Business Wire

Veracode Acquires Phylum, Inc. Technology to Transform Software Supply Chain Security

Share

Veracode, a global leader in application risk management, today announced it has acquired certain assets of Phylum, Inc., including its malicious package analysis, detection, and mitigation technology. The acquisition enhances Veracode’s ability to identify and block malicious code in open-source libraries, marking continued investment in its software supply chain risk management capabilities. This gives customers a more comprehensive view of risks associated with open-source code usage, strengthening their defenses against emerging threats.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250106967344/en/

Veracode acquires technology from Phylum, Inc. (Graphic: Business Wire)

With software supply chain attacks projected to triple in cost from $46 billion in 2023 to $138 billion by 20311, safeguarding against these risks is now mission-critical for organizations. Through Phylum’s innovative technology, Veracode empowers customers to proactively prevent attacks by identifying and blocking malicious packages and vulnerabilities in real time. The addition of a package management firewall and an unmatched malicious package database further strengthens Veracode’s ability to mitigate emerging software threats before they impact customers.

Ravi Iyer, Chief Product Officer at Veracode, said, “This acquisition advances Veracode’s mission to be the most comprehensive application risk management platform by significantly expanding our ability to identify, mitigate, and remediate risks across the software supply chain. With Phylum’s unmatched database and cutting-edge research—proven to detect 60 percent more malicious packages than any other vendor—our customers will gain the confidence to innovate faster, knowing their software is protected against evolving threats.”

Veracode Prevents, Detects and Fixes Malicious Packages

Malicious packages have become a prevalent attack vector in the software supply chain, capable of infecting networks, stealing sensitive information, and enabling remote code execution. Identifying and mitigating these threats is now a critical component of any robust software composition analysis (SCA) solution. Effective tools must go beyond detection to quarantine and block suspicious packages in real-time.

With Phylum’s fully automated malicious code analysis pipeline, Veracode significantly shortens the window of opportunity for attackers. Newly published packages are analyzed within seconds, helping customers proactively prevent attacks. Phylum’s recent research identified nearly half a million malicious packages, including 2,500 targeted malware campaigns aimed at industries like finance and cryptocurrency, demonstrating the scale and sophistication of these threats.

“Uniting Veracode’s platform and Phylum’s malicious package detection and mitigation technology creates exceptional value for our customers worldwide,” said Aaron Bray, CEO & Co-founder of Phylum, Inc. “By combining our advanced research capabilities with Veracode’s industry-leading platform, we’re expanding the fight against software supply chain threats. Together, we will deliver even greater protection and peace of mind to organizations navigating an increasingly complex threat landscape, and we are excited to join the team.”

Phylum’s technology, including its malicious package database and package management firewall, will be integrated into Veracode’s SCA product, with general availability expected early this year. The acquisition also bolsters Veracode’s renowned security research team with Phylum’s experts, further elevating the company’s ability to protect customers from evolving threats.

For more information about the acquisition and software supply chain security, contact the Veracode team.

1 Gartner Inc., “Leader’s Guide to Software Supply Chain Security”, June 20, 2024

About Veracode

Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, and Penetration Testing.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.

Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

View source version on businesswire.com: https://www.businesswire.com/news/home/20250106967344/en/

Contacts

For more information, please contact:
Katy Gwilliam
kgwilliam@veracode.com

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

www.businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Geoswift Launches Visa Direct to Enhance Cross-Border Payment Offers in Over 30 Countries30.4.2025 04:00:00 EEST | Press release

Geoswift announced today the integration of Visa Direct with Geoswift's cross-border payments platform. Visa Direct facilitates payouts to more than 140 countries and territories. The integration will enable payouts in 32 countries and territories, across 13 currencies, covering major markets in Asia Pacific, North America, Europe and Middle East, with plans for more in the future. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250423288249/en/ Bryan Ma, SVP, Head of Geoswift Global Payments, and Swapnil Mhasde, Head of Visa Direct Commercialization and Solutions, Asia Pacific, celebrating the launch in Singapore. Geoswift is a leading provider of cross-border payment services and solutions globally. With over two decades of innovation, it has become a trusted name in B2B, education, eCommerce, remittance, and travel payment use cases. Raymond Qu, Group CEO of Geoswift, stated, "At Geoswift, our vision has always been to del

Logitech Announces Q4 and Full Fiscal Year 2025 Results29.4.2025 23:03:00 EEST | Press release

SIX Swiss Exchange Ad hoc announcement pursuant to Art. 53 LR — Logitech International (SIX: LOGN) (Nasdaq: LOGI) today announced financial results for the fourth quarter and full Fiscal Year 2025 ended March 31, 2025. For Fiscal Year 2025: Sales were $4.55 billion, up 6 percent in US dollars and 7 percent in constant currency, compared to the prior year. GAAP operating income was $655 million, up 11 percent compared to the prior year. Non-GAAP operating income was $775 million, up 11 percent compared to the prior year. GAAP earnings per share (EPS) was $4.13, up 7 percent compared to the prior year. Non-GAAP EPS was $4.84, up 14 percent compared to the prior year. Cash flow from operations was $843 million. The year-ending cash balance was $1.5 billion. The Company returned $797 million of cash to shareholders through its annual dividend payment and share repurchases. For Q4 Fiscal Year 2025: Sales were $1.01 billion, flat in US dollars and up 2 percent in constant currency, compared

U.S. Patent and Trademark Office Invalidates Pharmacyclics Patent Asserted Against BeiGene29.4.2025 22:32:00 EEST | Press release

BeiGene, Ltd. (NASDAQ: ONC; HKEX: 06160; SSE: 688235), a global oncology company that intends to change its name to BeOne Medicines Ltd., today announced that the U.S. Patent and Trademark Office (USPTO) rendered a Final Written Decision invalidating all claims of Pharmacyclics LLC’s (Pharmacyclics) U.S. Patent No. 11,672,803 (the ‘803 patent) that were challenged by BeiGene in a post-grant review (PGR) proceeding. On November 1, 2023, BeiGene filed a PGR petition with the USPTO challenging the validity of certain claims of the ‘803 patent, in response to a patent infringement lawsuit Pharmacyclics brought against BeiGene concerning BRUKINSA® (zanubrutinib). On May 1, 2024, the USPTO granted BeiGene’s petition to institute the PGR. The USPTO’s Final Written Decision is appealable by Pharmacyclics. Commenting on the ruling, BeiGene General Counsel Chan Lee said: “We are pleased that the USPTO invalidated all challenged claims of the ‘803 patent. Today’s decision reinforces our belief th

One out of Three Secure Civil IDs Delivered Each Year Is Powered by Thales29.4.2025 17:50:00 EEST | Press release

Each year, Thales powers one in three smart civil IDs (official electronic documents) issued worldwide, highlighting the company’s key role in shaping the future of identities and helping governments and citizens transition smoothly to digital. With its Civil Identity Suite, Thalesenables the issuance and management of both physical and digital identities, as well as all means of enrolling citizens and enabling seamless ID verification for access to services, both in-person and online. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250429687137/en/ Thales Civil Id Suite (Photo: Thales Shutterstock) Thales, a global leader in advanced technologies and #1 global leader in ID documents, has recently earned the new title of #1 provider of Digital ID solutions as recognized by Juniper Research (2024). With unmatched experience and scale, Thales empowers governments to modernise their identity systems, ensuring they meet the deman

Andersen Global Enhances European Valuation Capabilities through Collaboration with Value & Risk Valuation Services29.4.2025 16:30:00 EEST | Press release

Andersen Global continues to strengthen its valuation capabilities through a Collaboration Agreement with Value & Risk Valuation Services, a prominent European valuation firm headquartered in Germany with offices in Luxembourg and Austria. Founded in 1996, Value & Risk Valuation Services is a management-owned firm specializing in the valuation of financial assets across diverse asset classes and varying complexities. The firm also provides complementary services, including independent price verification (IPV), risk analysis, and transaction cost analysis. Since 2009, the company has been led by Gil Bender, who is dedicated to delivering high-quality, client-centric valuation solutions. As one of the few European providers offering external valuation services in compliance with the European Alternative Investment Fund Managers Directive (AIFMD), Value & Risk upholds the highest industry standards for regulatory compliance and service excellence. “Since our inception, we have focused on

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye