We improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10

Global
🐶 Come and get some serious puppy therapy at our Puppy Lounge courtesy of @depthfirstlabs! 🐾❤️ Take a moment to switch off, recharge, and enjoy some very good cuddles during Global AppSec US. And the best part? These adorable pups are all looking for their forever homes and are fully adoptable! 🏡🐕 📍 Expo Hall, Pacific Concourse Add a visit to your agenda! 😍 owaspglobalappsecusa2026.sch… #GlobalAppSecSanFran26 #GlobalAppSec26
2
8
2,156
We are proud to support ICCC26, the 25th International Common Criteria Conference, taking place Next week, 28 September–1 October 2026 at Cardo Roma in Rome, Italy. ICCC brings together cybersecurity certification leaders from government, industry, certification schemes, laboratories, standards organizations, and the product security community to address Common Criteria, EUCC, the U.S. Cyber Trust Mark, and an expanding global compliance landscape. Learn more and register: iccconference.org/ #ICCC26 #CommonCriteria #CybersecurityCertification #CyberCompliance
2
7
3,729
OWASP® Foundation retweeted
We released a new version of #OWASP #Wrongsecrets ! With devcontainer and AI related challenges. Try it out at wrongsecrets.com/ and give the repo a ⭐️ if you like it!
2
7
911
🔥 OWASP Jeopardy is coming to Global AppSec USA! We’re looking for teams of 3 to battle it out. Think you’ve got what it takes? Get ready to put your AppSec knowledge to the test on Thursday, November 5, 4:30–5:30 pm at Global AppSec USA in San Francisco! Bring the energy, bring your team, and show us what you know! 🏆 👥 Grab two teammates and get involved! owasp.wufoo.com/forms/z1oswm… #GlobalAppSecSanFran26 #GlobalAppSec26 #OWASP #AppSec
2
2
10
3,365
🔍 What if security scanners had a better way to prove what they can actually find? That’s the idea behind OWASP VulnerableApp: building a benchmark designed to help evaluate the next generation of security scanners against realistic, intentionally vulnerable applications. Curious how it works and what the team is building? Read Karan Preet Singh Sasan's blog 👇 owasp.org/news/owasp-vulnera… #OWASP #AppSec #Cybersecurity #SecurityTesting
3
2
15
3,954
OWASP® Foundation retweeted
Detecting the🤖 is only half the battle. Can you prove the app is real? Join us Wed 9/23 to hear a talk by Mark Mazur where he explains "can this application be trusted at all?" 👉 RSVP: luma.com/ik2qe9ji #OWASP #AppSec #MobileSecurity #APIsecurity #AIagents #Cybersecurity
1
2
982
Opening and Closing Remarks 🎤 Vandana Verma Sehgal @infosecvandana 🗓 Sep 22 | 3:30 PM–3:45 PM PDT 📺 piped.video/owaspglobal #OWASP25 #OWASPCommunity #OpenSourceSecurity #AppSec
1
4
2,876
Securing Distributed Systems with Privacy-Aware Governance and ML Controls 🎤 Projjal Kumar Ghosh 🗓 Sep 22 | 2:45 PM–3:30 PM PDT 📺 piped.video/owaspglobal #OWASP25 #PrivacyEngineering #DistributedSystems #MachineLearning #DataGovernance
1
4
2,477
What happens when an AI assistant retrieves an attacker-controlled document and treats it as trusted knowledge? 🎤 Anjali S 🗓 Sep 22 | ⏰ 2:45 PM–3:30 PM PDT 📺 piped.video/owaspglobal #OWASP25 #RAGSecurity #AIPoisoning #LLMSecurity #AISecurity
2
2
1,983
AMMF: Attention-Driven Multi-Feature Fusion for Scalable Cross-Architecture Binary Vulnerability Detection 🎤 Akshaya Jayaram 🗓 Sep 22 | 2:00 PM–2:45 PM PDT 📺 piped.video/owaspglobal #OWASP25 #BinarySecurity #VulnerabilityResearch #MachineLearning #SoftwareSupplyChain
1,626
The demo worked. Production added customer data, costly actions, token loops, and consequences. 🎤 Morgan Willis 🗓 Sep 22 | ⏰ 2:00 PM–2:45 PM PDT 📺 piped.video/owaspglobal #OWASP25 #AgenticAI #CloudSecurity #ResponsibleAI #AISecurity
2
3
2,031
A security agent producing the right answer once does not prove it can survive a real workflow. 🎤 Mudita Khurana 🗓 Sep 22 | ⏰ 1:15 PM–2:00 PM PDT 📺 piped.video/owaspglobal #OWASP25 #SecurityAgents #AgenticAI #AIEngineering #AppSec
1
2
2,333
Building, Owning, and Securing Private AI Infrastructure 🎤 Anant Shrivastava 🗓 Sep 22 | 1:15 PM–2:00 PM PDT 📺 piped.video/owaspglobal #OWASP25 #PrivateAI #AISecurity #LLMSecurity #InfrastructureSecurity
2,033
A plugin installed once can remain trusted long after its code, dependencies, or behaviour have changed. 🎤 Sheshananda Reddy Kandula 🗓 Sep 22 | ⏰ 11:30 AM–12:15 PM PDT 📺 piped.video/owaspglobal #OWASP25 #MCPSecurity #SupplyChainSecurity #AgenticAI #AppSec
1
1
2
2,092
How a Clean Security Audit Became a Breach Notification Six Months Later 🎤 Advait Patel 🗓 Sep 22 | 11:30 AM–12:15 PM PDT 📺 piped.video/owaspglobal #OWASP25 #CloudSecurity #IAM #SecurityAudit #DevSecOps
1,786
OWASP Cornucopia: Gamifying AI Threat Modeling and Security Requirement Analysis 🎤 Johan Sydseter 🗓 Sep 22 | 10:45 AM–11:30 AM PDT 📺 piped.video/owaspglobal #OWASP25 #OWASPCornucopia #ThreatModeling #AppSec #AISecurity
1
1,375
An AI agent should work for you, not quietly become your newest data-leak channel. 🎤 Ihor Sasovets 🗓 Sep 22 | ⏰ 10:45 AM–11:30 AM PDT 📺 piped.video/owaspglobal #OWASP25 #AgenticAI #AISecurity #DataProtection #Pentesting
1
1
5
2,645
An SBOM can tell you what is inside your software. But when AI enters the system, code is only part of the story. 🎤 Anitha Dakamarri 🗓 Sep 22 | ⏰ 10:00 AM–10:45 AM PDT 📺 piped.video/owaspglobal #OWASP25 #AIBOM #SBOM #AISecurity #SoftwareSupplyChain
1
2
1,617
From Silos to Alliances: Cryptographic Threat Hunting in OT Environments 🎤 Ahmed Elmesiry 🗓 Sep 22 | 10:00 AM–10:45 AM PDT 📺 piped.video/owaspglobal #OWASP25 #OTSecurity #ThreatHunting #Cryptography #CyberSecurity
3
2,207
Keynote: Capability Isn't Delegability 🎤 Caroline Wong 🗓 Sep 22 | 9:00 AM–10:00 AM PDT 📺 piped.video/owaspglobal #OWASP25 #OWASP #AISecurity #ResponsibleAI #ApplicationSecurity
1
1
3,302