New hybrid engine triples the industry’s average fidelity score while cutting false positives by 60%
PARAMUS, N.J., June 15, 2026 (GLOBE NEWSWIRE) -- Checkmarx, the global leader in agentic application security, today announced a major advancement to the Checkmarx One platform: a new hybrid static application security testing (SAST) scanning engine set to deliver the industry’s highest fidelity, known in the industry as an F1 score. AI-accelerated development is driving an unprecedented surge in software vulnerabilities, leaving organizations facing a tsunami of risk that no single scanning approach can address alone.
Neither rules-based analysis nor AI models tell the whole story alone. Deterministic scanning is the precision standard for the languages it covers, but AI-assisted development has introduced new and emerging languages that fall outside any fixed rule set. AI extends coverage to that new ground. However, scanning at volume surfaces findings faster than teams can act on them, burying the vulnerabilities that matter in noise. Today, 49% of code in production is AI generated and measurably more insecure, and exploit windows collapsing from months to minutes. Organizations need both the precision of deterministic analysis and the reach of AI.
To meet this moment, Checkmarx is introducing a new next generation SAST hybrid scanning engine within Checkmarx One. It combines three layers of protection: a deterministic rules-based foundation refined over two decades of enterprise AppSec; a purpose-tuned LLM engine that extends that proven foundation to any language, including AI-generated code and emerging languages; and the new Finding Analysis Engine (FAE), which confirms true positives and suppresses false ones before a single finding reaches a developer.
“No single approach – rules-based or AI – tells the whole story on its own,” said Sandeep Johri, CEO of Checkmarx. “Deterministic scanning has earned its place as the precision standard, and AI extends that reach to code the rules were never written for. But neither alone separates the findings that matter from the ones that don't. At today's volumes, that noise is what slows teams down and drives up cost. Checkmarx One’s hybrid engines bring together the best of both in a fundamentally different architecture.”
In head-to-head testing across seven real production codebases, Checkmarx One’s hybrid engine achieved an F1 score of 0.64 – more than three times the 0.20 average across competing approaches that Checkmarx evaluated – while reducing false positives by 60%. The result: teams cut through massive findings volumes to high-confidence signals, focus remediation on what is genuinely exploitable, and stay protected as AI-generated code keeps introducing new risk.
Key capabilities of the new Checkmarx One hybrid scanning engine include:
- Finding Analysis Engine (FAE): Reasons over every raw finding, suppressing false positives and confirming true ones – turning raw signals into high-fidelity results teams can act on immediately.
- Language-agnostic scanning: Extends proven detection to any language, including AI-generated code, emerging languages, and polyglot codebases (applications that combine multiple programming languages) – closing the new gaps that AI coding assistants introduce without sacrificing precision on established ones.
- Defensible governance: Board-grade evidence of what is exploitable and what has been resolved, anchored to real attackability rather than raw counts – so leaders can make risk decisions.
“AI has handed developers an unprecedented productivity boost, but independent benchmarks show that even the best models produce insecure code in a third to nearly half of cases – and the tools meant to catch it can burn through compute budgets chasing false positives,” said Jonathan Rende, Chief Product Officer at Checkmarx. “What teams need isn’t just more findings, it’s confidence and predictability: surfacing the vulnerabilities that truly matter, eliminating the noise, and doing it without blowing past budgets. That’s the assurance Checkmarx One now gives every customer – the highest fidelity in the industry, with the economics to match.”
The new hybrid scanning engines and Finding Analysis Engine are available in early access now as part of the Checkmarx One platform. For more information, visit checkmarx.com or join the upcoming virtual summit Agentic AppSec Unleashed ’26 on June 16, 2026.
About Checkmarx
Checkmarx is the leader in agentic application security, delivering enterprise-grade protection while lowering engineering costs and accelerating development velocity. The Checkmarx One platform scans trillions of lines of code each year for companies, cutting vulnerability density by more than half. Its autonomous security agents detect and counter AI-driven threats across the SDLC, providing prevention-first protection for legacy, modern, and AI-generated code at enterprise scale. Follow Checkmarx on LinkedIn, YouTube, and X.
For more information:
PR@checkmarx.com
-
从消费者真实反馈出发,博西家电618深化高端家电本土化实践今年618,家电消费正在从单纯产品功能、价格比较,转向对家庭生活质量的综合判断。尤其在厨房、洗护与餐后清洁等高频场景中,消费者对产品的期待进一步延伸到空间是否2026-06-15
-
博西家电“AI家电管家”斩获CXOU 100人工智能案例奖6月12日,2026 CXOU AI未来大会在上海举行,CXOU 100颁奖典礼同期举办。CXOU 100评选聚焦人工智能与数字化转型领域的创新实践,旨在发掘具有技术应用价值与行业示范意2026-06-15
-
海信RGB MiniLED助力2026年国际足联世界杯™国际广播中心VAR执裁工作中国青岛2026年6月15日 美通社 -- 全球消费电子与家电领域的领先品牌海信作为2026年国际足联世界杯™(FIFA World Cup 2026™ )视频助理裁判(VAR)显示设备供应商,进一步2026-06-15
-
抗癌黑科技再升级:美杰医疗多模态肿瘤治疗技术“i”系列全球首发上海2026年6月15日 美通社 -- 盛夏姑苏,高朋满座。2026年6月11日至14日,第二十届亚太心血管与介入放射学术大会(APSCVIR 2026)在苏州国际博览中心盛大举行。大会由中国2026-06-15
-
和铂医药携手百图生科发起共建MegaStream TechBio:全球药物开发领导平台遇上最强生命科学基础大模型,共同定义复杂大分子AI研发新基准中国上海、美国马萨诸塞州剑桥和荷兰鹿特丹2026年6月15日 美通社 -- 和铂医药(股票代码:02142.HK),一家专注于免疫性疾病、肿瘤及其他领域创新抗体疗法发现及开发的全2026-06-15
-
AMD股价暴跌17%创近9年之最,苏姿丰紧急回应:AI增速远超想象
-
Ledger 中国销售渠道说明:广州馨潇贸易有限公司官方直营渠道公示
-
江苏省脑机接口产业联盟在宁成立,麦澜德分享前沿成果
-
艾芬达入选国家知识产权强国建设示范创建对象:二十载长期主义,兑现每一份用户价值
-
Esentia宣布成功完成2033年到期的6.125%优先票据和2038年到期的6.500%优先票据的定价
-
中荷人寿北京分公司成功举办中荷创享家品牌发布暨协同发展启航仪式
-
华为系具身智能公司具脑磐石完成新一轮融资:对标JEPA,押注类脑智能的认知世界模型
-
北京暑假补习班有哪些?家长首推一对一权威机构金博升学
-
上海高新技术企业代理机构深度访谈与推荐
-
2026 雷瓦亮相京东 MALL ,匠心筑造专业造型新标杆
