Backdoor threats can be inserted by "bad actors" in the development process, or by accident when code writers leave old debugging code in the final version, according to Veracode's chief technology officer, Chris Wysopal.
The vendor first conducted extensive research into backdoor threats to create four distinct categories, before writing scans to detect these different types of threat, he explained.
"The biggest category was unintentional debugging code," he added. " [Traditional security] is very mature now so attacks are moving towards the applications, because developers make mistakes and attackers take advantage. Offering this as a service means we can be the intermediary between customer and development teams"
Wysopal also argued that by creating a taxonomy of backdoor threats, the firm could help to educate the marketplace about these often overlooked threats.
iTnews State of Security Breakfast Melbourne
NiCE World APAC 2026
Sydney Cloud & Datacenter Convention 2026
iTnews Executive Retreat - Security Leaders Edition
Can Testing Keep Up? Quality in the Age of Accelerating Delivery



