Orca Security
Reports
All Statistics
99.9% of AI vulnerabilities with an available fix remain unpatched.
Among organizations adopting AI, 64% run vector databases.
Between 87% and 98% of AI workloads across the three major cloud providers lack customer-managed encryption.
11.92% of organizations have exposed Databricks credentials.
24.82% of repositories predate GitHub’s 2023 default token hardening and may retain legacy access settings.
28.49% of organizations have exposed Hugging Face tokens.
85% of organizations have plaintext secrets embedded in their source code repositories.
93% of organizations have at least one privileged service account, linked to Kubernetes adoption
84% of organizations now use AI in the cloud.
Among organizations adopting AI, 55% operate four or more AI services simultaneously.
56% of organizations have deployed AI agents into production.
50% of AI package vulnerabilities have a publicly available exploit, a 250-fold increase over 2024.
51% of organizations use AI to build custom applications.
81% of organizations using AI packages have at least one known vulnerability, up from 62% in 2024.
Nearly one-third of organizations expose valid secrets in code.
18.39% of organizations have exposed OpenAI credentials.
11.01% of organizations have active malicious packages embedded in production environments.
10.10% of organizations have exposed Anthropic credentials.
29.15% of organizations are vulnerable to the React2Shell RCE vulnerability.
57.87% of organizations have IAM users without MFA.
More than 81% of organizations deploy vulnerable dependencies.
Over 77% of organizations leave high or critical container vulnerabilities unpatched for more than 90 days.
26.35% of repositories require no code review before merging.
80% of organizations lack proper logging in infrastructure as code.
46.20% of organizations remain exposed to Log4Shell years after disclosure.
21.68% of organizations maintain overly permissive CI/CD token permissions.
30.60% of repositories do not require signed commits.
41.88% of production organizations have leaked AI or ML credentials.
36% of organizations have at least one cloud asset supporting more than 100 attack paths.
62% of organizations have at least one vulnerable AI package.
Nearly a third of cloud assets are neglected today.
76% of organizations have at least one public-facing asset that enables lateral movement.
Each neglected cloud asset contains on average 115 vulnerabilities.