Uploaded December 2025 | Updated September 2026, 2 weeks ago
The CycloneDX standard continues to evolve to meet the increasing demands of software transparency, AI accountability, and supply chain security. Version 1.7 introduces targeted improvements including improvements for cryptographic assets, and added support for patents and TLP. But 2.0 is a major architectural shift: a modular, model-driven approach designed to increase reuse, expressiveness, and long-term maintainability.
This session will walk through the new capabilities introduced in CycloneDX 1.7 and preview the roadmap to 2.0. We'll discuss practical benefits for tool developers and adopters, explain how the new model structure works, and offer guidance for preparing for the transition. Whether you're building SBOM tooling, managing compliance, or contributing to the standard, this talk will equip you with the latest and next directions for CycloneDX.
Steve Springett
ServiceNow
Creator of OWASP Dependency-Track and Chair of CycloneDX SBOM Core Working Group and Ecma TC54
Chicago
about.me/stevespringett
linkedin.com/in/stevespringett
Managed by the OWASP® Foundation
owasp.org
The CycloneDX standard continues to evolve to meet the increasing demands of software transparency, AI accountability, and supply chain security. Version 1.7 introduces targeted improvements including improvements for cryptographic assets, and added support for patents and TLP. But 2.0 is a major architectural shift: a modular, model-driven approach designed to increase reuse, expressiveness, and long-term maintainability.
This session will walk through the new capabilities introduced in CycloneDX 1.7 and preview the roadmap to 2.0. We'll discuss practical benefits for tool developers and adopters, explain how the new model structure works, and offer guidance for preparing for the transition. Whether you're building SBOM tooling, managing compliance, or contributing to the standard, this talk will equip you with the latest and next directions for CycloneDX.
Steve Springett
ServiceNow
Creator of OWASP Dependency-Track and Chair of CycloneDX SBOM Core Working Group and Ecma TC54
Chicago
about.me/stevespringett
linkedin.com/in/stevespringett
Managed by the OWASP® Foundation
owasp.org








![OWASP Mobile Application Security (MAS) - Sven Schleier, Carlos Holguera
[This version has the sound fixed from Zoom]
In this talk, Carlos Holguera and Sven Schleier, the OWASP Mobile Application Security (MAS) Project Leaders, will take a hands-on look at some of the latest OWASP MAS developments, in particular the new MASWE (Mobile Application Security Weakness Enumeration). This talk will introduce the concepts of weaknesses, atomic tests and demos that are the basis of the upcoming MASTG v2. Attendees will gain practical knowledge through detailed examples that show the journey from definition to implementation using both static and dynamic analysis techniques available in MASTG. In addition, discover the newly developed MAS test apps designed to streamline research and improve the development of robust MAS tests. Dont miss this opportunity to improve your mobile app security skills and make your apps hack-proof. Whether youre looking to bolster your defenses or learn how to uncover vulnerabilities, this session will provide you with the cutting-edge resources you need to stay ahead in mobile security!
-
Managed by the OWASP® Foundation
https://owasp.org/ OWASP Mobile Application Security (MAS) - Sven Schleier, Carlos Holguera](https://i.ytimg.com/vi/Vgj5VqQaRho/mqdefault.jpg)

