AI AppSec Tools: Only 5% Agreement on Security Findings
Summary
AI application security tools agree on only five percent of security findings. This comes as software vulnerabilities are being exploited within hours, while security teams face patch backlogs stretching back years. Here's the thing: adversaries touch the average application every four minutes. Most of this is automated scanning, but confirmed exploit attempts happen 42 times per application each month. These are not just probes; the vulnerabilities are triggered. Untrusted deserialization is a top exploit, along with path traversal and method tampering. SQL injection is also a major concern across all industries. What's interesting is that applications monitored by Contrast Security have an average of 106 vulnerability findings, with 22 being high or critical severity. Fixing a critical vulnerability takes about 92 days, and teams only close a few each month. Even older issues like Spring4Shell and Log4Shell are still widespread. The bottom line is that AI has intensified this challenge, with vulnerabilities weaponized in hours, making rapid defense more critical than ever.
This is an AI-generated audio summary. Always check the original source for complete reporting.