07/11/2025
The OWASP Top 10 (2025) Just Released !!
The OWASP Foundation has released its 8th official update, the OWASP Top 10:2025 (Release Candidate 1). This update redefines the most critical web application security risks in today’s digital landscape.
Read the full report :
2025 RC1 — Official Introduction : https://owasp.org/Top10/2025/0x00_2025-Introduction/
────────────────────────────
What’s Changed Since 2021
The 2025 edition shifts its focus from surface-level vulnerabilities to the root causes of insecurity. It goes beyond code-level flaws to include risks in processes, dependencies, and overall system design.
• Broken Access Control remains at number one and now includes Server-Side Request Forgery (SSRF).
• Security Misconfiguration rises from number five to number two, reflecting challenges in complex cloud and container environments.
• Injection drops from number three to number five as more secure frameworks reduce traditional attack vectors.
• Cryptographic Failures and Insecure Design move down slightly, showing gradual improvement in these areas.
────────────────────────────
New in 2025
• A03: Software Supply Chain Failures — an expanded category that covers risks in third-party dependencies, build systems, and CI/CD pipelines.
• A10: Mishandling of Exceptional Conditions — a new category that addresses poor error and exception handling, which can expose sensitive data or disrupt systems.
────────────────────────────
What’s Been Removed
• Vulnerable and Outdated Components have merged into Software Supply Chain Failures to reflect modern dependency-driven risk.
• SSRF has been consolidated under Broken Access Control due to similar exploitation methods.
────────────────────────────
Why It Matters
The OWASP Top 10:2025 reminds us that security today goes beyond writing secure code. Modern threats exist in configurations, pipelines, and dependencies. Every part of the ecosystem must be secured.
At TARAXON, we have adjusted our pe*******on testing, secure code review, and continuous QA frameworks to meet the OWASP 2025 standards and help businesses stay ahead of evolving threats.
Security isn’t just a tool; it’s a way of thinking.
────────────────────────────
www.taraxon.com
[email protected]