RECENT STORIES:

Addressing digital sovereignty in a data-driven world
Arctech Shines at SNEC 2026, securing over 3 GW orders with its “...
Taishin Bank Selected as Demonstration Bank for One-Stop Banking Servi...
YY Group (NASDAQ: YYGH) Wins Prestigious HAPA Solutions Excellence Awa...
Amartha Initiates Coalition to Advance Financial Health for Grassroots...
FPT and NVIDIA Collaborate to Release the Nemotron Personas Vietnam Da...
LOGIN REGISTER
DigiconAsia
  • Features
    • Featured

      In AI missions, who governs the agents

      In AI missions, who governs the agents

      Thursday, June 4, 2026, 4:06 PM Asia/Singapore | Features
    • Featured

      The 48-hour lifeline: How the IRC rewrote the rules for crisis care

      The 48-hour lifeline: How the IRC rewrote the rules for crisis care

      Friday, May 29, 2026, 12:28 PM Asia/Singapore | Case Studies, Features
    • Featured

      Hidden trade-offs behind enterprise AI ambitions

      Hidden trade-offs behind enterprise AI ambitions

      Tuesday, May 26, 2026, 3:27 PM Asia/Singapore | Features
  • News
    • Featured

      AI models governing simulated societies show divergent stability, crime, survival outcomes

      AI models governing simulated societies show divergent stability, crime, survival outcomes

      Thursday, June 4, 2026, 10:26 AM Asia/Singapore | News
    • Featured

      JWST finds Milky Way-like barred spiral galaxies in early universe

      JWST finds Milky Way-like barred spiral galaxies in early universe

      Wednesday, June 3, 2026, 2:02 PM Asia/Singapore | News
    • Featured

      AI leaders soften job loss warnings amid policy debates, memo leaks and public backlashes

      AI leaders soften job loss warnings amid policy debates, memo leaks and public backlashes

      Tuesday, June 2, 2026, 4:49 PM Asia/Singapore | Future of Work, News
  • Perspectives
  • Tips & Strategies
  • Whitepapers
  • Directory
  • E-Learning

Select Page

News

AI coding tools introduce security flaws in 87% of pull requests: report

By DigiconAsia Editors | Friday, March 13, 2026, 10:40 AM Asia/Singapore

AI coding tools introduce security flaws in 87% of pull requests: report

Recent research tested leading agents building full apps, uncovering 143 vulnerabilities such as improper token handling across models.

In a report on coding security released on 11 March 11, 2026, an “AI-native” cybersecurity firm has claimed to discover significant security shortcomings in leading AI coding tools.

DryRun Security, an Austin, Texas-based firm, had tested Anthropic’s Claude, OpenAI’s Codex, and Google’s Gemini, by tasking them with developing two full applications — a family allergy tracker web app and a browser racing game —via sequential pull requests mimicking real engineering workflows.

Across 38 scans, 143 vulnerabilities surfaced, with 87% of pull requests introducing at least one flaw, according to a report in Yahoo news:

  • Claude had generated the most unresolved high-severity issues in the final codebases
  • Codex showed the strongest remediation, fixing more problems iteratively and ending with the fewest critical vulnerabilities
  • Gemini had placed between them, addressing some early flaws in later changes but still leaving multiple severe risks
  • None of the coding agents produced a secure product, as all overlooked key protections
  • The AI coding agents generated functional software quickly, but security was not built into their processes, and the bots often skipped essential features or botched authentication logic
  • Common failures spanned all models, including improper JSON Web Token handling, no defenses against brute-force attacks, susceptibility to token replay exploits, and weak refresh token cookie settings.
  • Authentication safeguards, when created for REST APIs, were inconsistently applied to WebSocket endpoints, exposing app segments.

These results amplify enterprise ongoing worries about AI-assisted coding. A February 2026 study had found over 25% of AI-generated code contained OWASP Top 10 vulnerabilities, but DryRun’s recent work uniquely tracks flaws compounding over full development cycles.

As software development teams speed up them projects via agents, ongoing scans during workflows—not just end-stage reviews — are vital to curb risk buildup and technical debt, according to industry observers.

Share:

PreviousCGTN AMERICA & CCTV UN: China in Springtime: China’s Development Opportunities for the World
NextIoT trends APAC enterprises cannot ignore in 2026

Related Posts

Riding the hyper-connectivity wave requires collaboration, security and trust   

Riding the hyper-connectivity wave requires collaboration, security and trust   

December 16, 2024

AI platform offers hope for men stigmatized with turning up for sexually-transmitted-disease testing

AI platform offers hope for men stigmatized with turning up for sexually-transmitted-disease testing

July 21, 2022

The rise of embedded finance in Asia Pacific

The rise of embedded finance in Asia Pacific

September 21, 2022

When the going gets tough in Malaysia, the tough get online

When the going gets tough in Malaysia, the tough get online

January 26, 2021

Leave a reply Cancel reply

You must be logged in to post a comment.

Awards Nomination Banner

gamification list

PARTICIPATE NOW

top placement

Whitepapers

  • Achieve Modernization Without the Complexity

    Achieve Modernization Without the Complexity

    Transforming IT infrastructure is crucial …Download Whitepaper
  • 5 Steps to Boost IT Infrastructure Reliability

    5 Steps to Boost IT Infrastructure Reliability

    In today's fast-evolving tech landscape, …Download Whitepaper
  • Simplify Payroll Setup for Your Small Business

    Simplify Payroll Setup for Your Small Business

    In our free guide, "How …Download Whitepaper
  • Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Overcoming the Challenges of Cost & Complexity in the Cloud-first Era.

    Download Whitepaper

Middle Placement

Case Studies

  • The 48-hour lifeline: How the IRC rewrote the rules for crisis care

    The 48-hour lifeline: How the IRC rewrote the rules for crisis care

    In a world where crises …Read More
  • CALB upgrades data platform to support analytics, security, and battery lifecycle tracking

    CALB upgrades data platform to support analytics, security, and battery lifecycle tracking

    Deploying a petabyte-scale data lake …Read More
  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your …Read More
  • Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

    Liverpool FC to deliver more personalized, real-time digital fan experiences with AI

    The football club will deepen …Read More

Bottom Sidebar

Other News

  • Arctech Shines at SNEC 2026, securing over 3 GW orders with its “Tracker+” Ecosystems

    June 5, 2026
    SHANGHAI, June 5, 2026 /PRNewswire/ …Read More »
  • Taishin Bank Selected as Demonstration Bank for One-Stop Banking Services for Foreigners, Enhancing Banking Accessibility for International Talent

    June 5, 2026
    TAIPEI, June 5, 2026 /PRNewswire/ …Read More »
  • YY Group (NASDAQ: YYGH) Wins Prestigious HAPA Solutions Excellence Award, Validating Enterprise AI Marketplace Adoption in Southeast Asia

    June 5, 2026
    Independent industry recognition highlights YY …Read More »
  • Amartha Initiates Coalition to Advance Financial Health for Grassroots Communities in Indonesia

    June 5, 2026
    The coalition, titled the Indonesian …Read More »
  • FPT and NVIDIA Collaborate to Release the Nemotron Personas Vietnam Datasets

    June 5, 2026
    HANOI, Vietnam, June 5, 2026 …Read More »
  • Our Brands
  • CybersecAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 DigiconAsia All Rights Reserved.