Urgent.News

What's breaking now, across thousands of outlets.

Tech

Security Teams Are Fixing Vulnerabilities Faster Than Ever. So Why Is Software Getting Riskier?

AI is speeding up dependency decisions, making point-of-selection security essential for reducing vulnerable components, downstream tickets and avoidable rework.

Security Teams Are Fixing Vulnerabilities Faster Than Ever. So Why Is Software Getting Riskier?

Security teams have been making significant strides in fixing software vulnerabilities more rapidly in recent times. However, the increasing pace of software development and vulnerability discovery has led to growing concerns about the risk associated with applications. While the median age of unresolved critical and high vulnerabilities has decreased by 59% since January 2024, more than half of resolved violations are now addressed within a day.

Yet, software production and vulnerability discovery continue to escalate, necessitating a deeper examination of the initial software decision-making process.

AI-powered coding assistants and agents are rapidly changing the way developers make dependency decisions, compressing hundreds of component choices into shorter development cycles. This acceleration of decision-making comes with the risk of placing undue pressure on security controls, as vulnerabilities are only evaluated after they have been selected.

When a vulnerable dependency is chosen, a downstream scan is triggered, an alert or ticket is generated, and the developer is eventually prompted to reconsider the dependency. By then, valuable time may have been wasted on rework.

To address this issue, several changes are recommended. First, security intelligence should be brought closer to the decision-making point, providing developers and agents with current information about vulnerabilities, component health, and organizational policies. This will enable them to make more informed choices and reduce the number of rework tickets.

Second, agents should receive similar guardrails as developers, with organizational policies around approved components, risk, and licensing guiding their component decisions. As agents gain more autonomy, these guardrails should follow them. Third, automating the process of upgrading to safer dependencies is crucial, as it provides developers with a validated path forward and reduces the number of alerts they must investigate.

Finally, teams should measure the frequency of avoidable risks introduced into the pipeline. By tracking both the speed of vulnerability remediation and the introduction of preventable risks, development teams can identify areas for improvement and optimize their processes accordingly.

Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at devops.com →

More in Tech

Lo que aprendí buscando tarifas y condiciones dentro de un producto fintech

Muchas veces hablamos de UX como si todo fuera botones, colores y menús. Pero hoy, revisando Qavlixa, me interesó otro tipo de experiencia: encontrar información operativa.

  • User sought simple answers to basic questions about fintech product.
  • Maker-taker logic behind pricing and jurisdiction-based availability evident.
  • Complexity should reside behind the product, not in user experience.

Local Kubernetes Development with Tilt: Fast Inner Loop

Most Kubernetes teams debug their platform in the one place it does not run: their laptop. Production is 82% likely to be Kubernetes ( CNCF Annual Cloud Native Survey , 2025, up from 66% in 2023), yet…

  • Tilt accelerates local Kubernetes development for faster inner loop
  • Real production environment is 82% likely to be Kubernetes
  • Kind and Tilt provide idempotent local cluster setup

More from Tuesday 6 October →