Eighty-six per cent of developers reported knowledge of code loopholes.

26 April, according to the latest questionnaire survey results, 86 per cent of software developers and AppSec managers were informed of gaps in the codes. Eighty-eight per cent of the AppSec managers interviewed indicated that they had been attacked for code loopholes in the past year.

The Market Investigation Agency Checkmarx conducts surveys of more than 1,500 Chief Information Security Officers (CISO), App Managers and software developers, and finds that 60 per cent of loopholes can be detected at the code construction or test Sec.

Citing the report, 34 per cent of respondents found that the AppSec scanning was fully integrated and automated into their software configuration management (SCM) systems, integrated development environments (IDE) and continuous integration (CI)/continual delivery (CD) tools.

CISO indicated that the greatest risk in the codes was the use and exposure of APs, accounting for 37 per cent; followed by the source software supply chain (i.e., the malicious code) (37 per cent), application of containerization (37 per cent), source software (36 per cent) and infrastructure, i.e. code risk (36 per cent).

AppSec Managers who have experienced an attack indicated that the first three reasons for their ranking included source software supply chain attacks (41 per cent), theft, confidential or weak identification / authorization (40 per cent) and known and/or unknown loopholes (39 per cent) in codes issued to the production environment.