AI Code Security: Sandeep Johri on App Dev Risks

1h ago·0:00 listen·Source: Dark Reading

Summary

AI-generated code introduces a critical security risk in app development. Sandeep Johri, CEO of Checkmarx, states that this code has a higher density of security vulnerabilities. He warns that while AI coding assistants are used by nearly 99% of enterprises, the chance to build in security early is quickly diminishing. Johri explains that relying only on LLM-based scanning can lead to missed vulnerabilities and high false positive rates, sometimes up to 80%. This method can also be slow and expensive. He suggests a hybrid approach, combining deterministic and LLM-based scanning, is crucial for secure development. What's interesting is that AI-powered tools can also help. Johri believes these tools can transform how security teams prioritize and fix issues, offering developers automated fix recommendations. This allows organizations to manage risk across different applications. This information is important because it highlights the need for robust security measures as AI becomes more integrated into software creation.

Read the full article on Dark Reading

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening