#Veracode

2025-11-24

New insights from Veracode’s CISO Sohail Iqbal on how attackers infiltrate CI/CD pipelines and escalate inside runtime environments using stolen tokens, API keys, and misconfigurations.

Full interview:
technadu.com/how-hackers-slip-

#AppSec #Veracode #CyberSecurity #CICD #ThreatDetection #SupplyChainSecurity

How Hackers Slip Into Pipelines and Stay Undetected: The Quiet Risks Hidden in Your Software Supply Chain
2025-09-24

@Piloot Overigens gebruiken wij daar #Veracode en #Renovate voor. De eerste zorgt ervoor dat de pipeline omvalt bij een vulnerability en de tweede maakt automatisch merge requests aan om je dependencies up te graden.

2025-09-11

Nou hebben ze me ooit ingehuurd als #Java developer die ook ops mocht gaan doen, maar for some reason is ons team nagenoeg volledig ops geworden.

Gelukkig mocht ik laatst wat lelijke #Cucumber-tests met dynamisch aangemaakte #WireMock stubs all over the place fixen. Daarvoor had ik een analyse-utility geschreven en ik had en passant het buildscript gereshuffled zodat #Veracode er niet meer 20 minuten over deed. Ik heb geleerd dat het geen #ScopeCreep is zolang je het maar #BoyScoutRule noemt. 😁

Three panel comic.

Dilbert's boss: I hired a creep to help determine our product's features.

Scope Creep: You need more features.

Dilbert's boss: Good work. When can you have that done?

Dilbert: GAAAAAAA!!!
Gus Schenkel :slackware: :kde:gbschenkel@fosstodon.org
2025-03-27

This week they want do a PoC with #VeraCode and #GitHub

How that will be more cheap than #GitLab Ultimate price?

I had created a report in which I evaluated all missing features from GitHub that need to be contracted to compensate GitLab Ultimate.

Values from GitLab was $570K year, versus $1.04M-$2.35M(value depends on the 3rd party tool)

The total is based on 600 licenses.

2025-03-12

Waarom checkt #Veracode mijn pom? 🤔

Dus dan schrijf je software. Die software maakt gebruik van dependencies. In die dependencies kunnen vulnerabilities zitten. En dan zeg je in je dependency management: doe eens even de juiste versie van die transitive dependency gebruiken. En dus komt alleen de juiste versie in mijn JAR terecht. En dan zegt Veracode: check, die zie ik, maar ik leid uit je pom ook nog eens een impliciete versie van diezelfde dependency af. En die is vulnerable. Foei. 🤨

Security products like #veracode need to stop forcing customers to follow outdated password requirements.

2021-03-12

Encore Edition: Veracode CEO Sam King on Infosec’s Leaky Talent Pipeline - Women are more than 50% of the population, but barely 20% of the information security workforce. Why... feeds.feedblitz.com/~/64641811 #womenintheworkforce #womenshistorymonth #womanexecutive #cybersecurity #companies #diversity #spotlight #business #podcasts #veracode

2020-10-27

Holiday Shopping Craze, COVID-19 Spur Retail Security Storm - Veracode's Chris Eng discusses the cyber threats facing shoppers who are going online due to the p... threatpost.com/holiday-shoppin #vulnerabilities #holidayshopping #amazonprimeday #onlineshopping #retailsecurity #retailsoftware #websecurity #blackfriday #cybermonday #podcasts #covid-19 #magecart #pandemic #veracode #podcast #retail #target

2020-05-27

Open source libraries a big source of application security flaws - How many vulnerabilities lurk inside the open source libraries that today’s developers happily bor... more: nakedsecurity.sophos.com/2020/ #developmentlibraries #opensourcebugs #vulnerability #veracode

2020-05-25

70 Percent of Mobile, Desktop Apps Contain Open-Source Bugs - A lack of awareness about where and how open-source libraries are being used is problematic, resea... more: threatpost.com/70-of-apps-open #securityvulnerabilities #mostrecentthreatlists #percentageofapps #vulnerabilities #mobilesecurity #appsecurity #opensource #codereuse #libraries #thereport #veracode #bugs #iot

Dr. Roy Schestowitz (罗伊)schestowitz@gnusocial.de
2018-04-11
#Veracode is truly toxic. Uses NSA back doors in Microsoft Windows (WannaCry) as an argument against FOSS!!! https://gnusocial.de/url/5146151

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst