Many companies keep seeing the same kind of security bugs pop up, month after month, year after year. And oftentimes these aren’t new, esoteric, never before seen bug classes. No, these are classic bug classes we’ve known about and have been on the OWASP Top 10 for years - cross-site scripting (XSS), SQL injection, etc.