Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
standards-framework-updateinternet-facing-service-vulnerabilitycloud-misconfiguration

OWASP Top 10 2025 Release and Key Changes

Updated 3mo agoFirst seen Nov 7, 20256 sources

The Open Worldwide Application Security Project (OWASP) unveiled the 2025 edition of its Top 10 list of critical risks to web applications at the Global AppSec conference in Washington, D.C. This update, the first since 2021, reflects a significant shift in focus from individual code-level vulnerabilities to broader, systemic risks. Notable changes include the merging and redefinition of previous categories, the elevation of Security Misconfiguration to the second position, and the introduction of a new risk: "Mishandling of Exceptional Conditions." The list is the result of a community-driven process involving extensive data analysis and industry feedback, and is intended as a starting point for organizations to build robust security programs.

Industry experts highlight that the 2025 Top 10 is now more aligned with the concerns of CISOs and security leaders, emphasizing risks such as software supply chain failures and security misconfigurations. The inclusion of these categories reflects the growing importance of third-party software and deployment practices in the modern threat landscape. While the list serves as a guide for prioritizing risk, it is not meant to be a compliance checklist but rather a strategic tool for organizations to address the most pressing security challenges in web application development and deployment.

Share:
OWASP Top 10 2025 Release and Key Changes
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Nov 11, 20258mo ago

OWASP confirms broken access control remains the top risk

Subsequent reporting on the 2025 update emphasized that broken access control continued to hold the top position in the OWASP Top 10. This reinforced continuity in the highest-ranked application security issue despite other changes to the list.

Nov 8, 20258mo ago

OWASP 2025 Top 10 adds software supply chain failures

Coverage of the 2025 list noted that software supply chain failures were added as a new category and described as a leading community concern. Multiple reports highlighted this as one of the most significant changes in the updated rankings.

Nov 7, 20258mo ago

OWASP releases the 2025 Top 10 application security risks list

OWASP published its 2025 Top 10 update for application security risks, a revised ranking highlighted across multiple reports and conference coverage. The update modernized the list and reflected current risk trends in software and web application security.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

OWASP Top 10 2025 Release and Key Changes | Mallory