Business Wire

MA-VERACODE

8.12.2022 13:51:40 CET | Business Wire | Press release

Share
Veracode Research Finds a Quarter of Technology Applications Contain ‘High Severity’ Security Flaws, Which Pose a Serious Cybersecurity Risk If Exploited

Veracode, a leading global provider of modern application security testing solutions, today revealed that 24 percent of applications in the technology sector contain security flaws that are considered high risk—meaning they would cause a critical issue for the application if exploited. With, arguably, a higher proportion of applications to contend with than other industries, tech firms would benefit from implementing improved secure coding training and practices for their development teams.

Chief Research Officer at Veracode, Chris Eng, said, “Giving developers real, hands-on experience of what it takes to spot and exploit a flaw in code—and its potential impact on the application—provides the context and understanding to build their intuition about software security. Our research found that organizations whose developers had completed just one lesson in our hands-on Security Labs training program fixed 50 percent of flaws two months faster than those without such training.”

The data was published in Veracode’s annual State of Software Security (SoSS) report v12, which analyzed 20 million scans across half a million applications in the technology, retail, manufacturing, healthcare, financial services, and government sectors. Overall, the technology industry was revealed to have the second-highest proportion of applications that contain security flaws, at 79 percent, making it marginally better than the public sector at 82 percent. The tech sector lands in the middle of the pack when it comes to the proportion of flaws that are fixed.

Tech Firms Are Comparatively Quick to Fix Software Security Flaws

Encouragingly, when tech firms do discover flaws in their applications, they are comparatively fast to reach the halfway point of remediation. In fact, the sector boasts industry-leading fix times for flaws discovered by static analysis security testing (SAST) and software composition analysis (SCA). While this is a laudable accomplishment, the industry still takes up to 363 days to fix 50 percent of flaws, suggesting there is still ample room for improvement.

Eng added, “Log4j sparked a wake-up call for many organizations last December. This was followed by government action in the form of guidance from the Office of Management and Budget (OMB) and the European Cyber Resilience Act, both of which have a supply chain focus. To improve performance in the year ahead, technology businesses should not only consider strategies that help developers reduce the rate of flaws introduced into code, but also put greater emphasis on automating security testing in the Continuous Integration/Continuous Delivery (CI/CD) pipeline to increase efficiencies.”

Server configuration, insecure dependencies, and information leakage are the most common types of flaws discovered by dynamic analysis of technology applications, which broadly follows a similar pattern to other industries. Conversely, the sector exhibits the highest disparity from the industry average for cryptographic issues and information leakage, perhaps indicating that developers in the tech industry are more savvy on data protection challenges.

The Veracode State of Software Security v12 technology snapshot is available to download here and the full report is available here.

About the State of Software Security Report

The Veracode State of Software Security (SoSS) v12 analyzed the full historical data from Veracode services and customers. This accounts for a total of more than half a million applications (592,720) that used all scan types, more than a million dynamic analysis scans (1,034,855), more than five million static analysis scans (5,137,882) and more than 18 million software composition analysis scans (18,473,203). All those scans produced 42 million raw static findings, 3.5 million raw dynamic findings, and six million raw SCA findings.

The data represents large and small companies, commercial software suppliers, software outsourcers, and open-source projects. In most analyses, an application was counted only once, even if it was submitted multiple times as vulnerabilities were remediated, and new versions uploaded.

About Veracode

Veracode is a leading AppSec partner for creating secure software, reducing the risk of security breach, and increasing security and development teams’ productivity. As a result, companies using Veracode can move their business, and the world, forward. With its combination of process automation, integrations, speed, and responsiveness, Veracode helps companies get accurate and reliable results to focus their efforts on fixing, not just finding, potential vulnerabilities. Learn more at www.veracode.com, on the Veracode blog, on LinkedIn, and on Twitter.

Copyright © 2022 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20221208005101/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

AI Meets Traditional Culture: Huangshan Captures Widespread Attention at ITB Berlin7.3.2026 10:22:00 CET | Press release

Huangshan, one of China’s most iconic scenic destinations, drew significant attention at this year’s ITB by presenting a compelling fusion of traditional Chinese culture and cutting-edge artificial intelligence under the slogan “The world of Huangshan is for the world.” This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260307909978/en/ International visitor admires Huangshan cultural and creative exhibits at the Huangshan stand during ITB Berlin. Located in eastern China’s Anhui Province, Huangshan is famed for its “Five Natural Wonders” — fantastic pines, grotesque rocks, sea of clouds, hot spring and winter snow. The mountain is widely regarded as one of China’s greatest mountain landscapes. It is also a rare natural heritage site that simultaneously holds multiple international designations, including UNESCO World Cultural and Natural Heritage status, a UNESCO Global Geopark and a World Biosphere Reserve. At ITB, the Huangsh

Incyte Announces the European Commission Approval of Zynyz® (retifanlimab) for the First-Line Treatment of Advanced Squamous Cell Carcinoma of the Anal Canal (SCAC)6.3.2026 22:42:00 CET | Press release

- Zynyz® (retifanlimab) in combination with carboplatin and paclitaxel (platinum-based chemotherapy) is the first systemic treatment for adult patients with advanced SCAC in Europe- The EC approval is based on results of the POD1UM-303 study which showed that adult patients with advanced SCAC achieved significantly improved progression-free survival with Zynyz in combination with carboplatin and paclitaxel as a first-line treatment compared to chemotherapy alone.1 Incyte (Nasdaq:INCY) today announced that the European Commission (EC) has approved Zynyz® (retifanlimab) in combination with carboplatin and paclitaxel (platinum-based chemotherapy) for the first-line treatment of adult patients with metastatic or with inoperable locally recurrent squamous cell carcinoma of the anal canal (SCAC). “The EC approval of Zynyz marks an important step forward for patients with advanced SCAC, a rare cancer for which meaningful treatment advances have not occurred in several decades,” said Bill Meur

Dfns Launches Payouts6.3.2026 21:27:00 CET | Press release

Dfns today announced the launch of Payouts, a new API enabling institutions to convert stablecoins to fiat and route payouts across multiple bank accounts while keeping wallet-level governance and controls in place. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260305327930/en/ Convert stablecoins to fiat and settle payouts to bank accounts in 94 countries, today. Solving the problem of single-rail off-ramps Today, most fintechs and institutions still hard-wire a single payout provider into their stack, or rely on vertically integrated models that bundle routing, pricing, custody, and settlement together. That approach may be convenient early on, but it creates structural problems at scale: weak price discovery because there is no competitive pressure on margins, limited auditability because routing decisions are opaque, and operational fragility because a single provider degradation in any corridor requires architectural i

Klarna Group Plc Clarifies Mechanics of March 9 Lock-Up Expiration6.3.2026 20:23:00 CET | Press release

Klarna Group plc (NYSE: KLAR) today issues the following clarification to ensure investors and market participants have accurate information regarding the mechanics of its lock-up expiration on March 9, 2026, the processes required before pre-IPO shares can be traded on the NYSE, and the prior liquidity opportunities already available to shareholders. This release contains only factual descriptions of the Company's share structure and applicable processes. It does not constitute guidance or a projection of any kind regarding future trading volumes, share price, or the intentions of any shareholder and speaks only as of the date of this press release. 1. 335 million locked-up shares — but two different categories Of the 378 million total ordinary shares outstanding, approximately 335 million are subject to lock-up restrictions expiring March 9, 2026. However, these shares fall into two distinct categories governed by separate sets of regulations. A. 159 million shares (48% of locked-up

Lone Star Funds Announces Agreement to Acquire the Capsules & Health Ingredients Division of Lonza Group AG6.3.2026 18:30:00 CET | Press release

Lone Star Funds (“Lone Star”) today announced that an affiliate of Lone Star Fund XII, L.P. has entered into a definitive agreement to acquire the Capsules & Health Ingredients (“CHI”) division of Lonza Group AG. As part of the transaction, Lonza will retain a 40% equity position in the business. Headquartered in Basel, Switzerland, CHI operates globally across the Americas, Europe and Asia Pacific. The business comprises three segments: Hard Empty Capsules: leading global manufacturer of gelatin and plant-based capsules offering a broad range of innovative solutions for pharmaceutical and nutraceutical customers. Dosage Form Solutions: end-to-end development and manufacturing platform serving nutraceutical and pharmaceutical customers. Health Ingredients: provider of branded, science-backed nutrition ingredients serving joint health, energy and active lifestyle markets. Lone Star believes CHI is a high-quality, globally recognized platform with strong technical capabilities, different

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye