LIVE · cybersecurity feed
Live wire
vulnerabilitieshigh

Enterprise Software Has 4.31x More Critical Vulnerabilities

A recent analysis indicates that enterprise software applications are now exhibiting a 4.31 times higher rate of critical and high-severity vulnerabilities. This trend coincides with an overall acceleration in the development of enterprise software.

zeroday.news ·

Enterprise applications are now exhibiting a 4.31-fold increase in critical and high-severity vulnerabilities compared to the period before the widespread adoption of AI in software development. This finding comes from a recent analysis by Sonatype, which examined four years of enterprise software development data. The study indicates that while the pace of application creation has accelerated nearly fivefold in the AI era, the median age of unresolved vulnerabilities has decreased by 59%, suggesting that organizations are addressing vulnerabilities more quickly.

Despite the faster remediation times, the overall volume of risk is growing. Sonatype's report links this trend directly to the increasing use of artificial intelligence in software development, which enables teams to produce applications at a significantly higher rate. However, this accelerated production introduces new risks faster than traditional security processes can effectively manage.

The firm emphasizes that the improvements in vulnerability remediation have not kept pace with the rapid growth in software creation. This imbalance creates pressure to identify and mitigate risks much earlier in the development lifecycle.

According to Sonatype, the current approach, which often relies on security reviews primarily after development is complete, is insufficient. Instead, organizations need to integrate security decisions into the software assembly process itself. This shift would ensure that better security choices are made at the moment software components are put together, whether by human developers or AI agents.

The report highlights that AI is fundamentally altering the dynamics of software development, leading to more software being built more quickly, but also introducing risk at an accelerated rate. The solution, therefore, is not to simply add more review steps at the end of the development cycle, but to embed security considerations into the initial stages of software creation.

vulnerabilitiesenterprise softwaresoftware developmentsecurity risk
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

CareCloud Data Breach Impact Grows to 3.7 Million Individuals

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact. The post CareCloud Data Breach Impact Grows to 3.7 Million Individuals appeared first on SecurityWeek.

finance

Banks look for fraud signals in customer behavior

Banks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking environment where social engineering, reimbursement requirements and growing case volumes are changing fraud operations. Social engineering moves the risk into the customer interaction Fifty-five percent of institutions survey

ai

ChatGPT’s new feature could give infostealers a map of your Mac activity

OpenAI’s new Computer History feature turns recent Mac computer activity into memories ChatGPT and Codex can use, and it’s raising questions about privacy and security along the way. Computer History (Source: OpenAI) What Computer History does Computer History builds a timeline out of everyday computer use, grouping activity into summaries and noting which apps and websites contributed to each one

breach

Australian hotel chain leaks guests’ PII after breach at third-party database operator

Unknown parties know where you stayed last summer, down under, across 120 Quest properties

security

ISC Stormcast For Wednesday, August 19th, 2026 (Wed, Aug 19th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

nation-state

China-Linked Hacker Shows AI Capabilities in APAC Attack

In the first purported "near-autonomous" attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise government agencies, likely in Taiwan.