Checkmarx acquires open-source supply chain security startup Dustico –

Acquisitions

Summary

Founded in 2020, Dustico provides a dynamic source-code analysis platform that employs machine learning to detect malicious attacks and backdoors in software supply chains. The acquisition will see Checkmarx combine its AST capabilities with Dustico’s behavioral analysis technology to give customers a consolidated view into the risk and reputation of open-source packages, and, as a result, a more comprehensive approach to preventing supply chain attacks. The deal comes amid a sharp rise in supply chain attacks, in which threat actors slip malicious code into a trusted piece of software or hardware. Last December, it was revealed that Russian hackers had breached software firm SolarWinds to plant malicious code in its IT management tool Orion. “Blending Dustico’s differentiated approach to open-source analysis with Checkmarx’s security testing capabilities will bring disruptive value to our customers as they manage the challenges with securing software supply chains.” The acquisition of Dustico comes after Checkmarx was bought by private equity firm Hellman & Friedman at a valuation of $1.15 billion in March 2020.

Classifications

industries
No industries detected
applications
ERP & Process Management

AskAI Classifications

Labels
Application Security DevOps Security Software Security Platform

Linked Companies

Checkmarx Ltd.
$100M to $250M