Seville, Spain
Seville, Spain
+(34) 624 816 969
Table of contents [Show]
Major SAST (Static Application Security Testing) providers are integrating large language models (LLMs) into their traditional scanning engines. Checkmarx, however, takes a different approach: the engine is not about the LLM itself, but about what happens after the analysis. The company has launched a new SAST engine that uses AI to prioritize and contextualize vulnerabilities, reducing false positives and accelerating remediation.

For operations and development teams, this means less noise and more action. The new engine not only detects flaws but also provides natural language explanations and suggests patches. This speeds up review cycles and allows developers to understand the risk without being security experts. Additionally, integration with CI/CD pipelines is smoother, as the analysis adapts to the project context.

From a business perspective, reducing false positives decreases time wasted on unnecessary investigations, resulting in cost savings and faster delivery. Moreover, the ability to prioritize critical vulnerabilities allows security teams to focus on what truly matters, improving the overall security posture. Checkmarx bets on an approach where AI is not the end, but the means to smarter remediation.

This move by Checkmarx reflects a broader trend: generative AI is transforming the developer's role, as we explored in our analysis on the developer as a solution architect. Code security is no longer a separate step but an integrated part of the software lifecycle. For system administrators, understanding these tools is key to maintaining secure and efficient environments.
Source: The New Stack. Analysis by ForgeNEX.