The CyberCX State of the Hack 2020 report provides an analysis of application security practices across Australia, highlighting significant trends and vulnerabilities identified through penetration testing. The report is based on data from 2,500 penetration tests, focusing on 189 web applications and services. It reveals a total of 3,539 vulnerabilities found in 2019, a decrease from 3,670 in 2018, primarily due to a reduction in low-risk vulnerabilities. However, high-risk vulnerabilities increased, indicating ongoing security challenges. The report categorizes vulnerabilities according to the OWASP Top 10, with 'Security Misconfiguration' identified as the most common issue. It also discusses the importance of multi-factor authentication and the risks associated with outdated SSL/TLS protocols. The analysis emphasizes the need for organizations to adopt robust security measures and align with industry standards to mitigate risks effectively. Furthermore, it notes a shift in root causes of vulnerabilities, with design flaws becoming more prevalent compared to configuration flaws.