Vulnerability

Category //

Vulnerability

Introducing AI Query Builder for SAST 

How SAST is customized for different applications Today, Checkmarx SAST provides tremendous flexibility  to scan applications based on how they are built. This is done using two constructs: Queries are building blocks for identifying potential vulnerabilities and critical for filtering

Read More »

Ericsson Sensitive Data Exposure via Trace.axd 

Research by David Sopas and João Morais  Checkmarx Security Research team reached out to Ericsson’s Responsible Disclosure Program, notifying them of the the finding on 14th March 2023. Ericsson acknowledged the finding and replied  that the issue was fixed on 11th April

Read More »

Apache Log4j Remote Code Execution – CVE-2021-44228

On December 9th, the most critical zero-day exploit in recent years was discovered affecting most of the biggest enterprise companies. This critical 0-day exploit was discovered in the extremely popular Java logging library log4j which allows RCE (Remote code execution)

Read More »

Recently Discovered Supply-chain Worm

Malicious Python Packages with Self-spreading Capabilities Caught Stealing Browser Credentials, Discord Tokens, and System Information. The malicious package is able to steal the user’s password from their Chrome browser, along with Discord tokens and system information, and exfiltrate this data

Read More »
Skip to content