MA-VERACODE
14.2.2024 13:51:34 CET | Business Wire | Press release
Veracode, a global leader in intelligent software security, today unveils its annual State of Software Security (SoSS) 2024 report, shedding light on the pressing issue of security debt in applications. Security debt, defined for this report as flaws that remain unfixed for longer than a year, exists in 42 percent of applications and 71 percent of organizations. Worryingly, 46 percent of organizations have persistent, high-severity flaws that constitute ‘critical’ security debt, putting businesses at serious risk in terms of impact on confidentiality, integrity, and availability.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240214981363/en/
State of Software Security 2024 Figure 25: Effect of flaw remediation speed on prevalence of security debt (Graphic: Business Wire)
According to the report, approximately 63 percent of applications have flaws in first-party code, while 70 percent contain flaws in third-party code imported via third-party libraries. This highlights the importance of testing both types throughout the software development life cycle. Remediation rates also vary by flaw type—fixing third-party flaws takes 50 percent longer, with half the known flaws fixed after 11 months, compared to seven months for first-party flaws.
There is good news, however: high-severity security flaws in applications have decreased by half since 2016, indicating progress in software security practices and that speed of remediation has a material impact on critical security debt.
SoSS 2024 reveals development teams that fix flaws the fastest reduce critical security debt by 75 percent—from 22.4 percent of applications to just over five percent. Moreover, these fast-acting teams are four times less likely to let critical security debt materialize in their applications in the first place.
Chris Eng, Chief Research Officer at Veracode, said, "While we continue to see improvements in the security landscape, these findings are a wake-up call for organizations to address their security debt head-on. By prioritizing flaw remediation, focusing on third-party code security, and adopting efficient development practices, organizations can significantly reduce their security debt and enhance the overall state of software security across the board."
Addressing AI and the Software Supply Chain
In an era where AI (artificial intelligence) is rapidly revolutionizing software development, the report highlights a concerning trend. Chris said, “Despite the speed and efficiency AI brings to software development, it does not necessarily produce code that’s secure. Research has shown that 36 percent of code generated by GitHub CoPilot contains security flaws.” This proliferation of insecure code at scale poses a significant risk to organizations and the software supply chain, leading to the accumulation of security debt over time.
Risk Prioritization is Key
Veracode’s research also found remediation capacity among teams to be constrained, with only 64 percent of applications having a remediation capacity that’s sufficient to eliminate critical security debt. In fact, only two out of ten applications show an average monthly fix rate that exceeds ten percent of all security flaws. This suggests, even in cases where teams’ fix capacity is sufficient, they are not prioritizing critical flaws.
Despite this, there is hope for success. Only three percent of all flaws constitute critical security debt, and this subset represents the largest risk exposure for applications. By prioritizing that three percent, organizations can achieve maximum risk reduction with focused effort.
Chris closed, "AI also paves the way for a new frontier in software security by empowering organizations to scale remediation efforts and more easily address the long backlog of security debt, as well as new flaws that emerge. The vast majority of CWEs (Common Weakness Enumeration) with a severity rating from medium to very high can be addressed through AI-generated code edits from Veracode Fix.”
The full State of Software Security 2024 report is available to download on the Veracode website. To access the report and gain deeper insights into the findings and recommendations, visit the website. A blog outlining the key findings from the report is also available to read.
-END-
About the State of Software Security Report
The Veracode State of Software Security 2024 report analyzed data from large and small companies, commercial software suppliers, software outsourcers, and open-source projects. The research draws from more than a million (1,007,133) applications across all scan types, 1,553,022 dynamic analysis scans, and 11,429,365 static analysis scans. All those scans produced 96 million raw static findings, 4 million raw dynamic findings, and 12.2 million raw software composition analysis findings.
About Veracode
Veracode is intelligent software security. The Veracode Software Security Platform continuously finds flaws and vulnerabilities at every stage of the modern software development lifecycle. Using powerful AI trained on a carefully curated, trusted dataset from experience analyzing trillions of lines of code, Veracode customers fix flaws faster with high accuracy. Trusted by security teams, developers, and business leaders from thousands of the world’s leading organizations, Veracode is the pioneer, continuing to redefine what intelligent software security means.
Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and Twitter.
Copyright © 2024 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240214981363/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Americhem Recognized Among Top 5% Globally for Sustainability Performance with EcoVadis Gold Rating11.2.2026 13:00:00 CET | Press release
Americhem, a globally recognized designer and manufacturer of custom color masterbatch, functional additives, engineered compounds, and performance technologies, has earned the EcoVadis Gold rating, placing the company among the top 5% of organizations assessed globally for sustainability performance in their sector. EcoVadis is one of the world’s most widely used business sustainability assessment platforms, evaluating companies across Environment, Labor & Human Rights, Ethics, and Sustainable Procurement. The Gold rating reflects not only the presence of sustainable policies but also the robustness of management systems, documentation, and implementation practices, as evaluated by EcoVadis across Americhem’s global operations. The EcoVadis Gold rating follows Americhem’s prior Silver ratings in recent years and reflects continued strengthening of environmental stewardship, governance, and management systems across the organization. “This recognition reflects how our teams run the bus
Echodyne to Open Major New Manufacturing Facility to Meet Rapidly Growing Global Demand11.2.2026 13:00:00 CET | Press release
$40M investment in 86,350-square-foot facility in Washington State, USA Annual production capacity of >30,000 radars across product lines More than 200 employees at full capacity Start of production in summer 2026 Echodyne, the radar platform company, today announces a major near-term expansion in its advanced radar production capacity. Echodyne’s new 86,350-square-foot facility will provide enough manufacturing and warehouse space to produce and ship more than 30,000 radars per year. The company’s modular manufacturing approach allows production capacity to flex to match varying demand across product lines as well as seamlessly introducing new product lines and capabilities. The investment reflects Echodyne’s continued commitment to: enhancing security and safety as UxS become ubiquitous on the battlefield and in society in general, staying ahead of the accelerating demand in the U.S. and in Allied countries around the globe, and strengthening America’s defense industrial base. Counte
Agentic AI Consulting: Sia Accelerates Its Development with More Than 400 Agents on Its Agent Store11.2.2026 12:17:00 CET | Press release
Sia, an international consulting group specializing in strategy, management, and AI, has reached a milestone in its Agentic AI journey. Born in the digital era, the firm now leverages the expertise of more than 3,000 consultants in 19 countries to help organizations scale AI-driven transformation. From GenAI to an Agent Store for All Industries and Functions After unveiling its Generative AI platform to clients in June 2023, the firm announced the launch of its Agent Store in September 2025. Built on a learn-by-design approach, Sia’s Agent Store grew from 50 AI agents to over 400 available for direct consultation, with over a dozen Minimum Viable Products ready for demonstration. Originally introduced as SiaGPT, the platform is now accessible via siagents.ai, reflecting the transition from custom GPTs to fully agentic services. Sia’s AI agents cover a wide range of industries such as Finance, Energy, Public Sector, Healthcare, and Retail and Consumer Goods, and address all corporate fu
BeOne Medicines to Announce Fourth Quarter and Full Year 2025 Financial Results on February 2611.2.2026 12:00:00 CET | Press release
BeOne Medicines Ltd. (NASDAQ: ONC; HKEX: 06160; SSE: 688235), a global oncology company, will report its fourth quarter and full year 2025 financial results on Thursday, February 26, 2026 before the financial markets open. Following the release of the financials, the Company will host a live webcast with management at 8:00 a.m. ET. The live webcast of this event can be accessed from the investors section of the Company’s website at https://ir.beonemedicines.com. To ensure a timely connection, it is recommended that participants register at least 15 minutes prior to the scheduled webcast. An archived webcast will be available on the Company’s website. About BeOne Medicines BeOne Medicines is a global oncology company domiciled in Switzerland that is discovering and developing innovative treatments that are more accessible to cancer patients worldwide. With a portfolio spanning hematology and solid tumors, BeOne is expediting development of its diverse pipeline of novel therapeutics thro
OpenX Strengthens EMEA Leadership with Appointment of Natalie Fisher-Brown11.2.2026 11:05:00 CET | Press release
As RVP, EMEA Buyer Development, the established adtech leader will lead buy-side sales and account management across the region. OpenX Technologies, Inc., one of the world’s leading omnichannel supply-side platforms, today announced the appointment of Natalie Fisher-Brown as Regional Vice President, EMEA Buyer Development. Fisher-Brown will lead, develop, and manage OpenX’s buy-side sales and account management organisations across EMEA, with a focus on strengthening key strategic markets and driving long-term growth for partners. In this new role, Fisher-Brown will oversee the development of senior-level relationships across agencies and brands. She will work closely with well-established and emerging partners to build strategic collaborations that support responsible innovation and sustainable growth. Fisher-Brown’s appointment follows recent hires in France and Germany, reflecting OpenX’s continued investment in market expansion as it evolves the role of the SSP to meet the needs of
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
