications protection. Achieving that bar isn&#8217;t a checkbox exercise; it&#8217;s a rigorous, independently assessed validation that a platform is built to protect the confidentiality, integrity, and availability of federal data.</p>



<p class="wp-block-paragraph">For Checkmarx, that data integrity isn&#8217;t just a compliance requirement, it&#8217;s foundational. An AppSec platform is only as trustworthy as the assurances it can make about the code, dependencies, and infrastructure it scans.</p>



<p class="wp-block-paragraph">Achieving its FedRAMP Moderate certification means Checkmarx One for Government has been independently vetted to meet that bar for the U.S. government&#8217;s most sensitive unclassified workloads. Checkmarx is also pursuing the FedRAMP High Impact Level for its most mission-critical use cases.</p>



<h2 class="wp-block-heading article-anchor" id="where-modern-risk-actually-enters">Where Modern Risk Actually Enters</h2>



<p class="wp-block-paragraph">Protecting the integrity of federal systems requires more than securing custom code. Agencies also depend on vast ecosystems of open-source libraries and third-party components, creating additional paths for malicious code to enter trusted software.</p>



<p class="wp-block-paragraph">Malicious packages are legitimate-looking software components &#8211; often libraries or modules &#8211; that have been intentionally crafted to perform harmful actions when installed or executed. Checkmarx has collected the largest malicious package database in the industry, over 400,000, helping organizations stay ahead of cyber threats and safeguard agencies from malware, spyware, and other threats.</p>



<p class="wp-block-paragraph">Bad actors also target organizations by exploiting vulnerabilities in their trusted vendors or suppliers. Malicious code that is unnoticed may inadvertently be included in packages or updates from outside developers. These attacks can spread rapidly, affecting numerous users and organizations that rely on the compromised software, resulting in widespread damage and disruption. Notable examples include <a href="https://securityweek.com/solarwinds-makes-third-attempt-at-patching-exploited-vulnerability/https://orx.org/resource/moveit-transfer-data-breacheshttps://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise">SolarWinds</a>, MOVEit, and 3CX Software, which involved the distribution of malicious code through legitimate software or updates.</p>



<h2 class="wp-block-heading article-anchor" id="ai-is-changing-the-math">AI Is Changing the Math</h2>



<p class="wp-block-paragraph">AI-assisted development is raising the stakes even further.</p>



<p class="wp-block-paragraph">AI has rapidly reshaped how software is built, <a href="https://checkmarx.com/press-releases/ninety-nine-percent-of-development-teams-use-ai-for-code-generation-while-eighty-percent-are-worried-about-security-threats-stemming-from-developers-using-ai-checkmarx-study-reveals/">with 99% of development teams using it for code generation</a>. Developers across government and industry are leaning on AI coding assistants to move faster, and the productivity gains are real.</p>



<p class="wp-block-paragraph">But so is the risk: AI-generated code is being shipped at a pace that often outstrips organizations&#8217; ability to review it, and a growing body of evidence shows that a large share of organizations using AI coding tools are shipping vulnerable code as a result.</p>



<p class="wp-block-paragraph">That shift changes what agencies need from application security in two important ways.</p>



<p class="wp-block-paragraph">First, the sheer volume of code being produced means scanning has to happen continuously and automatically – human-speed code review was never designed for AI-speed code generation.</p>



<p class="wp-block-paragraph">Second, the kinds of risk introduced by AI-generated code aren&#8217;t always the same patterns that legacy static analysis engines were tuned to catch, which means the depth and currency of an AppSec vendor&#8217;s detection engines matters more than ever.</p>



<p class="wp-block-paragraph">Federal agencies need security that can leverage AI to operate at the speed of modern development while also distinguishing meaningful, exploitable risk from noise.</p>



<h2 class="wp-block-heading article-anchor" id="code-to-cloud-the-need-for-unified-appsec">Code to Cloud: The Need for Unified AppSec</h2>



<p class="wp-block-paragraph">These changes make fragmented application security increasingly difficult to sustain.</p>



<p class="wp-block-paragraph">Agencies that stitch together disconnected scanners for code, dependencies, containers, and cloud infrastructure end up with fragmented risk visibility and duplicated effort.</p>



<p class="wp-block-paragraph">The challenge is no longer simply finding vulnerabilities. It is understanding how risks relate to one another, determining which findings matter most, and helping teams act before those risks reach production.</p>



<p class="wp-block-paragraph">That requires a unified platform spanning the full software development lifecycle, from the first line of code through deployment. It must continuously update as threats evolve, apply consistent security policies across environments, and give developers and security teams a shared view of risk.</p>



<h2 class="wp-block-heading article-anchor" id="why-saas-delivery-is-now-an-economic-necessity">Why SaaS Delivery Is Now an Economic Necessity</h2>



<p class="wp-block-paragraph">Agencies must meet these requirements while operating under growing fiscal and staffing constraints. Agencies are being asked to do more – modernize legacy systems, meet Zero Trust mandates, comply with executive orders on secure software development – without adding more operational burden. In that environment, SaaS delivery isn&#8217;t just a convenience; it&#8217;s an economic necessity.</p>



<p class="wp-block-paragraph">A FedRAMP-certified SaaS platform eliminates the need for agencies to stand up and maintain their own security infrastructure, reduces the redundant, agency-by-agency assessment cycles that FedRAMP was designed to eliminate in the first place, and shifts the burden of patching, scaling, and continuous monitoring to the vendor. That &#8220;do once, use many times&#8221; model is estimated to save significant time, cost, and staff effort across government.</p>



<p class="wp-block-paragraph">For AppSec specifically, this matters. The tooling must evolve continuously alongside new development practices, vulnerabilities, attack techniques, and software ecosystems. Delivering those capabilities as an updated service is often more sustainable than maintaining a static, self-hosted deployment – freeing agency teams to focus on reducing risk, not managing infrastructure.</p>



<h2 class="wp-block-heading article-anchor" id="the-breadth-federal-agencies-need">The Breadth Federal Agencies Need</h2>



<p class="wp-block-paragraph">Checkmarx One for Government is built for this environment. The platform brings application security capabilities together across the full development lifecycle, helping agencies reduce tool sprawl and manage risk through one consistent, FedRAMP-certified environment. Its capabilities include:</p>



<ul class="wp-block-list">
<li>
<strong>SAST (Static Application Security Testing)</strong>: identifying vulnerabilities directly in custom source code</li>



<li>
<strong>SCA (Software Composition Analysis)</strong>: securing open-source dependencies and managing license risk</li>



<li>
<strong>Malicious Package Detection</strong>: flagging compromised or intentionally malicious open-source packages before they reach production</li>



<li>
<strong>IaC Security</strong>: scanning Infrastructure as Code templates for misconfigurations before they&#8217;re deployed</li>



<li>
<strong>Container Security</strong>: securing container images and runtime environments</li>



<li>
<strong>ASPM (Application Security Posture Management)</strong>: correlating findings across all of the above into a unified, risk-prioritized view</li>



<li>
<strong>DAST (Dynamic Application Security Testing)</strong>: coming soon to the platform, extending coverage to runtime behavior and closing the loop from code to cloud.</li>
</ul>



<p class="wp-block-paragraph">Together, they give federal agencies consistent visibility and control across custom code, open-source software, infrastructure, containers, and deployed applications.</p>



<h2 class="wp-block-heading article-anchor" id="find-vulnerabilities-before-they-happen">Find Vulnerabilities Before They Happen</h2>



<p class="wp-block-paragraph">But visibility alone does not reduce risk. Agencies also need a practical way to understand which findings matter and help development teams address them before they reach production.</p>



<p class="wp-block-paragraph">That is where Application Security Posture Management (ASPM) becomes especially important. ASPM brings findings from across the application lifecycle into one unified, risk-prioritized view, helping security teams understand which vulnerabilities matter most, identify coverage gaps, track remediation progress, and maintain a clearer picture of their overall security posture.</p>



<p class="wp-block-paragraph">Rather than treating every finding as equally urgent, agencies can use that context to direct limited resources toward the vulnerabilities most likely to create meaningful exposure. This supports more proactive vulnerability management, stronger compliance, and better coordination between security and development teams.</p>



<p class="wp-block-paragraph">ASPM also helps translate that intelligence into prioritized tasks within the tools developers already use, allowing them to address issues closer to the moment code is created without repeatedly leaving their workflows to interpret disconnected security reports.</p>



<p class="wp-block-paragraph">For federal agencies, that matters. Security teams can apply consistent policies from development through deployment, reduce the number of vendors and consoles they manage, and turn fragmented findings into coordinated remediation.</p>



<p class="wp-block-paragraph">This code-to-cloud approach connects broad security coverage with the context and workflows teams need to act on it.</p>



<h2 class="wp-block-heading article-anchor" id="what-this-means-for-federal-agencies">What This Means for Federal Agencies</h2>



<p class="wp-block-paragraph">A FedRAMP-certified platform strengthens cybersecurity by standardizing environments, enabling continuous monitoring, and automating processes, freeing resources and helping security teams stay ahead of evolving threats.</p>



<p class="wp-block-paragraph">With Checkmarx’s FedRAMP Moderate certification established, federal agencies now have a faster, lower-friction path to deploying Checkmarx One for Government: a single, comprehensive, cloud-native AppSec platform, independently assessed against a rigorous federal security baseline, covering the full software development lifecycle.</p>



<p class="wp-block-paragraph">They can secure applications from code to cloud while reducing infrastructure overhead, consolidating disconnected tools, and giving development and security teams a shared view of risk.</p>



<p class="wp-block-paragraph">The platform is also backed by more than two decades of application security experience. Checkmarx helped define the SAST category and pioneered developer-centric approaches to finding and fixing vulnerabilities in custom code.</p>



<p class="wp-block-paragraph">That history matters in a federal environment. Agencies need confidence that the vendor securing their software supply chain can adapt to changing compliance frameworks, development models, threat patterns, and mission requirements.</p>



<p class="wp-block-paragraph">As agencies continue to navigate secure software development mandates, Zero Trust requirements, and constrained budgets, that combination of breadth, maturity, and compliance is becoming less of a nice-to-have and more of a baseline expectation – and <a href="https://checkmarx.com/company/public-sector/">Checkmarx One for Government </a>is built to meet it.</p>]]></content:encoded>
					
		
		
		
	</item>
		<item>
		<title>You&#8217;re Securing Your Code. But Are You Securing the AI Inside It? </title>
		<link>https://checkmarx.com/blog/youre-securing-your-code-but-are-you-securing-the-ai-inside-it/</link>
		
		<dc:creator><![CDATA[Emma Datny]]></dc:creator>
		<pubDate>Wed, 24 Jun 2026 09:02:30 +0000</pubDate>
				<category><![CDATA[AI & LLM Tools in Application Security]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Supply Chain Security]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI-Generated Code]]></category>
		<category><![CDATA[Open-Source Supply Chain]]></category>
		<category><![CDATA[shadow ai]]></category>
		<category><![CDATA[Software Supply Chain Security]]></category>
		<guid isPermaLink="false">https://staging.checkmarx.com/?p=113527</guid>

					<description><![CDATA[Modern applications&#160;don&#8217;t&#160;just run on code anymore. They run on models, agents, embeddings, datasets, and&#160;autonomous tools like MCP servers. Developers are pulling pre-trained LLMs from Hugging Face, integrating open-source agent frameworks, and wiring up AI pipelines faster than security teams can track them.&#160;Unlike&#160;rogue&#160;npm&#160;packages, these components&#160;don’t&#160;show up cleanly in your existing dependency graph.&#160; For AppSec teams, this [&#8230;]]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Modern applications&nbsp;don&#8217;t&nbsp;just run on code anymore. They run on models, agents, embeddings, datasets, and&nbsp;autonomous tools like MCP servers. Developers are pulling pre-trained LLMs from Hugging Face, integrating open-source agent frameworks, and wiring up AI pipelines faster than security teams can track them.&nbsp;Unlike&nbsp;rogue&nbsp;npm&nbsp;packages, these components&nbsp;don’t&nbsp;show up cleanly in your existing dependency graph.&nbsp;</p>



<p class="wp-block-paragraph">For AppSec teams, this creates&nbsp;two&nbsp;core&nbsp;problems:&nbsp;&nbsp;volume and visibility.&nbsp;</p>



<ul class="wp-block-list">
<li>
<strong>Volume</strong>. AI&nbsp;is&nbsp;speeding up&nbsp;development output,&nbsp;but&nbsp;AI-generated&nbsp;code&nbsp;produces&nbsp;<a href="https://coderabbit.ai/blog/state-of-ai-vs-human-code-generation-report" target="_blank" rel="noreferrer noopener"><strong>1.7x more vulnerabilities</strong></a><strong>&nbsp;than human-written code</strong>. More code means more findings per scan, growing backlogs, and a security team&nbsp;forced&nbsp;to&nbsp;choose between rigor and velocity.&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Visibility</strong>. The AI components&nbsp;<em>powering</em>&nbsp;development&nbsp;–&nbsp;models, datasets, MCP servers, agent frameworks, and prompt libraries&nbsp;–&nbsp;are entering codebases without formal review&nbsp;or&nbsp;governance.&nbsp;Most organizations&nbsp;don’t&nbsp;know which AI assets&nbsp;they’re&nbsp;running, where&nbsp;they’re&nbsp;embedded, or what risk they carry. That gap has consequences:&nbsp;over&nbsp;<a href="https://deepstrike.io/blog/supply-chain-attack-statistics-2025" target="_blank" rel="noreferrer noopener"><strong>75% of organizations</strong></a><strong>&nbsp;have experienced a software supply chain attack in the last year,&nbsp;</strong>because every new&nbsp;AI&nbsp;component&nbsp;introduces&nbsp;a&nbsp;potential attack path.&nbsp;&nbsp;</li>
</ul>



<p class="wp-block-paragraph">As development speeds up,&nbsp;these unmanaged AI components accumulate faster than security teams can evaluate them, pushing AppSec&nbsp;programs&nbsp;beyond the limits they were designed for.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="the-shadow-ai-problem-in-your-software-supply-chain">
<strong>The Shadow AI Problem in Your Software Supply Chain</strong>&nbsp;</h2>



<p class="wp-block-paragraph">This gap&nbsp;exists&nbsp;because&nbsp;traditional AppSec&nbsp;was built for a world where the building blocks of software were code, libraries, and configurations. That world still exists,&nbsp;but&nbsp;now&nbsp;it&nbsp;runs alongside a parallel supply chain of AI components that most tools&nbsp;can’t&nbsp;see.&nbsp;</p>



<p class="wp-block-paragraph">Today, a&nbsp;typical AI-enabled application might include&nbsp;a&nbsp;fine-tuned LLM pulled from a public model hub,&nbsp;an agent framework that invokes external tools autonomously, an MCP server connecting the app to live data sources,&nbsp;embeddings generated from sensitive internal documents,&nbsp;and system prompts hardcoded in config files.&nbsp;</p>



<p class="wp-block-paragraph">None of these appear in a standard SBOM&nbsp;and only&nbsp;a&nbsp;few&nbsp;get flagged in a standard code scan.&nbsp;Each&nbsp;introduces&nbsp;distinct&nbsp;risks,&nbsp;from model poisoning and unverified weights to unsafe autonomous tool invocation and exposed datasets.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Three forces are&nbsp;making&nbsp;this worse:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>
<strong>Visibility is breaking down.</strong>&nbsp;Most organizations&nbsp;can’t&nbsp;fully inventory which AI assets are in use, where&nbsp;they&nbsp;live, or what risk they introduce.&nbsp;It&nbsp;mirrors&nbsp;the&nbsp;early days&nbsp;of open-source governance, but with faster adoption and&nbsp;higher-stakes components.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>The toolchain has expanded.</strong>&nbsp;Every model, dataset, MCP server, API, and open-source dependency creates a&nbsp;potential&nbsp;attack path.&nbsp;This growing web of dependencies increases both complexity and&nbsp;exposure.&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Shadow AI is&nbsp;the new shadow IT.</strong>&nbsp;Just as shadow IT created governance blind spots in the cloud era, developers and DevOps teams are&nbsp;adopting AI tools, models, and plugins without formal security review,&nbsp;often because&nbsp;no<strong>&nbsp;</strong>review process&nbsp;exists&nbsp;yet.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The attack surface&nbsp;isn’t&nbsp;theoretical.&nbsp;The EU&nbsp;AI Act, ISO 42001, and NIST AI RMF&nbsp;now treat&nbsp;<a href="https://info.checkmarx.com/managing-cyber-risks" target="_blank" rel="noreferrer noopener">AI&nbsp;component&nbsp;governance as a compliance requirement</a>. If your AppSec program&nbsp;can’t&nbsp;answer&nbsp;<em>what AI is in&nbsp;your software</em>,&nbsp;<em>where&nbsp;it&nbsp;is</em>, and&nbsp;<em>what&nbsp;it&nbsp;does</em>,&nbsp;you have a gap.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="why-existing-approaches-fall-short">
<strong>Why Existing Approaches Fall Short</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Several vendors have taken a swing at AI security, but&nbsp;the results&nbsp;don’t&nbsp;quite land for AppSec teams.&nbsp;&nbsp;</p>



<ul class="wp-block-list">
<li>
<strong>Cloud-posture&nbsp;tools</strong>&nbsp;that<strong>&nbsp;</strong>view<strong>&nbsp;</strong>AI through the lens of services and infrastructure exposure. These tools are&nbsp;useful, but they miss&nbsp;what’s&nbsp;embedded directly in code and configuration.&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Artifact-level&nbsp;scanners</strong>&nbsp;review&nbsp;model files for malicious payloads, but&nbsp;don’t&nbsp;provide&nbsp;visibility into how those models are wired into your applications in the first place.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>SCA extensions</strong>&nbsp;that<strong>&nbsp;</strong>identify&nbsp;open-source LLM dependencies in package manifests, but&nbsp;don’t&nbsp;understand&nbsp;agent frameworks, MCP servers, embedded prompts, or dataset references.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Most importantly,&nbsp;tools that rely on AI&nbsp;inference&nbsp;to detect AI&nbsp;introduce&nbsp;the&nbsp;exact&nbsp;kind of non-determinism that&nbsp;worries&nbsp;auditors. If your compliance report is&nbsp;exclusively&nbsp;based on probabilistic detection, it&nbsp;isn’t&nbsp;audit-ready.&nbsp;</p>



<p class="wp-block-paragraph">To close this gap, you need a fundamentally different approach to discovery.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="deterministic-discovery-seeing-whats-actually-there">
<strong>Deterministic Discovery: Seeing What&#8217;s Actually There</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Checkmarx&nbsp;AI Supply Chain Security takes a different approach: code-first, deterministic detection&nbsp;with high-fidelity scanning. Instead of inferring the presence of AI assets, it reads them directly from imports, manifests, file paths, and configuration&nbsp;–&nbsp;the same signals a developer would&nbsp;traditionally&nbsp;follow&nbsp;to understand what a codebase depends on.&nbsp;</p>



<p class="wp-block-paragraph">This means:&nbsp;</p>



<ul class="wp-block-list">
<li>
<strong>LLMs and model references</strong>&nbsp;are&nbsp;identified&nbsp;by their identifiers in code and config, not guessed from patterns&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Agent frameworks</strong>&nbsp;are detected from imports and initialization code&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>MCP servers</strong>&nbsp;are discovered from configuration and integration points&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Datasets and embeddings</strong>&nbsp;are traced from references in source and manifests&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>System prompts</strong>&nbsp;are surfaced from hardcoded strings and config files&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The result is a complete, auditable AI asset inventory,&nbsp;not a probabilistic best guess. Every finding can be traced back to a specific line of code or configuration entry, which matters when&nbsp;you’re&nbsp;presenting results to a compliance auditor or explaining a finding to a developer.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="risk-assessment-built-for-ai-specific-threats">
<strong>Risk Assessment Built for AI-Specific Threats</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Visibility&nbsp;helps&nbsp;close the gap, but it&nbsp;doesn’t&nbsp;solve the volume problem.&nbsp;More assets mean more potential risks, more findings, and more decisions – now extending across an entirely new&nbsp;class of components.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Once you know what&nbsp;AI assets exist, you&nbsp;still&nbsp;need to understand what risks they&nbsp;introduce&nbsp;and how to&nbsp;address&nbsp;them&nbsp;at scale.&nbsp;</p>



<p class="wp-block-paragraph">Checkmarx&nbsp;AI Supply Chain Security&nbsp;assesses AI-specific supply chain risks that traditional AppSec tools&nbsp;weren’t&nbsp;built to find, including:&nbsp;</p>



<ul class="wp-block-list">
<li>
<strong>Model poisoning and unverified weights</strong>: Models pulled from public sources without integrity verification can carry malicious payloads or backdoors introduced during training. The LLM Security scanner&nbsp;identifies&nbsp;ML artifacts&nbsp;<strong>(</strong>PyTorch&nbsp;files, GGUF, H5, and others<strong>)&nbsp;</strong>and evaluates them for deserialization and execution risks.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Unpinned&nbsp;model versions</strong>:&nbsp;Floating model references&nbsp;(the AI equivalent of * in a package manifest)&nbsp;let upstream updates silently change&nbsp;your application&#8217;s&nbsp;behavior. Version pinning is enforced as a policy requirement.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Unsafe autonomous agents</strong>: Agents that invoke external tools without proper scope constraints create execution risks that are unique to AI systems. These are surfaced and assessed as part of the asset inventory.&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Exposed datasets and embeddings</strong>: Datasets used for fine-tuning or RAG pipelines can expose sensitive internal information if&nbsp;they&#8217;re&nbsp;not properly scoped. Dataset references are tracked as first-class assets with their own risk profiles.&nbsp;&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Dataset exposure and license violations</strong>: Open-source models and datasets carry licensing obligations that differ significantly from traditional software licenses. AI asset metadata includes license information, enabling policy enforcement before non-compliant components ship.&nbsp;</li>
</ul>



<div style="position: relative; width: 100%; padding-bottom: 56.25%; height: 0;">
  <iframe src="https://www.youtube.com/embed/44G0Wyj5Ip4?si=E4LRQCXsWKBJGyxV" title="YouTube video player" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%;" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen>
  </iframe>
</div>



<h2 class="wp-block-heading article-anchor" id="the-same-workflows-extended-to-cover-ai">
<strong>The Same Workflows. Extended&nbsp;To Cover AI.</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Adding a new security tool&nbsp;usually&nbsp;means adding friction: a new platform to learn, a new set of alerts to triage, a new reporting workflow to&nbsp;maintain&nbsp;in parallel with everything else.&nbsp;This is where AppSec integration matters.&nbsp;</p>



<p class="wp-block-paragraph">Checkmarx&nbsp;AI Supply&nbsp;Chain Security is built&nbsp;directly&nbsp;into&nbsp;Checkmarx&nbsp;One,&nbsp;the same platform where&nbsp;you’re&nbsp;already managing vulnerabilities, running SAST and SCA, enforcing policies, and generating compliance reports. There is no separate product&nbsp;or parallel workflow to manage.&nbsp;</p>



<p class="wp-block-paragraph">In practice, that means:&nbsp;</p>



<ul class="wp-block-list">
<li>
<strong>AI&nbsp;components&nbsp;appear&nbsp;alongside traditional findings</strong>&nbsp;in the same dashboards, with the same triage workflows.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Policy enforcement happens in pull requests and CI/CD</strong>, the same way you gate on open-source vulnerabilities or SAST findings today. You can block unapproved models, flag unsafe agents, or require version pinning without writing custom automation.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<a href="https://checkmarx.com/ai-bom/" target="_blank" rel="noreferrer noopener"><strong>AI-BOM generation</strong></a><strong>&nbsp;</strong>means that&nbsp;AI assets appear in the same Bill of Materials as your OSS dependencies, with origins, licenses, dependencies, and risk metadata attached.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>ASPM workflows</strong>&nbsp;including&nbsp;risk orchestration, analytics, dashboards,&nbsp;extend naturally to cover AI components without separate instrumentation.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>API and CLI support</strong>&nbsp;lets<strong>&nbsp;</strong>AI scanning&nbsp;drop&nbsp;into existing pipeline automation without new integrations.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">The goal is accountability without friction.&nbsp;You’re&nbsp;not replacing your AppSec workflow;&nbsp;you’re&nbsp;just&nbsp;extending it&nbsp;to cover a&nbsp;new&nbsp;class of components.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="heres-what-your-appsec-team-gets">
<strong>Here’s What Your&nbsp;AppSec Team&nbsp;Gets</strong>&nbsp;</h2>



<p class="wp-block-paragraph">The result is a practical extension of your existing AppSec program.&nbsp;</p>



<ul class="wp-block-list">
<li>
<strong>Complete AI asset inventory across the enterprise.</strong>&nbsp;Every LLM, agent framework, MCP server, dataset, embedding, and system prompt that exists in your codebase&nbsp;is&nbsp;surfaced&nbsp;deterministically from code and configuration, compiled into a searchable, auditable&nbsp;catalog.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>AI-specific risk assessment.</strong>&nbsp;Model poisoning, unverified weights, unsafe agents, exposed datasets, unpinned versions&nbsp;are detected&nbsp;with evidence-backed findings and actionable remediation guidance.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Regulatory readiness.</strong>&nbsp;AI-BOMs&nbsp;are&nbsp;aligned&nbsp;with&nbsp;compliance posture tracking against EU AI Act, ISO 42001, NIST AI RMF, and OWASP LLM Top 10,&nbsp;and ready to export when an auditor asks.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>Policy enforcement in the developer workflow.</strong>&nbsp;Approved model lists, framework allowlists, version pinning requirements&nbsp;are&nbsp;enforced&nbsp;in pull requests and CI/CD, not after the fact.&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li>
<strong>No new platform overhead.</strong>&nbsp;Everything lives in&nbsp;Checkmarx&nbsp;One, using the same permissions, dashboards, and reporting your team already relies on.&nbsp;&nbsp;</li>
</ul>


<section class="section-block-info light-theme">
    <div class="main-wrapper block-info__wrapper">
        <div class="block-info center">
			
							<p class="block-info__eyebrow">
					<span class="block-info__dash" aria-hidden="true"></span>Upcoming Live Webinar | 9 July 10:00AM EDT				</p>
			
							<h2 class="section-title article-anchor" id="shadow-ai-in-the-sdlc-a-practitioner-panel-on-visibility-risk-and-the-road-to-governed-ai">
					<span class="block-info__grad">Shadow AI in the SDLC:</span> A Practitioner Panel on Visibility, Risk, and the Road to Governed AI				</h2>
			
			
			<div class="actions">
				        <a href="https://checkmarx.local/shadow-ai-in-the-sdlc/" class="block-info__btn block-info__btn--primary">Register Now<svg class="block-info__arrow" viewbox="0 0 16.5 16.5" fill="none" aria-hidden="true" focusable="false"><path d="M4.55852 5.28761L11.9622 5.28761L11.9622 12.6913M11.9622 5.28761L4.53767 12.7121" stroke="currentColor" stroke-width="1.54688" stroke-linecap="square" stroke-linejoin="round"></path></svg></a>
        							</div>
        </div>
    </div>
</section>



<h2 class="wp-block-heading article-anchor" id="the-bottom-line-for-appsec">
<strong>The Bottom Line for AppSec</strong>&nbsp;</h2>



<p class="wp-block-paragraph">AI components&nbsp;have changed what your software is made of and&nbsp;are&nbsp;now&nbsp;part of the software supply chain.&nbsp;The question&nbsp;isn’t&nbsp;whether they&nbsp;exist, but&nbsp;whether&nbsp;your AppSec program can handle the visibility and volume that they introduce.&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Governing&nbsp;the AI supply chain&nbsp;isn’t&nbsp;optional anymore.&nbsp;Your AppSec program&nbsp;needs&nbsp;the&nbsp;visibility, tooling,&nbsp;and workflow integration&nbsp;to keep up.&nbsp;<a href="https://checkmarx.com/solutions/ai-supply-chain-security/" target="_blank" rel="noreferrer noopener">Checkmarx&nbsp;AI Supply Chain Security</a>&nbsp;is&nbsp;built for that.&nbsp;Deterministic discovery, evidence-backed risk assessment, and end-to-end governance built directly into&nbsp;developer&nbsp;workflows. It integrates&nbsp;with your existing&nbsp;pipelines,&nbsp;giving you&nbsp;a unified risk picture across&nbsp;code, dependencies, models, and runtime environments&nbsp;without&nbsp;adding&nbsp;another silo to manage.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="see-it-in-action">
<strong>See It in Action</strong>&nbsp;</h2>



<p class="wp-block-paragraph">If this gap sounds familiar, it&nbsp;likely&nbsp;already&nbsp;exists in your organization’s environment.&nbsp;The good news?&nbsp;&nbsp;It’s&nbsp;solvable&nbsp;without&nbsp;disrupting&nbsp;the AppSec program&nbsp;you’ve&nbsp;already built.&nbsp;</p>


<section class="section-block-info light-theme">
    <div class="main-wrapper block-info__wrapper">
        <div class="block-info center">
			
							<p class="block-info__eyebrow">
					<span class="block-info__dash" aria-hidden="true"></span>See it in Action				</p>
			
							<h2 class="section-title article-anchor" id="checkmarx-ai-supply-chain-security">
					Checkmarx AI Supply Chain Security				</h2>
			
			
			<div class="actions">
				        <a href="/request-a-demo/" class="block-info__btn block-info__btn--primary">Request a Demo<svg class="block-info__arrow" viewbox="0 0 16.5 16.5" fill="none" aria-hidden="true" focusable="false"><path d="M4.55852 5.28761L11.9622 5.28761L11.9622 12.6913M11.9622 5.28761L4.53767 12.7121" stroke="currentColor" stroke-width="1.54688" stroke-linecap="square" stroke-linejoin="round"></path></svg></a>
        							</div>
        </div>
    </div>
</section>]]></content:encoded>
					
		
		
		
		<media:content url="https://www.youtube.com/embed/44G0Wyj5Ip4" duration="119">
			<media:player url="https://www.youtube.com/embed/44G0Wyj5Ip4" />
			<media:title type="html">You&#039;re Securing Your Code. But Are You Securing the AI Inside It? </media:title>
			<media:description type="html">AI is reshaping software development and your attack surface. Learn how to govern and secure AI components across your software supply chain</media:description>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/06/44g0wyj5ip4.jpg" />
			<media:keywords>Agentic AI,AI-Generated Code,Open-Source Supply Chain,shadow ai,Software Supply Chain Security</media:keywords>
		</media:content>
	</item>
		<item>
		<title>Learnings From Checkmarx Agentic AppSec Unleashed ‘26</title>
		<link>https://checkmarx.com/blog/learnings-from-checkmarx-agentic-appsec-unleashed-26/</link>
		
		<dc:creator><![CDATA[Eran Kinsbruner]]></dc:creator>
		<pubDate>Mon, 22 Jun 2026 17:55:05 +0000</pubDate>
				<category><![CDATA[AI & LLM Tools in Application Security]]></category>
		<category><![CDATA[Application Security Trends & Insights]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[Agentic AppSec]]></category>
		<category><![CDATA[AI Agents]]></category>
		<category><![CDATA[AppSec]]></category>
		<guid isPermaLink="false">https://staging.checkmarx.com/?p=113481</guid>

					<description><![CDATA[Deterministic Meets Frontier: The New Blueprint for AppSec ]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Software is now being created faster than most organizations can secure it.</p>



<p class="wp-block-paragraph">AI coding assistants are helping developers move at unprecedented speed. But that same speed is creating a new security reality: more code, more vulnerabilities, faster exploitability, and a growing backlog that traditional AppSec processes were never designed to handle.</p>



<p class="wp-block-paragraph">That tension shaped the conversation at the second annual Agentic AppSec Unleashed Summit, held on June 16. Across six main sessions and four exclusive early-access discussions, CISOs, customers, and product leaders explored how security teams can adapt to the AI-driven software supply chain.</p>



<p class="wp-block-paragraph">One message came through clearly: <strong>Agentic development demands security that moves at the same pace.</strong></p>



<p class="wp-block-paragraph">The teams that succeed will not be the ones that slow down development. They will be the ones that learn how to secure software as fast as AI can create it.</p>



<h2 class="wp-block-heading article-anchor" id="the-future-of-appsec-deterministic-security-meets-frontier-ai">The Future of AppSec: Deterministic Security Meets Frontier AI</h2>



<p class="wp-block-paragraph"><strong>Checkmarx CEO Sandeep Johri </strong>opened the summit by framing the challenge facing security teams today. AI is helping enterprises write code two to three times faster, but that acceleration is also producing more vulnerable code than traditional AppSec programs can absorb.</p>



<p class="wp-block-paragraph">According to Johri, AI-generated code has a much higher concentration of vulnerabilities than human-written code, contributing to a threefold increase in the overall vulnerability backlog. Left unchecked, that backlog could slow the very innovation AI was meant to accelerate.</p>



<p class="wp-block-paragraph">At the same time, attackers are also using AI. Exploit creation is becoming faster, cheaper, and more scalable. In 2018, exploiting a zero-day vulnerability could take roughly two years. Today, that window has shrunk to just one or two days, and it continues to narrow.</p>



<p class="wp-block-paragraph">Given that speed, it may seem logical to fight AI with AI by relying on frontier models to find vulnerabilities faster. But Johri made clear that an “LLM-only” approach is not enough. Frontier models can uncover novel exploit paths, but they can also be inconsistent. Their results may change depending on the prompt, they can produce false positives, and they can still miss known critical vulnerabilities.</p>



<p class="wp-block-paragraph">That is where deterministic security remains essential. Unlike LLMs, deterministic tools apply consistent rules and proven detection logic, producing repeatable results that teams can trust and verify.</p>



<p class="wp-block-paragraph">The answer, Johri argued, is not AI or deterministic tooling – it&#8217;s both. Modern application security needs a hybrid platform that pairs deterministic ground truth with probabilistic AI reasoning, combining the consistency of traditional security with the speed and creativity of frontier models.</p>



<p class="wp-block-paragraph">Johri also made an important architectural point: a the same model producing the code should not be trusted to secure it. Just as a system should not manage its own permissions or store its own master keys, the security control plane must remain independent of the AI it evaluates. He called it a “separation of church and state.”</p>



<p class="wp-block-paragraph">That separation is central to the platform Checkmarx is building: one that combines deterministic ground truth with AI-powered reasoning while keeping security validation independent, consistent, and verifiable. The result is already showing impact, including a 60–70% reduction in false positives.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="936" height="376" src="https://checkmarx.com/wp-content/uploads/2026/06/image-7.png" alt="" class="wp-image-113482" srcset="https://checkmarx.com/wp-content/uploads/2026/06/image-7.png 936w, https://checkmarx.com/wp-content/uploads/2026/06/image-7-300x121.png 300w, https://checkmarx.com/wp-content/uploads/2026/06/image-7-768x309.png 768w, https://checkmarx.com/wp-content/uploads/2026/06/image-7-400x161.png 400w" sizes="(max-width: 936px) 100vw, 936px" /></figure>



<h2 class="wp-block-heading article-anchor" id="beyond-the-false-choice-how-ai-and-appsec-win-together">Beyond the False Choice: How AI and AppSec Win Together</h2>



<p class="wp-block-paragraph">The second session brought Johri together with other security leaders who are already navigating this shift:</p>



<p class="wp-block-paragraph"><strong>Michael Schrank</strong>, former Group CISO, Adidas; CEO, Three Rivers Advisory</p>



<p class="wp-block-paragraph"><strong>Joseph Wilson</strong>, SVP &amp; CIO, CSG</p>



<p class="wp-block-paragraph"><strong>Laurent Donnay</strong>, SVP IT Sales and Platforms, Deutsche Telekom</p>



<p class="wp-block-paragraph">The central question in this session was simple: If AI can write code, find vulnerabilities, and generate exploits, what is left for AppSec to do?</p>



<p class="wp-block-paragraph">The answer was not that AppSec becomes less important. It becomes the layer of trust, governance, and execution that makes AI-driven development safe.</p>



<p class="wp-block-paragraph">AI can accelerate coding, scanning, and even exploitation, but organizations still need deterministic security to validate results, prioritize real risk, and ensure findings lead to remediation.</p>



<p class="wp-block-paragraph">That is where the operational challenge begins. Most teams are not struggling because they lack security signals; they are struggling because those signals are fragmented and overwhelming. To turn findings into remediation, they need a connected view of risk that brings together code, runtime, identity, and data context to show what is truly exploitable and what should be fixed first. Wilson captured the maturity challenge directly: “Discovery without mitigation is just inventory.”</p>



<p class="wp-block-paragraph">From there, the panel focused on what mature AppSec programs need to do differently:</p>



<ul class="wp-block-list">
<li>
<strong>Measure what matters</strong>. Maturity isn&#8217;t how many vulnerabilities you find. It&#8217;s MTTR (mean time to remediation), how fast you resolve them.</li>



<li>
<strong>Integrate, don&#8217;t interrupt</strong>. Remediation belongs inside the existing SDLC, with agents proposing fixes directly in the pull request.</li>



<li>
<strong>Let agents do the grunt work</strong>. Triage and remediation that could take hours for developers can be completed by an LLM in two to three minutes.</li>
</ul>



<h2 class="wp-block-heading article-anchor" id="the-vulnerabilities-were-always-there-now-what">The Vulnerabilities Were Always There: Now What?</h2>



<p class="wp-block-paragraph">In my session with <strong>Jonathan Rende, Chief Product Officer at Checkmarx</strong>, we put numbers behind the problem.</p>



<p class="wp-block-paragraph">AI is not just changing how quickly software is written; it is changing how quickly security debt accumulates.</p>



<p class="wp-block-paragraph">AI-generated code is introducing more defects per unit of code, with defect rates up 1.7x. When that increase is multiplied across the growing volume of AI-generated software, it compounds into roughly 5x more exploitable flaws. In other words, organizations are not just writing more code. They are also creating more risk for security teams to manage.</p>



<p class="wp-block-paragraph">At the same time, attackers are moving faster and more cheaply than ever. A working CVE exploit can now cost as little as $1 and only minutes of compute. That means the window between disclosure and exploitation is no longer long enough for slow, manual response processes.</p>



<p class="wp-block-paragraph">The result is a widening gap between what teams find and what they fix. Over the last year, vulnerability submissions increased while monthly fixes fell 46%. Discovery has scaled with AI, but remediation has not. Critical vulnerabilities are now piling up faster than most teams can resolve them.</p>



<p class="wp-block-paragraph">The solution isn&#8217;t to replace traditional tooling with AI, but to combine both deliberately.</p>



<p class="wp-block-paragraph">AI is fast and creative, which makes it useful for surfacing novel patterns that traditional scanners may miss. Deterministic security is consistent and repeatable, which makes it essential for catching known vulnerabilities, validating findings, and producing the evidence auditors require.</p>



<p class="wp-block-paragraph">Put simply, AI casts the wide net, while deterministic logic confirms what is real.</p>



<p class="wp-block-paragraph">That combination produces better signal. In Checkmarx labs, the hybrid engine reached an F1 score of 0.64, compared to roughly 0.20 for a pure frontier model like Claude Opus 4.7. That difference matters because it turns a noisy alert pile into findings teams can actually trust and act on.</p>



<p class="wp-block-paragraph">Our conclusion was clear: discovery is no longer the hardest part. The teams that lead will be the ones that improve remediation throughput – their ability to fix vulnerabilities quickly, accurately, and consistently across both new code and the existing backlog.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="936" height="433" src="https://checkmarx.com/wp-content/uploads/2026/06/image-8.png" alt="" class="wp-image-113483" srcset="https://checkmarx.com/wp-content/uploads/2026/06/image-8.png 936w, https://checkmarx.com/wp-content/uploads/2026/06/image-8-300x139.png 300w, https://checkmarx.com/wp-content/uploads/2026/06/image-8-768x355.png 768w, https://checkmarx.com/wp-content/uploads/2026/06/image-8-400x185.png 400w" sizes="(max-width: 936px) 100vw, 936px" /></figure>



<h2 class="wp-block-heading article-anchor" id="getting-to-high-fidelity">Getting to High Fidelity</h2>



<p class="wp-block-paragraph"><strong>Checkmarx VP of Product Ori Bendet</strong> continued the case for a hybrid model by pointing to the limits of LLM-only security. In the BaxBench benchmark, even the best frontier models returned solutions that were incorrect or insecure more than 45% of the time. “If you go all-in on LLMs, you&#8217;re going to have missing results,&#8221; he said, &#8220;and those missing results create risk for your organization.”</p>



<p class="wp-block-paragraph">Cost is another important factor. Scanning millions of lines of code with premium models can become expensive quickly, especially at enterprise scale. Security teams need an approach that is not only accurate, but also scalable, repeatable, and cost-effective.</p>



<p class="wp-block-paragraph"><strong>Frank Emery, Senior Director of Product Management</strong>, then explained how Checkmarx’s next-generation SAST engine is built to deliver that balance. It combines three core capabilities: a deterministic, rules-based foundation for consistency and trusted ground truth; an AI-based, language-agnostic scanner that expands coverage to frameworks and languages traditional tools may not support; and a Findings Analysis Engine that reviews findings in context and removes false positives before they reach developers.</p>



<p class="wp-block-paragraph">Together, these capabilities feed the Checkmarx ASPM platform, which helps teams understand where risk lives. From there, AI-powered agents, including Developer Assist, Triage Assist, and Remediation Assist, can identify issues earlier, triage zero-day and backlog vulnerabilities faster, and support remediation before risks escalate.</p>



<p class="wp-block-paragraph">The result is less noise, broader language support, and stronger fidelity than traditional SAST. Just as importantly, this approach is grounded in two decades of Checkmarx research, detection logic, and AppSec expertise.</p>



<h2 class="wp-block-heading article-anchor" id="remediation-at-ai-speed-from-ai-vibe-coding-to-verified-governed-code">Remediation at AI Speed: From AI Vibe Coding to Verified, Governed Code</h2>



<p class="wp-block-paragraph">The next session shifted from strategy to practice in a discussion moderated by <strong>Checkmarx VP of Product Management Harshil Parikh</strong>. He was joined by two PatientPoint security practitioners: <strong>Femi Oyesanya</strong>, application security engineer, and <strong>Lily Leith</strong>, application security risk analyst. Together, they explored a practical question facing many AppSec teams today: remediation has always mattered, but how does AI’s speed change the way teams approach it?</p>



<p class="wp-block-paragraph">For Oyesanya, the opportunity is clear. “We have a better, more reliable, faster way of doing it,” he said. But he also cautioned that automation brings new complexity. Risk does not come only from application code; it can also come from SCA vulnerabilities, compromised libraries, and other parts of the software supply chain. That means controls need to extend across the infrastructure, not just the code.</p>



<p class="wp-block-paragraph">Leith described how PatientPoint has moved from a reactive model to a more anticipatory one. Instead of spending hours responding to the “attack of the day,” her team now uses automation to shorten response times. That includes monitoring new CVEs, checking whether GitHub packages are malicious, and using agents to determine what is actually exploitable.</p>



<p class="wp-block-paragraph">The key, both speakers emphasized, is trusted context. By pulling in intelligence from sources like Checkmarx, teams can decide whether a vulnerability should trigger a break-build policy or move through another remediation workflow.</p>



<p class="wp-block-paragraph">They also stressed that humans still need to stay in the loop. Developers remain the experts on their own codebases, so they need to review AI-generated fixes, catch hallucinations, and make sure suggested changes do not introduce new risk. For critical or externally facing systems, formal change management remains essential.</p>



<p class="wp-block-paragraph">That is where governance becomes critical. Security gates, policies, and review processes keep AI-accelerated development accountable. Parikh closed on a note of hard-won optimism: the industry has been “notorious about not fixing things,” but he believes agentic remediation can finally help drive down MTTR with a solution built for practitioners.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="936" height="451" src="https://checkmarx.com/wp-content/uploads/2026/06/image-9.png" alt="" class="wp-image-113484" srcset="https://checkmarx.com/wp-content/uploads/2026/06/image-9.png 936w, https://checkmarx.com/wp-content/uploads/2026/06/image-9-300x145.png 300w, https://checkmarx.com/wp-content/uploads/2026/06/image-9-768x370.png 768w, https://checkmarx.com/wp-content/uploads/2026/06/image-9-400x193.png 400w" sizes="(max-width: 936px) 100vw, 936px" /></figure>



<h2 class="wp-block-heading article-anchor" id="bring-visibility-across-the-supply-chain">Bring Visibility Across the Supply Chain</h2>



<p class="wp-block-paragraph">The final session focused on one of the biggest governance challenges in the AI era: visibility across the AI software supply chain. <strong>Checkmarx Product Director for SSCS David Dewaele</strong> and <strong>AWS Principal Solution Architect for ISV Security Paul DeLaria</strong> discussed how organizations can identify, assess, and govern the AI components now entering modern applications.</p>



<p class="wp-block-paragraph">Most large organizations are familiar with shadow IT, where employees use tools that were never approved by the company. Security teams now face a newer and more complex version of the same problem: shadow AI.</p>



<p class="wp-block-paragraph">Developers moving quickly may adopt unsanctioned AI tools, models, agents, MCP servers, or other AI components, creating risk that security teams cannot manage if they cannot see it.</p>



<p class="wp-block-paragraph">DeLaria’s central point was simple and important: organizations cannot secure what they cannot see. Many leaders do not yet know which AI components are running inside their applications. Without that visibility, it becomes difficult to assess risk, enforce policy, or demonstrate compliance.</p>



<p class="wp-block-paragraph">Visibility begins with the Shared Responsibility Model. Cloud providers are responsible for securing the cloud infrastructure itself, while enterprises are responsible for what they build and run on top of it. In the AI era, that includes identity and access management for agents, the AI tool supply chain, and observability into what those agents are doing.</p>



<p class="wp-block-paragraph">Dewaele outlined a three-layer approach to AI supply chain governance.</p>



<ul class="wp-block-list">
<li>
<strong>Detection</strong>: Identify every AI asset, from LLMs to agents to MCP servers, across the whole SDLC.</li>



<li>
<strong>Risk assessment</strong>: Run purpose-built scanners that catch new threats like malicious artifact injection and dangerous model loaders, alongside traditional scans.</li>



<li>
<strong>Governance and compliance</strong>: Generate AI Bills of Materials (AI-BOMs) to evidence security against frameworks like the EU AI Act, NIST, and ISO.</li>
</ul>



<p class="wp-block-paragraph">The goal is not only to detect risk. It is to create the visibility, context, and evidence organizations need to govern AI-driven development responsibly.</p>



<h2 class="wp-block-heading article-anchor" id="thats-a-wrap">That&#8217;s a Wrap</h2>



<p class="wp-block-paragraph">The summit ended where it began: with the central idea that securing software at the speed of AI cannot be solved by one tool, one team, or one model. It requires a new AppSec discipline that is built layer by layer, from detection to remediation to governance.</p>



<p class="wp-block-paragraph">That discipline starts with deterministic ground truth. It adds AI-driven reasoning where AI can provide speed, scale, and broader coverage. It uses agents to accelerate triage and remediation, and it creates visibility across the full software supply chain, including the new AI components that are quickly becoming part of modern applications.</p>



<p class="wp-block-paragraph">AI has made it easier, cheaper, and faster for attackers to exploit software, but it has also created a new opportunity for defenders. With the right architecture, security teams can move faster without giving up trust. They can reduce noise without missing critical issues. They can govern AI-generated code without slowing innovation.</p>



<p class="wp-block-paragraph">That is the blueprint Checkmarx laid out at Agentic AppSec Unleashed ’26: deterministic security and frontier AI, working together so organizations <strong>can secure software as fast as AI can build it.</strong></p>



<p class="wp-block-paragraph"><a href="https://checkmarx.ai/on-demand-sessions/?__hstc=206289484.3289b36b7a3f390435f359ca407c0e41.1776181577790.1781716862935.1782140796982.84&amp;__hssc=206289484.11.1782140796982&amp;__hsfp=2d3796ce4f8e2359fec9023e3d638e0a">The full sessions and slides are available on demand.</a></p>]]></content:encoded>
					
		
		
		
		<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/06/image-7-150x150.png" />
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/06/image-7.png" medium="image">
			<media:title type="html">image</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/06/image-7-150x150.png" />
		</media:content>
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/06/image-8.png" medium="image">
			<media:title type="html">image</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/06/image-8-150x150.png" />
		</media:content>
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/06/image-9.png" medium="image">
			<media:title type="html">image</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/06/image-9-150x150.png" />
		</media:content>
	</item>
		<item>
		<title>Checkmarx Named a Leader in Inaugural 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security</title>
		<link>https://checkmarx.com/blog/checkmarx-named-a-leader-in-inaugural-2026-gartner-magic-quadrant-for-software-supply-chain-security/</link>
		
		<dc:creator><![CDATA[Checkmarx Team]]></dc:creator>
		<pubDate>Mon, 22 Jun 2026 15:26:02 +0000</pubDate>
				<category><![CDATA[AI & LLM Tools in Application Security]]></category>
		<category><![CDATA[Application Security Trends & Insights]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Supply Chain Security]]></category>
		<category><![CDATA[Leadership]]></category>
		<category><![CDATA[Security Leadership]]></category>
		<category><![CDATA[SSCS]]></category>
		<guid isPermaLink="false">https://staging.checkmarx.com/?p=113455</guid>

					<description><![CDATA[We&#8217;re proud to share that Checkmarx has been positioned as a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security. We believe this recognition validates our dev-first, unified approach to comprehensive supply chain protection and centralized governance. Gartner evaluated vendors across two critical dimensions: Completeness of Vision and Ability to Execute, and [&#8230;]]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">We&#8217;re proud to share that <a href="https://checkmarx.com/checkmarx-named-a-leader-in-the-2026-gartner-magic-quadrant-for-software-supply-chain-security/?utm_source=blog&amp;utm_medium=post&amp;utm_campaign=gartner_mq_sscs_2026">Checkmarx has been positioned as a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security</a>.</p>



<p class="wp-block-paragraph">We believe this recognition validates our dev-first, unified approach to comprehensive supply chain protection and centralized governance.</p>



<p class="wp-block-paragraph">Gartner evaluated vendors across two critical dimensions: Completeness of Vision and Ability to Execute, and we feel our placement underscores our innovation in supply chain risk detection and ability to deliver measurable business impact for enterprises managing complex software dependencies.</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" width="2314" height="2560" src="https://checkmarx.com/wp-content/uploads/2026/06/Figure1-scaled.png" alt="" class="wp-image-113469" style="aspect-ratio:0.9039092055485498;width:597px;height:auto" srcset="https://checkmarx.com/wp-content/uploads/2026/06/Figure1-scaled.png 2314w, https://checkmarx.com/wp-content/uploads/2026/06/Figure1-271x300.png 271w, https://checkmarx.com/wp-content/uploads/2026/06/Figure1-926x1024.png 926w, https://checkmarx.com/wp-content/uploads/2026/06/Figure1-768x849.png 768w, https://checkmarx.com/wp-content/uploads/2026/06/Figure1-1389x1536.png 1389w, https://checkmarx.com/wp-content/uploads/2026/06/Figure1-1852x2048.png 1852w, https://checkmarx.com/wp-content/uploads/2026/06/Figure1-529x585.png 529w" sizes="(max-width: 2314px) 100vw, 2314px" /><figcaption class="wp-element-caption"><em>This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Checkmarx.</em></figcaption></figure>



<h2 class="wp-block-heading article-anchor" id="securing-the-supply-chain">Securing the Supply Chain</h2>



<p class="wp-block-paragraph">We believe this recognition reinforces our commitment to helping organizations detect and remediate supply chain risks in a way that fits seamlessly into how development teams work.</p>



<p class="wp-block-paragraph">By embedding security directly into developer workflows, through IDE integration, source control, and CI/CD pipelines, Checkmarx One makes it easy to catch supply chain risks early without slowing teams down. The unified platform covers SCA, container security, malicious package detection, secrets detection, SBOM generation, and our recently launched <a href="https://checkmarx.com/ai-bom/?utm_source=blog_announcement&amp;utm_medium=blog&amp;utm_campaign=gartner_mq_sscs_2026">AI-BOM solution</a> for managing AI components with audit-ready documentation.</p>



<h2 class="wp-block-heading article-anchor" id="ready-to-learn-more">Ready to Learn More?</h2>



<p class="wp-block-paragraph">Access the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security report or request a demo to learn more about Checkmarx One Software Supply Chain solutions.</p>



<p class="wp-block-paragraph">    </p>



<p class="wp-block-paragraph"> </p>



<div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p class="wp-block-paragraph"><em><sup>Gartner, Magic Quadrant for Software Supply Chain Security, Aaron Lord, Jason Gross, Johnny Walters, June 17, 2026.</sup></em></p>
</div></div>



<p class="wp-block-paragraph"><em><sup>Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.</sup></em></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><em><sup>Gartner and Magic Quadrant are trademarks of Gartner, Inc. and/or its affiliates.</sup></em></p>]]></content:encoded>
					
		
		
		
		<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/06/Figure1-150x150.png" />
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/06/Figure1-scaled.png" medium="image">
			<media:title type="html">Figure1</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/06/Figure1-150x150.png" />
		</media:content>
	</item>
		<item>
		<title>Your Scanner&#8217;s Accuracy Claims Are Only Half the Story</title>
		<link>https://checkmarx.com/blog/your-scanners-accuracy-claims-are-only-half-the-story/</link>
		
		<dc:creator><![CDATA[Avi Hein]]></dc:creator>
		<pubDate>Tue, 16 Jun 2026 04:53:51 +0000</pubDate>
				<category><![CDATA[AI & LLM Tools in Application Security]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[SAST]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[Agentic AppSec]]></category>
		<category><![CDATA[AI generated code]]></category>
		<category><![CDATA[AppSec]]></category>
		<guid isPermaLink="false">https://staging.checkmarx.com/?p=113276</guid>

					<description><![CDATA[At some point, developers on your team stopped acting on security findings. Not because they stopped caring about security, but because they learned that most findings are not real. A scanner flooded the queue with so much noise that ignoring it became the rational response. The question is how did that happen, and how can [&#8230;]]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">At some point, developers on your team stopped acting on security findings. Not because they stopped caring about security, but because they learned that most findings are not real. A scanner flooded the queue with so much noise that ignoring it became the rational response.</p>



<p class="wp-block-paragraph">The question is how did that happen, and how can you evaluate if your next tool will do the same thing?</p>



<p class="wp-block-paragraph">It comes down to how vendors measure accuracy.</p>



<p class="wp-block-paragraph">A scanner can lower its false positive count by simply flagging fewer things, but this means real vulnerabilities are passing through undetected. A scanner can also raise its detection rate by flagging everything, but this means your developers spend their time chasing noise until they stop looking at findings altogether. Both outcomes look fine on the summary slide – but neither is fine in practice.</p>



<p class="wp-block-paragraph">The metric that closes this loophole is the F<sub>1</sub> score, a specific type of F-score that weighs precision and recall equally. Improving it requires improving both simultaneously – gains in one don&#8217;t compensate for weakness in the other.</p>



<p class="wp-block-paragraph">It&#8217;s also why most AppSec vendors don&#8217;t advertise their F<sub>1</sub> score: the numbers reveal what they’d rather hide. Publish a weak F<sub>1</sub> and they’re admitting either that the scanner either misses critical vulnerabilities or that it drowns users in false positives. And neither is a compelling sales pitch.</p>



<h2 class="wp-block-heading article-anchor" id="the-basics-precision-and-recall">The Basics: Precision and Recall</h2>



<p class="wp-block-paragraph">Every security scanner produces four types of outputs:</p>



<ul class="wp-block-list">
<li>
<strong>True positives (TP)</strong>: real weaknesses the scanner correctly identified.</li>



<li>
<strong>False positives (FP)</strong>: findings that are not actually weaknesses.</li>



<li>
<strong>False negatives (FN)</strong>: real weaknesses the scanner missed.</li>



<li>
<strong>True negatives (TN)</strong>: clean code that the scanner correctly ignored.</li>
</ul>



<p class="wp-block-paragraph"><strong>Precision</strong> measures the share of findings that are real: <em>𝑇𝑃 / (𝑇𝑃 + 𝐹𝑃)</em>.<br>A high-precision scanner means fewer false positives so your team spends less time investigating findings that turn out to be nothing. The catch is that a scanner can achieve perfect precision by flagging almost nothing, which means real vulnerabilities sail through undetected.</p>



<p class="wp-block-paragraph"><strong>Recall</strong> measures the share of real vulnerabilities that were found: <em>𝑇𝑃 / (𝑇𝑃 + 𝐹𝑁)</em>.<br>A high-recall scanner misses very little. But its catch is that a scanner can achieve perfect recall by flagging everything, which destroys signal-to-noise ratio (and sends your developers back to ignoring the queue).</p>



<p class="wp-block-paragraph">AppSec vendors exploit this tension constantly. A tool can reduce false positives by simply reporting fewer findings, which quietly creates false negatives, letting real vulnerabilities pass through undetected. The tool looks precise on paper, but the vulnerabilities it stopped flagging didn&#8217;t disappear – they just stopped showing up in the report.</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" width="906" height="726" src="https://checkmarx.com/wp-content/uploads/2026/06/image-3.png" alt="" class="wp-image-113277" style="aspect-ratio:1.247939831472411;width:671px;height:auto" srcset="https://checkmarx.com/wp-content/uploads/2026/06/image-3.png 906w, https://checkmarx.com/wp-content/uploads/2026/06/image-3-300x240.png 300w, https://checkmarx.com/wp-content/uploads/2026/06/image-3-768x615.png 768w, https://checkmarx.com/wp-content/uploads/2026/06/image-3-730x585.png 730w, https://checkmarx.com/wp-content/uploads/2026/06/image-3-374x300.png 374w" sizes="(max-width: 906px) 100vw, 906px" /><figcaption class="wp-element-caption"><em>These two measures pull against each other. Optimizing for one in isolation tends to hurt the other.</em></figcaption></figure>



<h2 class="wp-block-heading article-anchor" id="what-the-f-score-captures">What the F Score Captures</h2>



<p class="wp-block-paragraph">The F score is the harmonic mean of precision and recall, a single number that captures both at once:</p>



<p class="has-text-align-center wp-block-paragraph"><math data-latex="F_1 = 2 \times \frac{\text{Precision} \times \text{Recall}}{\text{Precision} + \text{Recall}}"><semantics><mrow><msub><mi>F</mi><mn>1</mn></msub><mo>=</mo><mn>2</mn><mo>×</mo><mfrac><mrow><mtext>Precision</mtext><mo>×</mo><mtext>Recall</mtext></mrow><mrow><mtext>Precision</mtext><mo>+</mo><mtext>Recall</mtext></mrow></mfrac></mrow><annotation encoding="application/x-tex">F_1 = 2 \times \frac{\text{Precision} \times \text{Recall}}{\text{Precision} + \text{Recall}}</annotation></semantics></math></p>



<p class="wp-block-paragraph">Unlike a simple average, the harmonic mean heavily penalizes imbalance. A scanner with 90% precision but only 10% recall scores of 0.18, not 0.5. Both numbers must be high at the same time to produce a strong F<sub>1</sub> score. You cannot hide a weak recall behind a strong precision score, which is exactly what makes it a more honest benchmark than either metric alone.</p>



<p class="wp-block-paragraph">An F<sub>1</sub> score runs from 0 to 1. What counts as a good score depends on the data being analyzed. Controlled benchmark studies with purpose-built vulnerable code tend to produce higher scores across all tool categories than tests on real production code. On real production code, scores are lower across the board &#8211; for traditional SAST tools, LLM-native reviewers, and hybrid approaches alike. This isn’t a flaw in the tools, but a reflection of how messy the real world is compared to carefully constructed examples.</p>



<p class="wp-block-paragraph">This is why the test dataset matters as much as the score itself. A vendor quoting an F<sub>1</sub> score based on a controlled benchmark is making a very different claim than one quoting a score from real production code. And, if a vendor does not name the dataset, that is worth asking about.</p>



<h2 class="wp-block-heading article-anchor" id="why-this-matters-for-sast">Why This Matters for SAST</h2>



<p class="wp-block-paragraph">Static application security testing (SAST) is a classification problem at scale. On a single codebase, a scanner might analyze thousands of code paths and return hundreds of findings. For AppSec teams managing backlogs, false positives from scanners teach developers to ignore scanner output, leading to worse security outcomes.</p>



<p class="wp-block-paragraph">Traditional rules-based SAST engines tend to favor high recall: find every possible match for known patterns. The tradeoff is well understood: by casting a wider net, they inevitably produce a higher false positive rate. Most security teams have learned to accept this as the cost of minimizing missed vulnerabilities.</p>



<p class="wp-block-paragraph">AI-driven scanners take a different approach. Because they aren’t limited to simple pattern-matching, they can reason about the code in ways AI-only SAST engines cannot. But they introduce a different challenge: an AI model reviewing the code can&#8217;t self-police. It’s the computational equivalent of the fox guarding the hen house.</p>



<p class="wp-block-paragraph">Some vendors address the false positive problem by reducing recall, so the findings look cleaner, which in turn quietly increases false negatives. Vulnerabilities that are missed do not announce themselves – and as a result, vendors can advertise low false positive rates while quietly allowing more real issues to slip through. This is precisely why the F<sub>1</sub> score matters. It makes the “low FP” trick harder to get away with. Vendors that report recall without precision (or precision without recall) are just emphasizing whichever metric presents their product more favorably. The F<sub>1</sub> score puts both dimensions on the table simultaneously, providing a more balanced measure of scanner effectiveness.</p>



<h2 class="wp-block-heading article-anchor" id="what-good-looks-like-in-practice">What Good Looks Like in Practice</h2>



<p class="wp-block-paragraph">Checkmarx Zero research published benchmark data from a study across seven production codebases (Istio, indico, OpenMRS, Mezzanine, SimplCommerce, Jellyfinn, ThreatByte) comparing hybrid SAST against LLM-native scanning with Claude Opus 4.7. The results:</p>



<ul class="wp-block-list">
<li>
<strong>Checkmarx SAST</strong>: F<sub>1</sub> score of 0.64</li>



<li>
<strong>Claude Opus 4.7</strong> (standalone LLM reviewer): F<sub>1</sub> score of approximately 0.20</li>
</ul>



<p class="wp-block-paragraph">The gap is significant. Checkmarx Zero research tested an LLM-augmented SAST engine head-to-head against Claude Opus 4.7 across seven real production codebases in Python, Go, and C#, covering 747 findings. The Checkmarx engine had an 11% higher true positive rate than Opus 4.7, found 327 additional true positives that Opus missed entirely, and Opus 4.7 generated a 44.1% false positive rate. Nearly half its findings were wrong.</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" width="1600" height="1031" src="https://checkmarx.com/wp-content/uploads/2026/06/Code_Generated_Image.png" alt="" class="wp-image-113337" style="aspect-ratio:1.5519182471637656;width:764px;height:auto" srcset="https://checkmarx.com/wp-content/uploads/2026/06/Code_Generated_Image.png 1600w, https://checkmarx.com/wp-content/uploads/2026/06/Code_Generated_Image-300x193.png 300w, https://checkmarx.com/wp-content/uploads/2026/06/Code_Generated_Image-1024x660.png 1024w, https://checkmarx.com/wp-content/uploads/2026/06/Code_Generated_Image-768x495.png 768w, https://checkmarx.com/wp-content/uploads/2026/06/Code_Generated_Image-1536x990.png 1536w, https://checkmarx.com/wp-content/uploads/2026/06/Code_Generated_Image-908x585.png 908w, https://checkmarx.com/wp-content/uploads/2026/06/Code_Generated_Image-400x258.png 400w" sizes="(max-width: 1600px) 100vw, 1600px" /></figure>



<p class="wp-block-paragraph">The gap comes from architecture, not just model quality. The hybrid approach runs a deterministic rules engine first, extends coverage with a purpose-built AI model, then applies a classification layer that filters findings before they reach the analyst. Each layer addresses what the others cannot do alone.</p>



<p class="wp-block-paragraph">For the full methodology and benchmark detail: <a href="https://checkmarx.com/llm-application-security-governing-ai-driven-risk/">LLM Application Security: Governing AI-Driven Risk Across the Software Lifecycle</a>.</p>



<h2 class="wp-block-heading article-anchor" id="how-to-use-f-score-to-evaluate-a-scanner">How to Use F Score To Evaluate a Scanner</h2>



<p class="wp-block-paragraph">If the F<sub>1</sub> score is the most balanced measure of scanner performance, then it should also be one of the first metrics you ask about when evaluating a vendor. Unlike standalone precision or recall figures, the F score makes it much harder to hide tradeoffs between finding vulnerabilities and avoiding false alarms.</p>



<p class="wp-block-paragraph">Start by asking a vendor for their scanner’s F<sub>1</sub> score on a defined, real-world codebase. The dataset matters. Purpose-built, vulnerable-by-design projects are useful for research and benchmarking, but do not represent production code. What matters is results from real code shipped by real software teams.</p>



<p class="wp-block-paragraph">Ask if precision and recall are reported separately. A vendor willing to disclose both numbers is making a more credible claim than one that highlights only detection rates or false positive reduction. Without both numbers, it’s impossible to understand the actual performance.</p>



<p class="wp-block-paragraph">Watch for vendors who improve one metric by degrading the other. Lower false positives achieved by missing more vulnerabilities is not an accuracy improvement. F<sub>1</sub> exposes exactly that tradeoff.</p>



<p class="wp-block-paragraph">If a vendor cannot provide an F<sub>1</sub> score or refuses to identify the test dataset, that should prompt further investigation before making a purchasing decision.</p>



<h2 class="wp-block-heading article-anchor" id="the-bottom-line">The Bottom Line</h2>



<p class="wp-block-paragraph">Security vendors will always have metrics, benchmarks, and marketing claims. Detection rates, false positive reductions, and accuracy scores that can all look impressive in isolation. The problem is that each tells only part of the story – and many can only be improved by optimizing one outcome while sacrificing the other.</p>



<p class="wp-block-paragraph">The F<sub>1</sub> score is different. It rewards scanners that can do both: find real vulnerabilities and avoid overwhelming teams with false alarms. A scanner cannot achieve a strong F<sub>1</sub> score by excelling at only one side of that equation.</p>



<p class="wp-block-paragraph">That is why the F<sub>1</sub> score is one of the most useful measures of scanner performance. It forces precision and recall to be evaluated together, making tradeoffs visible instead of hiding them behind carefully selected statistics.</p>



<p class="wp-block-paragraph">When a vendor can provide an F<sub>1</sub> score on a named, real-world dataset, they are making a claim that can be examined, challenged, and compared. When they avoid quoting one, it is worth asking why.</p>



<p class="wp-block-paragraph">That is the starting point for any honest conversation about scanner accuracy.</p>



<p class="wp-block-paragraph"><em>See how our <a href="https://checkmarx.com/cxsast-source-code-scanning/">Checkmarx SAST</a> helps reduce noise, uncover more real vulnerabilities, and deliver balanced performance across precision and recall.</em></p>]]></content:encoded>
					
		
		
		
		<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/06/image-3-150x150.png" />
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/06/image-3.png" medium="image">
			<media:title type="html">image</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/06/image-3-150x150.png" />
		</media:content>
		<media:content url="https://checkmarx.com/wp-content/uploads/2026/06/Code_Generated_Image.png" medium="image">
			<media:title type="html">Code_Generated_Image</media:title>
			<media:thumbnail url="https://checkmarx.com/wp-content/uploads/2026/06/Code_Generated_Image-150x150.png" />
		</media:content>
	</item>
		<item>
		<title>Checkmarx Security, Delivered Through Every AI Tool Your Team Already Uses</title>
		<link>https://checkmarx.com/blog/checkmarx-security-delivered-through-every-ai-tool-your-team-already-uses/</link>
		
		<dc:creator><![CDATA[Steve Boone]]></dc:creator>
		<pubDate>Mon, 15 Jun 2026 15:27:17 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[AppSec]]></category>
		<category><![CDATA[Checkmarx MCP]]></category>
		<category><![CDATA[Developer]]></category>
		<guid isPermaLink="false">https://staging.checkmarx.com/?p=113067</guid>

					<description><![CDATA[Introducing&#160;Checkmarx&#160;MCP Server, a single connection that puts your security data inside Claude Code, Windsurf, ChatGPT, and any other MCP-compatible AI tool. No context switching. No custom&#160;integrations.&#160;Security where the work actually happens. Security is falling behind how software actually gets built.&#160; Developers are spending more of their day inside AI assistants than inside any web platform. [&#8230;]]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph"><em>Introducing&nbsp;Checkmarx&nbsp;MCP Server, a single connection that puts your security data inside Claude Code, Windsurf, ChatGPT, and any other MCP-compatible AI tool. No context switching. No custom&nbsp;integrations.&nbsp;Security where the work actually happens.</em></p>



<p class="wp-block-paragraph">Security is falling behind how software actually gets built.&nbsp;</p>



<p class="wp-block-paragraph">Developers are spending more of their day inside AI assistants than inside any web platform. AppSec teams are answering the same questions,&nbsp;what are my riskiest projects, which findings need triage, how does this week compare to last,&nbsp;but still doing it by logging in, clicking through dashboards, and switching between tools. Security leaders need visibility on demand, not after a report gets pulled.&nbsp;</p>



<p class="wp-block-paragraph">The interface layer is changing. AI assistants are becoming the primary way people interact with their tools. In a growing number of cases, agents are executing workflows without a visible interface at&nbsp;all, triggering&nbsp;builds, resolving dependencies, making decisions without a human ever opening a tool. This is what headless application security looks like in practice: security that either&nbsp;participates&nbsp;in the workflow at execution&nbsp;time, or&nbsp;misses it entirely.&nbsp;</p>



<p class="wp-block-paragraph">If security is not present in that layer, it gets consulted after the fact. Or not at all.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="why-this-matters-now">Why This Matters Now&nbsp;</h2>



<p class="wp-block-paragraph">MCP has quickly become the standard for connecting AI tools to external systems.&nbsp;</p>



<p class="wp-block-paragraph">MCP-related SDKs reached 97 million monthly downloads within their first year. OpenAI adopted MCP in early 2025, deprecating its own Assistants API. In December 2025, Anthropic donated the protocol to the Linux Foundation, with OpenAI, Microsoft, AWS, Cloudflare, and Bloomberg as founding members.&nbsp;</p>



<p class="wp-block-paragraph">This is no longer an emerging standard. It is the standard.&nbsp;</p>



<p class="wp-block-paragraph">As AI assistants become the primary interface for software development and security operations, the question for every security tool is simple: are you present where decisions get made, or are you consulted after the fact?&nbsp;</p>



<p class="wp-block-paragraph">Today, that question has an answer.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="introducing-checkmarx-mcp-server">Introducing&nbsp;Checkmarx&nbsp;MCP Server&nbsp;</h2>



<p class="wp-block-paragraph">Checkmarx MCP Server connects your&nbsp;Checkmarx&nbsp;One environment directly to any MCP-compatible AI tool, including your IDE assistant, your chat interface, and your automated pipeline.&nbsp;</p>



<p class="wp-block-paragraph">Configure it once, and Checkmarx becomes a native tool available everywhere your team already works.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Built for How Security Work Actually Happens</strong>&nbsp;</p>



<p class="wp-block-paragraph">MCP serves the entire security workflow, not just developers.&nbsp;</p>



<p class="wp-block-paragraph">Developers stay in flow inside their IDE or CLI. They can trigger scans, retrieve findings, drill into vulnerabilities, and explore remediation options without switching tools.&nbsp;</p>



<p class="wp-block-paragraph">AppSec teams replace dashboards with queries. They can ask for findings across projects, compare scan results, and analyze application posture from a chat interface without logging into the platform.&nbsp;</p>



<p class="wp-block-paragraph">Security leaders get instant visibility. They can ask how many critical issues exist across the organization, which applications carry the highest risk, and how posture is changing — without waiting for reports.&nbsp;</p>



<p class="wp-block-paragraph">The result is simple: security moves from a system you visit to something that works alongside you.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="what-you-can-do-with-it">What You Can Do&nbsp;With&nbsp;It&nbsp;</h2>



<p class="wp-block-paragraph">At launch,&nbsp;Checkmarx&nbsp;MCP Server ships with around 20 tools covering the core security workflow directly inside your AI assistant. You can:&nbsp;</p>



<ol start="1" class="wp-block-list">
<li>Trigger SAST, SCA,&nbsp;IaC, and Secrets scans&nbsp;</li>
</ol>



<ol start="2" class="wp-block-list">
<li>Retrieve and filter findings with full context&nbsp;</li>
</ol>



<ol start="3" class="wp-block-list">
<li>Get risk visibility across projects and applications&nbsp;</li>
</ol>



<ol start="4" class="wp-block-list">
<li>Manage applications and projects&nbsp;</li>
</ol>



<ol start="5" class="wp-block-list">
<li>Run the complete create to scan to review to act loop without leaving your environment&nbsp;</li>
</ol>



<p class="wp-block-paragraph">These are not raw API calls wrapped in a tool. They are high-level, composable actions designed for natural language interaction, built so an AI agent can reason over them and chain them dynamically based on what you ask.&nbsp;</p>



<h2 class="wp-block-heading article-anchor" id="simple-to-connect-enterprise-ready-by-design">Simple to Connect, Enterprise Ready by Design&nbsp;</h2>



<p class="wp-block-paragraph">Connecting takes minutes. An admin enables access&nbsp;once&nbsp;and it becomes available across the organization.&nbsp;</p>



<p class="wp-block-paragraph">Developers can connect from any MCP-compatible client through marketplace and connector integrations — available now on Claude, GitHub, Cursor, Visual Studio Code, and OpenAI,&nbsp;that handle configuration automatically. For advanced setups, standard JSON-based configuration is also supported.&nbsp;</p>



<p class="wp-block-paragraph">Enterprise-grade controls are&nbsp;built in&nbsp;from the start, including RBAC passthrough, multi-tenant isolation, audit logging, and TLS. The same security posture you expect from&nbsp;Checkmarx&nbsp;One, extended to the agent layer.&nbsp;</p>



<!-- ====================================================================
  CHECKMARX · MCP BLOG CTA CARD  (v2 — theme-proof fonts + responsive)
  How to use: paste this entire block into a "Custom HTML" block
  in the WordPress editor.

  ➊ ADD YOUR LINKS — two spots below are marked 🔗 (or search href="#").
     Replace the # with the full URL, e.g. href="https://checkmarx.com/..."
  ➋ FONT — DM Sans is loaded two ways (the <link/> below AND an @import
     inside the <style>) so it survives plugins/themes that strip one or
     the other. If the theme already loads DM Sans, you can delete both.
     Note: if a privacy/GDPR or performance plugin blocks Google Fonts
     site-wide, ask the web team to enqueue DM Sans in the theme instead.
==================================================================== -->
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=DM+Sans:wght@400;500;700&#038;display=swap" rel="stylesheet">

<div class="cxcta">
  <style>
    @import url('https://fonts.googleapis.com/css2?family=DM+Sans:wght@400;500;700&display=swap');

    /* Scoped under .cxcta. Typography carries !important on every text
       element because WP theme rules like ".entry-content p" otherwise
       out-rank the card's classes and swap in the theme's own font,
       sizes, and spacing — which is what broke v1. */
    .cxcta{
      --cx-violet:   #6B34FD;
      --cx-magenta:  #A822BF;
      --cx-orange:   #F25929;
      --cx-midnight: #140921;
      --cx-white:    #FCF9FE;
      --cx-font: "DM Sans","Helvetica Neue",Helvetica,Arial,sans-serif;
      font-family: var(--cx-font);
      margin: 2.5rem 0;
    }
    .cxcta, .cxcta *, .cxcta *::before, .cxcta *::after{ box-sizing:border-box; }

    .cxcta .cxcta-card{
      position: relative;
      overflow: hidden;
      text-align: center;
      background:
        radial-gradient(120% 90% at 50% -10%, rgba(107,52,253,.32), transparent 55%),
        radial-gradient(70% 60% at 100% 110%, rgba(168,34,191,.20), transparent 60%),
        radial-gradient(60% 50% at 0% 100%,   rgba(107,52,253,.16), transparent 60%),
        var(--cx-midnight);
      border: 1px solid rgba(107,52,253,.45);
      border-radius: 24px;
      padding: clamp(40px,7vw,76px) clamp(20px,6vw,72px);
      -webkit-font-smoothing: antialiased;
      -moz-osx-font-smoothing: grayscale;
    }

    /* Eyebrow */
    .cxcta p.cxcta-eyebrow{
      margin: 0 0 18px !important;
      padding: 0 !important;
      font-family: var(--cx-font) !important;
      font-size: .78rem !important;
      font-weight: 500 !important;
      letter-spacing: .22em !important;
      line-height: 1.5 !important;
      text-transform: uppercase !important;
      color: #A685FD !important; /* Quantum Violet 60% tint */
    }
    .cxcta .cxcta-dash{
      display: inline-block;
      width: 22px; height: 2px;
      margin: 0 12px 4px 0;
      vertical-align: middle;
      border-radius: 2px;
      background: var(--cx-violet);
    }

    /* Headline — fluid from phone to desktop */
    .cxcta h2.cxcta-title{
      margin: 0 auto 16px !important;
      padding: 0 !important;
      font-family: var(--cx-font) !important;
      font-size: clamp(1.75rem, 1.1rem + 3.4vw, 2.9rem) !important;
      font-weight: 700 !important;
      letter-spacing: -.02em !important;
      line-height: 1.12 !important;
      color: var(--cx-white) !important;
      text-wrap: balance;
    }
    .cxcta .cxcta-grad{ /* approved violet → orange gradient on one key word */
      background: linear-gradient(90deg,var(--cx-violet),var(--cx-orange));
      -webkit-background-clip: text;
      background-clip: text;
      color: transparent;
      -webkit-text-fill-color: transparent;
    }
    @supports not ((-webkit-background-clip:text) or (background-clip:text)){
      .cxcta .cxcta-grad{ background:none; color:var(--cx-orange); -webkit-text-fill-color:currentColor; }
    }

    /* Intro copy — fluid size */
    .cxcta p.cxcta-intro{
      max-width: 620px;
      margin: 0 auto !important;
      padding: 0 !important;
      font-family: var(--cx-font) !important;
      font-size: clamp(1rem, .9rem + .55vw, 1.2rem) !important;
      font-weight: 400 !important;
      letter-spacing: 0 !important;
      line-height: 1.65 !important;
      color: rgba(252,249,254,.78) !important;
    }
    .cxcta p.cxcta-intro strong{
      color: var(--cx-white) !important;
      font-weight: 700 !important;
    }

    /* Buttons */
    .cxcta .cxcta-actions{
      display: flex;
      flex-wrap: wrap;
      gap: 14px;
      justify-content: center;
      margin-top: 34px;
    }
    .cxcta a.cxcta-btn{
      display: inline-flex;
      align-items: center;
      justify-content: center;
      gap: 8px;
      min-height: 54px;
      padding: 15px 30px;
      border-radius: 12px;
      font-family: var(--cx-font) !important;
      font-size: 1.0625rem !important;
      font-weight: 700 !important;
      line-height: 1.2 !important;
      text-align: center;
      text-decoration: none !important;
      border-bottom: none !important;
      box-shadow: none !important;
      transition: transform .18s ease, filter .18s ease,
                  background-color .18s ease, border-color .18s ease;
    }
    .cxcta a.cxcta-btn--primary{
      background-image: linear-gradient(90deg,var(--cx-violet),var(--cx-magenta));
      color: var(--cx-white) !important;
    }
    .cxcta a.cxcta-btn--primary:hover{ filter: brightness(1.1); transform: translateY(-1px); }
    .cxcta a.cxcta-btn--ghost{
      background: rgba(252,249,254,.05);
      border: 1px solid rgba(252,249,254,.28);
      color: var(--cx-white) !important;
    }
    .cxcta a.cxcta-btn--ghost:hover{
      border-color: rgba(107,52,253,.9);
      background: rgba(107,52,253,.14);
    }
    .cxcta a.cxcta-btn:focus-visible{ outline: 3px solid #A685FD; outline-offset: 3px; }
    .cxcta .cxcta-arrow{ flex:none; transition: transform .18s ease; }
    .cxcta a.cxcta-btn--primary:hover .cxcta-arrow{ transform: translateX(3px); }

    /* ---------- Responsive ----------
       Desktop ≥ 901px: full padding, buttons side by side.
       Tablet 641–900px: fluid type steps down, buttons stay inline
       and wrap gracefully if the column is narrow.
       Mobile ≤ 640px: buttons stack full-width, tighter eyebrow.   */
    @media (max-width: 900px){
      .cxcta .cxcta-card{ border-radius: 20px; }
      .cxcta .cxcta-actions{ margin-top: 30px; }
    }
    @media (max-width: 640px){
      .cxcta{ margin: 2rem 0; }
      .cxcta .cxcta-card{ border-radius: 18px; }
      .cxcta p.cxcta-eyebrow{ font-size: .7rem !important; letter-spacing: .16em !important; margin-bottom: 14px !important; }
      .cxcta .cxcta-dash{ width: 16px; margin-right: 9px; }
      .cxcta .cxcta-actions{ flex-direction: column; align-items: stretch; gap: 12px; margin-top: 26px; }
      .cxcta a.cxcta-btn{ width: 100%; padding: 15px 18px; font-size: 1rem !important; }
    }
    @media (max-width: 380px){
      .cxcta h2.cxcta-title{ font-size: 1.55rem !important; }
    }
    @media (prefers-reduced-motion: reduce){
      .cxcta *{ transition: none !important; }
    }
  </style>

  <div class="cxcta-card">

    <p class="cxcta-eyebrow"><span class="cxcta-dash" aria-hidden="true"></span>The new agentic application security</p>

    <h2 class="cxcta-title article-anchor" id="secure-what-comes-next">Secure What Comes <span class="cxcta-grad">Next.</span>
</h2>

    <p class="cxcta-intro">Security work is moving into AI assistants, automated pipelines, and multi-agent systems. The interface is changing. The workflows are changing. The expectations are changing. If AI becomes the interface for development, MCP becomes the interface for security. <strong>Checkmarx is already there.</strong></p>

    <div class="cxcta-actions">

      <!-- 🔗 LINK 1 of 2 · paste the MCP solution page URL into href="#" below -->
      <a class="cxcta-btn cxcta-btn--primary" href="https://checkmarx.com/solutions/checkmarx-mcp/">Explore the MCP Solution<span class="cxcta-arrow" aria-hidden="true">&rarr;</span></a>

      <!-- 🔗 LINK 2 of 2 · paste the Developer Assist trial URL into href="#" below -->
      <a class="cxcta-btn cxcta-btn--ghost" href="https://dev.checkmarx.com/free-trial/">Start a Free Developer Assist Trial</a>

    </div>

  </div>
</div>
<!-- ==================== END CHECKMARX CTA CARD ==================== -->]]></content:encoded>
					
		
		
		
	</item>
	</channel>
</rss>
