Close Menu
  • Home
  • AI
  • Big Data
  • Cloud Computing
  • iOS Development
  • IoT
  • IT/ Cybersecurity
  • Tech
    • Nanotechnology
    • Green Technology
    • Apple
    • Software Development
    • Software Engineering

Subscribe to Updates

Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

    What's Hot

    Empowering Protected Area Technicians with IT skills through Cisco Networking Academy

    January 26, 2026

    Apple scores six Academy Award nominations

    January 26, 2026

    Codenotary updates its free SBOM scanning tool with capabilities that better support AI apps

    January 26, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Big Tee Tech Hub
    • Home
    • AI
    • Big Data
    • Cloud Computing
    • iOS Development
    • IoT
    • IT/ Cybersecurity
    • Tech
      • Nanotechnology
      • Green Technology
      • Apple
      • Software Development
      • Software Engineering
    Big Tee Tech Hub
    Home»Software Development»OWASP Top 10 updated after four years, with many of the same concerns still impacting applications
    Software Development

    OWASP Top 10 updated after four years, with many of the same concerns still impacting applications

    big tee tech hubBy big tee tech hubNovember 13, 2025003 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    OWASP Top 10 updated after four years, with many of the same concerns still impacting applications
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    unnamed1unnamed1

    The OWASP Foundation has revealed the first Release Candidate for the 2025 OWASP Top 10 list, which ranks the most critical security concerns developers should be thinking about.

    The top 10 security concerns on the updated list are:

    1. Broken Access Control
    2. Security Misconfiguration
    3. Software Supply Chain Failures
    4. Cryptographic Failures
    5. Injection
    6. Insecure Design
    7. Authentication Failures
    8. Software or Data Integrity Failures
    9. Logging and Alerting Failures
    10. Mishandling of Exceptional Conditions

    This list features many of the same concerns from the 2021 versions, with a few notable changes, such as Server-Side Request Forgery, which was in last place in 2021, being rolled into the Broken Access Control category.

    Additionally, a new category, Software Supply Chain Failures, was added and includes Vulnerable and Outdated Components (#6 in 2021), and Mishandling of Exceptional Conditions made the list for the first time, containing CWEs related to improper error handling, logical errors, failing open, and other related scenarios.

    “Mishandling of Exceptional Conditions is a category that has been just outside the Top 10 for several years. In this iteration, there was enough data and support from the community survey to push it over the line and into the Top 10,” said Brian Glas, one of the lead authors of the report.

    Broken Access Control maintained its position as the top concern, with 3.74% of applications OWASP tested including one or more of the 40 CWEs in this category.

    Cryptographic Failures, Injection, and Insecure Design dropped down in the list, while Security Misconfiguration rose to number two.

    The OWASP Top 10 is decided based on two main data collection methods. The primary way is that companies contributed their findings from SAST, DAST, IAST, and other security testing from 2020 to 2024. This data included over 2.8 million applications that were tested. The second method is a community survey to account for new categories of vulnerabilities that the industry may not have developed adequate tests for yet.

    “It’s essential to understand why we construct the Top 10 in this manner,” said Glas. “If it were purely data-driven, we would not have an accurate list, as it would only be looking into the past. The community survey is crucial in enabling people on the ground to share what they perceive as important risks that require visibility and attention, which may not be reflected in the data.”

    Glas concluded that this updated OWASP Top 10 highlights the fact that software development is becoming more complex, and developers are being asked to be responsible for more things. He cited the rise of Software Supply Chain Failures and Security Misconfiguration as evidence for this change.

    The OWASP Top 10 2025 will be open for comments until November 20th.



    Source link

    applications concerns impacting OWASP Top updated Years
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    tonirufai
    big tee tech hub
    • Website

    Related Posts

    Codenotary updates its free SBOM scanning tool with capabilities that better support AI apps

    January 26, 2026

    This week in AI updates: GitHub Copilot SDK, Claude’s new constitution, and more (January 23, 2026)

    January 25, 2026

    How to Hire a Remote Development Team and Manage It Effectively in 2026

    January 24, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Empowering Protected Area Technicians with IT skills through Cisco Networking Academy

    January 26, 2026

    Apple scores six Academy Award nominations

    January 26, 2026

    Codenotary updates its free SBOM scanning tool with capabilities that better support AI apps

    January 26, 2026

    Engineered mucus-tethering bispecific nanobodies enhance mucosal immunity against respiratory pathogens

    January 26, 2026
    About Us
    About Us

    Welcome To big tee tech hub. Big tee tech hub is a Professional seo tools Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of seo tools, with a focus on dependability and tools. We’re working to turn our passion for seo tools into a booming online website. We hope you enjoy our seo tools as much as we enjoy offering them to you.

    Don't Miss!

    Empowering Protected Area Technicians with IT skills through Cisco Networking Academy

    January 26, 2026

    Apple scores six Academy Award nominations

    January 26, 2026

    Subscribe to Updates

    Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

      • About Us
      • Contact Us
      • Disclaimer
      • Privacy Policy
      • Terms and Conditions
      © 2026 bigteetechhub.All Right Reserved

      Type above and press Enter to search. Press Esc to cancel.