1、State of AppSec ReportWhen Development Velocity Exceeds Security Maturity 2026 2026 ORCA SECURITY.ALL RIGHTS RESERVED.Application security has fundamentally changed,but many programs still operate as if it hasnt.Software is built on open-source dependencies,automated pipelines,and infrastructure as
2、code,while AI is increasing both scale and risk.Yet security teams are expected to manage this complexity with outdated approaches.Across real production environments,risk is visible but rarely actionable without context.AI is accelerating development and expanding the attack surface,from generated
3、code to model dependencies,making prioritization essential.This report helps organizations understand where traditional approaches fall short and how to focus on the changes that materially reduce risk.”GIL GERON,CEO AND CO-FOUNDER OF ORCA SECURITY9.Conclusion2026 STATE OF APPLICATION SECURITY REPOR
4、TInside This ReportForeword01About the Orca Research Pod02Executive summary03Key findings041.1 Major Supply Chain Attacks071.The Rise of Supply Chain Attacks052.Vulnerabilities in AI Packages 083.1 High/Critical Vulnerability Patching Velocity143.Container Vulnerability Landscape124.1 The AI/ML Secr
5、ets Crisis174.Secrets Management156.Infrastructure as Code Security 22387.1 Code Review and Approval Gaps7.2 Branch Protection Weakness7.3 Access Control and Hygiene3132337.Repository and SCM Security295.CI/CD Pipeline Security185.1 CI/CD Platform Adoption5.2 GitHub Actions Security20212.1 Critical
6、Remote Code Execution Vulnerabilities2.2 Malicious Packages:Still Lurking in Production10116.1 IaC Platform Adoption6.2 Storage and Data Protection6.3 Identity and Access Management6.4 Network Security6.5 Container Security in IaC24252627288.1 Immediate Actions(0-30 Days)8.2 Short-term Initiatives(3