
OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise
While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.

While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.

The post-mortems of two compromises by rogue AI agents show that security teams need to focus on guardrails, not the AI model.

Research into an Active Directory takeover with a single AI prompt highlights why organizations need to focus on agentic SOCs.

Traditional SBOMs, signing, and provenance all have blind spots, making them no longer capable of assuring software security.

Delaying software upgrades creates a buffer against poisoned packages, but transitive dependencies continue to be a problem.

Industry heavyweights bring new focus to vulnerabilities in the age of AI. Here’s how it might help improve security.

Threat Advisor could help teams with AI-specific risks. But a broader AppSec strategy rethink is needed in the AI era.

The Institute for Security and Technology's 'Driving AI Transparency' policy paper makes the case for AI-BOM minimum requirements.

The Magic Quadrant™ for Software Supply Chain Security is a 45-minute read. Here's what we feel security leaders need to pull from it.

With a ‘vulnpocalypse’ expected, AppSec leaders are calling for the companies to invest in a Great Refactor Fund to secure open source.

Agentic AI is moving the perimeter from components to data — and most strategies aren't built for that.

Coding agents are privileged insiders — with keys to CI/CD pipelines even as they give rise to ‘slopsquatting.’ Here’s how to govern them.

Disabling scripts by default closes the vector worms like Shai-Hulud rely on. Here's what the update fixes — and what it doesn't.

The standard connecting AI agents to tools and data leaves security to others. Make it a do-over.

OWASP's new dependency scanner gives developers actionable fixes. But supply chain attacks aren’t yet CVEs.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial