The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents. The two top entries – Prompt Injection and Sensitive Information Disclosure – remained constant, but the order shifted more than in past years below them: The 2025 and 2026 versions of OWASP 2026 LLM Top 10, compared (Source: OW

The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications, marking the first time the list has incorporated real-world incident data in its ranking methodology. While previous iterations relied solely on expert consensus, the 2026 list weighted practitioner votes at 75% and integrated data from 6,639 incidents, sourced from public vulnerability databases and an AI-harm database, for the remaining 25%.
This new methodology led to several shifts in the rankings compared to the 2025 list. "Prompt Injection" maintained its position as the number one risk, despite a relatively low number of recorded incidents. OWASP attributes this to a "defense effect," suggesting that extensive efforts to mitigate prompt injection attacks prevent many successful incidents from appearing in public records, thus understating the actual risk.
Conversely, "Misinformation" saw a significant jump of two places, driven primarily by the incident data, which ranked it much higher than expert votes. OWASP explained that incorrect, incomplete, or misleading outputs from LLMs can appear believable to both humans and agents, leading to system-level failures. These failures can manifest as financial losses, security incidents, safety hazards, or operational disruptions, especially as model outputs increasingly drive tool calls, code generation, system state inference, action authorization, and agent coordination.
"Excessive Agency," which describes AI systems with too much autonomous power, climbed to third place, a position supported by both expert votes and incident data indicating that agentic deployments are a significant source of damage. "Unbounded Consumption" rose four places, reflecting practitioners' increased concern over resource and cost exhaustion. "Output Handling" fell from fifth to tenth place and had its scope broadened.
"System Prompt Leakage" was renamed and expanded to "Hidden Context Exposure." Additionally, several existing categories absorbed new, sharper risks. "Prompt Injection" now encompasses cross-modal attacks embedded in images or audio, while "Data and Model Poisoning" includes fine-tuning subversion.
A central theme of the 2026 list is a shift in focus from preventing models from being fooled to controlling the blast radius when they inevitably are. OWASP emphasizes building systems around LLMs so that critical functions remain intact even if the model itself is compromised.
The project also clarified the scope of the LLM Top 10, stating that it addresses risks associated with models as components within applications. Risks related to models acting as autonomous agents with tools, memory across sessions, and downstream consequences are now covered by the OWASP Agentic Top 10.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets