Friday , June 5 2026
OWASP

OWASP Unveils Agentic AI Security Guidance

OWASP has released new guidelines for securing AI applications that use large language models. The guidance, released on July 28, provides technical recommendations for builders and developers of AI agents, particularly targeting AI/ML engineers, software developers, security experts, and AppSec professionals.

“As AI systems evolve toward more autonomous, tool-using, and multi-agent architectures, new security challenges emerge that traditional AppSec can’t handle alone. That’s why the OWASP Gen AI Security Project has published the Securing Agentic Applications Guide v1.0, the most comprehensive and actionable open source security resource yet for Agentic AI developers and defenders,” OWASP wrote on a LinkedIn post.

Cisco SD-WAN Flaw Exploited and Trend Micro Flaws Allows to Security Bypass

Trend Micro’s Deep Security Agent for Linux has a design flaw. This issue lets a local attacker, who does not...
Read More
Cisco SD-WAN Flaw Exploited and Trend Micro Flaws Allows to Security Bypass

Ransomware Crisis Deepens: 4,089 Victims Hit Across 121 Countries in 2026

According to the latest ransomware numbers from 2026, cybercrime is still a big worry worldwide. In 2026, 4,089 groups have...
Read More
Ransomware Crisis Deepens: 4,089 Victims Hit Across 121 Countries in 2026

CVE-2026-20230
Cisco Patches in Unified CM as Exploit Code Goes Public

Cisco has fixed a flaw in Unified Communications Manager that allows an attacker on the network to write files to...
Read More
CVE-2026-20230  Cisco Patches in Unified CM as Exploit Code Goes Public

1-Click GitHub Token Flaw Allows Attackers Steal Users’ OAuth Tokens

A serious security flaw in Visual Studio Code’s webview lets attackers take GitHub OAuth tokens. This includes read/write access to...
Read More
1-Click GitHub Token Flaw Allows Attackers Steal Users’ OAuth Tokens

TP-Link Router Flaw Enables Remote Command Execution Attacks

TP-Link has revealed a serious security problem in its Archer BE450 and Archer BE7200 Wi-Fi routers. This flaw could let...
Read More
TP-Link Router Flaw Enables Remote Command Execution Attacks

ALERT
Google patches one exploited Android zero-day and 124 issues

Google has shared the June 2026 Android security updates to fix 124 flaws, including one zero-day issue used in special...
Read More
ALERT  Google patches one exploited Android zero-day and 124 issues

CISA warns two-year-old Oracle Vuln as actively exploited in attacks

CISA has given a new warning about a serious Oracle WebLogic Server flaw, named CVE-2024-21182, and added it to its...
Read More
CISA warns two-year-old Oracle Vuln as actively exploited in attacks

Hackers Use Meta’s AI Bot to Take Over Instagram Accounts

Many Instagram users lost access to their accounts because attackers tricked Meta's AI support tools into thinking they were the...
Read More
Hackers Use Meta’s AI Bot to Take Over Instagram Accounts

Anthropic confirms Claude Mythos-class models will be public

Anthropic has said it will release Mythos-class models to the public. They had to delay this because of security concerns...
Read More
Anthropic confirms Claude Mythos-class models will be public

Threat Actors Fake FIFA Sites to Steal Personal Info

The FBI warned people in a Public Service Announcement Alert I-052726-PSA on May 27, 2026, that bad actors are running...
Read More
Threat Actors Fake FIFA Sites to Steal Personal Info

A new resource has been created due to the rising use of AI agents in organizations. AI agents can work independently and share data or results with other AI tools.

These tools function faster than older LLM-based systems and don’t require human prompts. They can adjust to changing environments automatically. The absence of human oversight raises serious security issues, particularly with AI applications in coding and system configuration.

Experts warn that technology will enable cybercriminals to automate more aspects of cyberattacks, including account takeovers.

Agentic AI Security Focus Areas

The OWASP guidance covers security across the full agentic AI development and deployment lifecycle.

Securing agentic architectures: The guidance highlights the importance of including security in the architecture, focusing on user permissions and authentication, such as asking for credentials when tasks require user interaction with their browser or computer.

Design and development security: This section focuses on steps to prevent AI models from being misused or behaving unexpectedly.

Enhanced security actions: Organizations are advised to add extra security tools and measures to their systems to reduce risks from AI agents, such as using OAuth 2.0 for permissions and authorization, managing identities to avoid storing passwords, and encrypting sensitive data.

Supply chain security: Organizations should reduce risks from third-party code in agentic AI by managing data access and checking for code vulnerabilities.

Assuring agentic applications: The guidance recommends conducting regular red teaming exercises to uncover vulnerabilities and potential attack vectors in agentic systems

Securing deployments: Basic security measures should be implemented in production environments to protect AI agents.

Runtime hardening: Security teams should mix standard VM security measures with specific controls like sandboxing, audit tracking, and runtime behavior monitoring

Check Also

Microsoft’s MDASH VS Anthropic’s Mythos VS OpenAI’s Daybreak

The newly launched of Microsoft MDASH, OpenAI Daybreak, and Anthropic Mythos shows a big change …