LIVE · cybersecurity feed
Live wire
vendor

Owasp

2 CVEs published in the last four months and 4 stories. Exploited flaws first.

Critical0
High2
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-527478.6highmodsecurityModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx.92d ago
CVE-2026-422687.5highmodsecurityModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx.151d ago

Filter the full tracker by Owasp →

Our coverage of Owasp

security

OWASP Noir: Open-source static analysis tool

OWASP has released Noir, a new open-source static analysis tool designed to inventory application endpoints. Unlike dynamic application security testing (DAST) tools, which interact with a running application, Noir analyzes source code directly to identify all exposed paths, HTTP methods, parameters, headers, and cookies, linking each to its originating file and line number. This approach…

ai

OWASP Flags Top AI Skill Risks in New Security Blueprint

The Open Worldwide Application Security Project (OWASP) has released a new security blueprint that identifies the top ten security risks associated with artificial intelligence (AI) skills. This new list is designed to address the unique security challenges presented by the increasing integration of AI capabilities into applications and systems. A key component of this blueprint is the…

ai

OWASP 2026 LLM Top 10: “The model will be fooled”

The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications, marking the first time the list has incorporated real-world incident data in its ranking methodology. While previous iterations relied solely on expert consensus, the 2026 list weighted practitioner votes at 75% and integrated data from 6,639 incidents, sourced from public vulnerability databases…

owasp

Is Your AppSec Program Built to Close the OWASP Top 10 2025 Coverage Gap?

Many application security (AppSec) programs face significant gaps in their ability to cover the latest OWASP Top 10 categories, particularly those introduced or emphasized in the 2025 update. Traditional security scanners often struggle with modern authentication methods and complex API interactions, leaving critical vulnerabilities unaddressed.