Business Wire

MA-VERACODE

14.2.2024 13:51:34 CET | Business Wire | Press release

Share
Veracode Reveals Critical Security Debt Can Be Reduced by 75% With Speed of Remediation

Veracode, a global leader in intelligent software security, today unveils its annual State of Software Security (SoSS) 2024 report, shedding light on the pressing issue of security debt in applications. Security debt, defined for this report as flaws that remain unfixed for longer than a year, exists in 42 percent of applications and 71 percent of organizations. Worryingly, 46 percent of organizations have persistent, high-severity flaws that constitute ‘critical’ security debt, putting businesses at serious risk in terms of impact on confidentiality, integrity, and availability.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240214981363/en/

To view this piece of content from mms.businesswire.com, please give your consent at the top of this page.

State of Software Security 2024 Figure 25: Effect of flaw remediation speed on prevalence of security debt (Graphic: Business Wire)

According to the report, approximately 63 percent of applications have flaws in first-party code, while 70 percent contain flaws in third-party code imported via third-party libraries. This highlights the importance of testing both types throughout the software development life cycle. Remediation rates also vary by flaw type—fixing third-party flaws takes 50 percent longer, with half the known flaws fixed after 11 months, compared to seven months for first-party flaws.

There is good news, however: high-severity security flaws in applications have decreased by half since 2016, indicating progress in software security practices and that speed of remediation has a material impact on critical security debt.

SoSS 2024 reveals development teams that fix flaws the fastest reduce critical security debt by 75 percent—from 22.4 percent of applications to just over five percent. Moreover, these fast-acting teams are four times less likely to let critical security debt materialize in their applications in the first place.

Chris Eng, Chief Research Officer at Veracode, said, "While we continue to see improvements in the security landscape, these findings are a wake-up call for organizations to address their security debt head-on. By prioritizing flaw remediation, focusing on third-party code security, and adopting efficient development practices, organizations can significantly reduce their security debt and enhance the overall state of software security across the board."

Addressing AI and the Software Supply Chain

In an era where AI (artificial intelligence) is rapidly revolutionizing software development, the report highlights a concerning trend. Chris said, “Despite the speed and efficiency AI brings to software development, it does not necessarily produce code that’s secure. Research has shown that 36 percent of code generated by GitHub CoPilot contains security flaws.” This proliferation of insecure code at scale poses a significant risk to organizations and the software supply chain, leading to the accumulation of security debt over time.

Risk Prioritization is Key

Veracode’s research also found remediation capacity among teams to be constrained, with only 64 percent of applications having a remediation capacity that’s sufficient to eliminate critical security debt. In fact, only two out of ten applications show an average monthly fix rate that exceeds ten percent of all security flaws. This suggests, even in cases where teams’ fix capacity is sufficient, they are not prioritizing critical flaws.

Despite this, there is hope for success. Only three percent of all flaws constitute critical security debt, and this subset represents the largest risk exposure for applications. By prioritizing that three percent, organizations can achieve maximum risk reduction with focused effort.

Chris closed, "AI also paves the way for a new frontier in software security by empowering organizations to scale remediation efforts and more easily address the long backlog of security debt, as well as new flaws that emerge. The vast majority of CWEs (Common Weakness Enumeration) with a severity rating from medium to very high can be addressed through AI-generated code edits from Veracode Fix.”

The full State of Software Security 2024 report is available to download on the Veracode website. To access the report and gain deeper insights into the findings and recommendations, visit the website. A blog outlining the key findings from the report is also available to read.

-END-

About the State of Software Security Report

The Veracode State of Software Security 2024 report analyzed data from large and small companies, commercial software suppliers, software outsourcers, and open-source projects. The research draws from more than a million (1,007,133) applications across all scan types, 1,553,022 dynamic analysis scans, and 11,429,365 static analysis scans. All those scans produced 96 million raw static findings, 4 million raw dynamic findings, and 12.2 million raw software composition analysis findings.

About Veracode

Veracode is intelligent software security. The Veracode Software Security Platform continuously finds flaws and vulnerabilities at every stage of the modern software development lifecycle. Using powerful AI trained on a carefully curated, trusted dataset from experience analyzing trillions of lines of code, Veracode customers fix flaws faster with high accuracy. Trusted by security teams, developers, and business leaders from thousands of the world’s leading organizations, Veracode is the pioneer, continuing to redefine what intelligent software security means.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and Twitter.

Copyright © 2024 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240214981363/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

JTB to Acquire Asian DMC Leader EXO Travel for Accelerated Global Growth18.6.2026 04:00:00 CEST | Press release

— Advancing JTB's “Departing Globally, Arriving Globally” Vision — JTB Corp. today announced that it has reached an agreement to acquire all the shares of All Wise Holdings Pte. Ltd., the operator of Bangkok-based EXO Travel Group, a leading Destination Management Companies (DMCs) in Asia. The acquisition will be made through a JTB group company in the Asia-Pacific region. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260615106801/en/ EXO Travel operates in the B2B market, primarily across Asia Pacific. For over 30 years, it has consistently maintained high customer satisfaction based on trust, achievements and high-quality service. The company has a strong brand presence in the affluent markets of Europe, North America and Australia, where the trust of partner companies contributes significantly to its value. Additionally, EXO Travel leverages its extensive network of destinations in Asia Pacific to develop strong products

LabGenius Therapeutics and LG Chem Enter a Research Collaboration, Option and License Agreement to Develop an AI/ML-Designed Tumour-Targeting Antibody18.6.2026 01:01:00 CEST | Press release

The companies have entered into a multi-year research collaboration, option and licensing agreement in which LabGenius Therapeutics will leverage its AI/ML-driven antibody discovery platform,EVA™, to design and engineer next-generation multispecifics with enhanced therapeutic properties LabGenius Therapeutics will receive an undisclosed upfront payment and potential early milestones, plus, if the option is exercised, potential triple-digit million clinical, regulatory, and commercial milestones, along with royalties on net sales LabGenius Therapeutics (“LabGenius”), a drug discovery company combining machine learning (ML) and high-throughput experimentation to optimise therapeutic antibodies, today announced a multi-year research collaboration, option and licensing agreement with LG Chem. The collaboration aims to identify next-generation multispecific antibodies designed to overcome the key limitations of existing immunotherapies, including on-target, off-tumour toxicities. Together,

Joe Vernachio Named President of SOREL18.6.2026 00:00:00 CEST | Press release

Columbia Sportswear Company (Nasdaq: COLM), a leading innovator in active outdoor apparel, footwear, accessories and equipment, today announced that Joe Vernachio will be the next President of SOREL. Founded in 1962, SOREL is a leader in functional and lifestyle footwear that can be worn anywhere from the tundra to the streets of New York City. “We’re excited to welcome Joe Vernachio back to the Columbia Sportswear family,” said Tim Boyle, CEO and Chair of the Board. “Joe is a terrific leader who can build on the great work, talent and momentum in place at SOREL.” Mr. Vernachio led the Mountain Hardwear brand for several years, until he left to become the COO and ultimately, the CEO of Allbirds. His background also includes time as Global Vice President for Product and Operations at The North Face, and key roles at Nike, Spyder, Roots, Calvin Klein and Patagonia. “Joe is a consumer‑focused, collaborative leader with a deep passion for product and brand storytelling. His energy, experti

Venture Global and EnBW Announce New LNG Purchase Agreements17.6.2026 22:30:00 CEST | Press release

Today, Venture Global, Inc. (NYSE: VG) and EnBW announced the execution of new, binding agreements for the purchase of approximately 0.82 million tonnes per annum (MTPA) of U.S. liquefied natural gas (LNG) from Venture Global for approximately five years commencing in 2026, to be supplied from Venture Global’s portfolio. The new agreements add to the existing long-term sales and purchase agreements (SPAs) between Venture Global and EnBW for 2 MTPA for 20 years. “As one of Germany’s top LNG suppliers, Venture Global is proud to strengthen our partnership with EnBW and support the region’s energy security with a reliable supply of LNG,” said Venture Global CEO Mike Sabel. “The new mid-term agreements build on our strong, long-standing relationship with EnBW and reflects our commitment to meeting our customers’ evolving energy needs. Our dynamic marketing platform uniquely positions us to provide supply solutions across the short, medium, and long term.” About Venture Global Venture Globa

Kinaxis Announces Results of Voting at Annual and Special Meeting of Shareholders17.6.2026 22:05:00 CEST | Press release

Kinaxis® Inc. (“Kinaxis” or the “Company”) (TSX:KXS), a global leader in end-to-end supply chain planning and orchestration, received approval for all resolutions put forward to shareholders at today’s Annual and Special Meeting of Shareholders (the “Meeting”), as detailed in the Company’s management information circular dated May 5, 2026 (the “Circular”). 1. Election of Directors Shareholders voted to elect all eight directors nominated to the Kinaxis board, to hold office until the close of the next annual meeting of shareholders of the Company or until their successors are elected or appointed. Name of Nominee Total Number of Votes For Percentage of Votes For Total Number of Votes Against Percentage of Votes Against Razat Gaurav 21,870,163 99.01% 219,468 0.99% Robert Courteau 20,882,945 94.54% 1,206,685 5.46% Gillian (Jill) Denham 21,474,486 97.22% 615,143 2.78% José Alberto Duarte 21,699,181 98.23% 390,448 1.77% Lynn Loewen 21,952,244 99.38% 137,387 0.62% Angel Mendez 21,410,402 96

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye