{"id":108738,"date":"2026-05-14T08:57:37","date_gmt":"2026-05-14T06:57:37","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?p=108738"},"modified":"2026-05-14T08:57:39","modified_gmt":"2026-05-14T06:57:39","slug":"somethings-wrong-with-your-code-and-attackers-know-it","status":"publish","type":"post","link":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/","title":{"rendered":"Something\u2019s Wrong With Your Code. And Attackers Know It."},"content":{"rendered":"<p>Picture this: you ask an AI to write a novel and it can deliver it in under an hour. And that\u2019s really impressive \u2013 until you read it closely. The plot drifts, key details contradict each other, some ideas vanish halfway through, while others appear out of nowhere.<\/p>\n\n\n\n<p>Now imagine handing that novel to a meticulous editor whose only job is to find every flaw. You\u2019re in trouble.<\/p>\n\n\n\n<p>That\u2019s the analogy <a href=\"https:\/\/www.youtube.com\/watch?v=_O1VTfWu8Xo\">Checkmarx CEO Sandeep Johri used in his recent conversation with the New York Stock Exchange (NYSE)<\/a>, and it captures what&#8217;s happening to modern codebases. AI is accelerating software creation at a staggering pace, but it\u2019s also introducing inconsistencies, blind spots, and unintended behavior just as quickly. And unlike a novel, your code doesn\u2019t get a friendly editor; it gets attackers actively searching for those gaps.<\/p>\n\n\n\n<p>According to Johri, the volume of AI-generated code is growing faster than the security programs designed to protect it. The result is that developers are no longer just building software, they\u2019re also responsible for securing a much larger and more complex codebase.<\/p>\n\n\n\n<p>And the stakes are rising.<\/p>\n\n\n\n<p>With systems like <a href=\"https:\/\/checkmarx.com\/blog\/checkmarx-application-security-guide-to-claude-mythos\/\">Anthropic\u2019s Claude Mythos<\/a> reportedly capable of autonomously discovering and exploiting vulnerabilities at unprecedented speed and scale, the imbalance is only getting worse.<\/p>\n\n\n\n<p>The question isn\u2019t whether your code has gaps; it\u2019s whether your security can keep up with how fast they\u2019re being created and how quickly someone else can find them.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\">More\u00a0Code,\u00a0More\u00a0Risk\u00a0<\/h2>\n\n\n\n<p>Johri\u2019s core point is straightforward: AI coding agents are producing more code \u2013 and more vulnerabilities. In fact, AI-generated code can contain two to three times the density of vulnerabilities compared to code written solely by humans, and the overall volume is growing fast.<\/p>\n\n\n\n<p>Before AI, developers had a deep understanding of the code they wrote. Now, a single prompt can generate hundreds of lines instantly. The code works, but the context behind it \u2013 the decisions, trade-offs, and potential risks \u2013 is often missing.<\/p>\n\n\n\n<p>Open source adds another layer. <strong>Roughly 70% of a typical enterprise application is made up of open-source components<\/strong>. Developers rely on it to move quickly, trusting that the code has been properly maintained and secured upstream. Sometimes that trust is well placed, but other times vulnerabilities or malicious code slip through.<\/p>\n\n\n\n<p>The result is a growing backlog of risk. According to <a href=\"https:\/\/checkmarx.com\/report-future-of-appsec-2025\/\">Checkmarx\u2019s Future of Application Security report<\/a>, <strong>81% of organizations knowingly ship software with vulnerabilities they\u2019ve already identified<\/strong>. These aren\u2019t unknown threats or zero-days, they\u2019re known issues that get deprioritized in favor of speed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\">Developers Are in the Crosshairs<\/h2>\n\n\n\n<p>Developers are at the center of this problem because that\u2019s where code begins. But most developers aren\u2019t security experts \u2013 and they shouldn\u2019t have to be. Their job and discipline is to build the functionality the business needs, and to build it fast. Security has historically been a separate discipline, applied after the fact, by a completely different team. But in the age of AI, later is really just too late.<\/p>\n\n\n\n<p>What\u2019s changed is the level of exposure. Because now developers aren\u2019t just introducing risk, they\u2019re being directly targeted. Attackers go after their package registries, plant malicious open-source dependencies, and compromise their credentials to gain access to codebases. The developer\u2019s entire workflow \u2013 the IDE, the coding assistant, the dependencies \u2013 has become the attack surface.<\/p>\n\n\n\n<p><a href=\"https:\/\/checkmarx.com\/blog\/checkmarx-application-security-guide-to-claude-mythos\/\">Anthropic\u2019s Claude Mythos<\/a> makes this shift even harder to ignore. When Mythos found a 27-year-old bug in OpenBSD and catalogued vulnerabilities across major open-source dependencies, it wasn\u2019t finding anything new. Those vulnerabilities were already there, sitting in production systems that developers had built on top of for years. What Mythos demonstrated is that finding and exploiting them is now fast, automatic, and cheap \u2013 <strong>roughly $1 per exploit in 10 to 15 minutes with no specialized expertise required.<\/strong><\/p>\n\n\n\n<p>And these vulnerabilities that developers unknowingly ship won\u2019t sit idle anymore. With AI, the window between disclosure and active exploitation has shrunk, from roughly <strong>840 days in 2018 to about 1.6 days today<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" width=\"922\" height=\"582\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/image-3.png\" alt=\"\" class=\"wp-image-108779\" style=\"aspect-ratio:1.584205097981435;width:699px;height:auto\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/image-3.png 922w, https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/image-3-300x189.png 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/image-3-768x485.png 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/image-3-400x252.png 400w\" sizes=\"(max-width: 922px) 100vw, 922px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\">AI Is Also Creating New Threats<\/h2>\n\n\n\n<p>AI development isn\u2019t just introducing more vulnerabilities, but it\u2019s also introducing entirely new kinds of risk.<\/p>\n\n\n\n<p>Coding assistants can hallucinate package names that don\u2019t exist, and attackers are already registering those names to turn a simple mistake into a malicious dependency. Applications that pass user input into LLMs are now exposed to prompt injection, an entirely new attack vector with no real equivalent in traditional software. And as development becomes more agent-driven, with AI systems taking actions through MCP servers, the attack surface is expanding beyond what conventional security tools were designed to handle.<\/p>\n\n\n\n<p>Some coding tools are starting to layer in security features, but as Johri points out, they don\u2019t do it as exhaustively or with the full enterprise context of purpose-built AppSec platforms \u2013 and that includes Claude Code Security.<\/p>\n\n\n\n<p>As AI-driven development accelerates, closing this gap will require security tools built specifically for how software is being created today, not how it was built before in the pre-AI era.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-4\">Security Has To Become Agentic Too<\/h2>\n\n\n\n<p>Johri\u2019s conclusion is simple: application security needs to become agentic. The human-in-the-loop model that\u2019s worked until now can\u2019t keep pace with the velocity of AI-generated code. Agents generating code need security tools that can be called automatically, integrated into the pipeline, and capable of acting on what they find rather than just flagging it for someone to review later.<\/p>\n\n\n\n<p>That urgency is reinforced by developments like Anthropic\u2019s Project Glasswing, a coalition of 40+ technology organizations built around using Mythos defensively. It\u2019s a clear signal that the industry sees what\u2019s coming \u2013 but a coalition isn\u2019t the same thing as a security program.<\/p>\n\n\n\n<p>What\u2019s really needed in this new age is a hybrid approach that combines AI\u2019s speed and scale with deterministic analysis that doesn\u2019t hallucinate. On its own, AI scanning produces findings that erode trust: it will flag an exception already caught upstream, describing a race condition in single-threaded code. Without a rules-based SAST, SCA, and IaC layer to validate what the AI finds, you\u2019re just generating noise at scale.<\/p>\n\n\n\n<p>And timing is just as important. Security has to begin at the moment code is created, while context still exists. In AI-driven development, even a short delay means that context is gone. And when vulnerabilities are found later, developers have to revisit code they\u2019ve already moved past and no longer have the context for \u2013 and that retrace slows everything down and increases the chance risk will slip through.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-5\">Keeping Up With the Code<\/h2>\n\n\n\n<p>The takeaway here is that AI is accelerating how code is written, but security isn\u2019t keeping up. More code, less context, and faster exploitation are all converging at once \u2013 and with the recent Mythos announcement, that gap is widening.<\/p>\n\n\n\n<p>The good news is that slowing down development isn\u2019t the answer. The path forward is bringing security into the same flow as development for a more seamless experience: integrated, automated, and able to keep pace with how code is created.<\/p>\n\n\n\n<p>That\u2019s where agentic application security comes in. It needs to move beyond detection to help developers understand, prioritize, and remediate issues in real time, without adding friction or noise.<\/p>\n\n\n\n<p>Watch the full interview <a href=\"https:\/\/www.youtube.com\/watch?v=_O1VTfWu8Xo\">here<\/a>, or learn more about how <a href=\"https:\/\/checkmarx.com\/product\/checkmarx-one-assist\/\">Checkmarx One<\/a> is tackling this with <a href=\"https:\/\/checkmarx.com\/product\/developer-assist\/\">Developer Assist<\/a>, <a href=\"https:\/\/checkmarx.com\/product\/triage-and-remediation\/\">Triage Assist<\/a>, and <a href=\"https:\/\/checkmarx.com\/product\/triage-and-remediation\/\">Remediation Assist<\/a>.<\/p>\n\n\n<section class=\"dark-theme section-video light-theme-2\">\n    <div class=\"main-wrapper section-video__wrapper\">\n        <div class=\"left\">\n\t\t\t        <\/div>\n        <div class=\"right\">\n            <div class=\"video-container\">\n                <div class=\"show-video\">\n\t\t\t\t\t\t\t\t\t<iframe src=\"https:\/\/www.youtube.com\/embed\/_O1VTfWu8Xo?autoplay=1&#038;enablejsapi=1\" title=\"YouTube video player\" frameborder=\"0\" allow=\"autoplay\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>                <\/div>\n            <\/div>\n        <\/div>\n    <\/div>\n<\/section>","protected":false},"excerpt":{"rendered":"<p>Checkmarx CEO Sandeep Johri shares insights from a recent conversation with the New York Stock Exchange (NYSE) on how AI is reshaping modern codebases.<\/p>\n","protected":false},"author":11,"featured_media":108780,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":true,"footnotes":""},"categories":[85,84],"tags":[1272,142,87,395,403],"class_list":["post-108738","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-application-security-trends","category-blog","tag-agentic-ai","tag-application-security-testing","tag-appsec","tag-awareness","tag-leadership"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Something\u2019s Wrong With Your Code. And Attackers Know It.<\/title>\n<meta name=\"description\" content=\"AppSec needs to move beyond detection to help developers prioritize and remediate issues in real time, without adding friction or noise.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Something\u2019s Wrong With Your Code. And Attackers Know It.\" \/>\n<meta property=\"og:description\" content=\"AppSec needs to move beyond detection to help developers prioritize and remediate issues in real time, without adding friction or noise.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-14T06:57:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-14T06:57:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/Copy-of-Blog-Banner-1-_5_-1024x512.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"512\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Checkmarx Team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Checkmarx Team\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/\"},\"author\":{\"name\":\"Checkmarx Team\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/25482b0b490209da942049e2c8b0d3aa\"},\"headline\":\"Something\u2019s Wrong With Your Code. And Attackers Know It.\",\"datePublished\":\"2026-05-14T06:57:37+00:00\",\"dateModified\":\"2026-05-14T06:57:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/\"},\"wordCount\":1246,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/Copy-of-Blog-Banner-1-_5_.webp\",\"keywords\":[\"Agentic AI\",\"Application Security Testing\",\"AppSec\",\"Awareness\",\"Leadership\"],\"articleSection\":[\"Application Security Trends &amp; Insights\",\"Blog\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/\",\"url\":\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/\",\"name\":\"Something\u2019s Wrong With Your Code. And Attackers Know It.\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/Copy-of-Blog-Banner-1-_5_.webp\",\"datePublished\":\"2026-05-14T06:57:37+00:00\",\"dateModified\":\"2026-05-14T06:57:39+00:00\",\"description\":\"AppSec needs to move beyond detection to help developers prioritize and remediate issues in real time, without adding friction or noise.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/Copy-of-Blog-Banner-1-_5_.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/Copy-of-Blog-Banner-1-_5_.webp\",\"width\":2560,\"height\":1280,\"caption\":\"AI risk and modern code\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/25482b0b490209da942049e2c8b0d3aa\",\"name\":\"Checkmarx Team\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/cropped-cx_favicon-150x150.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/cropped-cx_favicon-150x150.webp\",\"caption\":\"Checkmarx Team\"},\"url\":\"https:\/\/checkmarx.com\/author\/checkmarx-team\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Something\u2019s Wrong With Your Code. And Attackers Know It.","description":"AppSec needs to move beyond detection to help developers prioritize and remediate issues in real time, without adding friction or noise.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/","og_locale":"en_US","og_type":"article","og_title":"Something\u2019s Wrong With Your Code. And Attackers Know It.","og_description":"AppSec needs to move beyond detection to help developers prioritize and remediate issues in real time, without adding friction or noise.","og_url":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_published_time":"2026-05-14T06:57:37+00:00","article_modified_time":"2026-05-14T06:57:39+00:00","og_image":[{"width":1024,"height":512,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/Copy-of-Blog-Banner-1-_5_-1024x512.webp","type":"image\/webp"}],"author":"Checkmarx Team","twitter_card":"summary_large_image","twitter_creator":"@checkmarx","twitter_site":"@checkmarx","twitter_misc":{"Written by":"Checkmarx Team","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/"},"author":{"name":"Checkmarx Team","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/25482b0b490209da942049e2c8b0d3aa"},"headline":"Something\u2019s Wrong With Your Code. And Attackers Know It.","datePublished":"2026-05-14T06:57:37+00:00","dateModified":"2026-05-14T06:57:39+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/"},"wordCount":1246,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/Copy-of-Blog-Banner-1-_5_.webp","keywords":["Agentic AI","Application Security Testing","AppSec","Awareness","Leadership"],"articleSection":["Application Security Trends &amp; Insights","Blog"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/","url":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/","name":"Something\u2019s Wrong With Your Code. And Attackers Know It.","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/Copy-of-Blog-Banner-1-_5_.webp","datePublished":"2026-05-14T06:57:37+00:00","dateModified":"2026-05-14T06:57:39+00:00","description":"AppSec needs to move beyond detection to help developers prioritize and remediate issues in real time, without adding friction or noise.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/blog\/somethings-wrong-with-your-code-and-attackers-know-it\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/Copy-of-Blog-Banner-1-_5_.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/05\/Copy-of-Blog-Banner-1-_5_.webp","width":2560,"height":1280,"caption":"AI risk and modern code"},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/25482b0b490209da942049e2c8b0d3aa","name":"Checkmarx Team","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/cropped-cx_favicon-150x150.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/cropped-cx_favicon-150x150.webp","caption":"Checkmarx Team"},"url":"https:\/\/checkmarx.com\/author\/checkmarx-team\/"}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/108738","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/comments?post=108738"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/108738\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/108780"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=108738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/categories?post=108738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/tags?post=108738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}