Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 341, Issue 4IT NewsAI

OWASP Updates Top 10 Security Risks for LLM Applications

SC Media, Wednesday, August 26th, 2026

OWASP's 2026 LLM Top 10 keeps prompt injection at No. 1 and adds hidden context exposure as a new risk.

The OWASP GenAI Security Project has released its 2026 Top 10 for Large Language Model Applications, updated for systems that are increasingly autonomous and embedded in enterprise workflows.

Prompt injection remains the top risk, followed by sensitive information disclosure and excessive agency, with supply chain risk, data and model poisoning, unbounded consumption, misinformation, hidden context exposure, vector and embedding weaknesses, and improper output handling filling out the list.

Hidden context exposure is new, covering system prompts and tool schemas that users were never meant to see. OWASP mapped all ten risks against nine external frameworks, including MITRE ATLAS and ATT&CK.

more →  ·  More from AI →