Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Hacking & PentestingHacker erbeuten Bankdaten von LMU-Studenten - OVB Heimatzeitungen |(20.09.2026 um 23:44 Uhr)
AI & KI NachrichtenUS and China agree to dialogue on AI ahead of Trump-Xi meeting(21.09.2026 um 03:11 Uhr)
Sichere ProgrammierungThe AI Interview Paradox: Decoupling Skill Assessment from Tool Usage(21.09.2026 um 02:01 Uhr)
Sichere ProgrammierungI Built a 100% Free AI Toolbox with No Sign-Up (Here's How)(21.09.2026 um 02:02 Uhr)
Sichere ProgrammierungUnreal C++ Course Chapter 109(21.09.2026 um 02:02 Uhr)
Sichere ProgrammierungWhen Your Impact Is No Longer Measured in Pull Requests(21.09.2026 um 02:04 Uhr)
Hacking & PentestingHacker erbeuten Bankdaten von LMU-Studenten - OVB Heimatzeitungen |(20.09.2026 um 23:44 Uhr)
AI & KI NachrichtenUS and China agree to dialogue on AI ahead of Trump-Xi meeting(21.09.2026 um 03:11 Uhr)
Sichere ProgrammierungThe AI Interview Paradox: Decoupling Skill Assessment from Tool Usage(21.09.2026 um 02:01 Uhr)
Sichere ProgrammierungI Built a 100% Free AI Toolbox with No Sign-Up (Here's How)(21.09.2026 um 02:02 Uhr)
Sichere ProgrammierungUnreal C++ Course Chapter 109(21.09.2026 um 02:02 Uhr)
Sichere ProgrammierungWhen Your Impact Is No Longer Measured in Pull Requests(21.09.2026 um 02:04 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Government and Education Have the Highest Percentage of Apps With Security Flaws

Reagiere als Erste:r — dein Feedback zählt!

It???s been a stressful year, to say the least, for the government and education sector. Government organizations were challenged with pivoting their operations to a digital model while schools were forced to decide between hybrid or remote learning programs for their students.

The rise of digital operations has made application security (AppSec) more important than ever. But, in our recent State of Software Security v11 (SOSS) report, we found that compared to other industries, the government and education sector has the highest percentage of applications with security flaws, the second-slowest fix rate, and the second-longest median time to fix flaws.

SOSS Gov and Edu

How can the government and education sector improve its fix rate and half-life?

For this year???s SOSS report, we looked at how ???nature??? and ???nurture??? contribute to the time it takes to close out a security flaw. We found that the ???nature??? of applications ??? size, age, and flaw density ??? can have a negative effect on how long it takes to remediate a security flaw. But we also found that ???nurturing??? the security of applications ??? using DAST with SAST, frequent scanning, using SAST through API???s, steady scan cadence, and using SCA with SAST ??? can have a positive effect on how long it takes to remediate security flaws.

Remediation

When looking at the ???nature??? of government and education applications, it???s a bit of a mixed bag. Compared to other industries, government and education have the youngest applications and the smallest organizations ??? both of which are positive attributes. But, on the other hand, government and education applications are fairly large and have the highest flaw density.

In terms of ???nurturing,??? the government and education sector scan more frequently and use APIs more often than other industries. But the sector has the lowest ranking for use of DAST and scan cadence and a middle-of-the-road ranking for SCA.

Nature vs Nurture

In order to improve its median time to flaw remediation and increase its fix rate, the government and education sector needs to start using DAST and SCA more frequently and improve its scan cadence (which should help eliminate security debt). Just using some DevSecOps best practices will not move the needle.

Which flaws should the government and education sector keep an eye on?

In the government and education sector, 80 percent of applications have security flaws. Of those flaws, we found that Cross-Site Scripting (XSS) and input validation are especially high in the government and education sector when compared to other industries. On a positive note, we found the sector to have a lower-than-average prevalence of CRLF injection flaws. It???s important to understand the flaw types affecting your organization and to set rules regarding which flaws should be remediated first.

To learn more about the security trends in the government and education sector, download The State of Software Securityツ? Industry Snapshot: Government and Education.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Government and Education Have the Highest Percentage of Apps With Security Flaws

Thematisch verwandte Begriffe: Government, Education, Have, Highest · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93968 | A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affec…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick