State of DevSecOps | Datadog
Shipping secure code rapidly and at scale is a challenge across the software industry, as evidenced by continued news of high-profile data breaches and critical vulnerabilities. To address this challenge, organizations are increasingly adopting DevSecOps, a practice in which application developers work closely alongside operations and security teams throughout the development life cycle. DevSecOps looks at application security holistically, recognizing that code must be secure not only in how it’s written but also in how it’s deployed and run in production. We analyzed tens of thousands of applications and container images and thousands of cloud environments to assess the security posture of applications today and evaluate the adoption of best practices that are at the core of DevSecOps—infrastructure as code, automated cloud deployments, secure application development practices, and the usage of short-lived credentials in CI/CD pipelines. Our findings demonstrate that modern DevOps pr
Fact 1 Nearly all organizations have known exploitable vulnerabilities in deployed services Eighty-seven percent of organizations have at least one exploitable vulnerability , affecting 40% of all services . These vulnerabilities remain most prevalent in Java services at 59%, with .NET at 47% and Rust at 40%. Where vulnerabilities are known to be actively exploited, there's an increased chance that vulnerable services will be compromised. Tweet Share Keeping languages and runtime environments up to date is a primary way to prevent exploitable vulnerabilities in applications and services, and i
Explore this link on the map →related reading
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2softwareanalyst.substack.com
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- We should all be using dependency cooldownsblog.yossarian.net
- Vulnerability Research Is Cooked - Quarrelsomesockpuppet.org
- Security incident disclosure — July 2026huggingface.co
- Measuring LLMs' impact on N-day exploits \ Anthropicred.anthropic.com
- Software Supply Chain Security (Part 1)softwareanalyst.substack.com
- Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies | by Alex Birsan | Mediummedium.com
- Report: The Evolution of DevOps | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com
- FIRST Mid-Year Vulnerability Forecast Confirms Historic Surge, Projects ~66,000 CVEs in 2026first.org
- Mythos finds a curl vulnerability | daniel.haxx.sedaniel.haxx.se