logo

28 application security stats that matter

ID: 68d24418-c538-5f3b-a2c6-135223f38142

STIX ID: report--68d24418-c538-5f3b-a2c6-135223f38142

Feed Name: ReversingLabs Blog

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-30

Author: Jaikumar Vijayan

...
...

**Executive summary:** This report compiles 28 AppSec statistics showing escalating software supply-chain attacks, weaponization of open-source ecosystems, pervasive unpatched and outdated dependencies, widespread leakage of developer secrets, and emerging risks from AI-generated code and unvetted ML models — notable findings include a registry-native worm (Shai-hulud) affecting ~1,000 npm packages and exposing ~25,000 repositories, a doubling of malicious npm packages to ~10,819, high percentages of codebases with vulnerabilities, long remediation times, and widespread use of unvetted third-party and AI components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.