To remain relevant and address emerging threats, leading security frameworks routinely update their guidelines and best practices. The OWASP Top 10 is no exception – it evolves to reflect the most critical risks facing modern applications. The latest update, announced as a Release Candidate (RC1) in November 2025, introduces significant changes aligned with today’s software reality. While this RC is not yet final, OWASP has confirmed that only minor refinements are expected before publication. What follows is an overview of the updates in the OWASP Top 10:2025 and how these changes reflect today’s threat landscape.
The OWASP Top 10 has always been the benchmark for application security priorities. The 2025 RC1 marks a turning point: while traditional flaws like Broken Access Control and Injection remain, the list now emphasizes systemic and ecosystem-level risks.
Key changes include:
This evolution signals that application security is no longer just about fixing bugs – it’s about safeguarding the entire software lifecycle. While secure design and supply chain integrity have long been promoted as best practices, the ubiquity and adherence to the OWASP Top 10 mean these priorities are now effectively required by this updated standard. Organizations must adopt a holistic approach that integrates security into design, development, deployment, and operations to stay aligned with this new reality.
Organizations can no longer rely on patching vulnerabilities after deployment; they need proactive strategies that address risk across the entire software lifecycle. These four realities explain why the latest OWASP changes matter:
UltraViolet Cyber delivers a unified security platform combining Managed Detection and Response (MDR), vulnerability management, penetration testing, and red teaming – and with our August 2025 acquisition of Black Duck’s Application Security Testing (AST) team, we’ve greatly expanded our expertise in SAST, DAST, SCA, DevSecOps engineering, and security consulting.
By integrating deep AST expertise with our existing offensive and defensive capabilities, UltraViolet Cyber helps organizations address the OWASP 2025 shift head-on – from code-level vulnerabilities to ecosystem-wide risk.
The OWASP Top 10 for 2025 makes one thing clear: security must extend beyond code to the systems that build and run it. UltraViolet Cyber helps organizations embrace this reality by combining enhanced application security expertise with unified security operations. Together, these capabilities deliver measurable risk reduction across the entire software lifecycle.