VendorsOrca Security
Orca Security
Cybersecurity reports and statistics published by Orca Security
8 categories2 reports
Research Reports
Reports and publications from Orca Security
Recent Statistics & Reports
26.35% of repositories require no code review before merging.
5/27/2026•
Code ReviewRepositories
80% of organizations lack proper logging in infrastructure as code.
5/27/2026•
Infrastructure as CodeLogging
10.10% of organizations have exposed Anthropic credentials.
5/27/2026•
AI SecuritySecrets ManagementAnthropic
18.39% of organizations have exposed OpenAI credentials.
5/27/2026•
AI SecuritySecrets ManagementOpenAI
11.01% of organizations have active malicious packages embedded in production environments.
5/27/2026•
MalwareMalicious Packages
Over 77% of organizations leave high or critical container vulnerabilities unpatched for more than 90 days.
5/27/2026•
ContainersVulnerability ManagementContainer Vulnerabilities
46.20% of organizations remain exposed to Log4Shell years after disclosure.
5/27/2026•
VulnerabilitiesLog4ShellSupply Chain Attacks
21.68% of organizations maintain overly permissive CI/CD token permissions.
5/27/2026•
CI/CD Token PermissionsAccess Control
11.92% of organizations have exposed Databricks credentials.
5/27/2026•
AI SecuritySecrets ManagementDatabricks Credentials
24.82% of repositories predate GitHub’s 2023 default token hardening and may retain legacy access settings.
5/27/2026•
RepositoriesAccess ControlGitHub
29.15% of organizations are vulnerable to the React2Shell RCE vulnerability.
5/27/2026•
VulnerabilitiesReact2Shell RCE Vulnerability
28.49% of organizations have exposed Hugging Face tokens.
5/27/2026•
AI SecuritySecrets ManagementThird-Party Services
30.60% of repositories do not require signed commits.
5/27/2026•
RepositoriesCode Integrity
57.87% of organizations have IAM users without MFA.
5/27/2026•
IAM Access ControlAuthentication
More than 81% of organizations deploy vulnerable dependencies.
5/27/2026•
Vulnerable DependenciesVulnerabilitiesSoftware Dependencies
Nearly one-third of organizations expose valid secrets in code.
5/27/2026•
Secrets ManagementApplication SecuritySecrets Exposure
41.88% of production organizations have leaked AI or ML credentials.
5/27/2026•
AI SecuritySecrets ManagementCloud Security
85% of organizations have plaintext secrets embedded in their source code repositories.
6/5/2025•
Cloud
93% of organizations have at least one privileged service account, linked to Kubernetes adoption
6/5/2025•
Cloud
84% of organizations now use AI in the cloud.
6/5/2025•
CloudAI
Showing 1-20 of 25 results