AI finding zero-days makes for a great headline, but what actually happens when you put LLM-based vulnerability hunting to the test? Our Checkmarx Zero research team did exactly that, taking a deep look at Claude Opus 4.6 and its “security-review” capabilities to understand where it truly delivers value… and where important limits show up. The findings are nuanced. LLMs can surface real issues, but they can also miss vulnerabilities, inflate false positives, and struggle without a tightly-scoped context. This isn’t about hype. It’s about helping security teams make informed decisions. Read the full breakdown: https://lnkd.in/eBzMNsmY
About us
Checkmarx helps the world’s largest enterprises get ahead of application risk without slowing down development. We end the guesswork by identifying the most critical issues to fix and give AppSec the tools they need, all while letting developers work the way they want. From DevSecOps to developer experience, security and development teams can now work better together. That’s why 1700+ customers rely on Checkmarx to scan over 1 trillion lines of code annually, improve developer productivity by 50%, and deliver 2X AppSec ROI. Checkmarx. Always Ready To Run.
- Website
-
http://www.checkmarx.com
External link for Checkmarx
- Industry
- Computer and Network Security
- Company size
- 501-1,000 employees
- Headquarters
- Paramus, New Jersey
- Type
- Privately Held
- Founded
- 2006
- Specialties
- Application Security, AppSec, Software Security, DevOps, Application Security Testing, Static Application Security Testing, Interactive Application Security Testing, Software Composition Analysis, Developer Training, and DevSecOps
Locations
-
Primary
Get directions
140 E Ridgewood Ave
South Tower Suite 415
Paramus, New Jersey 07652, US
Employees at Checkmarx
Updates
-
When everything is labeled “critical,” nothing actually is. AppSec teams aren’t struggling to find vulnerabilities. They’re drowning in them. Every tool flags something. Every finding looks urgent. Developers lose clarity, and real risk slips through. In this piece, Emma Datny breaks down why severity alone isn’t enough and how contextual risk scoring helps teams focus on what actually matters. Because “critical” doesn’t always mean urgent. Read more: https://lnkd.in/e8hnR7GV
-
-
AI code security is becoming a category of its own. Claude’s Code Security announcement is a clear sign that AI-generated code is reshaping how detection works inside the IDE. That’s progress. But the bigger conversation isn’t just about finding vulnerabilities differently. It’s about securing an AI-driven development lifecycle end-to-end. From generation → to triage → to remediation → to governance. That’s where the real transformation is happening. 🚀 Eran Kinsbruner breaks down what this shift means for modern AppSec teams 👇https://lnkd.in/ePaPi73d #agenticapplicationsecurity #agenticappsec
-
-
AI is reshaping how software is built and how risk enters the system. On March 11, we’re partnering with Archipelo to explore what this shift means for modern security teams. Save the date. Registration details coming soon.
🚨 Save the Date — March 11, 2026 (1:00 PM ET) | Live Webinar On March 11, Archipelo and Checkmarx will present how vulnerability findings can be correlated with development-origin context — including developer identity, actions, workflow metadata, and code provenance — to help teams understand how risk entered the system. AI-assisted development changes how software risk is created — but security tools still focus on where vulnerabilities exist, not how they entered the system. Modern production code is produced by multiple actors: - human developers - human developers using AI - autonomous agents - automated workflows Security teams increasingly need to understand: - who initiated the change - whether AI participated - what workflow conditions contributed Registration details to follow. #DevSPM #Cybersecurity #Archipelo #Checkmarx #DevSecOps #AI #AISecurity #GRC #Security #CISO #CTO #CIO #Compliance #DevSIEM #DevDR #ShiftLeft #AICoding #VibeCoding #ASPM
-
-
Today, engineers are configuring agents that generate and iterate on code at machine speed. When that happens, security can’t just show up after commit and hope to catch up. If AppSec isn’t part of the generation loop, it becomes the cleanup crew. We wrote about what this shift really means for roles, ownership, and security in 2026 and why the Agentic Development Lifecycle changes more than most teams realize. Full breakdown in our newsletter. 👇 #agenticapplicationsecurity #agenticappsec
-
#RSAC 2026 is almost here, and we’re showing up big. We’ll be in San Francisco March 23–26 with live demos, new launches, and real conversations about where AppSec is headed next. See you there: https://lnkd.in/etgUQ-BG #AgenticAppSec #AgenticApplicationSecurity
-
We’re bringing IDE-native, agentic application security to Kiro. 🚀 With new support directly in an AI-powered IDE, Checkmarx Developer Assist brings real-time security insight directly into AWS Kiro, right where developers are already working. No jumping between tools or waiting on downstream scans. Developer Assist runs directly in the Kiro workflow, helping developers spot and fix issues as code is written, while AppSec teams still get centralized visibility and control through Checkmarx One. The result: teams can move faster with AI-assisted development, without pushing risk to the end of the pipeline or slowing delivery. Learn more: https://lnkd.in/eGQpztg4
-
-
AI writes the code. Who guides the risk? As more developers lean on AI to move faster, the real challenge isn’t speed. It’s stopping insecure patterns from quietly sneaking into production. Checkmarx Developer Assist analyzes AI-generated code in real time, directly in the IDE, so AI-introduced risk gets caught early. 👉 Free trial now available: https://lnkd.in/e2hDu8mR #agenticapplicationsecurity #agenticappsec