Checkmarx调查:近半数生产代码由AI生成,漏洞率高出3.4倍

Nearly half of all production code is now generate…

精选理由

Checkmarx报告用数据告诉你:AI写代码虽快,但漏洞风险飙升,别只图效率忽视安全。

AI 摘要

Checkmarx对2350名工程师的调查显示,依赖AI生成代码的公司漏洞部署率是较少使用AI公司的3.4倍。96%的开发者使用安全工具,但仅9%的公司能在三个月内修复90%以上已发现的漏洞。75%的团队承认曾发布明知有缺陷的代码,30%因认为无人发现而为之。报告指出AI生成代码的安全隐患已成为严重问题。

原文 · Ate-a-Pi

Nearly half of all production code is now generate…

Nearly half of all production code is now generated by AI.

Checkmarx surveyed 2,350 engineers, and the results are concerning:

Companies that rely more on AI-generated code ship vulnerabilities at 3.4x the rate of those companies that use AI less for the code.

The more AI-generated code you create, the higher the rate of vulnerable code you deploy and the more breaches you suffer.

This is not looking good.

Here is the funny part:

• 96% of devs use tools to flag security problems • 99.6% of them say those tools work

And yet only 9% of these companies fix more than 90% of the bugs they find within three months.

We have the tools, but we aren't using them.

The report gets even better:

• 75% of teams say they ship code they know is broken • 30% do it because they know nobody will find out • 95% of security chiefs have been pressured to bury/delay findings

People seem to be choosing to look away.

There are a ton of other findings, but the bottom line is clear:

Security in AI-generated code has become a huge problem.

Here is the link to the full report:

https://t.co/LcxQ7R9uOZ

Thanks to the @Checkmarx team for sharing their report and collaborating with me on this post.