Business Wire

Veracode Revolutionizes Cloud-Native Security with Dynamic Duo: DAST Essentials and Veracode GitHub App

Share

AWS re:Invent booth #270 – Veracode, a global leader in intelligent software security, today announced product innovations to enhance the developer experience. The new features integrate security into the software development lifecycle (SDLC) and drive adoption of application security techniques in the environments where developers work.

According to a recent study by analyst firm IDC, 84 percent of organizations say developer acceptance of security tooling is the “most important requirement” or a “very important requirement” for DevSecOps adoption.¹ Veracode’s latest innovations redefine the approach to securing cloud-native applications throughout the SDLC, reinforcing the company’s commitment to providing a unified platform for comprehensive security risk management.

Brian Roche, Chief Product Officer at Veracode said, “Developers face immense pressure to rapidly deliver innovations, often resorting to mechanisms such as LLMs and open source to expedite the process. Unfortunately, this approach can result in insecure code consumption and solutions that exacerbate security risks rather than mitigate them. The situation is compounded by existing security tools that add complexity rather than simplifying the process for developers.

Veracode addresses this challenge by providing a unified platform that not only monitors and mitigates risk but also streamlines developer workflows across repositories, IDEs, and the cloud. By delivering developer-friendly security tools, we empower organizations to deliver secure software faster, eliminating the need to compromise between security and speed.”

The Next Frontier: DAST Essentials

In a world where web applications account for 60 percent of breaches² and API attacks skyrocketed by 137 percent in 2022,³ ensuring cloud-native applications are sufficiently protected and continuously monitored is paramount. Dynamic scanning analyzes live runtime systems using real-world attack methods in a safe environment and can be performed in a pre-production environment—within the SDLC. Traditional point solutions fall short and often don’t offer the scalability and flexibility required by growing organizations. In contrast, Veracode’s DAST Essentials is an agile solution that empowers developers and security teams to address risk easily at speed and scale.

"As organizations continue to grapple with the challenge of securing an ever-expanding attack surface, the need for comprehensive solutions is undeniable. Balancing speed of development with robust security is a daunting task, hindered by the time-consuming nature of regular dynamic scans and the disconnect between development and security teams," said Katie Norton, senior research analyst, DevOps and DevSecOps, at IDC. "Solutions, like Veracode DAST Essentials, that are integrated and reduce friction for developers can help to accelerate secure software development, unify remediation efforts, and empower organizations to strengthen their defenses in the evolving cybersecurity landscape.”

With one of lowest customer-reported false-positive rates (below five percent), Veracode DAST Essentials scans and tests multiple web applications and APIs (Application Programming Interfaces) simultaneously. Veracode’s State of Software Security research found 80 percent of web applications have critical vulnerabilities that can only be identified through dynamic scanning. This emphasizes the critical role DAST (Dynamic Application Security Testing) plays in a robust application security program, ensuring organizations can address exploitable vulnerabilities in cloud-native software accurately and swiftly.

Supply chain solutions specialist, Manhattan Associates, chose to partner with Veracode on its dynamic analysis and cloud-native security program. Rob Thomas, Executive Vice President, Research & Development and Cloud Operations at Manhattan Associates, said, “Veracode’s tenure in the industry and the fact that they are cloud-based means they can continually deliver new innovation. Having a cloud-native partner like Veracode enables us to scan our software continuously so we have real-time confidence that our solution is as safe as possible.”

Enhancing Developer Workflows: Veracode GitHub App

Veracode understands the challenges developers face in adopting cloud-native security measures without disrupting their workflows. The Veracode GitHub App facilitates developer adoption, allowing application security teams to configure once and seamlessly onboard developers. This integration enables developers to fix code quickly in the environments where they work with a single tool for static, software composition analysis (SCA), and container security scanning. The result is a faster, frictionless development process that doesn’t compromise security.

Enhanced Repo Scanning

Scanning cloud-native applications for the first time is often a manual, complex and frustrating process. The Veracode GitHub App simplifies this by providing developers with frustration-free scan results in their preferred environment. DevOps teams can easily onboard repositories without manual setup, maintaining development velocity and streamlining scan processes. With the ability to standardize scan configurations across hundreds of repositories using a single click, DevOps teams can reduce friction and integrate cloud-native security much earlier in the development cycle.

Roche closed, “Ensuring the security of cloud-native applications has never been more crucial. Developers are assembling code just as much as they’re writing it, meaning even the most meticulously built applications are susceptible to threat. To protect the software supply chain, modern application development demands a paradigm shift in security practices. As distributed cloud app development methods take hold, these latest product innovations demonstrate Veracode is embracing the dynamic nature of the cloud-native landscape to lead the charge in securing our digital future."

This announcement follows the launch earlier this year of AI-powered remediation engine, Veracode Fix, which was named one of the 20 Hottest Cybersecurity Products and most interesting products to see at RSA Conference 2023.

AWS re:Invent Unveiling

The market availability of all these capabilities will be announced at AWS re:Invent 2023, November 27th to December 1st in Las Vegas, Nevada.

Visit booth #270 at AWS re:Invent to find out more about Veracode’s intelligent software security platform innovations, including Veracode DAST Essentials, Veracode GitHub App, and Veracode Fix.

-END-

¹ IDC, “DevSecOps Adoption, Techniques, and Tools Survey, 2023,” Katie Norton and Jim Mercer, May 2023
² Verizon, “2023 Data Breach Investigations Report,” June 2023
³ Akamai, State of the Internet (SOTI) report, April 2023

About Veracode

Veracode is intelligent software security. The Veracode Software Security Platform continuously finds flaws and vulnerabilities at every stage of the modern software development lifecycle. Using powerful AI trained on a carefully curated, trusted dataset from experience analyzing trillions of lines of code, Veracode customers fix flaws faster with high accuracy. Trusted by security teams, developers, and business leaders from thousands of the world’s leading organizations, Veracode is the pioneer, continuing to redefine what intelligent software security means.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and Twitter.

Copyright © 2023 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

For more information, please contact:
Katy Gwilliam
kgwilliam@veracode.com

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Fujirebio Receives Marketing Clearance for Lumipulse ® G pTau 217/ β-Amyloid 1-42 Plasma Ratio In-vitro Diagnostic Test as an Aid to Identify Patients With Amyloid Pathology Associated With Alzheimer’s Disease17.5.2025 09:58:00 EEST | Press release

Fujirebio today announced that the U.S. Food and Drug Administration (FDA) has granted 510(k) clearance for the company’s Lumipulse® G pTau 217/β-Amyloid 1-42 Plasma Ratio in-vitro diagnostic (IVD) test for the assessment of amyloid pathology in patients being evaluated for Alzheimer’s disease and other causes of cognitive decline. The test, which was granted Breakthrough Device Designation by the FDA, is the first FDA cleared blood-based IVD test in the U.S. to aid to identify patients with amyloid pathology associated with Alzheimer’s Disease (AD). Alzheimer’s disease currently affects an estimated 7.2 million Americans, a number projected to rise to nearly 14 million by 2060.1 It is a leading cause of disability and death. AD develops over many years, long before symptoms are evident, but the lack of accessible, minimally invasive diagnostics results in many patients remaining undiagnosed until the disease is well advanced, when few effective interventions remain. The Lumipulse G pT

IFF Announces Pricing of Tender Offers For Certain Outstanding Series of Notes17.5.2025 00:17:00 EEST | Press release

IFF (NYSE: IFF) announced today the Total Consideration (as defined below) payable in connection with its previously announced tender offers to purchase for cash: (i) up to $1,100,000,000 aggregate purchase price, excluding accrued and unpaid interest (the “Amended Pool 1 Maximum Amount”), of its 1.230% Senior Notes due 2025 (the “2025 Notes”), 1.832% Senior Notes due 2027 (the “2027 Notes”), 4.450% Senior Notes due 2028 (the “2028 Notes”) and 2.300% Senior Notes due 2030 (the “2030 Notes” and collectively with the 2025 Notes, the 2027 Notes and the 2028 Notes, the “Pool 1 Notes”) and (ii) up to $900,000,000 aggregate purchase price, excluding accrued and unpaid interest (the “Amended Pool 2 Maximum Amount” and, together with the Amended Pool 1 Maximum Amount, the “Amended Maximum Amounts”), of its 3.268% Senior Notes due 2040 (the “2040 Notes”), 4.375% Senior Notes due 2047 (the “2047 Notes”), 5.000% Senior Notes due 2048 (the “2048 Notes”) and 3.468% Senior Notes due 2050 (the “2050

Origins Launches in the U.S. Amazon Premium Beauty Store16.5.2025 16:00:00 EEST | Press release

Origins, with over 30 years of expertise in combining naturally-derived and scientifically crafted ingredients for powerful skincare, announced its official debut in the U.S. Amazon Premium Beauty store today. Origins will offer its iconic skincare and body care products along with giftable sets that are perfect for any occasion. Origins will now bring naturally-derived, effective beauty to Amazon customers nationwide with convenience and thoughtful gifting in mind. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250516435958/en/ This launch marks a strategic step in Origins’ ongoing efforts to meet the evolving needs of skincare shoppers, seeking high-performance, conscious beauty on their favorite platforms. By expanding to the U.S. Amazon Premium Beauty store, Origins reinforces its commitment to delivering both efficacy and accessibility to even more consumers. Amazon customers will now be able to discover and purchase Or

The smarter E Europe 2025: Studies, Technologies and Market Trends for the Energy System of Tomorrow16.5.2025 13:47:00 EEST | Press release

Exactly one week has passed since The smarter E Europe closed its doors in Munich. Once again, Europe’s largest alliance of exhibitions for the energy industry turned the Bavarian capital into the epicenter of the global energy sector and impressed with outstanding results. Over the course of three days, 2,737 exhibitors from 57 countries showcased their technologies, business models and market-ready solutions for an intelligent, interconnected and fully renewable energy system. Around 107,000 professionals from 157 nations took the opportunity to connect, initiate partnerships and launch new projects. The accompanying conferences and side events also attracted strong interest, drawing more than 2,600 participants. The message sent out by The smarter E Europe and its four exhibitions – Intersolar Europe, ees Europe, Power2Drive Europe and EM-Power Europe – was clear: We are the energy system. This press release features multimedia. View the full release here: https://www.businesswire.c

IFF Announces Early Tender Results and Increase of Tender Offers for Certain Outstanding Series of Notes16.5.2025 13:30:00 EEST | Press release

IFF (NYSE: IFF) announced today the early tender results for its tender offers to purchase for cash certain of its outstanding series of Notes. IFF also announced it has increased the previously announced Pool 1 Maximum Amount (as defined below) from $1,000,000,000 to $1,100,000,000 (the “Amended Pool 1 Maximum Amount”), the Pool 2 Maximum Amount (as defined below) from $800,000,000 to $900,000,000 (the “Amended Pool 2 Maximum Amount”, and together with the Amended Pool 1 Maximum Amount, the “Amended Maximum Amounts”), the 2027 Series Tender Cap (as defined below) from $300,000,000 to $400,000,000 and the 2050 Series Tender Cap (as defined below) from $600,000,000 to $649,114,000. The 2025 Notes Series Tender Cap and the 2040 Notes Series Tender Cap (each as defined below) remain unchanged at $500,000,000 and $450,000,000, respectively. Details of tender offers IFF initially offered to purchase for cash: (i) up to $1,000,000,000 aggregate purchase price, excluding accrued and unpaid in

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye