#OWASP's
I'm on my way to Denver for OWASP's #SnowFroc conference!
March 12, 2025 at 7:45 PM
Who is a fan of OWASP's DSOMM?
November 15, 2024 at 1:07 AM
Got listed as a contributor in OWASP's Application Security Verification Standard (ASVS) 5.0 because I bitched about Session Storage on GitHub.

Life is fun.
May 28, 2025 at 5:31 PM
Im just gonna leave this here.

youtu.be/gUNXZMcd2jU?...
OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed
YouTube video by IBM Technology
youtu.be
July 2, 2026 at 3:54 PM
🐝 It’s official: OWASP’s 2025 Top 10 now includes Software Supply Chain Failures.

Half of survey respondents ranked it their top concern, a long overdue recognition in a year marked by high-impact supply chain attacks.

→ socket.dev/blog/owasp-2... #owasp #appsec #cybersecurity
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranke...
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
socket.dev
November 9, 2025 at 5:57 PM
Finding my First SQL Injection On HackerOne
Finding my First SQL Injection On HackerOne
SQL injections have been a persistent aspect of web application security, maintaining their position on OWASP’s top 10 vulnerabilities year…
infosecwriteups.com
January 19, 2025 at 7:17 AM
We’re thrilled to welcome Missie Lindsey as OWASP’s new Director of Corporate Relations,
to help us grow corporate sponsorships and support OWASP’s global open-source security mission. 🎉

Join us in welcoming her to the community!

owasp.org/blog/2026/...

#OWASP #AppSec #OpenSource #NewAppointment
The OWASP Foundation appoints Missie Lindsey as Director of Corporate Relations | OWASP Foundation
The OWASP Foundation appoints Missie Lindsey as Director of Corporate Relations on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
owasp.org
April 27, 2026 at 12:28 PM
#OWASP Top 10 Non-Human Identity Risks for 2025 have just been released - What You Need to Know (blog post by GitGuardian):
👇
blog.gitguardian.com/owasp-top-10...
OWASP Top 10 Non-Human Identity Risks for 2025: What You Need to Know
Learn about OWASP’s newest focus on Non-Human Identities and how to mitigate risks like secret leakage, overprivileged NHIs, and insecure authentication with GitGuardian.
blog.gitguardian.com
January 12, 2025 at 12:02 PM
A compromised AI agent can redirect workflows, trigger unauthorized API calls, and persist malicious instructions in memory.

That's why OWASP's Agentic Top 10 exists alongside the LLM Top 10—two frameworks for two layers.

Learn more. ➡️ https://bit.ly/4wqqTPJ
September 24, 2026 at 1:04 PM
I have written 10 articles covering OWASP's top 10, as security is one of my passions and something I must cover even more at work these days!

Thanks to @talsecofficial.bsky.social for accepting to publish these articles on their blogs, as they are pioneer in mobile security.

What do you think? 👇
OWASP Top 10 For Flutter — M2: Inadequate Supply Chain Security in Flutter
Part 2 in series of articles covering OWASP Top 10 For Flutter by @mhadaily.bsky.social

docs.talsec.app/appsec-artic...

#flutter #CyberSecurity #appdeveloper #eprivacy
March 24, 2025 at 6:03 PM
Prompt injection is still king, but “excessive agency” just jumped to #3 in OWASP’s Top 10 for LLM apps. Stop chasing unbreakable models—start containing fooled agents. jpmellojr.blogspot.com/2026/08/owas... #AIsecurity #OWASP #LLM #AppSec
OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise
Prompt injection is still king, but “excessive agency” just jumped to #3 in OWASP’s Top 10 for LLM apps. Stop chasing unbreakable models—s...
jpmellojr.blogspot.com
August 12, 2026 at 10:12 PM
OWASP 25th Anniversary Virtual Conference

I am very happy to share that I will be speaking at this year's OWASP 25th Anniversary Virtual Conference on the 24. of February. owasp25thanniversaryvirtual.sched.com/event/2DjqY/...

Please join, it's free! owasp.glueup.com/event/owasp-...
OWASP 25th Anniversary Virtual Conference | The OWASP Foundation Inc.
Join us as we celebrate OWASP’s 25th Anniversary with a free virtual conference dedicated to the global community that makes our mission possible. This milestone event features a dynamic lineup of ins...
owasp.glueup.com
January 29, 2026 at 12:47 PM
OWASP Top 10 2025: What to Expect
OWASP Top 10 2025: What to Expect
The OWASP Top 10 is set for its next update in early 2025. According to OWASP’s official page, the data collection process is currently…
infosecwriteups.com
January 2, 2025 at 6:27 AM
Prompt injection has held the 1️⃣ spot on OWASP's LLM Top 10 since 2023 - every edition, no exceptions. Indirect injection (hidden instructions in emails, web pages) now accounts for over half of observed attacks. #ai
Prompt injection: why LLMs can't be fully secured | Psyll
LMs mix instructions and data in one channel, making prompt injection unfixable by filters alone. Here's how attacks work and what actually limits the damage.
psyll.com
August 4, 2026 at 6:14 PM
OWASP's new Non-Human Identity (NHI) Top 10 tackles machine credential security risks (API keys, etc.), addressing vulnerabilities like excessive permissions and OAuth phishing, absent from existing lists. It prioritizes risks by exploitability and impact, providing actionable developer guidance.
January 27, 2025 at 12:02 PM
OWASP's Web Security Testing Guide + DeepWiki + DeepResearch could potentially be a killer combo.

- EZPZ to use
- Directly ask it questions
- No need to drag context around to different chats / agents or mess with uploads
May 1, 2025 at 12:42 PM
OWASP dropped in 2026, the Top 10 for Agentic AI 🚨

The threat landscape for agentic systems goes way beyond prompt injection. Worth a read if you're building with AI agents.

🔗 graylog.org/post/what-is...

#AgenticAI #OWASP #CyberSecurity #AppSec #LLMSecurity
What is the OWASP Top 10 Agentic AI
Explore OWASP’s 2025 Agentic AI Threats & Mitigations Guide. View the top risks of autonomous AI agent and strategies to secure multi-agent systems and safeguard data.
graylog.org
May 11, 2026 at 1:44 PM
Understanding OWASP’s Top 10 list of non-human identity critical risks
Understanding OWASP’s Top 10 list of non-human identity critical risks
Non-human identities represent a vast chunk of credentials used by a typical organization, up to 50 times higher than the number of human identities. Here is an explanation of OWASP’s new Top 10…
buff.ly
February 21, 2025 at 9:42 AM
National Instruments has good meeting space and has sponsored meetups like OWASP's Austin Chapter.
December 10, 2024 at 8:47 PM
"OWASP's first major Top 10 update since 2021 and is notable for its emphasis on supply chain risks and systemic design weakness rather than just common software coding errors."

www.darkreading.com/application-... #infosec #cybersecurity #appsec
OWASP Highlights Supply Chain Risks in New Top 10
Security misconfiguration jumped to second place as organizations improve defenses against traditional coding flaws.
www.darkreading.com
November 12, 2025 at 6:59 AM
Non-human identities (NHI), including software workloads, #AI agents & service accounts & their associated credentials vastly outnumber human identities in most environments. To address this growing threat, #OWASP released the first-ever #NHI Top 10. go.aembit.io/s/owasp-s-to...
OWASP's Top 10 Security Risks for Non-Human Identities
Learn the 10 biggest security risks facing non-human identities, from secrets leakage to overprivileged access and how to mitigate them.
go.aembit.io
June 22, 2026 at 5:15 PM
OWASP’s 2025 Wake-Up Call: Why Broken Access Control Still Haunts Web Security
November 18, 2025
OWASP’s 2025 findings show broken access control remains one of the most persistent and damaging web security problems.
kbala97.github.io/CyberTechHea...
Cyber Technology and Health
kbala97.github.io
November 18, 2025 at 9:32 PM
Join the OWASP Contributor Mixer alongside NDC Security! No slides, no sales, just real conversations with the people behind OWASP’s open-source projects. Grab a drink, meet collaborators, and see how to get involved. All welcome. luma.com/txn0myuk
#owasp #opensource #mixer #NDC #community
February 17, 2026 at 6:44 PM