Director, Tanzu Application Platform GTM & Sales Execution. Tech junkie focused on dev experience and security on k8s and agile dev to help businesses innovate.
Choosing a software supply chain security vendor can feel complicated.
Effective questions are: How strong is the vendor on provenance and attestation? Can it help prevent malicious packages? Will it work without slowing teams down?
🔗 A useful guide: sprou.tt/1g0PdepjzE1
#AI is creating more code and more security tools to manage.
In a new Techstrong TV interview, I had the chance to discuss why AppSec teams need better context, prioritization and remediation workflows as AI scales.
#AppSecsprou.tt/1qBDPcwWk6a
A more capable AI model doesn’t necessarily mean a more secure one.
Veracode’s latest testing found that GPT-5.6 Sol improved significantly in Python security, but gains weren’t consistent.
🔑 A model has a security profile, not just a security score. sprou.tt/1SY9A9veIwm
Join Veracode 10/8 at the Boston Cybersecurity Summit — our team will be onsite to discuss the latest in Application Security & share our thoughts during the AI and Emerging Tech at the 2026 Security Frontline Panel.
We hope to see you there! sprou.tt/1GSoM8Nf5xR
If you care about proactive security research and strengthening defenses, GRRCon is the place to be. Can’t wait for the deep-dive sessions, hands-on demos, and the chance to exchange strategies with the community. Let’s make security better together. sprou.tt/1N65zHWqbwf
Join Veracode 10/1 at the Seattle Cybersecurity Summit — our team will be onsite to discuss the latest in Application Security & share our thoughts during the AI and Emerging Tech at the 2026 Security Frontline Panel. We hope to see you there! sprou.tt/1huccVz1zc0
There is still time to reserve a spot at the Gartner Global CISO Community Executive Summit this month! Our CISO will be sharing his insights on navigating AI in a safe and productive way without slowing down your application development. sprou.tt/1XXunJNOm5K
Great interview with our CEO Brian Roche on where software security is headed in the #AI era. Speed without trust is a liability.
Read the full interview on Investment Reports and check out Brian's comments in the Washington Post: washingtonpost.com/creativeg…sprou.tt/1eiplWDPMwN
CyberScoop cites Veracode research showing AI-generated code has an average security pass rate of about 56%, with 44% of tests introducing #OWASP Top 10 vulnerabilities. AI patches should be reviewed like any other code change.
#GenAI#AppSecsprou.tt/1OEWcJtKqVY
Security debt grows when findings enter the system faster than fixes leave it.
@weldpond shares 4 workflow changes DevSecOps leaders can make now: measure throughput, move decisions into workflows, create a risk fast lane, and budget capacity.
#DevSecOpssprou.tt/1vjmxLW3Wsf
Dark Reading cites Veracode research showing AI-generated code had a 56% average security pass rate across 100+ models. #AI output can look complete and functional while remaining unreliable from a security standpoint. Verify before you ship.
#GenAIsprou.tt/1b0ji2zE6uE
Java Source Code Scanning lets teams scan source files directly, with no compilation required. That means faster feedback in pull requests, fewer build configuration headaches, and flexible source, binary, or hybrid scanning.
#Java#AppSec#DevSecOpssprou.tt/1VJirPKH4Ja
Who authorized that tool call?
Chris Wysopal’s Black Hat USA 2026 takeaway: #AI agent security controls need to sit where sensitive actions happen.
They need trusted authorization evidence, runtime constraints, and auditability.
#AppSec#AgenticAIsprou.tt/11MYW2a3N4H
AI code generation is accelerating. AI code security isn't - the average security pass rate is still 56%.
Chris Wysopal and Samuel Guyer will break down the 2026 GenAI Code Security Report findings and what security leaders should do now in this webinar. sprou.tt/1tdVsvjkgA1
Security teams have been talking about security debt for years. It's time for the board to pay attention too.
In TechRadarPro, Veracode's Sohail Iqbal explains why software risk deserves the same attention as financial risk in the boardroom.
Read more: sprou.tt/1sJe97XPAbd
82% of organizations carry security debt, making it a serious business risk.
Veracode CISO Sohail Iqbal explains why leaders need to rethink how they measure, prioritize, and address security debt, and why this conversation belongs in the boardroom.
🔗: sprou.tt/1nhIZIBmTBL
Still need a pass to the upcoming Chicago CyberSecurity Summit on September 15? Use code CSS26-Veracode to join us at the event and discuss the latest research on how #GenAI is affecting application security.
Hope to see you there! sprou.tt/1aw9RPu5dZJ
Veracode’s latest GenAI Code Security Report found LLMs generated vulnerable code 44% of the time across 100+ AI models. As @weldpond told Forbes, AI-generated code needs to be traced, scanned and fixed so it is “never shipped blind.”
#GenAI#AppSecsprou.tt/18nECjHw1EO
AI can produce syntax-correct code 99% of the time, yet Veracode research cited by CSO found 44% of AI-generated code still contained OWASP Top 10 vulnerabilities.
Why is AI improving at syntax and exploit code, while secure coding still lags?
#AppSecsprou.tt/1tGNelIdzW6
LLMs can help find business logic gaps like missing authorization checks. Deterministic SAST is still essential for #OWASP Top 10 coverage, auditability, and policy enforcement.
Read why hybrid SAST is the practical path forward.
#GenAI#AppSecsprou.tt/1jcIL727wZu