Skip to main content
Veracode

Veracode

Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform offers adaptive software security and is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing.www.veracode.com

Search complete. 19 mentions across 7 episodes found for "Veracode".

Sep 15, 2026

Ryan LloydGUEST
8:32
I was at SmartBear Software for a while, which is all around automated testing and QA.
Ryan LloydGUEST
8:37
And then I went to Veracode after that.
Ryan LloydGUEST
8:41
That was kind of a nice transition from automated testing to automating security testing.
Seth LawHOST
8:47
And
Seth LawHOST
10:11
It had to have been 15 years ago at this point, but they were talking about the code review process.
Seth LawHOST
10:16
how many lines of code like developers could review in a manual code review session right and you know per hour or whatever it is and it was partially we were teaching manual code review from a security perspective and so they had this article that we referenced i mean yeah every time that we taught the course because it was like you know four to five hundred lines of code per hour is kind of that that maximum of what what people can actually consume at any given time.
Seth LawHOST
10:43
So it's a very difficult prospect when it comes to something like Veracode or what Dry Run is doing from a, you know, you're analyzing millions of lines of code.
Seth LawHOST
10:51
There's no way that a human can actually do that.
Keith HoodletGUEST
27:43
And naturally, I feel like people are just going to reach for large language models as a coding solution to this problem.
Keith HoodletGUEST
27:50
And knowing some of the research that had been presented from Veracode and sort of continuously updated around the consistent 44% rate of new vulnerability introduction in AI generated code made me wonder, you know, how capable is it of maybe editing existing code rather than building something new, like from like whole cloth? Yeah.
Keith HoodletGUEST
28:13
and uh yeah what we found out was certainly some interesting results that i think changed a lot of people's opinions on what it's capable of today
WadeHOST
28:20
i i feel like that that was the common answer was to just use ai to solve ai problems right like ai is generating all this stuff the only way to really fix it is to just embrace it and go with it which is also a scary thought but what did you expect to find after doing all this research

19 MINS LATER

Keith HoodletGUEST
47:09
And how many times do you have to do that until you get like a fully clean code base is going to be an outstanding question that a lot of people are going to have to ask.
WadeHOST
47:18
What improvements would you think need to happen before organizations can start trusting these AIs for vulnerability remediation?
Keith HoodletGUEST
47:25
I mean, a few things that we're thinking of right now is, and Chris Weisopel is quoted from Veracode.
Keith HoodletGUEST
47:33
He is one of the founders, and I think he's now chief security evangelist over there at Veracode.
Christopher SteffenHOST
0:56
And that creates a whole new kind of attack service.
Christopher SteffenHOST
0:59
And where does that lead the security leaders? So today I'm joined by Chris Insohal from Veracode.
Christopher SteffenHOST
1:05
Outstanding.
Christopher SteffenHOST
1:06
You wouldn't believe the conversations that we've already had today.
Chris WysopalGUEST
1:33
Great to be here with you, Chris.
Chris WysopalGUEST
1:34
So my name is Chris Weisopel.
Chris WysopalGUEST
1:36
I'm the co-founder of Veracode.
Chris WysopalGUEST
1:38
I'm currently our chief security evangelist.
Mike BelsitoHOST
8:28
Now, when it comes to code, there's lots of code out there that would be considered AI slop.
Mike BelsitoHOST
8:33
Actually, Veracode's 2026 security report found that roughly 44% of AI code generation tasks introduced a real exploitable vulnerability.
Mike BelsitoHOST
8:44
The average security pass rate across models tested was 56%.
Mike BelsitoHOST
8:48
But in the same period, AI-assisted developers were committing code three to four times faster than everyone else.
Ken JohnsonHOST
14:52
Obviously, that's kind of a silly statement to a degree because you can, you know, they set up these sessions where people can come and they can like learn about your product and all this kind of stuff.
Ken JohnsonHOST
15:01
I know that because the one thing that I can say is like, I actually did a presentation with Veracode because, you know, now Dry Run Security, our company has partnered with Veracode.
Ken JohnsonHOST
15:10
They kind of realized that Not kind of like their customers are realizing like, hey, like we need to modernize.
Ken JohnsonHOST
15:16
And so Verico needs an answer for that.
Steve WilsonGUEST
32:35
And You know, just to go through some examples, right? I say, scan your code.
Steve WilsonGUEST
32:43
Well, I could scan it today with the exact scanner that I have, which would be Snyk or Veracode or Checkmarks.
Steve WilsonGUEST
32:50
Scanning an agent with those is actually pretty useless.
Steve WilsonGUEST
32:52
It will tell you if you're vulnerable to certain classes of really dumb old school programming, but it won't tell you...
Andrew MorganHOST
11:38
Is it?
Keith HoodletGUEST
11:41
I mean, I think both between the research that we've published as well as research coming out of Veracode and others, we're working with the University of Alabama's High Performance Computing Center as well to do some tests, basically, or what are they called now? Is it an M? Anyway, I can't remember the name, I'll come back to it.
Keith HoodletGUEST
12:01
But we're doing some runs right now just to determine what does the scale look like in terms of reproduction rate of vulnerabilities over time, given what we know from Veracode's research earlier this year, as well as our own research.
Keith HoodletGUEST
12:14
And effectively, their runs currently show that we have an exponential runaway of vulnerabilities being introduced by AI in all likelihood, at least given current research and numbers that we've seen.
Keith HoodletGUEST
12:25
So I think it's a really great job description for security professionals who are going to have to sit there and address these problems.
Keith HoodletGUEST
15:21
And yeah, mythos was on everyone's mind.
Keith HoodletGUEST
15:25
You know, the wave of vulnerabilities or tsunami, as some people are calling it, was one of those things that I think all of us were pretty concerned about.
Keith HoodletGUEST
15:33
And given some of the research from Veracode, where they just had their spring update on Gen-AI code security and the introduction of vulnerabilities as sort of a consistent 50-ish percent rate for net new code in their study.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.