Whitepapers/Guides

Whitepapers

Resources

OWASP GenAI LLM Top 10 2026

OWASP Top 10 for LLM Applications 2026 is the latest community-driven guide to the most critical security risks facing applications powered by large language models. Developed by hundreds of AI security experts, this edition introduces updated rankings, expanded threat coverage, and new research grounded in thousands of real-world AI security incidents. The guide provides practical […]

OWASP GenAI LLM Top 10 2026 Read Post »

Resources

Solutions Landscape – Red Teaming Taxonomy

  This document serves as the foundational taxonomy for the AI and Agentic Red Teaming Solutions Guide. It establishes a common language and structured classification of capabilities across red, blue, and purple teaming, organized by practitioner lifecycle stages. The taxonomy is intended to support companion solutions guides and cheat sheets that map, in detail, how

Solutions Landscape – Red Teaming Taxonomy Read Post »

Resources

State of Agentic AI Security and Governance 2.01

The State of Agentic AI Security and Governance provides a comprehensive view of today’s landscape for securing and governing autonomous AI systems. It explores the frameworks, governance models, and global regulatory standards shaping responsible Agentic AI adoption. Designed for developers, security professionals, and decision-makers, the report serves as a practical guide for navigating the complexities

State of Agentic AI Security and Governance 2.01 Read Post »

Resources

AIUC-1: Crosswalks OWASP Top 10 For Agentic Applications

The AIUC-1 Crosswalk of the OWASP Top 10 for Agentic Applications provides a bidirectional mapping between AIUC-1 requirements and the OWASP Agentic Security Initiative’s Top 10 risks for autonomous and agentic AI systems. It helps organizations understand how AIUC-1 controls align with threats such as agent goal hijacking, tool misuse, identity and privilege abuse, memory

AIUC-1: Crosswalks OWASP Top 10 For Agentic Applications Read Post »

Resources

OWASP GenAI Data Security Risks & Mitigations 2026

The OWASP GenAI Data Security Risks and Mitigations 2026 guide provides a critical, forward-looking analysis of the unique data security challenges posed by the rapid, widespread adoption of Generative AI (GenAI) across enterprise environments, anticipating the landscape by 2026. This comprehensive guide moves beyond traditional software security paradigms to address the novel attack surfaces that

OWASP GenAI Data Security Risks & Mitigations 2026 Read Post »

Resources

A Practical Guide for Secure MCP Server Development

A Practical Guide for Secure MCP Server Development provides actionable guidance for securing Model Context Protocol (MCP) servers—the critical connection point between AI assistants and external tools, APIs, and data sources. Unlike traditional APIs, MCP servers operate with delegated user permissions, dynamic tool-based architectures, and chained tool calls, increasing the potential impact of a single

A Practical Guide for Secure MCP Server Development Read Post »

Resources

OWASP Vendor Evaluation Criteria for AI Red Teaming Providers & Tooling v1.0

Vendor Evaluation Criteria for AI Red Teaming Providers & Tooling is a practical guide for organizations assessing vendors that offer AI red teaming services or automated testing tools. Developed under the OWASP GenAI Security Project, the document outlines clear criteria for evaluating both simple GenAI systems (such as chatbots and RAG applications) and advanced systems

OWASP Vendor Evaluation Criteria for AI Red Teaming Providers & Tooling v1.0 Read Post »

Resources, Publications

OWASP Top 10 for Agentic Applications for 2026

The OWASP Top 10 for Agentic Applications 2026 is a globally peer-reviewed framework that identifies the most critical security risks facing autonomous and agentic AI systems. Developed through extensive collaboration with more than 100 industry experts, researchers, and practitioners, the list provides practical, actionable guidance to help organizations secure AI agents that plan, act, and make decisions across complex workflows. By distilling a broad ecosystem of OWASP GenAI Security guidance into an accessible, operational format, the Top 10 equips builders, defenders, and decision-makers with a clear starting point for reducing agentic AI risks and supporting safe, trustworthy deployments.

OWASP Top 10 for Agentic Applications for 2026 Read Post »

Resources, Publications

OWASP GenAI Security Project – Solutions Reference Guide Q2_Q3’25

The OWASP GenAI Security Project – Solutions Reference Guide (Q2–Q3 2025) is a comprehensive, vendor-agnostic resource for organizations seeking to secure Large Language Models (LLMs) and Agentic AI applications. It extends the OWASP Top 10 for LLMs and the Agentic Risks and Mitigations Taxonomy by mapping identified risks to practical, open-source and commercial security solutions.

OWASP GenAI Security Project – Solutions Reference Guide Q2_Q3’25 Read Post »

Resources

CheatSheet – A Practical Guide for Securely Using Third-Party MCP Servers 1.0

The Practical Guide for Securely Using Third-Party MCP Servers from the OWASP GenAI Security Project provides a detailed framework for safely deploying and managing external Model Context Protocol (MCP) servers. It outlines the unique security risks introduced by connecting AI models to third-party tools and data sources, including tool poisoning, prompt injection, memory poisoning, and

CheatSheet – A Practical Guide for Securely Using Third-Party MCP Servers 1.0 Read Post »

Scroll to Top

CheatSheet – A Practical Guide for Securely Using Third-Party MCP Servers 1.0