A worrying amount of apps found to have high-severity security flaws


A worrying amount of commonly-used apps have high-severity security flaws, especially those used by companies in the technology sector, new research has found.
A report from Veracode analyzing 20 million scans across half a million applications in technology, manufacturing, retail, financial services, healthcare, and government sectors, found 24% of apps in the technology sector carry high-severity flaws.
Comparatively, that’s the second-highest proportion of applications with security flaws (79%), with only the public sector having it worse (82%).
Fixing the flaws
Among the most common types of vulnerabilities are server configurations, insecure dependencies, and information leakage, the report further states, saying that these findings “broadly follow” a similar pattern to other industries. However, the sector has the highest disparity from the industry average when it comes to cryptographic issues and information leakage, prompting the researchers to speculate how devs in the tech industry are savvier on data protection challenges.
When it comes to the number of fixed issues, the tech sector is somewhere in the middle. The companies are relatively fast to address the problems, though. It takes them up to 363 days to fix 50% of the flaws. While this is better than the average, there’s still plenty of room for improvement, Veracode added.
For Chief Research Officer at Veracode, Chris Eng, it’s not just about discovering the flaws, it’s also about reducing the number of flaws introduced into the code, in the first place. Furthermore, he believes businesses need to focus more on security testing automation.
“Log4j sparked a wake-up call for many organizations last December. This was followed by government action in the form of guidance from the Office of Management and Budget (OMB) and the European Cyber Resilience Act, both of which have a supply chain focus,” said Eng. “To improve performance in the year ahead, technology businesses should not only consider strategies that help developers reduce the rate of flaws introduced into code, but also put greater emphasis on automating security testing in the Continuous Integration/Continuous Delivery (CI/CD) pipeline to increase efficiencies.”
Cybercriminals often analyze internet-facing apps used by businesses, for vulnerabilities and flaws in the code. When they find one, they often use it to deploy web shells, which subsequently give them access to the company network, and endpoints (opens in new tab). After mapping out the network, and identifying all of the devices and data, they can launch the second stage of the attack, which is often either ransomware, malware, or data wipers.
Audio player loading… A worrying amount of commonly-used apps have high-severity security flaws, especially those used by companies in the technology sector, new research has found. A report from Veracode analyzing 20 million scans across half a million applications in technology, manufacturing, retail, financial services, healthcare, and government sectors, found…
Recent Posts
- I installed iOS 18.4 dev beta and the big Siri intelligence update is nowhere to be found
- Apple’s News app is getting a recipes section
- Amazon just overtook Walmart in revenue for the first time
- South of Midnight’s Southern Gothic folklore world is rooted in authenticity
- What to expect at Mobile World Congress 2025: Nothing, Samsung, Xiaomi and more
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010