28: Average number of organizations per month that experienced supply chain attacks
The number found from the period between April 2025 and October 2025 was more than double the 13 attacks per month recorded between early 2024 and March 2025.
1,000: Total number of npm packages the Shai-hulud attack affected
With two separate attacks in 2025, this first known instance of a registry-native worm exposed developer secrets across an estimated 25,000 repositories.
Exposures created by vulnerable, outdated, or poorly maintained components
51%: Percentage of teams that said third-party vulnerabilities were No. 1 risk
Concerns over software vulnerabilities ranked only below worries about data breaches and malware/ransomware attacks. Some 35% in this survey were concerned about their lack of visibility over their software vendors’ cybersecurity practices.
87%: Share of audited codebases that contained at least one vulnerability
More than three-quarters (78%) of the codebases contained high-risk vulnerabilities, including critical flaws that enabled remote code execution and significant data compromises.
93%: Percentage of codebases with no development for the past two years
A startling 92% contained components that were at least four years out of date, making them vulnerable to compromise. A mere 7% contained the latest component versions.
73%: Year-over-year increase in malicious open-source packages
The biggest increase across public repos was on npm, where the number of malicious packages more than doubled, from 5,290 in 2024 to 10,819 last year. That number represented almost 90% of all open-source malware in 2025.
891: Number of Python malware samples detected on Python Package Index (PyPI) last year
That represented a 43% drop from the 1,575 samples detected on the repository in 2024. Malware detections on the NuGet .NET package repository dropped even more sharply, from 35 in 2024 to just 14 in 2025.
358: Average number of days organizations took to half of vulnerabilities
The complexities associated with remediating vulnerabilities in third-party code or components, combined with the nature of flaws in direct and transitive dependencies, continued to drive up the time organizations required to address them.
50%: Share of teams that deployed third-party software within a day of release
Twelve percent used public Amazon Machine Images and 32% used public Docker images within a day of release before vetting them, heightening the risk of installing malicious software.
81%: Percentage of teams who said their developers knowingly ship vulnerable code
Instead of shifting security left, many development organizations, under pressure to deliver, have adopted patch-later models, despite the higher risk.
New risks introduced by AI coding tools and AI software components
34%: Percentage of respondents who said over 60% of their code is AI-generated
In a survey of over 1,500 application security stakeholders, this study found thatAI is writing the code at a fast-growing number of companies. And development teams are deploying the code with little regard to potential vulnerabilities in it.
91%: Frequency with which findings flagged by SAST tools were false positives
The story was even worse when looking only atcommand injection issues in Python/Flask projects, with nearly 99.5% of flagged issues being false positives.
65%: Proportion of new vulnerabilities that had no NVD-assigned severity scores in 2025
Severity tools use these scores to quantify the potential impact and exploitability of a CVE so security teams can prioritize remediation. Without scores, the tools are useless.
18%: Percentage of vulnerabilities that remain critical after doing analysis
Dropoffs were most dramatic for .NET dependency vulnerabilities (98% get downgraded in severity after exploitability context is added). At the other extreme, 49% of PHP dependency vulnerabilities remain critical.
Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.
Topics
Black Hat 2026: AI rewrites the rules of cybersecurity
The annual cybersecurity conference focused on frontier AI agents — and what they mean for cyber. Here are three key takeaways.