Blog

Security writing from Corgea

Engineering-focused posts on code security, remediation workflows, and product updates.

Showing 20 of 54 posts

Corgea Reporting: Security and Developer Insights in One View

Track code, dependency, code quality, IaC, scan activity, aging, and developer insights in one place. Filter reporting by project, tags, and time to see trends clearly.

Corgea Security Team Corgea Security Team
Mar 6, 2026 • Product

New Integration: Bitbucket

Connect Corgea to Bitbucket in a day with an API-native integration—no CI/CD setup. Scan repos, get PR feedback, use Corgea Agent in Bitbucket, and open fix pull requests automa...

Corgea Security Team Corgea Security Team
Feb 26, 2026 • Product

New in Corgea: Container Scanning + IaC Scanning

Scan container images for known CVEs and catch IaC misconfigurations before deploy. Corgea adds container/image scanning and Infrastructure as Code scanning for AppSec and devel...

Corgea Security Team Corgea Security Team
Feb 25, 2026 • Product

New Feature: Corgea Agent

Corgea Agent brings security into pull requests so developers can triage findings without leaving their workflow. Security teams get auditable feedback history and insights in t...

Corgea Security Team Corgea Security Team
Feb 24, 2026 • Product

New Product: Code Quality

Code Quality in Corgea finds high-confidence code quality issues using multi-file context and CWE-based categorization, with optional automated fixes. Try it now or book a demo.

Corgea Security Team Corgea Security Team
Feb 23, 2026 • Product

AI Application Security: How AI Is Transforming AppSec in 2026

Codebases are growing faster than security headcount, scanner output is a firehose of noise, and developers treat security findings like spam. AI application security is the fir...

Corgea Security Team Corgea Security Team
Feb 17, 2026 • Product

Best Java Static Code Analyzer: Top Tools Ranked

Best Java static analyzer tools ranked for security and CI/CD, comparison table, pitfalls, configs, and a worked example.

Corgea Security Team Corgea Security Team
Feb 4, 2026 • Product

Top 6 AI SAST tools in 2026

Discover the top AI SAST tools for 2026. Compare Corgea, Checkmarx, Veracode, Snyk, Semgrep, and Qwiet AI—AI triage, noise reduction, and fix guidance.

Corgea Security Team Corgea Security Team
Feb 2, 2026 • Product

Here's what happening the last 72-hours: 700+ Packages Compromised from Shai-Hulud 2.0 Worm (November 25, 2025)

Critical npm worm compromises 700+ packages including Zapier, PostHog, and Postman. 25,000+ GitHub repos infected, exposing 775+ tokens. Immediate mitigation steps inside.

Corgea Security Team Corgea Security Team
Nov 25, 2025 • Product

Sha1-Hulud: The Second Wave of npm Supply-Chain Attacks

Researchers uncovered a fast-moving npm supply-chain worm named Shai-Hulud. The malware injected malicious JavaScript (bundle.js) into popular packages.

Corgea Security Team Corgea Security Team
Nov 24, 2025 • Product

Introducing Smarter Auto-Fixing for SAST Findings

Corgea’s improved auto-fixing now delivers self-healing fixes, stronger quality checks, and 8% higher accuracy. Supports HTML, JSP, and integrates with Checkmarx, Fortify, Semgr...

Corgea Security Team Corgea Security Team
Oct 23, 2025 • Product

Introducing Extended APIs: Enhanced Security Management for Developers

Discover Corgea's new Extended APIs for scans, issues, blocking rules, and scan operations. Automate security workflows, integrate with CI/CD pipelines, and build custom securit...

Corgea Security Team Corgea Security Team
Oct 22, 2025 • Product

Introducing Corgea Dependency Scanning

Stay ahead of open-source risks with Corgea’s new Dependency Scanning. Automatically detect vulnerabilities, enforce licenses, and apply grouped fix versions across multiple eco...

Corgea Security Team Corgea Security Team
Oct 21, 2025 • Product

Announcing Reachability Analysis: Endpoint-Aware SAST in Corgea

Corgea’s new Reachability Analysis connects SAST findings to real web endpoints, showing which vulnerabilities are actually reachable from your API surface. Automatically maps e...

Corgea Security Team Corgea Security Team
Oct 20, 2025 • Product

Automate Your Security: Introducing Corgea's Scheduled Scans

Automate your security workflows with Corgea's new Scheduled Scans feature. Set up recurring SAST, SCA, secrets, and PII scans across projects with flexible scheduling, intellig...

Corgea Security Team Corgea Security Team
Sep 12, 2025 • Product

The Three Waves of SAST: From Rules to AI-Native Analysis

Explore the evolution of Static Application Security Testing (SAST) — from legacy Fortify and Checkmarx, to developer-first tools like Snyk and Semgrep, and now AI-native SAST r...

Corgea Security Team Corgea Security Team
Aug 24, 2025 • Product

Whitepaper: Javascript Security Scanning

java script security scanning

Corgea Security Team Corgea Security Team
Aug 12, 2025 • Product

The Best AI‑Powered SAST in 2025

Compare 2025 SAST tools—Corgea’s AI-native scanner, Snyk, Semgrep & GitHub Advanced Security—and choose the best AI-powered solution for your team. Ask ChatGPT

Corgea Security Team Corgea Security Team
Aug 1, 2025 • Product

Introducing the new Scan Details Page

Corgea’s Scan Details page gives security teams deep insight and control with an interactive dashboard to analyze and manage code vulnerabilities effectively.

Corgea Security Team Corgea Security Team
Jun 20, 2025 • Product

Introducing Source and Sink Tracing for Smarter Security

Corgea’s Source & Sink Analysis maps untrusted data flow end-to-end, bringing intelligent, enterprise-grade vulnerability analysis to your development workflow.

Corgea Security Team Corgea Security Team
Jun 19, 2025 • Product