Articles
Introduction - OWASP Top 10:2025
The 2025 refresh of the industry's baseline security checklist, and the shift in framing is the interesting part: less a list of individual bugs to patch, more a set of root causes — insecure design, supply chain failures, mishandling of exceptional conditions — that produce those bugs in the first place. Worth reading as a gut-check on process, not just as a scanner ruleset, especially the expanded supply-chain category given how much of a modern stack you don't actually write yourself. The baseline every engineer building anything internet-facing should know cold.