惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
MyScale Blog
MyScale Blog
博客园 - Franky
The Cloudflare Blog
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
博客园 - 聂微东
WordPress大学
WordPress大学
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
The Blog of Author Tim Ferriss
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
罗磊的独立博客
Google DeepMind News
Google DeepMind News
P
Proofpoint News Feed
Martin Fowler
Martin Fowler
aimingoo的专栏
aimingoo的专栏
J
Java Code Geeks
腾讯CDC
雷峰网
雷峰网
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
博客园 - 【当耐特】
美团技术团队
云风的 BLOG
云风的 BLOG

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
75% of Firms Deploy Vulnerable Code Amid Pressure on CISO...
Danny Palmer · 2026-06-09 · via www.infosecurity-magazine.com

Nearly all CISOs have felt pressured to suppress or delay compliance-related cybersecurity issues in code, especially when business deadlines need to be hit, a new report has warned.

According to the research, released on Jun 8 by Checkmarx, 95% of CISOs said they faced pressure to deprioritize or delay reporting of security issues by other parts of the business.

As a result of this pressure, 75% of those surveyed said that their organization had knowingly deployed vulnerable code into a production environment.

When asked why this code had been deployed, 30% responded that compensating controls were believed to sufficiently mitigate the risk and 27% said it was pushed out to meet a business, feature or security-related deadline. Meanwhile, a further 27% said that the vulnerability in the code was not detected until after deployment.

According to the survey, many respondents seem to believe that risk is just something that is associated with deploying code: 30% said they just hoped the vulnerability would not be discovered, while another 27% of respondents said the vulnerability was too difficult or time-consuming to fix.

All of this comes at a time when organizations are embracing the use of AI-generated code which boosts efficiency but also risks containing mistakes or vulnerabilities. An approach solely reliant on AI could therefore leave organizations vulnerable to cyber threats.

“This report points to a massive disconnect between the security crisis that organizations are facing and the incremental steps that they are taking to address it. A completely new model is required,” said Sandeep Johri, CEO of Checkmarx.

“Just like the student cannot grade their own exam, AI alone cannot secure code – and, as the research shows, it adds risk. Organizations need security that combines deterministic precision with probabilistic reasoning to identify novel exploitable patterns, while closing the gap between finding a vulnerability and fixing it with better human-guided remediation,” he added.

Read More: What Fronter AI Models Like Mythos and GPT-Cyber Mean for Modern Cybersecurity

The research also pointed to challenges around fixing and remediating vulnerabilities. Only 9% of organizations reported that they fix over 90% of vulnerabilities within 90 days, while almost a third remediate fewer than half of the vulnerabilities within the same timeframe.

This is leaving organizations vulnerable to cyber threats, especially in a post-Mythos era where new vulnerabilities are being uncovered faster than ever before.

“Every day a known vulnerability sits unpatched is a day the door is unlocked. The mean time to exploit has collapsed to minutes. Most organizations are still leaving their gates wide open for months,” warned the report.

Nonetheless, the paper concluded that organizations are optimistic that their security processes will rise to the challenge of meeting security needs in the AI era.

Efforts which organizations are implementing include strengthening governance – particularly around AI – and reducing fragmentation across tools, teams and processes.

The report was based on responses from 2350 CISOs, AppSec managers and developers from organizations in 14 countries.