Checkmarx Unveils Hybrid SAST Scanning Engine in Checkmarx One, Achieving Industry-Leading Accuracy and Cutting False Positives by 60 Percent

Checkmarx has launched a hybrid SAST scanning engine within Checkmarx One, combining deterministic analysis and AI-driven detection to achieve an F1 score of 0.64 and reduce false positives by 60 percent. The upgrade addresses rising risks from AI-generated code, improving accuracy, governance, and enterprise security outcomes.

 

Checkmarx, a global leader in agentic application security, has announced a major enhancement to its Checkmarx One platform with the introduction of a next-generation hybrid static application security testing scanning engine designed to deliver the highest level of detection fidelity in the industry. The development comes amid a rapidly escalating software security crisis driven by AI-accelerated coding practices, which are significantly increasing vulnerability exposure across enterprise environments.

The company stated that modern software development is facing unprecedented risk levels, as artificial intelligence is reshaping code creation at scale. According to industry observations cited by Checkmarx, nearly 49 percent of production code is now AI-generated and demonstrably more insecure, while exploit windows for vulnerabilities are shrinking dramatically from months to mere minutes. In this environment, traditional scanning methods alone are no longer sufficient to address evolving threats.

To address these challenges, Checkmarx has introduced a hybrid scanning architecture within Checkmarx One that integrates three core layers of protection. The first is a deterministic rules-based scanning foundation, refined over two decades of enterprise application security expertise. The second is a purpose-tuned large language model engine designed to extend detection capabilities to AI-generated code, emerging programming languages, and complex polyglot codebases. The third layer is the Finding Analysis Engine, which evaluates raw security findings to confirm true positives while suppressing false positives before results are delivered to developers.

Checkmarx Chief Executive Officer Sandeep Johri emphasized that no single approach can fully address modern application security challenges, noting that deterministic analysis provides precision while AI-driven techniques expand coverage into previously unsupported code environments. He further highlighted that combining both approaches within a unified architecture is essential to reduce noise and improve actionable security outcomes at scale.

Read More Bajaj Finance Personal Loan Eligibility Calculator Helps Borrowers Assess Loan Capacity Before Applying

In internal head-to-head testing across seven production codebases, the new hybrid engine achieved an F1 score of 0.64, which is more than three times higher than the average score of 0.20 recorded across competing approaches evaluated by Checkmarx. The system also reduced false positives by 60 percent, enabling development teams to focus on high-confidence vulnerabilities that are genuinely exploitable rather than being overwhelmed by excessive security alerts.

Read More Prateek Group Records Over Rs. 300 Crore Sales in Q4 FY26 as NCR Housing Demand Strengthens

The new Finding Analysis Engine plays a central role in this improvement by reasoning over every detected issue, filtering out false positives, and confirming real vulnerabilities. The system is designed to transform raw security signals into high-fidelity outputs that can be acted upon immediately by engineering teams. In addition, the platform supports language-agnostic scanning, enabling coverage across all programming languages, including those introduced or heavily used through AI-assisted development, without compromising accuracy in established codebases.

Read More Parimatch Sports Appoints Cricketer Nikhil Chaudhary as Brand Ambassador Following Breakthrough Big Bash League Rise

Checkmarx also highlighted the importance of defensible governance within the updated system, providing board-level evidence of exploitability and resolution status based on real attack potential rather than raw vulnerability counts. This approach is intended to support more informed risk decision-making at the executive level.

Chief Product Officer Jonathan Rende stated that while artificial intelligence has significantly improved developer productivity, independent evaluations show that a substantial proportion of AI-generated code remains insecure. He also noted that conventional tools often struggle with excessive compute consumption due to false positives. The new system, he said, is designed to provide confidence, predictability, and cost efficiency by prioritizing meaningful vulnerabilities and eliminating unnecessary noise.

The hybrid scanning engine and Finding Analysis Engine are currently available in early access as part of the Checkmarx One platform. The company’s broader platform reportedly scans trillions of lines of code annually and has helped reduce vulnerability density by more than half across enterprise environments. Checkmarx also announced that further details will be discussed at its upcoming virtual summit, “Agentic AppSec Unleashed ’26,” scheduled for June 16, 2026.

In conclusion, Checkmarx’s latest advancement reflects a significant shift in application security strategy, combining deterministic precision with artificial intelligence-driven adaptability to address the escalating risks introduced by AI-generated software development, while aiming to deliver higher accuracy, reduced noise, and stronger enterprise-grade governance across modern development pipelines.

 

Tags:

About The Author

Post Comment

Comment List

Latest News

Live Cricket Score

Advertisement

Science & Tech

Tesla Begins Deliveries of Model Y L in India, Marking Major Expansion in Premium Electric SUV Segment Tesla Begins Deliveries of Model Y L in India, Marking Major Expansion in Premium Electric SUV Segment
Tesla has begun deliveries of the Model Y L in India, marking a key expansion in its premium electric SUV...
Mercedes-Benz Unveils 2026 S-Class Facelift in India at Rs 2.20 Crore, Introduces Plug-in Hybrid Flagship Sedan

Health

Coffee-Based Home Remedies Gain Ground as Dermatologists Highlight Natural Skincare Benefits Coffee-Based Home Remedies Gain Ground as Dermatologists Highlight Natural Skincare Benefits
A growing number of dermatologists are endorsing coffee-based home remedies as natural, affordable alternatives to commercial skincare. From face scrubs...
Moringa’s Rise as a Global Superfood Gains Momentum Amid New Research

Lifestyle

 Food Pharmer Sparks Nationwide Debate Over Cheeslings Ingredients, Raises Questions on Food Safety Standards Food Pharmer Sparks Nationwide Debate Over Cheeslings Ingredients, Raises Questions on Food Safety Standards
Food influencer Revant Himatsingka, known as Food Pharmer, has sparked nationwide debate after revealing Cheeslings’ low cheese content and high...
From Gym Floor to City Streets: The Unexpected Revival of the Lopifit Treadmill-Bike
crossorigin="anonymous">