Press announcements, product launches, awards, and company updates from CodeHunter.

Stephen McCarney Joins CodeHunter as Chief Strategy Officer

stephen mccarney, chief strategy officer, CodeHunterCodeHunter has named Stephen McCarney as Chief Strategy Officer, adding a go-to-market leader with a track record of scaling category-defining security companies to help expand Zero Trust for Code across enterprise and government markets.

McCarney will lead corporate strategy, market expansion, strategic partnerships, and go-to-market execution as CodeHunter builds out its footprint across software supply chain, endpoint, DevSecOps, and security operations environments.

He joins from Merlin Group, where he served as Chief Marketing Officer helping scale disruptive cybersecurity companies for government and commercial critical infrastructure markets. Earlier in his career, he helped position and scale one of the industry’s first cloud-based SASE and Zero Trust Network Access platforms as VP of Marketing at OPAQ Networks, later acquired by Fortinet, and held senior marketing and security leadership roles at Arxan Technologies and Unisys. 

“Stephen has spent his entire career helping category-defining cybersecurity companies translate technical innovation into market leadership…His experience scaling Zero Trust, SASE, cloud security, application security, and emerging technology companies will be instrumental as we expand Zero Trust for Code into a critical control layer for enterprise and AI security,” said Ken Ammon, CEO of CodeHunter.

McCarney points to timing as the opportunity: AI-generated code, autonomous development tools, and machine-speed attacks are testing the assumptions behind traditional detection and software supply chain security, the exact gap Zero Trust for Code is built to close. 

Read Stephen’s thoughts on joining the CodeHunter team on LinkedIn. 

CodeHunter Welcomes Anurag Jain as SVP, Engineering

We are excited to share that Anurag Jain has joined CodeHunter as our new Senior Vice President of Engineering. Anurag brings more than 20 years of engineering leadership experience across cybersecurity, SaaS, and enterprise software, and he is taking on the work of scaling our platform and engineering organization as Zero Trust for Code continues to expand.

amurag jain headshot (3)

What makes Anurag the right person for this role is the through-line in his career. At OPAQ Networks (now Fortinet), he helped build the industry’s first cloud-based Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA) platform. At Diliko.ai, he scaled the engineering team behind an AI-driven analytics platform focused on automated data governance and security. Across both companies, he worked closely with our CEO, Ken Ammon. The combination of deep Zero Trust experience, modern engineering leadership, and a real working partnership with Ken made CodeHunter the right next step.

Anurag’s focus at CodeHunter will be extending the platform across the enterprise software supply chain, endpoint, and development environments. Zero Trust for Code is the next layer of the Zero Trust architecture, a pre-execution behavioral analysis approach that determines whether code should be allowed to run based on what it actually does. Building that layer at enterprise scale takes serious engineering, and Anurag is here to lead it.

In his own words: “Zero Trust has already transformed how organizations think about identity, devices, and network access, and now software execution represents its next frontier. CodeHunter is productizing Zero Trust for Code with a new approach to pre-execution software security. I’m looking forward to helping scale the platform and engineering organization behind that vision.”

If you want to learn more, download our latest Zero Trust for Code whitepaper. If you want to meet the team in person, we will be at the upcoming Gartner Security & Risk Management Summit and RVASec events.

Welcome to CodeHunter, Anurag!

Zero Trust for Code Starts With Understanding Intent

The software supply chain has become one of the most targeted attack surfaces in modern security. As organizations rely more heavily on third-party components, open-source libraries, and automated CI/CD pipelines, attackers have shifted their tactics to exploit trust itself. Malware today is no longer defined by static signatures or known indicators. It is adaptive, AI-generated, and designed to look entirely legitimate until it is too late.

Traditional tools that focus on what code looks like or where it came from are working from the wrong starting point. They make security decisions based on appearance and origin, and sophisticated threats are built specifically to pass those checks.

CodeHunter is proud to be named a winner of the 2026 Global InfoSec Award for Next-Gen Behavioral Malware Analysis at the RSAC 2026 Conference. This recognition reflects a fundamental shift in how code must be evaluated and controlled before it is authorized to run.

Verifying Intent with Zero Trust for Code

Zero Trust for Code starts from a different premise than traditional security tools. Instead of assuming software is safe because of its reputation, its origin, or how it looks, the framework holds that every artifact is untrusted by default. Trust is not conferred. It is earned through behavioral verification.

CodeHunter’s behavioral intent analysis deconstructs any software artifact, whether a binary, script, container, package, or AI-generated file, to surface its full behavioral capability. Every system interaction, network behavior, privilege operation, and persistence mechanism is identified before the execution decision is made. The result is a deterministic verdict: Allow, Block, Contain, or Escalate. Backed by forensic evidence. Auditable. Tied to explicit policy. This is what makes Zero Trust for Code actionable rather than theoretical.

Why Intent Is the Only Reliable Standard

Not all threats behave the same way, and that variation is intentional. Advanced threats are built to be stealthy, to blend into normal activity, to delay execution until trigger conditions are met, and to leverage legitimate system processes so their behavior does not stand out. Appearance-based controls cannot reliably catch threats designed to look legitimate. Origin-based controls cannot catch threats delivered through compromised but trusted channels.

The only standard that holds across all of these scenarios is behavioral intent: what is this code actually designed to do? When the analysis is pre-execution and the verdict is deterministic, there is no window for a sophisticated threat to exploit. The code is evaluated before it runs, and the decision is made by policy rather than by default.

Proactive Security Across the Full Lifecycle

Pre-execution behavioral intent analysis is not a single point control. It applies consistently across internal development artifacts, third-party dependencies, endpoint executables, and cloud workloads. The same behavioral standard governs code in the CI/CD pipeline and code on a remote laptop.

That consistency closes the gaps between development and production that attackers have learned to exploit. It reduces manual triage because verdicts are deterministic rather than probabilistic, and it transforms behavioral analysis from something that happens after an alert into something that prevents the alert from being generated in the first place.

Winning this award reinforces what CodeHunter customers already know. The future of security depends on asking a better question: not has this been seen before, but what can this software do? When you understand intent, Zero Trust for Code becomes actionable. When Zero Trust extends to code execution, prevention becomes possible. Read the full press release here.

CodeHunter and SentinelOne: Better Together

CodeHunter Integration with SentinelOne Delivers Unparalleled Protection Against Malware Threats

CodeHunter has recently launched its integration with SentinelOne to provide customers with automated detection and analysis of advanced unknown malware threats.

Read more