[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwDbzrxm_AHobFXAmD6OUiolYjy3FnRegfBAnQ4vG80I":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":45},"5603b0aa-33ba-4f9e-a6c7-678f5ca0245e","owasp-top-10-2025-update-highlights-critical-security-gaps","66c7fc55-51bb-4dcc-b07c-d983e9ac9152","OWASP Top 10 2025 Update Highlights Critical Security Gaps","The OWASP Top 10 2025 update reveals that organizations continue struggling with fundamental security controls, with Broken Access Control remaining the top risk and now explicitly including API authorization failures. The introduction of Software Supply Chain Failures as a new category reflects the growing threat from compromised dependencies and third-party components. Security Misconfiguration rising to #2 demonstrates that organizations are failing to properly secure their systems during deployment and maintenance. These findings, based on analysis of over 175,000 CVE records, emphasize the need for comprehensive security programs addressing both traditional web application risks and modern supply chain threats.","**Immediate actions:**\n- Conduct access control reviews for all web applications and APIs to identify BOLA\u002FBFLA vulnerabilities\n- Implement inventory management for all third-party components and dependencies\n- Review and harden security configurations across all web-facing systems\n\n**Long-term improvements:**\n- Establish secure coding practices that address all OWASP Top 10 categories in development lifecycle\n- Deploy automated security testing tools that can detect misconfigurations and access control flaws\n- Create supply chain security policies including vendor assessment and component monitoring\n\n**Monitoring measures:**\n- Enable logging for all access control decisions and API authorization events\n- Implement continuous vulnerability scanning for both custom code and third-party components\n- Set up alerts for configuration changes in production environments",[12,13,14,15,16,17,18],"CIS Control 3","CIS Control 12","CIS Control 16","NIST AC-3","NIST SA-15","NIST CM-6","OWASP ASVS","published","2026-06-15T16:20:14.433775+00:00","2026-06-15T16:20:14.281+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fblog.qualys.com\u002Fqualys-insights\u002F2026\u002F06\u002F15\u002Fwhat-changed-in-owasp-top-10-2025-and-recommendations-for-each-category","what-changed-in-owasp-top-10-2025-and-recommendations-for-each-category-8970ae","What Changed in OWASP Top 10 2025 and Recommendations for Each Category",[27,33,39],{"id":28,"name":29,"slug":30,"description":31,"color":32},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]