LIVE · cybersecurity feed
Live wire
owaspmedium

Is Your AppSec Program Built to Close the OWASP Top 10 2025 Coverage Gap?

The OWASP Top 10 2025 list introduces new vulnerabilities, particularly in API security and modern authentication flows, which many current application security programs fail to adequately address. Traditional security scanners often miss critical areas like Broken Object Level Authorization (BOLA) and Server-Side Request Forgery (SSRF) due to limitations in handling complex authentication and multi-role testing. Organizations need to adapt their security strategies to cover these evolving threats and close coverage gaps before they lead to significant remediation efforts.

zeroday.news · 26d ago

Many application security (AppSec) programs face significant gaps in their ability to cover the latest OWASP Top 10 categories, particularly those introduced or emphasized in the 2025 update. Traditional security scanners often struggle with modern authentication methods and complex API interactions, leaving critical vulnerabilities unaddressed.

A primary challenge identified is the handling of API security. While many programs treat API testing as an extension of Dynamic Application Security Testing (DAST), key categories like Broken Object Level Authorization (BOLA), Broken Function Level Authorization (BFLA), and Server-Side Request Forgery (SSRF) require authenticated, multi-role testing that standard scanners are not equipped to perform at scale. Modern authentication flows, including OAuth2, JWT validation, and multi-factor authentication (MFA) protected sessions, frequently fall outside the scope of conventional scans. This means that the specific endpoints where account takeover could occur often remain untested.

Furthermore, signature-dependent detection methods are insufficient for newer threats. Categories that the OWASP Top 10 2025 update has elevated, such as supply chain compromise, third-party script injection, and fail-open behavior, often manifest before a specific Common Vulnerabilities and Exposures (CVE) identifier or a detectable signature exists. This leaves organizations vulnerable to attacks that exploit unpatched or unknown weaknesses.

The accelerated pace of software development also contributes to coverage gaps. When full security scans take hours and risk overwhelming production environments, organizations are forced to limit scan frequency. This creates windows of exposure where misconfigurations, verbose error messages, exposed administrative interfaces, and infrastructure-as-code (IaC) drift can persist between release cycles.

Qualys's TotalAppSec platform is presented as a solution designed to address these specific challenges. It aims to provide coverage across all ten OWASP Top 10 2025 categories through a unified platform. This includes AI-powered DAST, dedicated API security testing, deep learning malware detection, and support for modern authentication mechanisms. The platform also claims to offer TruRisk prioritization to reduce alert noise, reportedly by approximately 95%.

TotalAppSec is designed to map to the OWASP Top 10 2025 categories. It is noted that A06 (Insecure Design) is a program-level discipline that no single scanner can fully own, though TotalAppSec contributes by detecting symptoms and providing risk-based views. The platform's API security capabilities, which cover approximately 600 checks for BOLA, BFLA, and other API-related issues, operate against the separate OWASP API Security Top 10 2023 standard.

In practice, TotalAppSec aims to expand visibility beyond the known attack surface by continuously discovering web applications and APIs across multi-cloud environments. This includes identifying assets through API gateways like MuleSoft, AWS API Gateway, Azure APIM, and Apigee, as well as incorporating AI and API discovery during active scans.

One customer reportedly used TotalAppSec's continuous discovery features to identify around 250 unknown web applications and 750 Swagger files. Another user scaled their AppSec coverage by 400% across a multi-team SaaS portfolio while maintaining a history of zero critical AppSec failures over more than 15 years.

The platform supports modern authentication flows, including OAuth2 and JWT, to test endpoints frequently targeted in account takeover attacks. Its deep learning detection is intended to identify threats that signature-based systems might miss, while business-risk prioritization helps teams focus on the most critical fixes.

Organizations that proactively audit their coverage gaps against the OWASP Top 10 2025 list and address discovery blind spots are expected to avoid significant remediation efforts in the future. The effectiveness of an AppSec program is increasingly being measured by its ability to align with current exploitation trends rather than just cataloging known vulnerabilities.

owaspappsecapi securityvulnerability management
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.