▾ G11 Media Network: | ChannelCity | ImpresaCity | SecurityOpenLab | Italian Channel Awards | Italian Project Awards | Italian Security Awards | ...
InnovationOpenLab

AI Is Breaking the Find-and-Fix Model for Application Security, New Contrast Research Finds

Contrast Security, the leader in runtime application security, today released AppSec Overflow 2026, a research report showing that the find-and-fix workflow underpinning modern application security no...

Immagine

Runtime telemetry from hundreds of thousands of applications and APIs shows attackers reaching exploitable code every day while defenders fall further behind.

PLEASANTON, Calif.: Contrast Security, the leader in runtime application security, today released AppSec Overflow 2026, a research report showing that the find-and-fix workflow underpinning modern application security no longer holds up against AI-accelerated attackers and AI-powered security assessments.

Drawing on runtime telemetry from inside hundreds of thousands of production applications and APIs worldwide, the report shows the growing pressure defenders face at the application layer. Attackers touch the average application 11,382 times per month, roughly once every four minutes. Of those, an average of 42 monthly attacks are viable, meaning exploitation attempts are confirmed to have reached and triggered real vulnerable code. For an enterprise running hundreds of applications, that means thousands of confirmed exploitation attempts every month, each one a real attack against a real weakness.

At the same time, AI is making it faster and easier for attackers to find and exploit vulnerabilities. Attackers have always used automated scanning, but AI lets them find and weaponize vulnerabilities with less skill than ever.

“AI is not going to triage its way out of this problem, and we have the data to prove it,” said David Lindner, Chief Information Security Officer at Contrast Security. “These tools disagree with each other; they disagree with themselves from one run to the next, and none of them can tell me how my application behaves when someone is actually attacking it. That is fine when AI is one input among several. It is a problem when it becomes the system of record, because that is what decides what my team works on Monday morning.”

“For twenty years the discipline of AppSec has been organized around a race: find the vulnerability, decide if it matters, and fix it before somebody with bad intent finds it first,” said Jeff Williams, Founder and CTO at Contrast Security, “AI ended that race, and defenders lost it. We are now seeing vulnerabilities weaponized in hours while the average critical fix takes weeks or months. You cannot close that gap by scanning harder or hiring more people. The only solution that stands the test of time is to defend applications and APIs from within, at runtime, so defenders can stop guessing and start acting to eliminate the risks that really matter.”

Key findings from the AppSec Overflow 2026 report include:

  • Attackers are reaching real vulnerabilities every day: Contrast’s data distinguishes between bulk probes and viable attacks, made possible because Contrast observes behavior from inside the running application rather than at the perimeter. Among the viable attacks the report tracks, untrusted deserialization leads by volume, followed by path traversal and method tampering. SQL injection appears in the top five viable techniques for every industry vertical analyzed.
  • The attack surface is expanding faster than defenders can keep up: The average application carries 106 vulnerability findings, 22 of them rated High or Critical. In third-party code, 54% of CVE instances observed in production come from CVEs published more than a year ago, with Spring4Shell (CVE-2022-22965) and Log4Shell (CVE-2021-44228) still widely present years after disclosure. Patching vulnerabilities takes months: critical vulnerabilities in custom code take an average of 92 days to remediate.
  • AI is making this worse as much as it’s making it better: Contrast Labs research included in the report found that three AI scanners analyzing the same codebase agreed on only 5% of findings, and a single scanner run three times against the same code reproduced only 17% of its own results. Scanning a 2 million-line codebase consumed roughly $315 in tokens, while triaging the resulting findings cost approximately $128,000.
  • Defenders face a prioritization crisis: CVSS, EPSS, and CISA KEV each carry a useful but incomplete signal. Static metadata like these cannot describe whether a vulnerability is safely protected in a development environment or exposed in an application absorbing 30,000 attacks a month. Not all applications require the same level of inspection; more than 60% see fewer than 3,000 attacks per month, while more than a quarter absorb upward of 30,000.

A defensive posture built for today’s application threats

AppSec Overflow 2026 concludes that finding, prioritizing, and remediating remains necessary but is no longer sufficient on its own. No remediation cadence matches the velocity at which AI-assisted attackers identify and exploit weaknesses, and no review process keeps pace with AI-assisted code generation and security assessment without slowing development to a crawl.

The report makes the case for moving more of the defense inside the application, where runtime visibility allows teams to see attacks as they happen and block them in real time. That means vulnerabilities can be protected before they are patched, whether they are newly discovered, still unknown or introduced by AI-generated code.

To download the full report, visit https://www.contrastsecurity.com/appsec-overflow-2026-report.

Methodology

Findings are drawn from anonymized aggregate telemetry collected from thousands of live applications and APIs in production worldwide, spanning trillions of security-critical observations per day. Contrast embeds a lightweight sensor into each monitored application, observing control flow, data flow, library invocation, and backend interactions. This inside-out perspective allows Contrast to determine not only whether a vulnerability exists in code, but whether it is reachable, triggerable, and exploitable in live production environments.

About Contrast Security

Contrast Security is the global leader in Application Detection and Response (ADR), empowering organizations to see and stop attacks on applications and APIs in real time. Contrast embeds patented threat sensors directly into the software, delivering unmatched visibility and protection. With continuous defense, Contrast uncovers hidden application-layer risks that traditional solutions miss. Contrast’s powerful Runtime Security technology equips developers, AppSec teams and SecOps with one platform that proactively protects and defends applications and APIs against evolving threats.

Fonte: Business Wire

If you liked this article and want to stay up to date with news from InnovationOpenLab.com subscribe to ours Free newsletter.

Related news

Last News

RSA at Cybertech Europe 2024

Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…

Italian Security Awards 2024: G11 Media honours the best of Italian cybersecurity

G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes

How Austria is making its AI ecosystem grow

Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries

Sparkle and Telsy test Quantum Key Distribution in practice

Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…

Most read

SimpleClosure Releases H1 2026 Shutdown Report with SaaS Startups Closing…

SimpleClosure, the industry standard for responsible company shutdowns, today published its H1 2026 Shutdown Report highlighting data trends from the…

AI Sold a Company. Now Montauk AI Is Opening Up a Market Assessment to…

#AI--One year ago, Montauk AI quietly did something no one has ever done before: it sold a real company to a public acquirer through a series of agents…

Orvera AI Featured as Core Performing on the CMP Prism for Voicebot/Conversational…

#AIAgents--Orvera AI proudly announces its placement on the CMP Prism, for Voicebot/Conversational IVR. The CMP Prism is an independent, analyst-led evaluation…

CrowdStrike’s Fal.Con 2026 Unites Cybersecurity’s Ecosystem to Secure…

CrowdStrike (NASDAQ: CRWD) today announced that Fal.Con 2026 will feature a record 150+ ecosystem sponsors, led by Amazon Web Services (AWS), Accenture,…

Newsletter signup

Join our mailing list to get weekly updates delivered to your inbox.

Sign me up!