Uploaded December 2025 | Updated September 2026, 1 week ago
Presentation sides: static.sched.com/hosted_files/owaspglobalappsecusa2025/35/DC2025%20-%20OWASP%20Top%20Ten%202025.pptx
The OWASP Top 10:2025 provides an updated view of modern applications' most common and impactful security risks. Based on both industry data and community survey input, the Top 10 is designed as an awareness tool, helping teams baseline the most relevant security concerns. This talk will walk through the changes since the 2021 edition, highlighting where categories have shifted, merged, or expanded to reflect the changes over the last four years. Each risk category will be introduced at a high level, covering its main issues and offering context for how organizations can use the list as a reference point in their security programs.
Tanya Janca
Victoria, Canada
twitter.com/shehackspurple
linkedin.com/in/tanya-janca
Tanya Janca, aka SheHacksPurple, is the best-selling author of 'Alice and Bob Learn Secure Coding', 'Alice and Bob Learn Application Security’ and the ‘AppSec Antics’ card game. Over her 28-year IT career she has won countless awards (including OWASP Lifetime Distinguished Member and Hacker of the Year), spoken all over the planet, and is a prolific blogger. Tanya has trained thousands of software developers and IT security professionals, via her online academies (We Hack Purple and Semgrep Academy), and her live training programs. Having performed counter-terrorism, led security for the 52nd Canadian general election, developed or secured countless applications, Tanya Janca is widely considered an international authority on the security of software.
Neil Smithline
Neil Smithline has been an OWASP Top 10 Co-Leader since 2016, driving development of the globally recognized security standard through multiple release cycles. With 25 years in application security, he has created numerous application security programs at companies ranging from startups to well-established enterprises.For the past 7 years, Neil has been focusing on running security programs for cryptocurrency companies. He created and led the security program at the Poloniex cryptocurrency exchange and is now contracting as the lead for two startup crypto companies.
Brian Glas
Union University
Department Chair and Assistant Professor of Computer Science and Cybersecurity
Jackson, TN
pgsecurityadvisors.com/blog
twitter.com/infosecdad
Brian Glas has worked in IT for 25 years and in information/application security for the last two decades. He started as an enterprise Java developer, then transitioned to helping build an application security program as both tech lead and manager. He later played the role of enterprise architect and did a little incident response and reverse engineering malware for fun. Glas then spent a number of years as a consultant helping clients build AppSec programs, create/update SDLCs, and other related initiatives. He has worked on the Trustworthy Computing team at Microsoft and is now chair and assistant professor of Computer Science at Union University, building and reimagining the Computer Science and Cybersecurity programs. He has also been a co-lead for SAMM v1.1-2.0+ and the OWASP Top 10 since 2017, along with helping develop the RABET-V program to assess non-voting election technology.
Managed by the OWASP® Foundation
owasp.org
Presentation sides: static.sched.com/hosted_files/owaspglobalappsecusa2025/35/DC2025%20-%20OWASP%20Top%20Ten%202025.pptx
The OWASP Top 10:2025 provides an updated view of modern applications' most common and impactful security risks. Based on both industry data and community survey input, the Top 10 is designed as an awareness tool, helping teams baseline the most relevant security concerns. This talk will walk through the changes since the 2021 edition, highlighting where categories have shifted, merged, or expanded to reflect the changes over the last four years. Each risk category will be introduced at a high level, covering its main issues and offering context for how organizations can use the list as a reference point in their security programs.
Tanya Janca
Victoria, Canada
twitter.com/shehackspurple
linkedin.com/in/tanya-janca
Tanya Janca, aka SheHacksPurple, is the best-selling author of 'Alice and Bob Learn Secure Coding', 'Alice and Bob Learn Application Security’ and the ‘AppSec Antics’ card game. Over her 28-year IT career she has won countless awards (including OWASP Lifetime Distinguished Member and Hacker of the Year), spoken all over the planet, and is a prolific blogger. Tanya has trained thousands of software developers and IT security professionals, via her online academies (We Hack Purple and Semgrep Academy), and her live training programs. Having performed counter-terrorism, led security for the 52nd Canadian general election, developed or secured countless applications, Tanya Janca is widely considered an international authority on the security of software.
Neil Smithline
Neil Smithline has been an OWASP Top 10 Co-Leader since 2016, driving development of the globally recognized security standard through multiple release cycles. With 25 years in application security, he has created numerous application security programs at companies ranging from startups to well-established enterprises.For the past 7 years, Neil has been focusing on running security programs for cryptocurrency companies. He created and led the security program at the Poloniex cryptocurrency exchange and is now contracting as the lead for two startup crypto companies.
Brian Glas
Union University
Department Chair and Assistant Professor of Computer Science and Cybersecurity
Jackson, TN
pgsecurityadvisors.com/blog
twitter.com/infosecdad
Brian Glas has worked in IT for 25 years and in information/application security for the last two decades. He started as an enterprise Java developer, then transitioned to helping build an application security program as both tech lead and manager. He later played the role of enterprise architect and did a little incident response and reverse engineering malware for fun. Glas then spent a number of years as a consultant helping clients build AppSec programs, create/update SDLCs, and other related initiatives. He has worked on the Trustworthy Computing team at Microsoft and is now chair and assistant professor of Computer Science at Union University, building and reimagining the Computer Science and Cybersecurity programs. He has also been a co-lead for SAMM v1.1-2.0+ and the OWASP Top 10 since 2017, along with helping develop the RABET-V program to assess non-voting election technology.
Managed by the OWASP® Foundation
owasp.org









