AI is breaking the find-and-fix model for application security

https://cdn1.expresscomputer.in/wp-content/uploads/2025/11/24153317/EC_03_CyberSecurity_Technology_750.jpg

Contrast Security recently released AppSec Overflow 2026, a research report showing that the find-and-fix workflow underpinning modern application security no longer holds up against AI-accelerated attackers and AI-powered security assessments.

Drawing on runtime telemetry from inside hundreds of thousands of production applications and APIs worldwide, the report shows the growing pressure defenders face at the application layer. Attackers touch the average application 11,382 times per month, roughly once every four minutes. Of those, an average of 42 monthly attacks are viable, meaning exploitation attempts are confirmed to have reached and triggered real vulnerable code. For an enterprise running hundreds of applications, that means thousands of confirmed exploitation attempts every month, each one a real attack against a real weakness.

At the same time, AI is making it faster and easier for attackers to find and exploit vulnerabilities. Attackers have always used automated scanning, but AI lets them find and weaponize...

Copyright of this story solely belongs to expresscomputer.in. To see the full text click HERE

Read more