CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

Code review used to be the only way to catch these bugs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3903

As cited

Copy frozen at (site build).

research

Code review used to be the only way to catch these bugs

Researchers at Palo Alto Networks' Unit 42 developed NOVA, an automated system that scanned 3,915 open-source projects and identified 14,090 previously undocumented vulnerabilities over two months. Validation against public records showed only 85 of NOVA's findings matched existing documentation, with most of those published weeks after the system's discovery, suggesting substantial gaps in current vulnerability tracking.

Why it matters: Open-source maintainers and enterprises relying on these projects face undetected vulnerabilities; practitioners should evaluate whether automated code analysis tools can supplement their existing security practices to catch issues before public disclosure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

research

Code review used to be the only way to catch these bugs

Researchers at Palo Alto Networks' Unit 42 developed NOVA, an automated system that scanned 3,915 open-source projects and identified 14,090 previously undocumented vulnerabilities over two months. Validation against public records showed only 85 of NOVA's findings matched existing documentation, with most of those published weeks after the system's discovery, suggesting substantial gaps in current vulnerability tracking.

Why it matters: Open-source maintainers and enterprises relying on these projects face undetected vulnerabilities; practitioners should evaluate whether automated code analysis tools can supplement their existing security practices to catch issues before public disclosure.

VendorsPalo Alto Networks
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary