DevSecOps 2024: Automation Gaps and Rising Software Supply Chain Risks
The Datadog State of DevSecOps 2024 report reveals that many organizations are still not fully embracing automation in cloud security. It highlights that 38% of AWS users still perform manual deployments, increasing risk. While 71% of AWS users use infrastructure as code (IaC), only 55% of Google Cloud users do the same. The report notes a rise in software supply chain attacks via malicious packages in public repositories like PyPI and npm. Long-lived credentials remain a concern, especially in CI/CD pipelines like GitHub Actions. Java applications are especially vulnerable to third-party library issues, with 90% affected by at least one critical or high-severity vulnerability. Automated scanners generate many alerts, but very few result in real threats, making context-based threat prioritization essential.
Comments
Post a Comment