HomeSecuritySoftware supply chain risks added to OWASP Top 10 list

Software supply chain risks added to OWASP Top 10 list

Software supply chain failures and poor handling of exceptional conditions are some of the additions to the updated OWASP Top 10, a list of the top web application vulnerabilities. Most of the list has remained unchanged since 2021. In fact, the top item, access control failure, has been on the Open Worldwide Application Security Project's list since its first edition in 2003.

See also: AI strengthens the attack chain in AWS environments

OWASP Top 10
Software supply chain risks added to OWASP Top 10 list

“Everyone is trying to create their own authentication and access control mechanisms,” says Jeff Williams, CTO and co-founder of Contrast Security.

Williams created the list and served as chair of the OWASP board for eight years. There are standard mechanisms out there, but most applications have specialized needs, he says. “I’ve seen some really horrible machines that people have built to do access controls, and they don’t build them elegantly. They build them piece by piece—and they build their own access control. And almost no one tests the access control.”

A typical web application can have a hundred access points, Williams says, each of which can be accessed by a number of different roles. Artificial intelligence didn’t make the top ten list, but it was included in a “next steps” section of topics that are on the cusp of inclusion, in addition to lack of application resilience and memory management failures.

This AI category is titled: X03:2025 Inappropriate Trust in AI-Generated Code ('Vibe Coding'). "While we had no data to support the fact that AI-generated code poses significantly more risk than human-written code, thanks to community feedback, professional experience, and the ongoing online sharing of such data, we felt it was prudent to add a section," says Tanya Janca, lead author of the OWASP Top 10 list.

Developers should read and fully understand AI-generated code before committing it, he says. The OWASP Top 10 list is based on a combination of security data from a dozen different organizations, covering nearly 3 million applications, as well as a survey of 221 security experts, says security metrics expert Aram Hovsepyan, CEO of Codific and an OWASP member.

See also: Shai-Hulud & Co.: The software supply chain as a weakness

Software supply chain risks added to OWASP Top 10 list
Software supply chain risks added to OWASP Top 10 list

OWASP Top 10:

  • Access control failure. When applications fail to properly enforce restrictions on what authenticated users are allowed to do, allowing attackers to access unauthorized functionality or data.
  • Security misconfiguration. Security settings are not properly defined, implemented, or maintained, leaving systems exposed to attack.
  • Software supply chain failures. Attackers compromise software during manufacturing, distribution, or updates to introduce malicious code that is distributed across multiple organizations.
  • Encryption failures. Applications fail to properly protect sensitive data through encryption or use weak or broken encryption algorithms.
  • Injection. Untrusted data is submitted as part of a command or query, tricking the application into executing unwanted commands or accessing unauthorized data.
  • Insecure design. Security was not properly considered during the application design phase, resulting in the lack or ineffectiveness of controls.
  • Authentication failures. Applications fail to properly authenticate users or protect authentication credentials and session tokens.
  • Software or data integrity failures. Applications fail to maintain trust boundaries and verify the integrity of software, code, and data.
  • Security logging and alerting failures. Applications fail to log security-related events or notify security teams when suspicious activities occur.

See also: Supply Chain Threat Protection: New security solution from SpyCloud

UNC2465 - DarkSide- supply chain attack
Software supply chain risks added to OWASP Top 10 list
  • Poor exception handling. Applications fail to properly handle errors, edge cases, and abnormal conditions, leading to security vulnerabilities.
Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS