Skip to content

other

OWASP

OWASP is a nonprofit community publishing open security standards and guidance, known for its Top 10 risk lists covering web, API, and LLM applications.

Known aliases

  • Open Web Application Security Project
  • Open Worldwide Application Security Project
  • OWASP Foundation
  • OWASP LLM application guidance

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

One SQLite transaction keeps a retried Buy click from creating a second order

Retried Buy clicks get the original order back in a dev.to guide that commits each order with its attempt key in one SQLite transaction. A disabled button only cuts double-clicks, and the guide's available text ends before it covers charging the card.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence50
build5 publishers

Zero Data Retention stops at OpenAI's edge. Your logs are still your problem

OpenAI's August 19 update promises it keeps nothing after a request. The copies your own app leaves behind in logs, queues and databases are governed by you, not by a toggle.

Perspective Coverage

5 publishers
Builder
Builder 34%
Operator
Operator 35%
Investor
Investor 31%

Reality

Evidence58
Adoption15
Hype gap+30
Incentives65
Confidence55
security3 publishers

Qrator finds x47.c's AI credit drain works only with a key the attacker already holds

Qrator says x47.c, a Windows botnet sold for up to $950, burns a victim's OpenAI or xAI credit with a valid API key while the website stays up. Website filtering never sees the requests, so the defenses are key revocation and spending caps.

Perspective Coverage

3 publishers
Builder
Builder 35%
Operator
Operator 55%
Investor
Investor 10%

Reality

Evidence40
Adoption
Insufficient
Hype gap+25
Incentives60
Confidence55
build1 publisher

Tool permissions set the maximum harm a hijacked security agent can do

Dev.to author dharani2d argues agent security depends on who picks the next tool call, citing Excessive Agency's rise from sixth to third at OWASP. The proposed control plane keeps identity, authorization, argument checks and approvals in deterministic code outside the model.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence40
security3 publishers

CISA reframes the CVE program around data quality as 2026 heads for 96,000 records

Disclosure volume is climbing faster than the process around it. CISA's answer is a framework that describes what a good CVE record is and how the program should be judged on producing one.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 50%
Investor
Investor 17%

Reality

Evidence68
Adoption
Insufficient
Hype gap+30
Incentives55
Confidence66
security3 publishers

Any local process can rewrite the dictation endpoint in Meta's new Muse assistant

Patrick Wardle published working code that sends Muse's dictated audio to a server of the attacker's choosing. Because the assistant holds file, microphone, camera, calendar and paired-iPhone access, whoever redirects it inherits all of it.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 54%
Investor
Investor 13%

Reality

Evidence70
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence65
build1 publisher

Renaming a class leaves behind the call graph an AI reads

A dev.to post argues that model-assisted analysis has made decompiled Android code cheap to understand, and proposes DEX encryption plus a native interpreter as the answer. Its own feature list shows what that costs to adopt.

Publishers:dev.to

Reality

Evidence22
Adoption
Insufficient
Hype gap+38
Incentives76
Confidence60
build1 publisher

Nine of OWASP's ten LLM risks land on whoever deployed the agent

A dev.to post argues the OWASP Top 10 for LLM Applications 2025 is a list of things a better model will not fix, including over-scoped permissions, unvalidated agent output, and retry loops that bill by the token.

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap+12
Incentives30
Confidence56

Earlier coverage

  1. A sixty-line route table pins the two vendors an overnight LLM batch is allowed to reach

    Build · September 13, 2026 · 1 publisher

  2. Security executives want AI agent limits enforced downstream of the model

    Leadership · September 13, 2026 · 1 publisher

  3. Freezing new work before revoking the leaked key keeps the refusals explainable

    Build · September 12, 2026 · 1 publisher

  4. Signed commits and commitlint move the first governance gate onto the developer's laptop

    Build · September 11, 2026 · 1 publisher

  5. Where the agent runs decides whose guardrails apply

    Build · September 10, 2026 · 1 publisher

  6. OWASP catalogues an attack that forges the approval dialog guarding AI agents

    Science · September 10, 2026 · 1 publisher

  7. OWASP's Cornucopia mobile deck turns a card game into a MASVS requirements lookup

    Build · September 10, 2026 · 1 publisher

  8. Prompt injection can rewrite the one-line summary in Claude Code's approval dialog

    Build · September 9, 2026 · 1 publisher

  9. Advancing the credential version only after the password commits keeps reset requests powerless

    Build · September 7, 2026 · 1 publisher

  10. IMDSv1 turns an SSRF finding into unauthenticated credential theft in one hop

    Build · September 6, 2026 · 1 publisher

  11. CVE-2025-54136 turns a one-time MCP approval into a permanently mutable surface

    Build · September 5, 2026 · 1 publisher

  12. AWS and SANS move agent authorization out of the prompt and into the RBAC layer

    Security · September 3, 2026 · 1 publisher

  13. Delta-v leads a $100m round into runtime security for the coding agents enterprises already ship

    Invest · September 2, 2026 · 2 publishers

  14. Why bounding the agent loop matters for a Well-Architected review

    Build · August 30, 2026 · 1 publisher

  15. One trailing character that cannot match turns /^(a+)+$/ into a CPU pin

    Build · August 29, 2026 · 1 publisher

  16. ClawHavoc's 12 accounts outshipped the malicious-skill census by 7.5 times

    Invest · August 28, 2026 · 1 publisher

  17. An atomic claim on one flow record makes a duplicate OAuth callback harmless

    Build · August 28, 2026 · 1 publisher

  18. The ICO fines what you cannot prove: Article 32 makes encryption and erasure an engineering liability

    Build · August 26, 2026 · 1 publisher

  19. 93% have had an AI infrastructure incident. A quarter would still ship HCL unread.

    Product · August 25, 2026 · 1 publisher

  20. An OAuth callback proves who logged in, not what the patient agreed to

    Build · August 24, 2026 · 1 publisher

  21. MCP's roadmap fast-tracks five priorities and quietly queues everything else

    Build · August 22, 2026 · 1 publisher

  22. If the model can move the CVSS score, the remediation queue is not auditable

    Build · August 22, 2026 · 1 publisher

  23. An AI reviewer called injectable SQL safe because it could not read the helper

    Build · August 19, 2026 · 1 publisher

  24. OWASP keeps prompt injection at number one and starts managing the blast radius

    Security · August 18, 2026 · 1 publisher

  25. A docs bot that refuses to answer is working: the case for an evidence gate over a bigger window

    Build · August 17, 2026 · 1 publisher

  26. The agent stack's attack surface is trust: pin the deps, audit the MCP servers

    Build · August 16, 2026 · 1 publisher

  27. OWASP now names seventeen agentic threats, and the control unit is the whole run

    Security · August 15, 2026 · 1 publisher