RECENT STORIES:

Addressing digital sovereignty in a data-driven world
Name Change Completed for C Capital’s Swiss Listed Entity, Ticke...
Korean Skincare Brand Meditherapy Tops Amazon U.S. Facial Serums, Brea...
Fox ESS Shines at The Smarter E Europe 2026 with Full-Ecosystem Offeri...
ZTE and GSMA Announce Co-location Between ZTE Global Summit & User...
Fractal Appoints Leandro DalleMule as Chief Practice Officer, Financia...
LOGIN REGISTER
DigiconAsia
  • Features
    • Featured

      Sovereign AI – a competitive advantage

      Sovereign AI – a competitive advantage

      Wednesday, June 24, 2026, 10:01 AM Asia/Singapore | Features
    • Featured

      Deployment outpacing validation in digital experience

      Deployment outpacing validation in digital experience

      Friday, June 12, 2026, 9:26 AM Asia/Singapore | Features
    • Featured

      Bridging the gap from AI prototype to production

      Bridging the gap from AI prototype to production

      Wednesday, June 10, 2026, 1:53 PM Asia/Singapore | Features
  • News
    • Featured

      UN approves first global rules for fully autonomous driving systems

      UN approves first global rules for fully autonomous driving systems

      Friday, June 26, 2026, 11:39 AM Asia/Singapore | News
    • Featured

      UN chief urges AI firms to disclose environmental costs

      UN chief urges AI firms to disclose environmental costs

      Thursday, June 25, 2026, 9:31 AM Asia/Singapore | News
    • Featured

      Wikipedia bars AI bots from direct editing over accuracy and trust concerns

      Wikipedia bars AI bots from direct editing over accuracy and trust concerns

      Wednesday, June 24, 2026, 2:14 PM Asia/Singapore | News
  • Perspectives
  • Tips & Strategies
  • Whitepapers
  • Directory
  • E-Learning

Select Page

News

AI coding tools introduce security flaws in 87% of pull requests: report

By DigiconAsia Editors | Friday, March 13, 2026, 10:40 AM Asia/Singapore

AI coding tools introduce security flaws in 87% of pull requests: report

Recent research tested leading agents building full apps, uncovering 143 vulnerabilities such as improper token handling across models.

In a report on coding security released on 11 March 11, 2026, an “AI-native” cybersecurity firm has claimed to discover significant security shortcomings in leading AI coding tools.

DryRun Security, an Austin, Texas-based firm, had tested Anthropic’s Claude, OpenAI’s Codex, and Google’s Gemini, by tasking them with developing two full applications — a family allergy tracker web app and a browser racing game —via sequential pull requests mimicking real engineering workflows.

Across 38 scans, 143 vulnerabilities surfaced, with 87% of pull requests introducing at least one flaw, according to a report in Yahoo news:

  • Claude had generated the most unresolved high-severity issues in the final codebases
  • Codex showed the strongest remediation, fixing more problems iteratively and ending with the fewest critical vulnerabilities
  • Gemini had placed between them, addressing some early flaws in later changes but still leaving multiple severe risks
  • None of the coding agents produced a secure product, as all overlooked key protections
  • The AI coding agents generated functional software quickly, but security was not built into their processes, and the bots often skipped essential features or botched authentication logic
  • Common failures spanned all models, including improper JSON Web Token handling, no defenses against brute-force attacks, susceptibility to token replay exploits, and weak refresh token cookie settings.
  • Authentication safeguards, when created for REST APIs, were inconsistently applied to WebSocket endpoints, exposing app segments.

These results amplify enterprise ongoing worries about AI-assisted coding. A February 2026 study had found over 25% of AI-generated code contained OWASP Top 10 vulnerabilities, but DryRun’s recent work uniquely tracks flaws compounding over full development cycles.

As software development teams speed up them projects via agents, ongoing scans during workflows—not just end-stage reviews — are vital to curb risk buildup and technical debt, according to industry observers.

Share:

PreviousCGTN AMERICA & CCTV UN: China in Springtime: China’s Development Opportunities for the World
NextIoT trends APAC enterprises cannot ignore in 2026

Related Posts

Elevating Finance’s role to that of a Strategic Business Partner, with digitalization

Elevating Finance’s role to that of a Strategic Business Partner, with digitalization

July 22, 2020

Facial recognition technology key to unlocking ‘Smart Nation’ ambitions

Facial recognition technology key to unlocking ‘Smart Nation’ ambitions

March 26, 2020

Using smartphone metadata to expedite credit worthiness assessment in India

Using smartphone metadata to expedite credit worthiness assessment in India

March 23, 2021

Connected-vehicle analysis showed EV growth, collision drops across fleets: analysis

Connected-vehicle analysis showed EV growth, collision drops across fleets: analysis

April 7, 2026

Leave a reply Cancel reply

You must be logged in to post a comment.

Awards Nomination Banner

gamification list

PARTICIPATE NOW

top placement

Whitepapers

  • Achieve Modernization Without the Complexity

    Achieve Modernization Without the Complexity

    Transforming IT infrastructure is crucial …Download Whitepaper
  • 5 Steps to Boost IT Infrastructure Reliability

    5 Steps to Boost IT Infrastructure Reliability

    In today's fast-evolving tech landscape, …Download Whitepaper
  • Simplify Payroll Setup for Your Small Business

    Simplify Payroll Setup for Your Small Business

    In our free guide, "How …Download Whitepaper
  • Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Download Whitepaper

Middle Placement

Case Studies

  • The 48-hour lifeline: How the IRC rewrote the rules for crisis care

    The 48-hour lifeline: How the IRC rewrote the rules for crisis care

    In a world where crises …Read More
  • CALB upgrades data platform to support analytics, security, and battery lifecycle tracking

    CALB upgrades data platform to support analytics, security, and battery lifecycle tracking

    Deploying a petabyte-scale data lake …Read More
  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your …Read More
  • Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

    Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

    The football club will deepen …Read More

Bottom Sidebar

Other News

  • Name Change Completed for C Capital’s Swiss Listed Entity, Ticker Symbol CCAP Goes Live

    June 27, 2026
    HONG KONG, June 27, 2026 …Read More »
  • Korean Skincare Brand Meditherapy Tops Amazon U.S. Facial Serums, Breaking Into Beauty Best Sellers Top 20

    June 26, 2026
    NEW YORK, June 26, 2026 …Read More »
  • Fox ESS Shines at The Smarter E Europe 2026 with Full-Ecosystem Offerings and AI-Driven Booth Experience

    June 26, 2026
    MUNICH, June 26, 2026 /PRNewswire/ …Read More »
  • ZTE and GSMA Announce Co-location Between ZTE Global Summit & User Congress and GSMA M360 ASEAN at MWC26 Shanghai

    June 26, 2026
    ZTE and GSMA to co-locate …Read More »
  • Fractal Appoints Leandro DalleMule as Chief Practice Officer, Financial Services & Insurance

    June 26, 2026
    “Leandro will lead the practice …Read More »
  • Our Brands
  • CybersecAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 DigiconAsia All Rights Reserved.