Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AWS Security Live from Black Hat 2026 with Johnny Wong from Veracode

In this episode, hosts Ryan and Brian are joined by Johnny Wong, VP of Solutions Architecture at Veracode, to explore how AI-assisted “vibe coding” is changing the way software gets built—and the new security risks that come with it. While large language models are making developers faster and more productive, studies shared in the discussion show that a significant portion of AI-generated code still contains security vulnerabilities, raising concerns about scale and speed in modern development pipelines.

CISO Risk Intel Brief: Material Exposures, Control Gaps, and Program Response

This executive intelligence briefing covers two distinct horizons: the past week (12–19 August 2026) and the past month (approximately 20 July–19 August 2026). It prioritizes AppSec, software supply chain, state-actor activity, cloud/IaC, identity, ransomware resilience, and regulatory developments with board-level implications. Analysis focuses on residual risk, control effectiveness, and business enablement rather than volume metrics alone.

Managing LLM Code Security at Scale with Hybrid SAST

The amount of code being generated in the era of AI is staggering, and some non-trivial percentage of that code is insecure. According to the 2026 GenAI Code Security Report, roughly 44% of AI generated code test produced a known vulnerability. Organizations are more reliant than ever on cybersecurity programs that can scale at the velocity of AI while still managing risk with guardrails, governance, and compliance standards.

Who Authorized That Tool Call?

Veracode I have been going to Black Hat for more than 25 years, and I have spent many of those years on the Review Board. New technologies keep changing the shape of the systems we secure. The questions I find myself asking stay remarkably familiar. Where does untrusted data enter? What authority does a component have? Which boundary controls a sensitive operation? How do we know that control worked?

Meet Captain Veracode | Guardian of Secure Code

In the year 2079, vulnerabilities are endless and breaches are a daily reality. Jordan Kodak, a weary engineer, dreams of a world where developers can innovate without fear. She leaves Earth in search of Secura Prime—a legend of flawless code—and decades later receives a distress signal from a temporal anomaly. Meet Cipher, a sentinel from 2177, where secure coding finally took root. Armed with future knowledge, Jordan realizes the utopia she sought isn’t a place… it’s a practice.

Java Source Code Scanning that Works the Way You Do

Many tools fail to adapt to diverse developer use cases, leading to workflow interruptions in IDEs and CI pipelines. Managing dependencies for multi-module projects can be complex and time-consuming, often causing delays. And developers frequently work across varied environments – whether it’s IDEs, CI pipelines, or repositories, each with unique requirements. These challenges create friction and slow down the development process, making it harder to deliver secure applications on time.

CISO Risk Intel Brief: Application Risk Intelligence for Early August 2026

Senior security leadership continues to confront a dual acceleration: self-propagating software supply-chain worms that weaponize developer credentials at unprecedented velocity, and the persistent security debt introduced by AI-generated code. This briefing synthesizes material developments across the most recent seven days and the preceding thirty days, framed strictly around residual risk, control effectiveness, and business enablement.