Skip to main content
VendorsOrca Security

Orca Security

Cybersecurity reports and statistics published by Orca Security

8 categories2 reports

Recent Statistics & Reports

26.35% of repositories require no code review before merging.

5/27/2026
Code ReviewRepositories

80% of organizations lack proper logging in infrastructure as code.

5/27/2026
Infrastructure as CodeLogging

10.10% of organizations have exposed Anthropic credentials.

5/27/2026
AI SecuritySecrets ManagementAnthropic

18.39% of organizations have exposed OpenAI credentials.

5/27/2026
AI SecuritySecrets ManagementOpenAI

11.01% of organizations have active malicious packages embedded in production environments.

5/27/2026
MalwareMalicious Packages

Over 77% of organizations leave high or critical container vulnerabilities unpatched for more than 90 days.

5/27/2026
ContainersVulnerability ManagementContainer Vulnerabilities

46.20% of organizations remain exposed to Log4Shell years after disclosure.

5/27/2026
VulnerabilitiesLog4ShellSupply Chain Attacks

21.68% of organizations maintain overly permissive CI/CD token permissions.

5/27/2026
CI/CD Token PermissionsAccess Control

11.92% of organizations have exposed Databricks credentials.

5/27/2026
AI SecuritySecrets ManagementDatabricks Credentials

24.82% of repositories predate GitHub’s 2023 default token hardening and may retain legacy access settings.

5/27/2026
RepositoriesAccess ControlGitHub

29.15% of organizations are vulnerable to the React2Shell RCE vulnerability.

5/27/2026
VulnerabilitiesReact2Shell RCE Vulnerability

28.49% of organizations have exposed Hugging Face tokens.

5/27/2026
AI SecuritySecrets ManagementThird-Party Services

30.60% of repositories do not require signed commits.

5/27/2026
RepositoriesCode Integrity

57.87% of organizations have IAM users without MFA.

5/27/2026
IAM Access ControlAuthentication

More than 81% of organizations deploy vulnerable dependencies.

5/27/2026
Vulnerable DependenciesVulnerabilitiesSoftware Dependencies

Nearly one-third of organizations expose valid secrets in code.

5/27/2026
Secrets ManagementApplication SecuritySecrets Exposure

41.88% of production organizations have leaked AI or ML credentials.

5/27/2026
AI SecuritySecrets ManagementCloud Security

85% of organizations have plaintext secrets embedded in their source code repositories.

6/5/2025
Cloud

93% of organizations have at least one privileged service account, linked to Kubernetes adoption

6/5/2025
Cloud

84% of organizations now use AI in the cloud.

6/5/2025
CloudAI

Showing 1-20 of 25 results