Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

June 25, 2026

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

June 25, 2026
Facebook X (Twitter) Instagram
Thursday, June 25
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Exploitable Vulnerabilities Present in 87% of Organizations
Cyber Security

Exploitable Vulnerabilities Present in 87% of Organizations

Team-CWDBy Team-CWDFebruary 27, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Eighty-seven percent of organizations have at least one exploitable software vulnerability in production, affecting 40% of all services, a new report from DataDog has revealed.

The observability and security specialist revealed the findings in its State of DevSecOps Report, which is based on telemetry from tens of thousands of applications and additional datasets.

It noted that vulnerabilities are most common in Java services (59%), followed by .NET (47%) and Rust (40%).

However, not all CVEs need prioritizing. DataDog claimed that only 18% of critical dependency vulnerabilities stay critical after adjusting the severity score according to runtime and CVE context.

This is most common in .NET environments: Datadog said that 98% of .NET dependency vulnerabilities are downgraded from critical once context is considered.

By context, it means whether the vulnerability is in production, whether the affected service is under active attack, the availability of an exploit, and the likelihood of exploitation.

Read more on open source vulnerabilities: Researchers Uncover 454,000+ Malicious Open Source Packages.

“When almost everything is labeled ‘critical,’ nothing is,” argued Andrew Krug, head of security advocacy at Datadog.

“Teams get paged for noise while threats that pose real risk slip through. Without context, prioritization becomes harder – leading to burnout, slower response times and accumulated risk. Teams need better visibility into what actually requires action.”

Update Quickly, but Not Too Quickly

The report also revealed security risks at both ends of the software lifecycle.

The median software dependency is now 278 days out of date – 63 days more than last year’s figure. Java (492 days) and Ruby (357) dependencies fared even worse.

This matters, because older versions are more likely to have more vulnerabilities, the report claimed.

Broken down by service, libraries published in 2025 have on average 1.3 vulnerabilities, compared to 1.9 in 2024 and 3.8 in 2023.

However, updating dependencies too quickly could also land developers in trouble.

The report found that half of organizations (50%) adopt new library versions within 24 hours of release, and only 4% pin all public GitHub Actions to a specific version using commit hashes.

This unwittingly exposes build and deployment pipelines to silent changes in third-party code, Datadog claimed.

Supply chain attacks like s1ngularity and Shai-Hulud spread in part due to DevOps teams using malicious versions of libraries as soon as they were released, the report noted. To mitigate this risk, Datadog recommended pinning dependency versions to a full-length commit Secure Hash Algorithm (SHA).

Krug argued that security practices haven’t kept pace with the way software is built today.

“DevSecOps teams are caught between moving too slowly and moving too fast. Go slow, and outdated software accumulates known vulnerabilities. Go fast, and automation can introduce unvetted code,” he added.

“The real challenge, though, isn’t speed – it’s clarity. As environments grow more complex, AI-assisted workflows help ensure top priorities get attention first.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAeternum Botnet Shifts Command Control to Polygon Blockchain
Next Article Critical Flaws Found in Four VS Code Extensions with Over 125 Million Installs
Team-CWD
  • Website

Related Posts

Cyber Security

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

June 25, 2026
Cyber Security

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage

June 25, 2026
Cyber Security

UK Museums Face Cybersecurity Risks, MPs Warn

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Here’s how to avoid a ‘second strike’

April 11, 2026

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

January 16, 2026

Beware of Winter Olympics scams and other cyberthreats

February 2, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.