Veracode
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform offers adaptive software security and is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing.www.veracode.com
19
MENTIONS
7
EPISODES
6
PODCASTS
Search complete. 19 mentions across 7 episodes found for "Veracode".
Sep 15, 2026
Episode 334 - w/ Ryan Lloyd - Mobile Application Security
R
8:32Ryan LloydGUEST
I was at SmartBear Software for a while, which is all around automated testing and QA.
R
8:37Ryan LloydGUEST
And then I went to Veracode after that.
R
8:41Ryan LloydGUEST
That was kind of a nice transition from automated testing to automating security testing.
S
8:47Seth LawHOST
And
S
10:11Seth LawHOST
It had to have been 15 years ago at this point, but they were talking about the code review process.
S
10:16Seth LawHOST
how many lines of code like developers could review in a manual code review session right and you know per hour or whatever it is and it was partially we were teaching manual code review from a security perspective and so they had this article that we referenced i mean yeah every time that we taught the course because it was like you know four to five hundred lines of code per hour is kind of that that maximum of what what people can actually consume at any given time.
S
10:43Seth LawHOST
So it's a very difficult prospect when it comes to something like Veracode or what Dry Run is doing from a, you know, you're analyzing millions of lines of code.
S
10:51Seth LawHOST
There's no way that a human can actually do that.
AI models can find security vulnerabilities. Can they fix them? with Keith Hoodlet
K
27:43Keith HoodletGUEST
And naturally, I feel like people are just going to reach for large language models as a coding solution to this problem.
K
27:50Keith HoodletGUEST
And knowing some of the research that had been presented from Veracode and sort of continuously updated around the consistent 44% rate of new vulnerability introduction in AI generated code made me wonder, you know, how capable is it of maybe editing existing code rather than building something new, like from like whole cloth? Yeah.
K
28:13Keith HoodletGUEST
and uh yeah what we found out was certainly some interesting results that i think changed a lot of people's opinions on what it's capable of today
W
28:20WadeHOST
i i feel like that that was the common answer was to just use ai to solve ai problems right like ai is generating all this stuff the only way to really fix it is to just embrace it and go with it which is also a scary thought but what did you expect to find after doing all this research
19 MINS LATER
K
47:09Keith HoodletGUEST
And how many times do you have to do that until you get like a fully clean code base is going to be an outstanding question that a lot of people are going to have to ask.
W
47:18WadeHOST
What improvements would you think need to happen before organizations can start trusting these AIs for vulnerability remediation?
K
47:25Keith HoodletGUEST
I mean, a few things that we're thinking of right now is, and Chris Weisopel is quoted from Veracode.
K
47:33Keith HoodletGUEST
He is one of the founders, and I think he's now chief security evangelist over there at Veracode.
The New Attack Surface: Managing Risk in an AI and Open Source World
C
0:56Christopher SteffenHOST
And that creates a whole new kind of attack service.
C
0:59Christopher SteffenHOST
And where does that lead the security leaders? So today I'm joined by Chris Insohal from Veracode.
C
1:05Christopher SteffenHOST
Outstanding.
C
1:06Christopher SteffenHOST
You wouldn't believe the conversations that we've already had today.
C
1:33Chris WysopalGUEST
Great to be here with you, Chris.
C
1:34Chris WysopalGUEST
So my name is Chris Weisopel.
C
1:36Chris WysopalGUEST
I'm the co-founder of Veracode.
C
1:38Chris WysopalGUEST
I'm currently our chief security evangelist.
Inside Slack Code: what it is, and why Anthropic just became its founding partner
M
8:28Mike BelsitoHOST
Now, when it comes to code, there's lots of code out there that would be considered AI slop.
M
8:33Mike BelsitoHOST
Actually, Veracode's 2026 security report found that roughly 44% of AI code generation tasks introduced a real exploitable vulnerability.
M
8:44Mike BelsitoHOST
The average security pass rate across models tested was 56%.
M
8:48Mike BelsitoHOST
But in the same period, AI-assisted developers were committing code three to four times faster than everyone else.
Episode 331 - Being "Mythos" Ready, CRLF-Powered De-sync Attacks
K
14:52Ken JohnsonHOST
Obviously, that's kind of a silly statement to a degree because you can, you know, they set up these sessions where people can come and they can like learn about your product and all this kind of stuff.
K
15:01Ken JohnsonHOST
I know that because the one thing that I can say is like, I actually did a presentation with Veracode because, you know, now Dry Run Security, our company has partnered with Veracode.
K
15:10Ken JohnsonHOST
They kind of realized that Not kind of like their customers are realizing like, hey, like we need to modernize.
K
15:16Ken JohnsonHOST
And so Verico needs an answer for that.
When AI agents escape the sandbox
S
32:35Steve WilsonGUEST
And You know, just to go through some examples, right? I say, scan your code.
S
32:43Steve WilsonGUEST
Well, I could scan it today with the exact scanner that I have, which would be Snyk or Veracode or Checkmarks.
S
32:50Steve WilsonGUEST
Scanning an agent with those is actually pretty useless.
S
32:52Steve WilsonGUEST
It will tell you if you're vulnerable to certain classes of really dumb old school programming, but it won't tell you...
When AI Generated Patches Become the New Vulnerability
A
11:38Andrew MorganHOST
Is it?
K
11:41Keith HoodletGUEST
I mean, I think both between the research that we've published as well as research coming out of Veracode and others, we're working with the University of Alabama's High Performance Computing Center as well to do some tests, basically, or what are they called now? Is it an M? Anyway, I can't remember the name, I'll come back to it.
K
12:01Keith HoodletGUEST
But we're doing some runs right now just to determine what does the scale look like in terms of reproduction rate of vulnerabilities over time, given what we know from Veracode's research earlier this year, as well as our own research.
K
12:14Keith HoodletGUEST
And effectively, their runs currently show that we have an exponential runaway of vulnerabilities being introduced by AI in all likelihood, at least given current research and numbers that we've seen.
K
12:25Keith HoodletGUEST
So I think it's a really great job description for security professionals who are going to have to sit there and address these problems.
K
15:21Keith HoodletGUEST
And yeah, mythos was on everyone's mind.
K
15:25Keith HoodletGUEST
You know, the wave of vulnerabilities or tsunami, as some people are calling it, was one of those things that I think all of us were pretty concerned about.
K
15:33Keith HoodletGUEST
And given some of the research from Veracode, where they just had their spring update on Gen-AI code security and the introduction of vulnerabilities as sort of a consistent 50-ish percent rate for net new code in their study.