'Coding [not specification or config] errors account for two-thirds' of security vulnerabilities