Veracode Delivers End-to-End Risk Coverage with New Tools: AI-Powered Dynamic Analysis Security Testing with External Attack Surface Management
Veracode, a global leader in application risk management, today announced new capabilities to help organizations address emerging threats, giving security professionals better visibility and control in one place. The launch includes new AI-powered functionality in the Dynamic Application Security Testing (DAST)product and an External Attack Surface Management (EASM) capability. Together, they enable security teams to discover their entire attack surface and prioritize the most critical risk to streamline and simplify security scanning.
“Security teams need to see and secure everything; not only what is inside their perimeter,” said Derek Maki, Head of Product at Veracode. “With our latest DAST capabilities and Application Risk Management platform enhancements, we’re helping organizations shift from vulnerability scanning to holistic risk management, to better identify risk residing in unidentified external assets.”
Tackling Risk Across a Growing Attack Surface
Modern development cycles and cloud adoption mean organizations are grappling with a rapidly expanding attack surface. According to the 2024 Verizon Data Breach Investigations Report, web applications remain a primary target for cyberattacks, accounting for nearly half of all incidents. Moreover, Veracode’s latest software security research found an alarming increase in the average fix time for flaws once discovered, with organizations taking three months—or 47 percent— longer than five years ago.
Veracode’s latest innovations address these critical challenges head on by offering frictionless integration for comprehensive risk management, faster remediation, and intuitive scans with real-time results. Organizations can more effectively balance the speed of modern development with software security.
Automated Discovery, Risk-based Prioritization, and Real-time Reporting
Veracode EASM capabilities automate external attack surface discovery by identifying and continuously monitoring potential entry points for bad actors. The product automatically tracks internet-exposed systems and services, including APIs, web apps, mobile applications, and cloud-based assets—many of which are often unknown or unmanaged. With automated discovery, EASM uncovers blind spots and delivers:
- Complete Visibility: Consistent identification and monitoring of all external assets to reduce visibility gaps.
- Risk-Based Prioritization: Streamlined focus on the most critical threats to minimize points of entry for an attacker.
- Seamless Security Integration: With a connector to Veracode Risk Manager (VRM) planned for later this year, static (SAST), software composition (SCA), and dynamic analysis findings are prioritized and contextualised in one place, giving a holistic view of risk and control.
Maki said, “In today’s threat landscape, organizations must contend with an unprecedented number of potential entry points,” Maki explained. “Veracode EASM provides security teams with the attacker’s perspective and delivers the capability to continuously identify, analyze, and mitigate risks before exploitation can occur.”
Veracode’s new Enterprise Mode for DAST Essentials is a significant advancement in dynamic application security testing. Leveraging the capability, security teams can more easily prioritize and remediate critical vulnerabilities in web applications and APIs.
With features designed to accommodate large-scale, complex application portfolios, key capabilities include:
- Advanced crawling and auditing for deep, highly customizable, and accurate scanning
- AI-Assisted auto-login to reduce authentication failures and easily implement the DAST program across the organization
- Internal Scan Management (ISM) for scanning behind corporate firewalls
- A Streamlined, intuitive interface for faster, simpler setup and configuration
- Real-time flaw reporting and a panoramic view of risk across projects
"DAST Enterprise Mode empowers security teams to work faster, smarter, and safer,” noted Maki. “With real-time analysis in a unified platform, it eliminates the challenge of fragmented tools and enables mature, resilient risk management with centralized visibility and control.”
Experience the Tools Live at RSAC 2025
Veracode will showcase its latest capabilities at RSAC Conference in San Francisco (April 28 - May 1, 2025). Visit booth #1243 for interactive demos and expert discussions on how to stay ahead of emerging threats and improve security posture.
Learn more about Veracode’s products on the website.
About Veracode
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform offers adaptive software security and is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing.
Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.
Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
View source version on businesswire.com: https://www.businesswire.com/news/home/20250423385599/en/
Contacts
For more information:
Katy Gwilliam
kgwilliam@veracode.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Pacific Defense Launches SABER, a Multi-Function Electronic Warfare Product Family for Multi-Domain Missions28.7.2025 23:29:00 EEST | Press release
Pacific Defense, the market leader in C5ISR Modular Open Suite of Standards (CMOSS) products and integrated mission systems, announces the launch of its SABER Multi-Function (MF) Electronic Warfare and Signals Intelligence (EW/SIGINT) product family. The first offering in the line is the EWS1090VP — a 9-slot 3U OpenVPX™ system that seamlessly integrates counter-UAS, counter-communications, counter-IED, and counter-radar electronic support capabilities. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250728389089/en/ SABER 3U OpenVPX™ Multi-Function Electronic Warfare Product Line for Multi-Domain Missions. Designed for rapid capability insertion and adaptation, SABER addresses the complexity of today’s electronic battlefield, where adversaries continuously adapt, and traditional countermeasures struggle to keep pace. Its tactical edge-based AI/ML capabilities enhance system performance, reduce operator burden, and counter eme
Skechers Responds to Kizik’s Patent Lawsuit28.7.2025 23:24:00 EEST | Press release
Skechers USA, Inc. (“Skechers”), the Comfort Technology Company and leader in hands-free footwear technology, announced today that it will vigorously defend the patent suit filed in Texas federal court against Skechers by Kizik Design, LLC (“Kizik”) alleging,in essence, that the entire line of Skechers Hands Free Slip-ins® (“Slip-ins”) infringe Kizik’s patents. The Company believes that Kizik’s allegations are baseless. As owners of a vast portfolio of intellectual property, Skechers respects the rights of others. Kizik’s complaint is based on the assertion that Kizik created the hands-free footwear category and is the only company that can legally use that century-old idea. Contrary to Kizik’s false assertion that Skechers patents have been rejected, Skechers has developed its own unique Slip-ins technology and has obtained more than 140 utility and design patents worldwide, including in the United States, and has vigilantly enforced its patent rights, resulting in numerous judgements
Zayed Sustainability Prize Sees Surge in Global Participation with 7,761 Entries28.7.2025 20:24:00 EEST | Press release
The UAE’s Zayed Sustainability Prize, a pioneering global award that has transformed the lives of over 400 million people, has officially closed submissions for its 2026 awards cycle. A total of 7,761 entries from 173 countries were received across the six categories of Health, Food, Energy, Water, Climate Action and Global High Schools, reflecting the Prize’s continued role in advancing impactful solutions to pressing global challenges. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250728506759/en/ Zayed Sustainability Prize beneficiaries celebrate receiving solar-powered lights (Photo: AETOSWire) Now in its 17th year, the Prize empowers small to medium-sized enterprises (SMEs), nonprofit organisations and high schools to develop and scale sustainable innovations that improve lives, especially in vulnerable and underserved communities. From clean energy and healthcare access to regenerative agriculture and safe drinking wa
Venture Global Announces Final Investment Decision and Financial Close for Phase 1 of CP2 LNG28.7.2025 19:03:00 EEST | Press release
Today, Venture Global, Inc. (NYSE: VG) is announcing a final investment decision (FID) and successful closing of the $15.1 billion project financing for the first phase of the company’s third project, Venture Global CP2 LNG (CP2), together with the associated CP Express Pipeline. This milestone represents the largest standalone project financing ever, and the second largest project financing after the combined financings of Venture Global’s Plaquemines LNG. The transaction garnered enormous interest from the world’s leading banks, resulting in over $34 billion of commitments, and required no outside equity investment. “We are extremely proud to have taken FID on our third greenfield project in under 6 years with over $80 billion in capital markets transactions executed to date,” said Venture Global CEO Mike Sabel. “This success would not be possible without the dedication and relentless execution of the entire Venture Global team. Our significant early investments and work on the proje
Beechcraft M-346N Unveiled as Ready-Now Solution for U.S. Navy Undergraduate Jet Training System28.7.2025 19:00:00 EEST | Press release
Textron Aviation Defense LLC, a Textron Inc. (NYSE: TXT) company, today announced its offering of the Beechcraft M-346N jet as a “ready-now” solution from an iconic American company for the U.S. Navy Undergraduate Jet Training System (UJTS) program. The U.S. Navy has released several Requests for Information related to an upcoming Request for Proposals for a new aircraft for the UJTS program. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250728874218/en/ Ready Now Beechcraft M-346N Textron Aviation Defense and Leonardo have entered into a teaming agreement to work together to meet the Navy’s requirements for its new jet trainer. The Beechcraft M-346N is part of a proven integrated training system based on the original M-346 aircraft developed by Leonardo. More than 100 Leonardo M-346 aircraft are already meeting the demanding student pilot training needs for 4th and 5th generation air forces worldwide, including at Italy’s
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom