News

Veracode Unveils AI-Powered Innovations for Software Security 2025

News | 21.07.2026

Advanced AI-Powered Solutions Reduce Remediation Time While Proactively Blocking 60% of Critical Supply Chain Threats

Enterprise security teams face a paradox: they are overwhelmed by vulnerability alerts yet still miss the risks that matter most. With 70 percent of critical security debt now stemming from third-party code and regulations such as the EU Digital Operational Resilience Act (DORA) tightening expectations, organizations need proactive controls across the software development lifecycle rather than reactive firefighting.

What was announced

Veracode has introduced a suite of innovations to its Application Risk Management platform that reduce vulnerability remediation time by up to 92 percent and prevent 60 percent of critical supply chain risk from entering organizations. The updates cover Veracode Risk Manager, Veracode Package Firewall, and developer productivity tools.

Veracode Risk Manager now includes six new integrations with industry leaders such as Wiz, aggregating and prioritizing issues across sources so security teams can act on the Best Next Action. Veracode Package Firewall uses AI analysis to block untrusted packages before they enter development pipelines, identifying and blocking 60 percent more malicious packages than competing solutions.

Security teams tell us they are drowning in vulnerability alerts while missing the risks that actually matter. Our latest innovations flip the script — instead of endless firefighting, teams can now prevent threats proactively and focus remediation efforts where they will have maximum business impact

Derek Maki, Head of Product at Veracode

Why this matters

For CIOs, CISOs, and procurement leaders, the shift from reactive alerting to preventive control changes the economics of application security. Blocking malicious packages at the gate reduces mean time to remediate, cuts operational overhead for SOC and AppSec teams, and supports compliance with DORA and similar frameworks. According to Gartner, organizations with a high-quality developer experience are 33 percent more likely to attain their business goals — making frictionless security a strategic advantage, not just a technical improvement.

Technical details

  • Veracode Risk Manager: Six new ASPM integrations including Wiz; up to 92% reduction in vulnerability remediation time.
  • Veracode Package Firewall: AI-driven blocking of malicious open-source packages; 60% more effective than competing solutions.
  • SCA and Malicious Package Detection: Neutralizes libraries harboring malicious code before ingestion.
  • AI-Assisted Login for DAST: Automates complex authentication flows, reducing script setup time by 50%.
  • Container and IaC Results: Centralized findings in the Veracode Platform for streamlined vulnerability management.
  • IDE and Git integrations: Visual Studio, IntelliJ IDEA, Eclipse, GitHub, GitLab, Azure DevOps — with 35% faster remediation.
  • Veracode Fix Usage Analytics: Dashboard tracking usage and CWEs addressed by IDE, project, and source file.

Softprom and Veracode

Softprom is the official distributor of Veracode. Enterprises can access the full application risk management portfolio, technical enablement, and licensing support through Softprom.

This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.