Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Veracode's 20th Anniversary: Two Decades of Data Powering the Future of Software Security

Twenty years ago, the idea of continuously scanning software for vulnerabilities at scale was ambitious. Today, it’s essential. As Veracode marks its 20th anniversary, we’re not just looking back at what we’ve built; we’re looking forward at what the data tells us about where software security needs to go next. And the data says a lot.

Stopping the Agentic Breach: How to Operationalize Your Defense Against Mythos-Speed Attacks

The industry has spent the past few weeks focused on Claude Mythos Preview and the rise of autonomous offensive AI. As outlined in Claude Mythos, Project Glasswing, and the Machine-Speed Security Race, this shift is not only about faster attacks. The same AI-driven acceleration that helps attackers discover weaknesses faster can also help defenders validate exposure sooner. For security operations teams, the challenge is turning that strategic shift into action.

Agentic AI Security: Governing Shadow Agents on Endpoints

Most enterprise security programs were built around a simple assumption, not invalid assumption that data moves when a person decides to move it. AI agents have broken that model, and now act autonomously, reading files, calling APIs, executing code, and transferring data across systems without waiting for a human to approve each step. Many of these agents were never sanctioned by IT or security.

Disrupting Glassworm: Inside CrowdStrike's Takedown of a Developer-Targeting Botnet

On May 26, 2026, at 14:00 UTC, the CrowdStrike Counter Adversary Operations team executed a coordinated takedown of the Glassworm botnet, a global threat targeting software developers through the open-source supply chain. In collaboration with Google and the Shadowserver Foundation, we struck all four of Glassworm's command-and-control (C2) channels simultaneously, severing the operators from their infected machines and their ability to deliver new malicious payloads.

How Unsafe Infrastructure Can Lead to Injury Lawsuits

Every cracked sidewalk has a story. Every collapsed railing, every ceiling that gives way, each one represents a chain of failures that too often ends with someone seriously hurt. Across Canada, thousands of people suffer preventable injuries each year in the very spaces they trust most: roads, parks, office buildings, public stairwells. Unsafe infrastructure isn't a bureaucratic talking point. It's a genuine public health crisis that affects ordinary people on ordinary days.

Invisible Cross-Tracking: How Mobile Apps Share Your Data and How to Stop It

Tracking user activity across apps on mobile devices is crucial, as data no longer flows from a single source on phones. For example, in the span of an hour, a user might open Instagram, Gmail, a shopping app, a weather app, and a free game, while various advertising tools quietly analyze network signals, device behavior, location data, and app usage patterns. A VPN won't remove every unique identifier in these apps, but it does make it harder to connect one link in this tracking chain: the digital network footprint.

How an AI SEO Agency Helps SaaS Businesses Rank Faster Online

Software companies often depend on search visibility long before paid acquisition becomes efficient. Yet many teams publish pages without a clear intent map, a crawl plan, or realistic ranking priorities. Results slow down for predictable reasons. Search growth usually improves when technical repair, keyword research, and content planning move in the right order. With that structure in place, SaaS brands can reach evaluators earlier, support longer buying cycles, and build a steadier pipeline from organic discovery.

How to Prepare Your Organization for Rigorous Federal Security Standards

Navigating the cybersecurity landscape for defense contractors has become far more complex than it was in the past. Requirements are evolving quickly as global threats grow more advanced and targeted. Companies that work with the government can no longer afford to overlook these standards if they want to maintain eligibility for contracts.