// AGGREGATE DATA

Threat Reports

Patterns pulled from our own engagement data — what we're actually finding, not industry survey averages.

Where the findings cluster

Across recent engagements, access control issues — broken object-level authorization, overly broad IAM roles, missing rate limits — account for the largest share of high-severity findings, ahead of classic injection vulnerabilities.

This tracks with the broader shift toward API-first architectures: more surface area for authorization logic to get inconsistent across endpoints.

What this means for prioritization

If your last assessment was framed purely around the OWASP Top 10, it may be under-weighting authorization and configuration issues relative to what we're actually seeing exploited. Worth checking when scoping your next test.

// STAY AHEAD

Want research findings applied to your systems?

This page covers general patterns. An assessment covers what's true for your environment specifically.