September took Veracode around the world. 🌍 From the US and UK to Brazil and Dubai, we connected with security leaders on AI, software supply chain risk, and securing software in the AI-coding era. Four countries. One packed month. On to October. 🚀
This week’s CISO Exec Update: residual risk after the patch. Andrea Mazzarini covers edge exploits, identity attacks, CI/CD risk, and what CISOs should prioritize now: https://t.co/RUOrul6R2Z
Anthony Barkley joins @TechstrongTV to discuss how the Veracode Marketplace tackles AI security vendor sprawl, including how Veracode’s deterministic scanning + @DryRunSec’s probabilistic AI reasoning bring broader coverage and context to AppSec. https://t.co/lZYUv0TW1Z
Third-party code is part of your application, and your risk. It drives 66% of the most dangerous, long-lived vulnerabilities. Learn how defense in depth can help teams get ahead of supply chain risk: https://t.co/c3sN71efUi
AI is reshaping how software gets built and secured. A new independent report names Veracode a “Difference Maker” in the top tier of the 2026 AST vendor pyramid. See how the AST market is evolving: https://t.co/Ey8sdGUiwf
🚨 ¡ Por segundo año consecutivo se suma @Veracode como sponsor de #CyberFinance en esta @Ekoparty 2026 🚀
Gracias por acompañarnos a construir un espacio donde ciberseguridad, fraude y finanzas se cruzan para anticipar las amenazas que vienen ⚡🛡️
#Cybersecurity#FraudeDigital
AI agents are writing code and acting across enterprise systems. Security and guardrails are critical.
Veracode is supporting NVIDIA’s Open Agent Safety Platform, securing agent-generated code alongside OpenShell and Sentry on BlueField-4.
Congrats to the @nvidia team!
Today, with over 100 industry partners, we introduced the NVIDIA Open Agent Safety Platform, bringing together OpenShell and Sentry.
Artificial intelligence is extraordinary technology that will advance discovery, productivity, security, health, and prosperity for generations to come.
But its full promise can only be realized when people have confidence that AI is being built to be safe and deployed with wisdom and responsibility.
This is bigger than a single product. It's the beginning of an open ecosystem to build the trust layer for safe agent systems.
Together, we are building the foundation of the AI economy.
Trust and innovation are not in conflict. Safety is how trust is earned. We must build not only the most capable AI, but the most trusted AI, so that this extraordinary technology can realize its enormous promise for the world. https://t.co/ugYWQ1MyRi
Vulnerability exploitation is now the leading breach vector, while 82% of organizations carry security debt. Building the business case for #AppSec means connecting risk to faster releases, efficient remediation and predictable costs.
Learn how: https://t.co/xNNR32SJ4W
AI can generate code roughly 10x faster than humans, putting new pressure on #AppSec. On The Security Strategist, Chris Wysopal and Sohail Iqbal discuss how organizations can keep risk from accumulating as AI-generated code grows.
Watch: https://t.co/Q5gPH0bz0e
Third-party code accounts for 66% of the most dangerous, long-lived vulnerabilities across application portfolios.
Our latest blog outlines three layers of software supply chain security: package firewalls, SCA and container/IaC scanning.
Learn more: https://t.co/YWlQOuWif9
EU Cyber Resilience Act reporting rules are now in effect. Companies worldwide that sell software or connected products in the EU may need to report exploited vulnerabilities within 24 hours.
Learn who’s affected and how to prepare: https://t.co/tN9s4svk4Z
Duplicate alerts and disconnected dashboards slow #DevSecOps. Our latest blog explores how to prioritize findings, bring testing into developer workflows, and expand scan coverage, with a real-world example.
Read more: https://t.co/SJXjLDMNTa
Finding vulnerabilities is only the start. Enterprise teams need to fix risk at scale, enforce policy, support audit readiness, and keep developers moving.
What should you look for in risk remediation software? Veracode breaks down the key criteria: https://t.co/3Z2pOfnXRE
OpenAI is urging organizations to raise the security bar for software, including AI-generated code. Veracode research found 44% of code-generation tasks introduced a known vulnerability. @WeldPond explains the need for continuous verification. #AppSec
https://t.co/z4Pzkb3E7q
AI-generated code security is stuck at 56% across 100+ models tested over four testing snapshots.
For security leaders, that’s not just a model issue. It’s a verification, release-control, and risk issue.
Join Veracode’s live webinar: https://t.co/nzp95Bc9af
New Veracode Research found GPT-5.6 Sol achieved a 70% secure-code pass rate, up 2 points from GPT-5.5. Results varied by language, with Python improving from 70% to 85%.
See the findings: https://t.co/zLOTGPiKfw #GenAI
At #BlackHat, Veracode’s Johnny Wong joined AWS Security Live to discuss vibe coding, the security risks of AI-generated code, and what organizations can do to keep pace as AI accelerates development.
Watch the conversation: https://t.co/OLAAaLRz0e
Security debt is a boardroom issue. In a new article for NODE, Veracode CISO Sohail Iqbal explores how aging vulnerabilities compound business risk and why leaders need to prioritize exposure and remediation capacity.
Read more: https://t.co/nR9X4PoQO5
The Trump administration is considering letting some U.S. companies “hack back” against foreign cybercriminals.
Veracode’s Chris Wysopal spoke with NPR about why offensive cyber operations carry serious risks, including collateral damage.
Listen: https://t.co/hmxeo2lSyL