#OWASP
10 stories taggedOWASP.

Reflectiz Launches AI Agent Team That Attacks Your Website So Criminals Don't Have To First
A new platform sends four specialised AI agents to probe websites for weaknesses continuously, not just once a year. Whether that actually closes the gap between releases and real-world attacks is the right question to ask.

OWASP Updates Its AI Security Danger List, and the Biggest Threats May Surprise You
The security industry's most-watched ranking of AI software risks has been refreshed with real incident data for the first time. Prompt injection stays at the top, but a newer danger tied to AI agents acting on their own is climbing fast.

Hidden Text in Emails Can Trick AI Assistants Into Showing You Fake Numbers
Researchers planted invisible instructions inside ordinary emails and watched an AI summariser rewrite invoice amounts and meeting dates without any warning to the reader.

OWASP Publishes First Security Watchlist for AI Agent 'Skills'
A real attack in July exposed more than 300,000 users to stolen credentials through fake AI skills. Now the group behind the web's most-used security checklists has named the top ten risks, and 'malicious skills' sits at number one.

A 15-Minute Framework for Spotting What AI Systems Can Do Wrong
Security expert Adam Shostack built PHANTOM-B to help organisations find the risks hiding inside AI-powered software before those risks find them.

Why Locking Down What AI Agents Can Do Is Not Enough
A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

Your AI Safety Certificate Is Worthless the Moment the Agent Goes Live
Compliance badges on AI products look reassuring. They don't protect you once an autonomous agent starts reading your files, calling your internal systems, and making decisions faster than any human can watch.

AI Agents Are Taking Over Enterprise Systems. Nobody Knows Who They Are.
A four-hour outage. A room full of people who couldn't say which human authorized the last action. A new six-stage model explains why AI agents are breaking identity security, and what it takes to fix it.

Two-Thirds of iPhone AI Chatbot Apps Are Bleeding API Keys
A study of 444 iOS chatbot apps found 282 exposing paid model access in plaintext network traffic, sometimes with no authentication at all.

AI-SPM Is Now a Real Category. Here's Why Your Organization Probably Needs It.
More than half of enterprise AI agents run without security oversight or logging. A maturing class of AI security posture management tools exists to fix that, if you know what to look for.