DevSecOps 2024: Automation Gaps and Rising Software Supply Chain Risks

The Datadog State of DevSecOps 2024 report reveals that many organizations are still not fully embracing automation in cloud security. It highlights that 38% of AWS users still perform manual deployments, increasing risk. While 71% of AWS users use infrastructure as code (IaC), only 55% of Google Cloud users do the same. The report notes a rise in software supply chain attacks via malicious packages in public repositories like PyPI and npm. Long-lived credentials remain a concern, especially in CI/CD pipelines like GitHub Actions. Java applications are especially vulnerable to third-party library issues, with 90% affected by at least one critical or high-severity vulnerability. Automated scanners generate many alerts, but very few result in real threats, making context-based threat prioritization essential.

https://www.datadoghq.com/state-of-devsecops

Comments

Popular posts from this blog

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

KEVIntel: Real-Time Intelligence on Exploited Vulnerabilities

OWASP SAMM Skills Framework Enhances Software Security Roles