Devops AI-Driven Vulnerabilities Surge, DevSecOps Overwhelmed
Article Content
- •Vulnerability backlogs have surged by 131% over two years.
- •Average resolution time for vulnerabilities has improved to 62 days.
- •70% of security leaders report faster arrival of new findings than remediation.
HackerOne's report reveals a significant rise in unresolved vulnerabilities, with a 131% increase over two years. Although the average resolution time has decreased from 135 days to 62 days, 70% of security leaders report that new findings are arriving faster than they can be addressed. The use of AI in vulnerability discovery is accelerating the rate of new findings, putting pressure on DevSecOps teams. Additionally, there has been a 557% increase in system prompt leakage reports and a 264% increase in output handling issues. Security researchers are actively upskilling with AI, leading to a 75% tracking of exposure debt among organizations. The report highlights the urgent need for teams to adopt AI for faster remediation as cybercriminals also leverage AI for exploit development.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What is the current state of vulnerability backlogs?
How has AI affected vulnerability discovery?
What should organizations do to manage this surge?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…