Checkmarx
PulseAugur coverage of Checkmarx — every cluster mentioning Checkmarx across labs, papers, and developer communities, ranked by signal.
-
Developers knowingly ship vulnerable AI-generated code due to deployment pressure
A survey of 2,350 developers and CISOs by Checkmarx reveals that 30% knowingly ship vulnerable code to production. A significant majority, 70%, believe AI-generated code contains more vulnerabilities but still deploy it…
-
Automated Security Testing Tools Crucial for Modern DevSecOps
The article discusses the critical role of automated security testing tools in modern DevSecOps environments. It highlights how the rapid pace of code development and deployment necessitates these tools to identify vuln…
-
Trellix source code breach exposes supply chain and CI/CD weaknesses
Security vendor Trellix has confirmed a breach where attackers accessed a portion of its source code, highlighting systemic weaknesses in software supply chains. This incident, alongside similar breaches at companies li…
-
Checkmarx uncovers TeamPCP sabotage of Jenkins plugin
Security researchers at Checkmarx have identified a new supply chain attack targeting the Jenkins CI/CD platform. Threat actors known as TeamPCP are exploiting a vulnerability in a Jenkins plugin to compromise developer…