Thursday, January 22, 2026
  • Login
No Result
View All Result
APN News | Authentic Press Network News
  • News
    • National
    • International
    • States
    • Views
    • Crime & Corruption
    • Headlines
    • Breaking News
    • Canada’s privacy commissioner launches investigation over the use of facial recognition technology
  • Business
    • Banking
    • Finance
    • Economy
    • Be an informer to I-T dept; earn up to Rs 5 crore
    • Markets
  • Tech & Industry
    • Tech
    • Auto
    • Information Technology
    • Telecom
    • Oil & Natural Gas
    • Gravitational wave event likely signaled birth of black hole
  • Entertainment
    • Malayalam Film
    • Media
    • Music
    • Shawn Mendes Released Highly Anticipated Self-Titled Album Today
    • Youth
      • Fashion
      • Kids
      • Life Style
  • Education
    • Campus News
    • ITM University, Gurgaon Student Palash Chhabra Represents Varsity at Google Student Ambassador Summit
  • Health
    • Medical News
    • Maharshi Shushruta, The Great Grandfather of Surgery!
  • Tourism
    • Travel
    • Food&Beverages
    • “Keraliya Ayurveda is Credible and Authentic”
    • Hospitality
  • Sports
  • Editor’s column
  • Magazine
  • News
    • National
    • International
    • States
    • Views
    • Crime & Corruption
    • Headlines
    • Breaking News
    • Canada’s privacy commissioner launches investigation over the use of facial recognition technology
  • Business
    • Banking
    • Finance
    • Economy
    • Be an informer to I-T dept; earn up to Rs 5 crore
    • Markets
  • Tech & Industry
    • Tech
    • Auto
    • Information Technology
    • Telecom
    • Oil & Natural Gas
    • Gravitational wave event likely signaled birth of black hole
  • Entertainment
    • Malayalam Film
    • Media
    • Music
    • Shawn Mendes Released Highly Anticipated Self-Titled Album Today
    • Youth
      • Fashion
      • Kids
      • Life Style
  • Education
    • Campus News
    • ITM University, Gurgaon Student Palash Chhabra Represents Varsity at Google Student Ambassador Summit
  • Health
    • Medical News
    • Maharshi Shushruta, The Great Grandfather of Surgery!
  • Tourism
    • Travel
    • Food&Beverages
    • “Keraliya Ayurveda is Credible and Authentic”
    • Hospitality
  • Sports
  • Editor’s column
  • Magazine
No Result
View All Result
APN News | Authentic Press Network News
No Result
View All Result
Home Tech & Industry Information Technology

JFrog Software Supply Chain Report Shows Most Critical Vulnerabilities Scores are Misleading

by NS
March 20, 2024
in Information Technology
0
0
SHARES
40
VIEWS
Share on FacebookShare on Twitter

 JFrog Ltd. (“JFrog”) (Nasdaq: FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, today released the findings of its annual Software Supply Chain State of the Union report 2024, which identifies emerging development trends, risks and best practices for securing enterprise software supply chains.

“DevSecOps teams worldwide are navigating a volatile field of software security, where innovation frequently meets demand in an age of rapid AI adoption,” said Yoav Landman, CTO and Co-Founder, JFrog. “Our data provides security and development organizations with a comprehensive snapshot of the rapidly evolving software ecosystem, including notable CVE scoring errors, perspectives on the security implications of using GenAI to code, the most risky packages to allow your organization to use for development, and more, so they can make more informed decisions.”

Key Findings

JFrog’s Software Supply Chain State of the Union report combines JFrog Artifactory developer usage data amongst 7000+ organizations, original CVE analysis by the JFrog Security Research team, and commissioned third-party survey data of 1,200 technology professionals worldwide to provide context into the broad, rapidly evolving software supply chain landscape. Key findings include:

●         Not all CVEs are what they seem: Traditional CVSS ratings look purely at the severity of the exploit as opposed to the likelihood it will be exploited, which requires context to make an effective assessment. The JFrog Security Research team downgraded the severity of 85% of Critical CVEs and 73% of High CVEs on average after analyzing 212 different high-profile CVEs discovered in 2023. Additionally, JFrog found that 74% of the reported common CVEs with High and Critical CVSS scores on the top 100 Docker Hub community images weren’t exploitable.

●         Denial of Service (DoS) attacks reign: Of the 212 high-profile CVEs analyzed by the JFrog Security Research team, 44% of them held the potential for a DoS attack vs. 17% with the potential to perform Remote Code Execution (RCE). This is good news for security organizations in the sense that RCE has a far more detrimental impact vs. DoS attacks due to their ability to offer full access to backend systems.

●         Security taking a toll on productivity: Forty percent of survey respondents said it typically takes a week or longer to get approval to use a new package/library, extending time to market for new apps and software updates. Additionally, approximately 25% of security teams’ time is spent remediating vulnerabilities, even when those vulnerabilities may be overrated or even non-exploitable given their current context.

●         Applying security checks is inconsistent across the software development lifecycle (SLDC) — The industry seems to be split pretty evenly down the middle when it comes to deciding where to apply application security testing across the software development lifecycle, underscoring the importance of shifting left and right simultaneously. Forty-two percent of developers claim it’s best to perform security scans during code writing while 41% say it’s best to perform scans on new software packages before bringing them into your organization from an Open-Source Software (OSS) repository.

●         Security tool sprawl continues — Nearly half of IT professionals (47%) say they use between four and nine application security solutions. However, a third of survey respondents and security professionals (33%) say they’re using 10 or more application security solutions. This supports a market-wide trend of needing security tooling consolidation with a movement away from point solutions.

●         Disproportionate use of AI/ML tools for security — While 90% of survey respondents indicate their organization currently uses AI/ML-powered tools in some capacity to assist in security scanning and remediation efforts, only one in three professionals (32%) claim their organization uses AI/ML-powered tools to write code, indicating the majority are still wary of the potential vulnerabilities Gen-AI developed code can introduce to enterprise software.

“Vulnerabilities are growing in number year over year, but that does not necessarily mean they are growing in severity. It’s clear that IT teams are willing to invest in new tools to bolster their security, but knowing where to put those tools, use their team’s time, and streamline processes is critical to keeping their SDLC secure,” said Shachar Menashe, Sr. Director, JFrog Security Research. “We designed this report to go beyond trend analysis, providing both counsel and clarity on the technology business leaders use to make decisions, whether it’s on AI navigation, malicious code, or security solutions.”

For deeper insights from the JFrog Software Supply Chain State of the Union 2024 download the full report. You can also register to join JFrog security and developer experts on Wednesday, April 17, 2024 at 10:00 a.m. PT for a webinar, “Safeguarding Software Supply Chains in 2024: A Deep Dive into the State of the Union Report,” detailing the challenges and complexities of managing and securing the software supply chain.

NS

NS

Next Post
YES BANK Partners with Indian Olympic Association as Official Banking Partner for Paris Olympics 2024

YES BANK Partners with Indian Olympic Association as Official Banking Partner for Paris Olympics 2024

Recent News

Mumbai Becomes a Historic Global Energy Epicentre as 8 Pranic Healing Masters Lead over 4,300 Arhatic Yogis from Across Continents

January 21, 2026
Pre-budget quote by ZEISS India |

Pre-budget quote by ZEISS India |

January 21, 2026
AU Real Estate Announces Upcoming DMart at Family Hub, Aditya World City

AU Real Estate Announces Upcoming DMart at Family Hub, Aditya World City

January 21, 2026
Guardian appoints Karunakaran Azhisur as the Country Head – India

Guardian appoints Karunakaran Azhisur as the Country Head – India

January 21, 2026
Samsung India Launches Sound Tower Featuring Powerful Sound, Customizable Lighting, and Extended Playtime in a Portable Design

Samsung India Launches Sound Tower Featuring Powerful Sound, Customizable Lighting, and Extended Playtime in a Portable Design

January 21, 2026

APNNEWS owned by a Group of Journalists is a 24 X 7 news portal spearheaded by veteran journalist Suresh Kumar.

Facebook Twitter Youtube

Categories

  • Corporate News
  • Finance
  • Tech & Industry
  • Education
  • Health
  • Life Style
  • Real Estate
  • Sports
  • Entertainment
  • New Products
  • Environment
  • Religion

Company

  • About Us
  • Terms of Service
  • Disclaimer
  • Contact Us
  • APN NEWS RSS
  • Advertise with Us
  • Your Ad Choices

APNNEWS owned by a Group of Journalists is a 24 X 7 news portal spearheaded by veteran journalist Suresh Kumar.

Facebook X-twitter Youtube
  • About Us
  • Terms of Service
  • Your Ad Choices
  • Advertise with Us
  • Contact Us
  • Disclaimer

© 2024 APN NEWS, All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • News
    • National
    • International
    • States
    • Views
    • Crime & Corruption
    • Headlines
    • Breaking News
    • Canada’s privacy commissioner launches investigation over the use of facial recognition technology
  • Business
    • Banking
    • Finance
    • Economy
    • Be an informer to I-T dept; earn up to Rs 5 crore
    • Markets
  • Tech & Industry
    • Tech
    • Auto
    • Information Technology
    • Telecom
    • Oil & Natural Gas
    • Gravitational wave event likely signaled birth of black hole
  • Entertainment
    • Malayalam Film
    • Media
    • Music
    • Shawn Mendes Released Highly Anticipated Self-Titled Album Today
    • Youth
      • Fashion
      • Kids
      • Life Style
  • Education
    • Campus News
    • ITM University, Gurgaon Student Palash Chhabra Represents Varsity at Google Student Ambassador Summit
  • Health
    • Medical News
    • Maharshi Shushruta, The Great Grandfather of Surgery!
  • Tourism
    • Travel
    • Food&Beverages
    • “Keraliya Ayurveda is Credible and Authentic”
    • Hospitality
  • Sports
  • Editor’s column
  • Magazine

© 2024 APN NEWS, All Rights Reserved.