Business Wire

MA-VERACODE

Share
Veracode Research Finds a Quarter of Technology Applications Contain ‘High Severity’ Security Flaws, Which Pose a Serious Cybersecurity Risk If Exploited

Veracode, a leading global provider of modern application security testing solutions, today revealed that 24 percent of applications in the technology sector contain security flaws that are considered high risk—meaning they would cause a critical issue for the application if exploited. With, arguably, a higher proportion of applications to contend with than other industries, tech firms would benefit from implementing improved secure coding training and practices for their development teams.

Chief Research Officer at Veracode, Chris Eng, said, “Giving developers real, hands-on experience of what it takes to spot and exploit a flaw in code—and its potential impact on the application—provides the context and understanding to build their intuition about software security. Our research found that organizations whose developers had completed just one lesson in our hands-on Security Labs training program fixed 50 percent of flaws two months faster than those without such training.”

The data was published in Veracode’s annual State of Software Security (SoSS) report v12, which analyzed 20 million scans across half a million applications in the technology, retail, manufacturing, healthcare, financial services, and government sectors. Overall, the technology industry was revealed to have the second-highest proportion of applications that contain security flaws, at 79 percent, making it marginally better than the public sector at 82 percent. The tech sector lands in the middle of the pack when it comes to the proportion of flaws that are fixed.

Tech Firms Are Comparatively Quick to Fix Software Security Flaws

Encouragingly, when tech firms do discover flaws in their applications, they are comparatively fast to reach the halfway point of remediation. In fact, the sector boasts industry-leading fix times for flaws discovered by static analysis security testing (SAST) and software composition analysis (SCA). While this is a laudable accomplishment, the industry still takes up to 363 days to fix 50 percent of flaws, suggesting there is still ample room for improvement.

Eng added, “Log4j sparked a wake-up call for many organizations last December. This was followed by government action in the form of guidance from the Office of Management and Budget (OMB) and the European Cyber Resilience Act, both of which have a supply chain focus. To improve performance in the year ahead, technology businesses should not only consider strategies that help developers reduce the rate of flaws introduced into code, but also put greater emphasis on automating security testing in the Continuous Integration/Continuous Delivery (CI/CD) pipeline to increase efficiencies.”

Server configuration, insecure dependencies, and information leakage are the most common types of flaws discovered by dynamic analysis of technology applications, which broadly follows a similar pattern to other industries. Conversely, the sector exhibits the highest disparity from the industry average for cryptographic issues and information leakage, perhaps indicating that developers in the tech industry are more savvy on data protection challenges.

The Veracode State of Software Security v12 technology snapshot is available to download here and the full report is available here.

About the State of Software Security Report

The Veracode State of Software Security (SoSS) v12 analyzed the full historical data from Veracode services and customers. This accounts for a total of more than half a million applications (592,720) that used all scan types, more than a million dynamic analysis scans (1,034,855), more than five million static analysis scans (5,137,882) and more than 18 million software composition analysis scans (18,473,203). All those scans produced 42 million raw static findings, 3.5 million raw dynamic findings, and six million raw SCA findings.

The data represents large and small companies, commercial software suppliers, software outsourcers, and open-source projects. In most analyses, an application was counted only once, even if it was submitted multiple times as vulnerabilities were remediated, and new versions uploaded.

About Veracode

Veracode is a leading AppSec partner for creating secure software, reducing the risk of security breach, and increasing security and development teams’ productivity. As a result, companies using Veracode can move their business, and the world, forward. With its combination of process automation, integrations, speed, and responsiveness, Veracode helps companies get accurate and reliable results to focus their efforts on fixing, not just finding, potential vulnerabilities. Learn more at www.veracode.com, on the Veracode blog, on LinkedIn, and on Twitter.

Copyright © 2022 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20221208005101/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Dubai Electricity and Water Authority PJSC Announces Record Breaking Revenue of AED 25 Billion and Operating Profit of AED 8.3 billion for the First Nine Months Ending Sept 202513.11.2025 11:19:00 CET | Press release

Dubai Electricity and Water Authority PJSC: This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251112162153/en/ HE Saeed Mohammed Al Tayer, MD & CEO of DEWA (Photo: AETOSWire) Record nine months of 2025 Results AED 24.9 billion AED 13.1 billion AED 8.3 billion AED 6.8 billion +5.9% YoY +11.9% YoY +21.5% YoY +24.8% YoY 9 months of 2025 Revenue 9 months of 2025 EBITDA 9 months of 2025 Operating Profit 9 months of 2025 Profit After Tax * figures are rounded Record Q3 2025 Results AED 10.3 billion AED 6.2 billion AED 4.6 billion AED 3.9 billion +4.5% YoY +20.4% YoY +29.8% YoY +35% YoY Q3, 2025 Revenue Q3, 2025 EBITDA Q3, 2025 Operating Profit Q3, 2025 Profit After Tax * figures are rounded Dubai Electricity and Water Authority PJSC (ISIN: AED001801011) (Symbol: DEWA), the Emirate of Dubai’s exclusive electricity and water services provider, which is listed on the Dubai Financial Market (DFM), today reported its consolidated financia

Quectel Unveils Advanced Matter over Thread Modules for Seamless Device Interoperability13.11.2025 10:00:00 CET | Press release

Quectel Wireless Solutions, an end-to-end global IoT solutions provider, today announced the launch of the KGM133S, the first in a range of Matter over Thread modules that provides innovative solutions for applications such as smart door locks, sensors, and lighting, helping the smart home industry overcome connectivity barriers and advance toward a new era of more efficient and seamless development. The KGM133S series modules are built based on the Silicon Labs EFR32MG24 chip, supporting the latest Matter 1.4 protocol. The modules are designed to enable seamless linkage of home devices across ecosystems, including Apple Home, Google Home, Amazon Alexa and Samsung SmartThings. “Protocol fragmentation remains one of the biggest obstacles to seamless smart device connectivity, and the Matter protocol is the key to overcoming it,” said Delbert Sun, Deputy General Manager at Quectel Wireless Solutions. “With our new Matter over Thread modules, we are helping the industry achieve true inter

SBC Medical Group Announces Commencement of Tender Offer for Shares of Waqoo, Inc.13.11.2025 09:57:00 CET | Press release

SBC Medical Group Holdings Incorporated (Nasdaq: SBC) (“SBC Medical” or the “Company”), a global provider of comprehensive consulting and management services to the medical corporations and their clinics, today announced that on November 13, 2025, SBC Medical Group Co., Ltd. (the “Tender Offeror”) has resolved to acquire shares of common stock of Waqoo, Inc. (Securities Code: 4937, listed on the Tokyo Stock Exchange Growth Market; the “Target Company”) through a tender offer (the “Tender Offer”) pursuant to the Financial Instruments and Exchange Act of Japan (Act No. 25 of 1948, as amended; the “FIEA”), as described below. The Tender Offeror is a Japanese subsidiary ultimately owned by SBC Medical Group Holdings Incorporated (“SBCHD”), a U.S. corporation listed on NASDAQ and engaged in management support services for medical clinics both domestically and internationally. As of today, the Tender Offeror holds 353,600 shares of the Target Company’s common stock (ownership ratio: 9.49%).

IQM Launches Halocene, a New Quantum Computer Product Line for Error Correction13.11.2025 09:56:00 CET | Press release

IQM Halocene is a new quantum computer product line aimed at error correction development. It will start with a150-qubit system to be delivered by the end of 2026 and extend all the way to 1,000-qubits. The new product line is based on an open and modular error correction stack, which will allow end-users to experiment and run different quantum error correction features. IQM’s goal is to enable users from supercomputing centers, research organizations, and universities to innovate on quantum error correction research with an open platform. IQM has sold more on-premises quantum systems globally than any other manufacturer, and the company expects the new Halocene product line to accelerate its revenue growth further IQM Quantum Computers, a global leader in superconducting quantum computers, today announced the launch of its new product line called IQM Halocene. The new product line is based on open and modular on-premises quantum computers designed for quantum error correction research

JSR Life Sciences Enters Definitive Agreement to Transfer Crown Bioscience to Adicon Holdings Limited13.11.2025 09:45:00 CET | Press release

Strategic Transaction Positions Crown Bioscience for Accelerated Growth in Translational Oncology JSR Life Sciences LLC ("JSR Life Sciences"), a global leader in life sciences materials and services, today announced it has entered into a definitive agreement to transfer Crown Bioscience Inc. ("Crown Bioscience") to Adicon Holdings Limited ("Adicon"), a premier independent clinical laboratory provider in China and a portfolio company of The Carlyle Group. The transaction, subject to customary closing conditions, is expected to close in 2026. This strategic move will enable Crown Bioscience to operate as a standalone entity under Adicon's ownership. Crown Bioscience's comprehensive portfolio of translational oncology services, including its world-leading patient-derived xenograft (PDX) models, tumor organoid platforms, immuno-oncology assays, and bioinformatics solutions, will transition to Adicon, positioning the company to accelerate advancements in precision medicine and drug discover

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye