Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 24 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

New Synopsys Research Reveals a Decrease in Software Vulnerabilities

The Latest 2023 Software Vulnerability Snapshot Report Unveils a 14% Reduction in Discovered Vulnerabilities Over the Previous Two Years.

by The Gurus
November 14, 2023
in Featured
vulnerability
Share on FacebookShare on Twitter

Today, Synopsys has released its 2023 Software Vulnerability Snapshot report, showcasing a notable decline in vulnerabilities within target applications. The Synopsys Cybersecurity Research Center (CyRC) analysed the data, revealing a decrease from 97% in 2020 to 83% in 2022. This positive trend suggests that practices such as code reviews, automated testing, and continuous integration are effectively reducing common programming errors.

The report spans three years of data (2020 – 2022) obtained from tests conducted by Synopsys Security Testing Services. These tests targeted web applications, mobile applications, network systems, and source code, employing various security testing techniques like penetration testing, dynamic application security testing (DAST), mobile application security testing (MAST), and network security testing.

While the industry celebrates this progress, the data underscores the inadequacy of relying solely on a single security testing solution, such as static application security testing (SAST). Notably, server misconfigurations accounted for an average of 18% of total vulnerabilities discovered over the three-year testing period. The report emphasizes the importance of a multi-layered security approach, combining SAST to identify coding flaws, DAST to assess running applications, SCA to pinpoint vulnerabilities from third-party components, and penetration testing to catch issues overlooked during internal testing.

Jason Schmitt, the general manager of the Synopsys Software Integrity Group, commented on the significance of the decrease in known vulnerabilities, stating, “For the first time in years, we’re seeing a decrease in the number of known vulnerabilities in software, which provides new hope that organisations are taking security seriously and prioritising a strategic and holistic approach to software security in order to make a lasting impact.”

Key findings from the report include:

  • High-severity vulnerabilities are less prevalent, with only 27% of tests revealing high-severity vulnerabilities and 6.2% containing critical-severity vulnerabilities.
  • Information leakage remains a top security risk, constituting an average of 19% of total vulnerabilities.
  • Cross-site scripting vulnerabilities are on the rise, accounting for 19% of high-risk vulnerabilities in 2022.
  • Third-party software poses increased risks, with 25% of tests uncovering vulnerabilities in third-party libraries among the top 10 security issues in 2022.

To delve deeper into the findings, interested parties can download the 2023 Software Vulnerability Snapshot: A Three-Year Analysis of the 10 Most Common Web and Software Application Vulnerabilities or read the detailed blog post.

ShareTweet
Previous Post

Centripetal Launches Global Partner Program

Next Post

Understanding Identity Security in the Digital Age

Recent News

Quantum computing: The data security conundrum

Trump Sets Post-Quantum Security Deadlines as White House Warns of Advanced Cryptographic Threats

June 23, 2026

Experts Warn: Passwords Still Winning Despite Passwordless Push

June 23, 2026
How Do Online Gaming Sites Keep Players and Their Data Safe?

KnowBe4 awarded in the email security industry

June 23, 2026
NHS cyber resilience deal signals shift toward specialist MSSPs, says Check Point

NHS cyber resilience deal signals shift toward specialist MSSPs, says Check Point

June 23, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol