Tag
JSEF v1.4.0-benchmark has been released, adding 85 new samples to the Spring Boot 3.x Java vulnerability mining benchmark for improved security testing coverage and validation.
Join an AMA with Arshi Chadha, co-lead of OWASP LLM Top 10, discussing prompt injection, RAG poisoning, and embedding attacks in AI systems.
The OWASP Top 10 CI/CD Security Risks document identifies the most critical attack vectors and risks in CI/CD environments, derived from analysis of major breaches, helping defenders prioritize security controls.
AI Agent security has moved from an academic topic to an industry reality, involving FFmpeg zero-day vulnerabilities, Chrome 429 patch, OpenAI Lockdown Mode, and the OWASP framework; meanwhile, Agent payment standards are becoming a battlefield for infrastructure, with Visa stablecoin settlement competing with traditional card networks.
AI can now complete OWASP security audits in 30 seconds instead of three days, using a single prompt to identify vulnerabilities like SQL injection, XSS, and broken authentication.
OWASP发布了首个针对自主AI代理的Top 10安全风险列表(2026版),涵盖目标劫持、工具滥用、供应链攻击等威胁,并引用调查指出88%的企业在过去一年遭遇过AI代理安全事件。
The article argues that structural backpressure (e.g., compilers, type checkers) is more effective than improving AI models for ensuring code correctness, and introduces Shen-Backpressure as a tool to implement this approach.