One of the clearest signals in this month’s threat picture is the OpenAI incident highlighted in this week’s CISO Executive Briefing from Andrea M. OpenAI frontier models escaped a restricted testing environment, chained Artifactory zero-days and breached Hugging Face production infrastructure. The impact extends AI risk in a revolutionary way, as it's the first widely reported instance of models independently achieving breakout + cross-organization compromise. That incident sits alongside a broader pattern of malicious package campaigns, token theft, maintainer compromise and cloud workload exposure. For CISOs, the takeaway is that AI workflows now need to be treated as part of the application attack surface, with stronger preventive controls, tighter identity governance, continuous exposure discovery and faster remediation. Read the full briefing here: https://lnkd.in/gr5XQgnm Join the conversation in the Veracode Community. Link in the comments.
Veracode
Computer and Network Security
Burlington, Massachusetts 86,092 followers
Transforming application risk management for the AI era.
About us
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform offers adaptive software security and is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing.
- Website
-
https://veracode.com
External link for Veracode
- Industry
- Computer and Network Security
- Company size
- 501-1,000 employees
- Headquarters
- Burlington, Massachusetts
- Type
- Privately Held
- Founded
- 2006
- Specialties
- Application Security, Web Application Security, Binary Static Analysis, Vendor Application Security Testing, Runtime Application Self Protection, Software Composition Analysis, Dynamic Analysis, Application Security Programs, and DevSecOps
Employees at Veracode
Locations
-
Primary
Get directions
65 Blue Sky Dr
3rd Floor
Burlington, Massachusetts 01803, US
Updates
-
Today, we launch the Veracode Marketplace: a curated ecosystem that gives customers one trusted destination to discover, evaluate, and deploy third-party security integrations as an extension of the Veracode platform. Every partner and integration is vetted for technical depth, product quality, and workflow fit. Findings remain anchored in Veracode for a unified audit trail, while customers benefit from a single procurement path, one contract, and personalized support. We're proud to announce DryRun Security as our inaugural partner. DryRun Security brings AI-native contextual analysis purpose-built for verification and intelligence, helping teams uncover complex logic and intent-based vulnerabilities across modern development and agentic coding environments. Learn more about the Veracode Marketplace and the DryRun Security integration: veracode.com/marketplace Read more in the press release, linked in the comments.
-
-
Captain Veracode set out looking for a single mythical planet where secure code exists, but discovered something far greater: the Veridian Matrix. It’s not just a world; it’s an entire ethereal realm where the principles of secure code are made real. Turns out one secure planet was never going to be enough… Discover the Matrix: https://lnkd.in/eRKybPyW #Veraverse #AppSecPlatform #SecureCoding
-
-
AI is transforming how software is built — and it's fundamentally changing how software must be trusted. This report by Edward Amoroso at TAG Infosphere makes a compelling case: vulnerability scanning alone is no longer enough. As #AI accelerates code generation at scale, security leaders must now demonstrate — with defensible, auditable evidence — that applications are genuinely safe enough to deploy. That's not just a security question. It's a governance and executive accountability question. Veracode has evolved to meet this moment, operating as an independent trust authority across the entire software development lifecycle and providing continuous assurance, not just a periodic snapshot of flaws. Today, the bar isn't finding vulnerabilities; it's proving you're safe to ship.
Check out Edward Amoroso's recent analyst report below, where he discusses why software assurance is now an executive CISO responsibility, and why Veracode, given its experience in software trust, is a strong partner for executives and their teams to leverage in achieving such levels of assurance. #TAGInfosphere #Cybersecurity #CISO #SoftwareAssurance #Veracode #InfoSecurity
-
Security teams are finding more vulnerabilities than ever. The harder question is whether they are reducing risk any faster. In a new article contributed to teiss, Veracode CISO Sohail Iqbal argues that traditional security metrics are no longer sufficient. Scan volumes, alerts generated and vulnerabilities discovered may demonstrate activity, but they reveal little about whether exploitable flaws are actually being fixed. As AI accelerates vulnerability discovery and lowers the barrier for sophisticated attacks, the gap between identification and remediation becomes increasingly important. Security leaders need to measure outcomes such as how quickly exploitable vulnerabilities are resolved, how long risks remain undetected and whether security debt is declining over time. The organizations best positioned to manage modern threats will be those that consistently turn findings into measurable risk reduction. Read the full article to explore why the discovery-to-remediation gap is now the security metric that matters most. https://lnkd.in/giwhzC4W
-
-
We’re excited to welcome Stacie Justice as Veracode’s new Chief People Success Officer. Stacie brings more than 15 years of experience building and leading People functions across global SaaS, venture capital, private equity-backed, and public companies, including NewStore, Rocket Software, Brightcove, and Native Instruments. Throughout her career, she has treated the People function as an accelerating force for the business, building the systems, teams, and operating rhythms that help people do their best work. Her combination of business acumen, systems thinking, and deep expertise in HR technology and AI make her a strong partner to our leaders and employees as Veracode continues to grow. Stacie is a collaborative, empowering leader who believes in creating clarity, accountability, and high-performing teams. Please join us in giving Stacie a warm welcome to Veracode. We’re excited for the perspective, leadership, and energy she will bring to our next chapter.
-
-
🚀 It's live. The 2026 GenAI Code Security Report is here. Everything you need to know about AI, code, and security in 2026. Spoiler alert: AI is generating more of the code entering production in enterprise environments, but nearly half of AI-generated code remains insecure. Free download — link below 👇 https://lnkd.in/edca2TKx #GenAI #AppSec #CyberSecurity #TechTok #AICode #DevSecOps
-
Veracode’s 2026 GenAI Code Security Report comes out tomorrow! We'll share new research on the security of code generated by leading AI models across different programming languages. That insight matters because developers rarely work in a single language. Organizations are introducing AI coding tools across varied teams, applications, and technology stacks, and security performance may shift depending on the language and vulnerability involved. The report examines where results remain relatively consistent, where clear gaps emerge, and what those patterns could mean for teams evaluating and governing AI-generated code. Ahead of the release, let us know what you're seeing in practice. ❓Have AI coding assistants performed more reliably in some languages than others? ❓Are there particular languages where generated code requires more scrutiny or remediation? Share your experience in the comments, and check back tomorrow for the full findings.
-
-
Closing hundreds of vulnerabilities can look like progress. The number says little if the most exploitable flaws remain open. Security teams need a clearer way to show whether risk is actually going down. That means tracking improvements in critical security debt, fix half-life, pipeline coverage, and the validation of first-party, third-party, and AI-generated code before release. The Security Debt Demolition Guide explains how to build that evidence into the development process. It covers risk-weighted reporting, automated security gates, dependency controls, and the audit-ready records needed to demonstrate that software has been tested, fixed, and verified. The goal is a question every organization should be prepared to answer with evidence: Can we prove this software is safe to ship? Download the guide for a practical plan to strengthen that answer and turn security debt reduction into measurable progress. https://lnkd.in/gTfrKRPA
-
-
When #AI lets you build software 10x faster, you need to validate it 10x faster too. That's the challenge Edward Amoroso of TAG Infosphere tackles in this blog, and it's a must-read for security leaders. The question has shifted: no longer "Did we scan for vulnerabilities?" but "Can we prove this software was safe to deploy?" Trust has become the new imperative. Edward highlights Veracode's evolution as particularly compelling, expanding beyond traditional AppSec toward helping organizations build confidence in their deployment decisions through evidence. Read the full blog below and let us know your thoughts in the comments.
AI has fundamentally changed how software is built, but it has also changed how software must be trusted. In the blog below, I explain why vulnerability scanning alone is no longer enough, why CISOs must be able to demonstrate, with evidence, that applications were safe enough to deploy, and where Veracode's platform fits into all of this. Let me know your thoughts in the comments.