IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
BreachLock report flags AI, cloud & web logic risks

BreachLock report flags AI, cloud & web logic risks

Thu, 30th Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

BreachLock has published its fifth annual Penetration Testing Intelligence Report, drawing on 4,970 penetration tests and 531,770 security findings.

The data points to artificial intelligence applications, cloud environments, mobile apps and web application logic as the main areas of exposure in the testing dataset. It also suggests that weaknesses tied to application behaviour and configuration are becoming more prominent than issues typically flagged by automated scanners.

AI findings

One of the report's clearest findings is the extent of security issues in AI systems. Every AI application BreachLock tested contained vulnerabilities aligned with the OWASP Top 10 for large language models.

Prompt injection, identified as LLM01 in that framework, was the most common issue in the AI sample, appearing in 28% of tested applications. The result adds to growing industry focus on AI-specific weaknesses as companies build more internal and customer-facing tools on top of large language models.

Web logic

The report also recorded a marked rise in insecure design and business logic flaws in web applications. Those findings, classified under OWASP A04, rose to 16% from 8% a year earlier.

Testers found attack paths involving race conditions in checkout processes, privilege escalation through parameter manipulation and the bypassing of approval workflows. These weaknesses often depend on how an application is designed to operate, rather than on a software defect detectable through standard scanning alone.

That distinction matters for security teams because business logic flaws can let attackers exploit normal functions in unintended ways. In practice, that can mean manipulating payments, altering permissions or sidestepping internal controls without triggering the alerts associated with more familiar technical exploits.

Cloud concentration

Cloud audits produced the highest concentration of severe risk in the dataset. Cloud security audits carried a critical finding rate of 1.34%, thirteen times higher than the rate in web application testing.

The report attributed much of that to exposed S3 buckets, leaking Lambda functions and disabled GuardDuty monitoring. The pattern reflects a long-running cloud security challenge, where misconfiguration rather than code vulnerability often creates the route to compromise.

Mobile exposure

Mobile applications showed a narrower but still acute risk profile. Hardcoded credentials in iOS applications accounted for 97% of all critical mobile findings in the dataset.

According to the report, such credentials can be extracted quickly with widely available tools. The finding underlines how secrets embedded in application code remain a basic but unresolved problem, particularly when mobile apps connect to back-end systems and cloud services.

Beyond the headline categories, the report also tracked sector-specific risk trends across manufacturing, telecommunications, financial services, healthcare, retail and technology. While BreachLock did not provide a sector-by-sector breakdown in the released material, it presented the report as a benchmark for how organisations are exposed across changing attack surfaces.

The report comes as boards and senior executives seek clearer evidence of which security weaknesses can be exploited in practice, rather than long lists of low-priority findings. In that context, penetration testing data is increasingly used to show not just where flaws exist, but whether they can be chained into workable attack paths.

Seemant Sehgal, Founder and Chief Executive Officer at BreachLock, framed the report around that point.

"Boards want to know which vulnerabilities can actually be used against them, and they want the answer as fast as an attacker can find it," said Seemant Sehgal, Founder and Chief Executive Officer, BreachLock.

"This industry has spent a decade producing lists of theoretical weakness. What matters now is proof of exploitability, tested at the same speed as the threat. For the third year running, we have contributed our dataset to the Verizon DBIR because the industry doesn't need more theory. It needs ground truth, and that's what this report delivers," Sehgal said.