With IBM's purchase of Ounce last week, many of the main application security companies that I covered back when I started with SD Times in late 2006 have gone the way of Yahoo!
IBM actually started it off when it acquired Watchfire (I will have a piece soon in which I talked to Dave Grant, an executive with IBM Rational, about IBM's plans with AppScan, Ounce, etc.) back in June 2007. Then, not wanting to be a kid on the playground with no security company to play with, HP made a play for SPI Dynamics.

So with Ounce out of the picture, Fortify Software and Klocwork are the two main application security companies remaining on the security playing field. It was heavily speculated during the Watchfire and SPI acquisitions that other big guns, like Microsoft and Oracle, would be in the hunt for some some security catches. Now that IBM has grabbed Ounce, maybe there will be a reverberation or two among the other industry heavies. Here's who's left:
Fortify- The maker of vulnerability detector Fortify 360 and other products could be a nice pickup for someone. Founder Brian Chess is a very knowledgeable exec on the security front, and knows his stuff. Definitely a bright mind for any company to have in the mix.
Klocwork- Most of its focus is on static and source code analysis, and like Fortify, holds much weight in the security market. Would be a good asset for any big company looking to augment its source code analysis offerings.
Honorable Mention-
Coverity
Selenium
Veracode
v.i. Labs
Be on the lookout for any big companies looking to secure their security!