
OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise
While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.

Freelance technology writer. John's work has appeared in the The Boston Globe and Boston Herald, as well as CFO, CIO, CSO, and Inc. magazines. He is a former managing editor of the Boston Business Journal and Boston Phoenix, as well as a staff writer for Government Security News.
find John P. Mello Jr. on:

While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.

Research into an Active Directory takeover with a single AI prompt highlights why organizations need to focus on agentic SOCs.

Traditional SBOMs, signing, and provenance all have blind spots, making them no longer capable of assuring software security.

AI coding requires the stack be reconstructed with mathematical proofs built in — a task well suited to the Lean language. Here’s the reality.

Delaying software upgrades creates a buffer against poisoned packages, but transitive dependencies continue to be a problem.

A new report finds weakening trust in AI-only testing — and more willingness to keep humans in the loop. Here's why.

Industry heavyweights bring new focus to vulnerabilities in the age of AI. Here’s how it might help improve security.

While this repository vector is not new, researchers have uncovered a new twist for exploiting trusted metrics to hide malicious code.

The Life and Times of Cybersecurity Professionals study highlights a trend that has accelerated as cyber has become more complex.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial