Skip to content

#011 — OWASP Top 10:2025

Stream #011

Date: July 24, 2026 | 19:00 London / 21:00 Kyiv
Format: Guest talk · technical deep-dive · ~75–90 minutes
Guest: Oleksandr Blazheiko
YouTube: https://youtube.com/live/pUNYHsXrT6g

Participants

Oleksandr Blazheiko — Software Development Engineer · Fullstack
Ukraine
LinkedIn · itvibe.party

What we'll cover

The official OWASP Top 10 just got its 2025 update. Oleksandr Blazheiko walks through all 10 risk categories, each with a real vulnerable code example.

What's new in 2025

  • A01 Broken Access Control — still holds #1
  • A03 Software Supply Chain Failures — new, expanded category (Shai-Hulud npm case)
  • A10 Mishandling of Exceptional Conditions — a brand-new category

All 10 categories

A01 Broken Access Control (+ JWT alg:none attack, GraphQL access control), A02 Security Misconfiguration, A03 Software Supply Chain Failures, A04 Cryptographic Failures, A05 Injection, A06 Insecure Design, A07 Authentication Failures, A08 Software or Data Integrity Failures, A09 Security Logging & Alerting Failures, A10 Mishandling of Exceptional Conditions

Key takeaways

Added after the stream.

Timecodes

Added after the stream.

Resources

IT Friday · @zloyleva