Business Wire

Veracode Releases Platform Enhancements as Software Supply Chain Attacks Surge

28.1.2026 14:50:00 EET | Business Wire | Press release

Share

Veracode, the global leader in application risk management, today announced significant platform innovations introduced through the second half of 2025. Headlining the release is Package Firewall, an industry-leading preventive control for software supply chains, advancing the company’s mission to help organizations run secure software from code to cloud. With supply chain-related third-party breaches doubling year over year— from 15 to 30 percent according to the Verizon 2025 Data Breach Investigations Report— the need to strengthen security across the software ecosystem has never been greater.

“The growing attack surface has created an unprecedented level of complexity for security and development teams,” said Tim Jarrett, Vice President of Product at Veracode. “The latest enhancements to our platform empower organizations to stop third-party risk from ever entering their software code, providing them with a prevention-first approach.”

Package Firewall Enhancement: Preventing Supply Chain Attacks at the Source

Package Firewall, originally launched in June 2025, provides organizations with preventive control over their software supply chains by blocking malicious and risky packages before they enter the development environment. While traditional Software Composition Analysis (SCA) tools identify vulnerabilities in packages that are already in use, Veracode Package Firewall stops threats at the point of ingestion.

The solution now integrates with Azure Artifacts and deploys in seconds with integrations into package managers and repositories, like NPM, PyPI, Maven, Nexus, and Artifactory. It also supports custom policies that enable organizations to enforce security standards while maintaining developer productivity. Organizations can configure policies based on package risk profiles, vulnerability thresholds, and specific security requirements.

Expanded Platform Capabilities and Developer Experience

Veracode continued to expand and enhance its platform capabilities and developer experience throughout the year, with each release improving detection accuracy. Dynamic Application Security Testing (DAST) Essentials gained manual application linking, enabling policy evaluation and consolidated reporting. Software Composition Analysis (SCA) was upgraded with intelligent policies that only fail builds when fixes are available for vulnerable components, reducing developer friction. Static Analysis support was added for cutting-edge frameworks, including .NET Semantic Kernel, Python frameworks like AWS Glue and FastAPI, Java JDK 25 (LTS), and Node.js 22.x.

The platform also saw significant updates to developer integrations for Visual Studio, JetBrains, Azure DevOps, and GitHub, alongside expansions to Veracode Security Labs, with training modules in container security content and the latest OWASP Top 10.

Enterprise-Grade Authentication for Developer Tools

The most recent platform update saw Veracode introduce the advanced enterprise-grade security required by modern organizations. The company added more thorough platform integration and deeper role-based access control to Veracode Risk Manager (VRM), and OAuth-based single sign-on (SSO) authentication across its entire Integrated Development Environment (IDE) plugin portfolio, including Visual Studio Code, Visual Studio, Eclipse, and JetBrains platforms. The integration eliminates Application Programming Interface (API) key management and delivers secure, enterprise-grade authentication with centralized access control.

Jarrett closed, “Our mission is to empower organizations to enhance their security posture, bridge critical skills gaps, and accelerate remediation—all within a unified, integrated platform. By listening closely to our customers, we continuously evolved Veracode’s platform in 2025 to meet their needs, enabling them to drive faster, more secure DevSecOps practices.”

To learn more about Veracode’s products and platform enhancements, visit the website.

About Veracode

Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, Package Firewall, and Penetration Testing.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.

Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands, or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

View source version on businesswire.com: https://www.businesswire.com/news/home/20260128773416/en/

Contacts

Press and Media Contacts
Katy Gwilliam
Head of Global Communications, Veracode
kgwilliam@veracode.com

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

www.businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Geoprofessionals Spend a Quarter of Their Time Managing Data and Are Increasingly Turning to AI, Reveals New Seequent Survey28.1.2026 16:00:00 EET | Press release

Seequent, the Bentley Subsurface company, says mining and civil geoprofessionals turning to AI still struggle to unlock value from increasingly complex, multisource datasets, according to its 7th Geoprofessionals Data Management Report. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260128879634/en/ Geoprofessionals spend a quarter of their time managing data and are increasingly turning to AI, reveals new Seequent survey. The global report, based on a survey of more than 1,000 geoprofessionals worldwide, highlights teams grappling with complex datasets across multiple software platforms, unmanaged historical data, and significant time spent on routine data administration. Angela Harvey, Chief Customer Officer, Seequent, said: ‘According to the report findings, geoprofessionals on average spend over a quarter of their time on data management. They are actively seeking to harness the information it contains for competitive ad

Brown Brothers Harriman Investor Services and SimCorp Forge Strategic Alliance to Provide Integrated End-to-End Technology, Data, and Services Solution for Global Asset Managers28.1.2026 16:00:00 EET | Press release

Brown Brothers Harriman (BBH), a privately held global financial services firm, and SimCorp, a leading global financial technology company, today announced a new strategic alliance to address the needs of global asset managers requiring an integrated, end-to-end technology, data, and services solution. Enhancing both firms’ existing offerings, this solution uses BBH Infomediary to integrate SimCorp One’s front and middle office capabilities, including a real-time IBOR managed by SimCorp’s Managed Business Services, with BBH’s fund servicing and custody suite. BBH Infomediary, BBH’s connectivity and data integration engine, will also enable a unique open architecture model that helps connect clients to third party technologies and service providers. “For managers seeking to streamline their technology and operations across the entire investment lifecycle, this offering delivers scalability, accelerates data strategies, and allows a sharper focus on investment results,” said Shawn McNinc

Wunderkind Joins Klaviyo Marketplace, Bringing Identity-Based Personalization and Revenue Growth to E-Commerce Brands28.1.2026 16:00:00 EET | Press release

Wunderkind, the AI decisioning platform that delivers identity resolution and cross-channel personalization to scale performance and reach, today announced its official debut on the Klaviyo App Marketplace. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260128210560/en/ The integration brings Wunderkind’s identity insights directly into Klaviyo’s B2C CRM, powering real-time profiles, segments, and flows that help brands recognize more customers earlier in the journey and deliver relevant experiences across email, SMS and other Klaviyo-powered channels. By layering Wunderkind’s industry-leading Identity Network — built on more than 9 billion device profiles and over a billion unique user identities — into Klaviyo’s unified customer profile, marketers can strengthen their understanding of who customers are, unify identity across channels, and activate personalization through Klaviyo without adding complexity to their tech stac

WeFi Technology Group Announces Partnership with PGA Tour Rising Star28.1.2026 15:40:00 EET | Press release

WeFi Technology Group, a global provider of technology-enabled working capital solutions, today announced a multi-year brand partnership with Aldrich Potgieter, the 2025 PGA Tour Rookie of the Year and one of the most promising young players on the international golf circuit. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260128340648/en/ Aldrich Potgieter, 2025 PGA Tour Rookie of the Year and one of the most promising young players on the international golf circuit. Leveraging its AI-powered platform, WeFi Technology operates at the intersection of finance, technology, and innovation in over 40 countries around the globe, delivering working capital solutions that drive client growth. Potgieter rose to global prominence at just 19 years old when he became the youngest winner in Korn Ferry Tour history, a milestone that signalled both elite talent and competitive maturity. His rapid progression since then, claiming his first

CSG Announces Contract Renewal with DISH Network28.1.2026 15:30:00 EET | Press release

CSG® (NASDAQ: CSGS) today announced a multi-year contract extension with DISH Network to continue powering best-in-class customer service. For 45 years, DISH has been connecting communities across the nation, evolving from a satellite pioneer into a diverse connectivity leader. CSG has been a trusted business enabler for much of that journey and will continue to help DISH support its customers through 2030. “CSG has been instrumental to how DISH serves customers,” said John Swieringa, President, Technology, and Chief Operating Officer, DISH. “Our collaboration with CSG will continue to bring us the flexibility and speed we need to deliver the exceptional experiences our customers deserve.” For three decades, DISH has trusted CSG to manage billing and payment services for millions of subscribers with accuracy and reliability. With CSG’s leading SaaS platform for billing, customer care, and business optimization, DISH can drive the next level of customer service with innovative offerings

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye