🎉 Big news! Early Bird tickets for OWASP Global AppSec Vienna 2026 are here! 25 years of OWASP ✨ Stunning Vienna 🇦🇹 World-class training 🧠 & a conference like no other 🔥 Why wait? Register now for early bird pricing: https://lnkd.in/eBct6_EE #appsec #owasp #cybersecurity #ealrybird #securesoftware #securebydesign
OWASP® Foundation
Software Development
Wakefield, MA 285,514 followers
Every vibrant technology marketplace needs an unbiased source of information. OWASP is synonymous with AppSec.
About us
The Open Worldwide Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of software. Our mission is to make application security "visible," so that people and organizations can make informed decisions about application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license. The OWASP Foundation is a 501c3 not-for-profit charitable organization that ensures the ongoing availability and support for our work.
- Website
-
http://owasp.org
External link for OWASP® Foundation
- Industry
- Software Development
- Company size
- 2-10 employees
- Headquarters
- Wakefield, MA
- Type
- Nonprofit
- Founded
- 2001
Locations
-
Primary
Get directions
401 Edgewater Place
Suite 600
Wakefield, MA 01880, US
Employees at OWASP® Foundation
Updates
-
OWASP® Foundation reposted this
The 𝗢𝗪𝗔𝗦𝗣 𝗧𝗼𝗽 𝟭𝟬:𝟮𝟬𝟮𝟱 is here — the 8th edition of the Ten Most Critical Web Application Security Risks 🚨 This release reflects not just data, but real-world insight from the global AppSec community. A huge thank you to everyone who contributed data, expertise, and perspective — this wouldn’t exist without you. 𝗪𝗵𝗮𝘁’𝘀 𝗻𝗲𝘄 𝗶𝗻 𝟮𝟬𝟮𝟱: • Two new categories and one consolidation • Stronger focus on root causes over symptoms • Expanded coverage of supply chain, misconfiguration, and failure-handling risks • From Broken Access Control (#1) to the newly added Mishandling of Exceptional Conditions (#10), this edition captures how modern software complexity is reshaping security risk. If you build, ship, or secure applications — this list is still your essential baseline. Link to the playlisy - https://lnkd.in/gC-SHihU Thank you to the community for continuing to raise the bar for application security #OWASP #OWASPTop10 #AppSec #ApplicationSecurity #SoftwareSecurity #DevSecOps #CyberSecurity #SecureCoding #SecurityCommunity
-
🔥 OWASP London Training Days - Trainer Spotlight 🔥 We’re excited to welcome Avi Douglen & Kim Wuyts to the lineup, leading a 1-Day Training: Application Privacy in the Shadow of AI 🤖🔐 https://lnkd.in/eHqMa-S3 This hands-on course is a fast track to technical privacy for security professionals and system architects. If you’re building systems and care about protecting users, this one’s for you. You’ll dive into privacy engineering essentials, from understanding how personal data flows through your systems, to spotting risks (including AI-driven ones 👀), and applying practical mitigations without slowing teams down. Expect real-world examples, high-impact learning, and collaborative exercises you can apply immediately.
-
-
OWASP® Foundation reposted this
Can we fully automate threat modeling with AI—or is it just an "Automation Illusion"? Georges Bolssens and I went down the rabbit hole to find out if AI is truly the silver bullet for scaling security programs. We’ve seen the rise of LLM-powered tools like STRIDE-GPT and AI architecture generators, but our research led us to some surprising conclusions. The truth? While AI is a mighty "copilot" for handling tedious analysis, threat modeling remains a "human-centric messy process". Our key findings from the (recorded) OWASP Germany Day session: 1️⃣ The Illusion: Buying a tool doesn't solve the scaling problem; human judgment and "soft skills" remain the critical bottleneck. 2️⃣ The "H" Word: AI can "make stuff up." Human verification is the only cure for hallucinations, ensuring technical validity. 3️⃣ The Surgeon Approach: Your team needs to evolve from "security police" to "AI Strategists," letting the machine handle triage while humans focus on critical incisions. Read the full research in our latest blog post. It includes the session recording, our NEW directory of threat modeling tools, and a guide to transforming your team. Blog post - https://lnkd.in/ecs_Rg-B 👇 Check out the slides attached below. Are you experimenting with AI in your threat modeling yet? Let’s discuss in the comments! #AppSec #ThreatModeling #CyberSecurity #GenerativeAI #OWASP #Toreon
-
We’re trying something new… and we think you’ll love it! Our CFPods is officially OPEN for Global AppSec Vienna 🎉 But wait — what on earth is a POD?! 🤔 PODs (Practical On-Demand activities) are 2–3 hour, hands-on, small-group sessions that run alongside the main conference. They’re interactive, asynchronous, and practical, less sitting back, more jumping in and doing 💪 If you’ve got an idea that gets people building, breaking, testing, or learning by doing, this is your moment 👉 Want the details? Head here: https://lnkd.in/eperk4UY ⏰ CFPods closes: February 16, 2026 #appsec #owasp #CTF #cybersecurity #workshop
-
-
OWASP® Foundation reposted this
AI security isn’t a new problem it’s old risks moving faster. Today’s OWASP LA virtual session with Caroline Wong Wong reinforced a critical point: as AI systems scale, familiar failure modes like supply chain risk and poor exception handling don’t disappear they amplify. For those who want to go deeper, here are a few resources Caroline shared that connect AI security back to fundamentals: 🔹 OWASP® Foundation Top 10 (2025) https://lnkd.in/gcjDB3US 🔹 A03 – Software Supply Chain Failures https://lnkd.in/d8Kp8kDH 🔹 A10 – Mishandling of Exceptional Conditions https://lnkd.in/ey5h6ahP 🔹 OWASP® Foundation Top 10 GitHub Repo https://lnkd.in/gEt5TPjp If you’re building or securing AI enabled systems, these are the risks to revisit before automation magnifies them. Thank you to Caroline Wong for sharing insights from her upcoming book The AI Cybersecurity Handbook and grounding the AI conversation in real, actionable security fundamentals. 🎉 Congratulations to the raffle winners who received preorders of the book we hope it sparks deeper exploration into AI security. Thanks to the OWASP LA team for making this event happen Edmond Momartin , Maryam Tehrani , Martin E.
-
🎉 Vienna is calling… and AppSec is answering! Early Bird tickets for OWASP Global AppSec Vienna 2026 are officially live! https://lnkd.in/eBct6_EE Pack your curiosity (and maybe lederhosen 👀) and join us as we celebrate 25 years of OWASP with a week packed full of learning, laughs, and legendary AppSec moments. 📅 Training: June 22–24, 2026 📅 Conference: June 25–26, 2026 What’s on the menu? 🚀 Big-idea keynotes 🎯 Fresh, reimagined tracks 🛠️ OWASP Project demos 🤝 Interactive PODS 📱 MobileAppSecCon #owasp #globalappsec #appsec #cybersecurity #conference #training
-
-
Thinking about attending the OWASP London Training Days? https://lnkd.in/emcN-E-d Watch this free video to get a taste of Dawid Czagan’s training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access: https://lnkd.in/ewgmasha HTTP Parameter Pollution - Video Tutorial Access Control Lists (ACLs) are not enough today: an HTTP Parameter Pollution (HPP) attack can completely bypass authorization even if your ACL works as expected. As a consequence, an attacker can, for example, transfer money in the opposite direction and steal money from a user’s account. This clearly shows how dangerous this attack is. Dawid Czagan will show you step by step how this attack works and how to check whether your application is vulnerable. #owasp #appsec #training #cybersecurity
HTTP Parameter Pollution
https://www.youtube.com/
-
OWASP® Foundation reposted this
Join us as a vendor at the foremost application security conference in New England. Since its beginnings in 2012, OWASP BASC has reliably attracted at least 150 attendees each year. By sponsoring our event, you will have the opportunity to connect with prominent specialists in the application security sector and enhance your visibility within the OWASP Community in New England and beyond. For additional information, please visit our sponsorship kit at www.basconf.org #appsec #owasp #basc2026 #basc #applicationsecurity
-
-
OWASP® Foundation reposted this
Thank you to everyone who submitted their application for the position of Director of Corporate Relations with OWASP® Foundation. We have had an astounding 483 applicants! So many qualified and awesome people. I will be whittling the selection to the final 20 by the end of this week, and scheduling interviews for January with the final 5. Please hang in there!