SQL injection is a thing of the past…. & other lies we tell ourselves

Injection attacks like SQL injection (SQLi) are older than the Internet Explorer, yet they still plague modern applications. Our recent research examined SQLi, Command Injection, Path Traversal, and Cross-Site Scripting (XSS) vulnerabilities in open and closed-source projects to understand their prevalence in modern apps. SQLi alone accounted for 6.7% of vulnerabilities in open-source and 10% of closed-source vulnerabilities discovered in 2024. Command injection, Path Traversal, and XSS also remain dominant threats. This presentation explores why injection attacks persist despite being ‘technically’ solved with parameterized queries and examines whether new AI technologies can finally eliminate them or make us more vulnerable. We’ll review our research methodology, which included analyzing over 50,000 closed-source projects, and highlight key findings. Real-world case studies, such as the MoveIT attack, will underscore their ongoing impact. We’ll conclude with prevention strategies and discuss why injection vulnerabilities may persist for another decade.
What are the key learnings from your session?
- What are injection-style attacks including XSS, Path Traversal, Command Injection SQL injection, and NoSQL injection
- How major incidents involving injection attacks unfolded in modern applications
- How prevalent injection attacks are in modern applications
- Why injection attacks still happen today
- How can we defend against injection-style attacks including secure coding methods and tools
Speaker

Mackenzie is the Field CTO for Aikido Security, helping tech leaders understand application security through an attacker’s lens. As the co-founder and former CTO the successful health tech company Conpago he understands …









