Legit Security's new research report emphasizes significant application risks within development environments, urging businesses to enhance their security strategies.
The 2025 State of Application Risk report illustrates the risks surfacing not just in code but across the entire software development lifecycle. Analyzing data from multiple organizations, the report reveals vulnerabilities within development pipelines, build servers, tools, and processes, and highlights the importance of prioritizing security measures effectively.
Key findings from the report include:
- All organizations surveyed exhibited high or critical risks in their development processes.
- A staggering 78% had redundant software composition analysis (SCA) tools, and 39% faced similar issues with static application security testing (SAST) tools.
- Secrets exposure was nearly universal, with all organizations confirming high or critical secrets embedded in their code.
- AI posed emerging risks, with 46% of organizations misusing AI models in ways that could compromise security.
- Misconfigurations were prevalent, with 89% reporting issues that heighten the chances of supply chain attacks.
- Fifty-five percent showed violations of least-privilege permissions, increasing vulnerability.
„Our research uncovered great risks everywhere throughout the development process,” stated Liav Caspi, Legit CTO and co-founder. He emphasized the lack of visibility that security teams currently face, which hinders their ability to identify risks beyond the code.
Legit Security's ongoing analysis aims to assist organizations in understanding and reducing risks throughout their software factories. This report outlines actionable insights necessary for improving application security.
For those wishing to delve deeper into the findings, the complete report is available for download.
Comments