Business Wire

Continuous Protection for the Cloud Era: Veracode Spotlights Latest Innovations for Advanced Software Security

Share

Advanced AI-Powered Solutions Reduce Remediation Time While Proactively Blocking 60% of Critical Supply Chain Threats

Veracode, a global leader in application risk management, today unveiled a suite of innovations that transform how enterprises approach security. The enhanced platform cuts vulnerability remediation time by up to 92 percent, while using proactive defense to prevent 60 percent of critical supply chain risk from ever entering organizations. These latest enhancements to Veracode’s Package Firewall and Risk Manager provide assurance, context, and continuity across the software development lifecycle.

“Security teams tell us they’re drowning in vulnerability alerts while missing the risks that actually matter. Our latest innovations flip the script—instead of endless firefighting, teams can now prevent threats proactively and focus remediation efforts where they’ll have maximum business impact,” said Derek Maki, Head of Product at Veracode.

Redefining Application Risk Management with End-to-End Risk Visibility

The latest enhancements to Veracode’s Application Risk Management platform enable security teams to identify and remediate vulnerabilities with greater speed and precision than ever before. Veracode Risk Manager sets a new standard for application security posture management (ASPM), featuring six new integrations with industry leaders, including Wiz. By aggregating and prioritizing issues across all sources, Risk Manager reduces vulnerability remediation time by up to 92 percent. This holistic view empowers security teams to act on the Best Next Action™—the actions that reduce the most riskwith precision.

Securing the Software Supply Chain

With 70 percent of critical security debt stemming from third-party code, enterprises are under unprecedented pressure to safeguard their software supply chains. Regulations like the European Union’s Digital Operational Resilience Act (DORA) highlight the vital role of open-source security in maintaining software supply chain integrity.

Veracode Package Firewall redefines supply chain security with an automated solution that blocks untrusted packages, before they can infiltrate development pipelines. Powered by advanced AI analysis, Package Firewall identifies and blocks 60 percent more malicious packages than competing solutions, effectively preventing vulnerabilities, malware, and policy violations from entering organizational systems.

Paired with Software Composition Analysis (SCA) and Malicious Package Detection, Veracode Package Firewall significantly reduces the risk of supply chain attacks by finding and neutralizing libraries harboring malicious code.

“Veracode Package Firewall represents a fundamental shift in how we think about supply chain security. While others are still alerting malicious packages after they’re in your codebase, we’re blocking them at the gate. This means security teams can finally get ahead of supply chain threats instead of scrambling to respond when legitimate packages get compromised or malicious packages slip through,” said Maki.

Built on proprietary threat intelligence, the product automates real-time risk management to ensure nefarious files and programs never make it into an organization’s codebase.

Empowering Developer Productivity with Frictionless Security

According to Gartner, Inc., organizations with a high-quality developer experience are 33 percent more likely to attain their business goals and 31 percent more likely to improve delivery flow. Veracode continues to champion developer productivity through an enhanced platform experience, featuring improved Integrated Developer Environment (IDE) plugins and new Git integrations that embed enterprise-level security directly into workflows.

“Developer productivity isn’t just a nice-to-have; it directly impacts your ability to ship secure software at market speed. Our IDE integrations deliver enterprise-grade security insights without the context switching that kills developer flow. This is why we’re seeing 35 percent faster remediation times with our IDE plugins and integrations, including Visual Studio, IntelliJ IDEA, and Eclipse, as well as GitHub, GitLab, and Azure DevOps,” said Maki.

Veracode’s latest developer-focused innovations eliminate operational inefficiencies and simplify workflows, removing unnecessary complexity from day-to-day DevSecOps processes. Additional innovations include:

  • AI-Assisted Login for Dynamic Application Security Testing (DAST): Automates complex authentication flows, reducing script setup time by 50 percent and expanding dynamic testing coverage.
  • Container and Infrastructure-as-Code (IaC) Results: Centralizes container and IaC findings in the Veracode Platform, streamlining vulnerability management.
  • Veracode Fix Usage Analytics: Provides a dashboard that tracks usage and Common Weakness Enumerations (CWEs) addressed, offering insights by IDE, project, and source file to optimize remediation.

Availability

Veracode’s latest product innovations are available to customers today. To find out more about the company’s application risk management platform and solutions, visit the website.

About Veracode

Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.

Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands, or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

View source version on businesswire.com: https://www.businesswire.com/news/home/20250724023276/en/

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Andersen Consulting forbedrer sine organisatoriske udviklingskapaciteter med Omni HR Consulting1.8.2025 19:22:00 CEST | Pressemeddelelse

Andersen Consulting udvider sine kompetencer inden for menneskelige ressourcer gennem en samarbejdsaftale med Omni HR Consulting, et sydafrikansk konsulentfirma med speciale i løsninger til forretnings- og personaleudvikling. Omni HR Consulting tilbyder en komplet pakke af tjenester, der omfatter organisationsudvikling, præstationsrådgivning, akkrediteret uddannelse, kompetenceudvikling og ledelsesprogrammer gennem sit Business and Leadership Academy. Virksomheden samarbejder med kunderne om at designe og implementere løsninger, der retter sig mod medarbejdernes kompetencer, optimering af resultater og strategisk tilpasning og understøttes af en konsekvent tilgang til projektledelse og overholdelse af sydafrikanske kvalitetsstandarder. "Hos Omni tror vi på, at effektiv udvikling starter med forståelse af konteksten," siger administrerende direktør Lize Moldenhauer. "Vi arbejder tæt sammen med vores kunder for at udvikle skræddersyede løsninger, der skaber målbare fremskridt – hvad ente

DevvStream Deploys Crypto Treasury with Initial Bitcoin and Solana Purchases; Intends to Expand Credit Facility to $300M1.8.2025 16:00:00 CEST | Press release

DevvStream Corp. (Nasdaq: DEVS) (“DevvStream” or the “Company”), a leading carbon management firm specializing in the development, investment, and sale of environmental assets, today announced the initial deployment of its crypto treasury strategy with purchases of Bitcoin ($BTC) and Solana ($SOL), funded by a portion of the first (US)$10 million tranche of its (US)$300 million senior secured convertible notes facility with Helena Global Investment Opportunities 1 Ltd. These acquisitions represent the operational launch of DevvStream’s digital treasury strategy, designed to combine institutional-grade liquidity with blockchain infrastructure. The Company believes Bitcoin provides a liquid, non-correlated store of value and that Solana’s high-throughput network supports the Company’s long-term objectives in, and the industry’s move towards, sustainability-linked tokenization. In parallel, DevvStream announced its intention to increase its existing Equity Line of Credit (ELOC) to (US)$30

BEYOND Launches PASSO, a Sculptural Icon on Palm Jumeirah1.8.2025 15:17:00 CEST | Press release

BEYOND Developments, the forward-thinking real estate brand shaping lifestyle destinations by the sea, has unveiled PASSO, a sculptural waterfront development located on the prestigious West Crescent of Palm Jumeirah. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250801880717/en/ PASSO by BEYOND, a Sculptural Icon on Palm Jumeirah. (Photo: AETOSWire) As BEYOND’s first flagship beyond its masterplan in Dubai Maritime City, PASSO marks a defining milestone in the company’s strategic growth to one of the world’s most iconic and desirable destinations. The project launched with a spectacular Palm Jumeirah event featuring Dubai’s first-ever “screens in the sky” show, a 13-minute performance with over 4,000 drones blending immersive visuals and live stage action. Comprising two sculptural towers, Avita and Bella, PASSO offers 625 residences in a refined mix of layouts. From one-bedroom retreats and two-to-four-bedroom-plus lifest

LevelBlue Completes Acquisition of Aon’s Cybersecurity and IP Litigation Consulting Groups1.8.2025 14:00:00 CEST | Press release

Strategic deal enhances LevelBlue's cybersecurity offerings, solidifying its position as the world’s largest leading independent, pure-play MSSP LevelBlue, a global leader in cloud-based, AI-driven managed security services, today announced the completion of its acquisition of Aon’s (NYSE: AON) Cybersecurity and Intellectual Property (IP) Litigation consulting groups, including the renowned cybersecurity firm, Stroz Friedberg, and Elysium Digital. With this completion the consulting group will operate as Stroz Friedberg, a LevelBlue company. This strategic acquisition adds elite cyber and high-tech IP litigation consulting expertise to the LevelBlue portfolio, which includes a globally recognized platform of approximately 300 technology professionals with deep relationships across Fortune 500 companies, 80 percent of the Am Law 100, and most of the UK’s top 20 law firms. As a result, LevelBlue will significantly fortify its incident response and advisory capabilities, while expanding i

SBC Medical to Announce Q2 2025 Financial Results and Hold Conference Call on August 13, 20251.8.2025 14:00:00 CEST | Press release

SBC Medical Group Holdings Incorporated (Nasdaq: SBC) (“SBC Medical” or the “Company”), a global franchise and provider of services for aesthetic clinics, today announced that it will report its Q2 2025 financial results on Wednesday, August 13, 2025, before the U.S. market opens. The Company will hold a conference call on Wednesday, August 13, 2025 at 8:30 am Eastern Time (or Wednesday, August 13, 2025 at 9:30 pm Japan Time) to discuss the financial results and take questions live. Please register in advance of the conference using the link provided below. https://edge.media-server.com/mmc/p/ukc9sp9j It will automatically direct you to the registration page of “SBC Q2 2025 Financial Results Presentation.” Please follow the steps to enter your registration details, then click “Submit.” Upon registration, you will be able to access the dedicated Conference Call viewing site. In addition to viewing the conference call, this site provides access to information about the speakers as well a

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye