OWASP
Coverage of OWASP in the Nexus archive.
- Sniff out stale AI override advice with this open source CLI
The CVE Lite CLI, an open-source tool endorsed by OWASP, helps developers scan dependencies to mitigate software supply chain attacks. Its recent update includes override auditing to address transitive dependency vulnerabilities, such as those seen in the node-ipc package incident and Shai-hulud attacks. The tool identifies broken overrides in projects like Cal.com, which had 11 ineffective override entries.
- Anthropic expanding access to Project Glasswing
Anthropic is expanding its Project Glasswing program to 150 new organizations across 15 countries, focusing on underrepresented sectors like power, water, and healthcare. The initiative, using its Claude Mythos Preview model, has already identified over 10,000 high- or critical-severity software vulnerabilities. Partners such as Cloudflare and Mozilla reported significant increases in bug discovery rates, but Anthropic emphasizes challenges in addressing these flaws due to human resource limitations.
- OWASP GenAI Security Project Gets Update, New Tools Matrix
OWASP updates its GenAI Security Project to address 21 generative AI risks, recommending combined strategies for defending GenAI and agentic AI systems. The project now includes a new tools matrix for security measures.