New Black Duck Research Finds High-Risk Sectors Riddled with Critical Vulnerabilities
Finance and Insurance sectors found to have the highest number of critical vulnerabilities
The findings provide insights into the current state of security for web-based applications and systems, and the potential impact of security vulnerabilities on business operations in high-risk sectors such as Finance, Insurance, and Healthcare. Notably, the report identified that the Finance and Insurance sector had the highest number of critical vulnerabilities (1,299), and the Healthcare and Social Assistance sector had the second-highest (992) within the data set.
Of the 96,917 total vulnerabilities identified, the two most critical categories were cryptographic failures (weaknesses in how an application secures sensitive information), with over 30,000 instances, and injection vulnerabilities (when malicious code tricks an application into executing unintended actions or accessing data without proper authorization), with just over 4,800 instances. Both pose significant threats to data across all industries, and potential breaches could lead to the theft of personally identifiable information (PII), financial data, and medical records, resulting in severe financial losses and reputational damage.
Additionally, the report found that there's no one-size-fits-all timeline for remediation approaches. In fact, there's significant variance when it comes to the mean time to remediate (MTTR) across industries, with stringent regulations forcing Finance and Insurance to move quicker (28 days for smaller/lower complexity web assets), compared to the Utilities sector, which had the longest time to close (107 days for smaller/lower complexity web assets). This is likely due to the sector operating on legacy systems that are difficult to patch and update.
Operational disruptions pose a large business risk, no matter the industry. The research found that widespread security misconfigurations (98% of applications affected) threaten business continuity and service availability.
"The high number of vulnerabilities found from the past year is a clear wake-up call that businesses cannot remain stagnant when deploying new security measures," said
To learn more, download a copy of the "2024 Software Vulnerability Snapshot" report, read the detailed blog post, or register for the upcoming
About Black Duck
Black Duck®, formerly known as the Synopsys Software Integrity Group, offers the most comprehensive, powerful, and trusted portfolio of application security solutions in the industry. We have an unmatched track record of helping organizations around the world secure their software quickly, integrate security efficiently in their development environments, and safely innovate with new technologies. As the recognized leaders, experts, and innovators in software security, Black Duck has everything you need to build trust in your software. Learn more at www.blackduck.com.
View original content to download multimedia:https://www.prnewswire.com/news-releases/new-black-duck-research-finds-high-risk-sectors-riddled-with-critical-vulnerabilities-302301393.html
SOURCE Black Duck Software
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- Ecovyst Issues 2025 Corporate Sustainability Report
- Clearmind Medicine Advances Its Innovation with Newly Granted U.S. Patent, Enhancing Global Patent Strength
- Helus Pharma Reports Recent Business Highlights and Fiscal Year 2026 Financial Results
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share