Adaptive application security for the AI era

Global
Vulnerability exploitation is now the leading breach vector, while 82% of organizations carry security debt. Building the business case for #AppSec means connecting risk to faster releases, efficient remediation and predictable costs. Learn how: veracode.com/resources/appli…
3
156
AI can generate code roughly 10x faster than humans, putting new pressure on #AppSec. On The Security Strategist, Chris Wysopal and Sohail Iqbal discuss how organizations can keep risk from accumulating as AI-generated code grows. Watch: em360tech.com/podcasts/new-a…
1
331
Third-party code accounts for 66% of the most dangerous, long-lived vulnerabilities across application portfolios. Our latest blog outlines three layers of software supply chain security: package firewalls, SCA and container/IaC scanning. Learn more: veracode.com/blog/mature-sof…
2
211
EU Cyber Resilience Act reporting rules are now in effect. Companies worldwide that sell software or connected products in the EU may need to report exploited vulnerabilities within 24 hours. Learn who’s affected and how to prepare: veracode.com/blog/eu-cyber-r…
1
161
Duplicate alerts and disconnected dashboards slow #DevSecOps. Our latest blog explores how to prioritize findings, bring testing into developer workflows, and expand scan coverage, with a real-world example. Read more: veracode.com/blog/devsecops-…
2
182
Finding vulnerabilities is only the start. Enterprise teams need to fix risk at scale, enforce policy, support audit readiness, and keep developers moving. What should you look for in risk remediation software? Veracode breaks down the key criteria: veracode.com/blog/risk-remed…
2
204
OpenAI is urging organizations to raise the security bar for software, including AI-generated code. Veracode research found 44% of code-generation tasks introduced a known vulnerability. @WeldPond explains the need for continuous verification. #AppSec veracode.com/blog/openai-cyb…
4
313
AI-generated code security is stuck at 56% across 100+ models tested over four testing snapshots. For security leaders, that’s not just a model issue. It’s a verification, release-control, and risk issue. Join Veracode’s live webinar: veracode.com/resources/webin…
1
1
2
329
New Veracode Research found GPT-5.6 Sol achieved a 70% secure-code pass rate, up 2 points from GPT-5.5. Results varied by language, with Python improving from 70% to 85%. See the findings: veracode.com/blog/gpt-sol-be… #GenAI
1
1
358
At #BlackHat, Veracode’s Johnny Wong joined AWS Security Live to discuss vibe coding, the security risks of AI-generated code, and what organizations can do to keep pace as AI accelerates development. Watch the conversation: piped.video/watch?v=5fujrAb_…
3
354
Comparing software supply chain security vendors in 2026? Evaluate application risk coverage, developer workflows, SBOM visibility, exploitability-aware prioritization, AI-assisted remediation and measurable risk reduction. Read the blog: veracode.com/resources/softw…
1
339
Security debt is a boardroom issue. In a new article for NODE, Veracode CISO Sohail Iqbal explores how aging vulnerabilities compound business risk and why leaders need to prioritize exposure and remediation capacity. Read more: node-magazine.com/thoughtlea…
1
1
227
The Trump administration is considering letting some U.S. companies “hack back” against foreign cybercriminals. Veracode’s Chris Wysopal spoke with NPR about why offensive cyber operations carry serious risks, including collateral damage. Listen: one.npr.org/?sharedMediaId=n…
1
270
Government agencies face a growing security challenge: vulnerabilities are being found faster than they can be fixed. Veracode’s new public sector report finds 82% of organizations carry security debt, and 60% carry critical security debt. Read more: veracode.com/resources/analy…
1
226
AI is making developers more efficient, but speed can’t come at the expense of security. At #BlackHat, Veracode’s Christian Dalomba shared why AI-assisted code needs the same security discipline as any other code: scan it, understand the risk, and secure it. #BHUSA #AI
1
382
Developers shouldn’t have to wrestle with build complexity before they can find security issues. Veracode’s Java Source Code Scanning lets teams scan source directly for faster #AppSec feedback, with source, binary, or hybrid options to fit the workflow. veracode.com/resources/java-…
3
251
Agentic AI is raising urgent questions about autonomy, accountability, and security. At #BlackHat, Veracode’s Chris Wysopal explains why stronger controls and clear governance are critical as AI agents become more capable and accessible. Watch the video below.
1
252
Software supply chain security goes beyond generating an SBOM. At #BlackHat, Veracode’s Zane Leonard explains how reachability analysis and Veracode Fix for SCA help teams prioritize risk and remediate vulnerable libraries faster. Visit Booth #4927. #BHUSA
1
340
The Black Hat show floor is open! Take a quick walkthrough with Veracode as the community comes together to talk AI-driven risk and what’s next for AppSec. Visit Booth #4927 to meet the team, see live demos, and schedule a meeting with our experts while you’re in Las Vegas.
1
224