The former CISO at the center of the SolarWinds SEC case. The co-founder who pioneered appsec. Veracode's Chief Strategy Officer.
One panel. One conversation. June 18 at 11 AM ET.
Register free → https://t.co/TshRVhdH7s
If #AI is helping developers code 10x faster, can your security program keep up? Veracode’s Sohail Iqbal shares what CISOs need to know about AI-assisted development, secure code validation, risk prioritization & bringing #AppSec into developer workflows.
https://t.co/38Qddu1R5n
80.7% of organizations got breached last year.
Read the 2026 Cyberthreat Defense Report to learn why — and what separates the 19.3% who didn't
https://t.co/5eclycKffD
66% of critical long-lived vulnerabilities come from third-party code, not your engineers. Add AI-generated code to the mix, and “scan once, patch later” no longer works. Here’s what modern software supply chain risk management actually looks like:
https://t.co/NEInL9w5rO
20 years of Veracode 🎉
From the early days of #AppSec to today’s AI-driven software landscape, we’ve helped organizations understand, reduce, and manage software risk at scale.
Trust matters more than ever.
Trust is Veracode. 💪
🖇️ https://t.co/gSBwgl77U1
31% of breaches now start with exploited vulnerabilities, making them the #1 attack vector. Meanwhile, 66% of critical vulns come from third-party code. Security teams need a real software supply chain security framework, not more point tools.
https://t.co/euRH5D7RmA
AI-enabled evasive malware = #1 security threat concern (45.5%). Traditional defenses? Not cutting it anymore.
Tomorrow at 11am ET, discover how leading orgs defend against AI-powered attacks. Register: https://t.co/oxnbp7Gc96
The 2026 Verizon #DBIR is out, and the findings for AppSec teams are hard to ignore. This year’s report includes a CWE survival analysis showing how long flaws stay open in production environments. We broke down what it means for developers and defenders:
https://t.co/uVYKbPkchJ
Top AppSec teams prioritize vulnerabilities based on:
→ Exploitability
→ Exposure
→ Business impact
Risk-based prioritization helps reduce noise, focus remediation efforts, and demonstrate measurable security outcomes.
https://t.co/0lYVywvKb3
80.7% of orgs are getting breached despite rising security budgets. The problem? Only 42.2% have fully implemented secure coding practices.
On May 21st at 11am ET, learn how to close the gap without slowing down:
https://t.co/oxnbp7Gc96
#DevSecOps#CyberSecurity
We tested 150+ AI models writing code. Only 55% of what they generated was secure.
The other 45% contained known vulns, and that number hasn’t really improved in 2 years.
AI coding tools are accelerating development & security debt at the same time.
https://t.co/lkGXW1pFUc
The scariest thing about AI in software development isn’t AI replacing developers. It’s software being created faster than trust can keep up. More code. More dependencies. Less human review. Our CEO Brian Roche on why software trust is the next frontier:
https://t.co/Iju9L7SOHP
Security budgets are up. Breaches are too.
81% of organizations were breached last year, according to the 2026 Cyberthreat Defense Report. You can’t fight AI-speed threats with human-speed remediation.
How leading teams are closing the AppSec gap: https://t.co/RIjB3IP4hP
The question used to be “Did we scan it?” That’s no longer enough.
Security leaders now need proof their software can be trusted. Continuous, portfolio-wide, supply chain aware, and evidence-driven.
What best-in-class looks like in 2026: https://t.co/HcJ8NlY6at
The “vulnpocalypse” is coming. AI-driven testing will expose years of hidden security debt fast, and discovery will outpace remediation.
Are you ready to handle the surge?
Here’s what to expect and how to prepare: https://t.co/60WvfhJ3cj
The 1990s hacking community helped shape modern security thinking. This podcast from @riskydotbiz revisits that era with Veracode's @WeldPond, from open collaboration to early infosec norms that still influence application risk management today. https://t.co/wcwvjo63z6
Spending big on supply chain security tools? Most get this wrong:
❌ Detection > prevention
❌ Severity > exploitability
❌ Disconnected tools
❌ No AI for remediation
66% of critical debt in 3rd-party code. Choose tools that cut risk without slowing devs
https://t.co/ZAWaIFr0AN
AI is accelerating software risk faster than frameworks can keep up. Checking the box ≠ being secure.
The new standard?
➡️ Prioritize risk
➡️ Fix what matters most
➡️ Provide continuous visibility
Great perspective from @WeldPond in @Forbes: https://t.co/CiGaHCf9nX
#AppSec
Dev teams are creating flaws faster than they fix them. The remediation gap is widening & critical security debt is rising.
Get the data in our 2026 State of Software Security Report: https://t.co/HzDNuDcb5v
“Did we scan it?” isn’t enough anymore.
AI is accelerating code and shrinking exploit windows.
The question now: can you prove what risk matters and trust what you ship?
More: https://t.co/peuTJ8szLr