Solutions
Platform
Checkmarx One Platform
SAST
SCA
AI Security
API Security
ASPM
Codebashing
Container Security
DAST
IaC Security
Malicious Package Protection
Repository Health
Secrets Detection
Solutions
Code to Cloud
Developer Experience
DevSecOps
Software Supply Chain Security
Services
Support
Services
Maturity Assessment
Plans and Packages
Partners
Partners
Our Partner Programs
Find a Partner
Programs
Channel Partners
GSI
Tech Partners
Existing Partners
Partner Portal
Academy
Partner Hub
Company
Checkmarx
About Us
Customers
Leadership
Awards & Recognition
News
Events
People
Careers at Checkmarx
Research
Checkmarx Zero
Get In Touch
Contact Us
Support Portal
Resources
Engage
Documentation
Packaging
Discover
Application Security Blog
Knowledge Hub
Case Studies
Events
News
Press Releases
E-books
White Papers
More resources
Checklist
Infographics & Interactives
Research & Reports
Solution Briefs
Videos
Webinars
Glossary
All Resources
Contact Us
Get a demo
Get a Demo
Technical Blog
March 30, 2023
CVE-2022-37734: graphql-java Denial-of-Service
Read More
March 17, 2023
From Zero to AppSec Anti-Hero: How AI Brings More Security Issues Than It Fixes
Read More
March 2, 2023
CocoaPods Subdomain Hijacked: This is How
Read More
February 21, 2023
How NPM Packages Were Used to Spread Phishing Links
Read More
February 14, 2023
Securing Open-Source Solutions: A Study of osTicket Vulnerabilities
Read More
February 1, 2023
Open Source vs Commercial AppSec Tools: Considerations for Enterprise
Read More
January 3, 2023
Exploiting GraphQL Query Depth
Read More
December 28, 2022
Alias and Directive Overloading in GraphQL
Read More
December 21, 2022
Didn’t Notice Your Rate Limiting: GraphQL Batching Attack
Read More
December 14, 2022
How 140k NuGet, NPM, and PyPi Packages Were Used to Spread Phishing Links
Read More
December 7, 2022
Move Over Verbose Error Messages, GraphQL APIs are Here
Read More
November 28, 2022
Attacker Uses a Popular TikTok Challenge to Lure Users Into Installing Malicious Package
Read More
November 28, 2022
What’s Old Becomes New Again: CSRF Attacks on GraphQL APIs
Read More
November 1, 2022
Analysis of OpenSSL CVE-2022-3786 and CVE-2022-3602
Read More
October 26, 2022
Attacking the Software Supply Chain with a Simple Rename
Read More
October 20, 2022
CVE-2022-42889: Text4shell Vulnerability Breakdown
Read More
October 7, 2022
LofyGang – Software Supply Chain Attackers; Organized, Persistent, and Operating for Over a Year
Read More
September 28, 2022
How We Created an API Security CTF
Read More
August 31, 2022
First Known Phishing Attack Against PyPi Users
Read More
August 26, 2022
Automatic Execution of Code Upon Package Download on Python Package Manager
Read More
August 22, 2022
Most Dangerous CWEs of 2021
Read More
August 17, 2022
Malicious PyPi User Strikes Again with Typosquatting, StarJacking and Unpacks Tailor-made Malware written in C#
Read More
August 14, 2022
Typosquatting Campaign Targeting Python’s Top Packages, Dropping GitHub Hosted Malware with DGA Capabilities
Read More
August 3, 2022
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware
Read More
July 15, 2022
Unverified Commits: Are You Unknowingly Trusting Attackers’ Code?
Read More
July 6, 2022
“CuteBoi” Detected Preparing a Large-Scale Crypto Mining Campaign on NPM Users
Read More
June 27, 2022
Spring Function Cloud DoS (CVE-2022-22979) and Unintended Function Invocation
Read More
June 14, 2022
CVE-2021-33420: NPM Replicator Remote Code Execution Deserialization
Read More
June 8, 2022
New Technique Used by Attackers in NPM to Avoid Detection
Read More
May 27, 2022
GitHub RepoJacking Weakness Exploited in the Wild by Attackers
Read More
May 25, 2022
Attacker Caught Hijacking Packages Using Multiple Techniques to Steal AWS Credentials
Read More
February 8, 2022
Our Response to NPM Account Takeover Attacks – ChainAlert, a Community-Backed Open Source Tool
Read More
February 3, 2021
Exploitable Path – How to Solve a Static Analysis Nightmare
Read More
August 24, 2020
Integrating Checkmarx Security Results within GitLab
Read More
August 18, 2020
You Better Get Going with Go
Read More
January 6, 2020
Breaking Down the OWASP API Security Top 10 (Part 2)
Read More
November 6, 2019
Breaking Down the OWASP API Security Top 10 (Part 1)
Read More
October 24, 2019
NFC False Tag Vulnerability – CVE-2019-9295
Read More
February 4, 2019
Your Smart Scale is Leaking More than Your Weight: Privacy Issues in IoT
Read More
December 20, 2018
Android WebView: Are Secure Coding Practices Being Followed?
Read More
May 7, 2018
Diving Deep into Regular Expression Denial of Service (ReDoS) in Go
Read More