AppSec Alert Overload: 95% of Fixes Fail to Reduce Real Risk
A new report from OX Security, as covered by The Hacker News, reveals that up to 98% of application security (AppSec) alerts do not require action and may even hinder organizations more than help. Analyzing over 101 million security findings across 178 organizations, the study found that out of an average of 570,000 alerts per organization, only about 202 represented true, critical issues. This deluge of low-priority alerts contributes to alert fatigue, strained developer relations, and wasted resources. Many of these alerts stem from issues with low exploitation probability, lack of known public exploits, or originate from unused or development-only dependencies. The report emphasizes the need for a shift from indiscriminate detection to evidence-driven prioritization, focusing on factors like code reachability, exploitability, business impact, and the origin of issues within the software development lifecycle. By adopting such a holistic approach, organizations can better identify and address the small percentage of vulnerabilities that pose genuine threats.
https://thehackernews.com/2025/05/new-research-reveals-95-of-appsec-fixes.html
Comments
Post a Comment