The Open Worldwide Application Security Project (OWASP) has launched a comprehensive initiative to address the security risks associated with agentic and autonomous AI systems. This includes the release of the "Top 10 for Agentic Applications 2026," a globally peer-reviewed framework that identifies the most critical security risks for these AI systems, along with an AI testing guide and a dynamic web-based vulnerability assessment tool. The framework highlights risks such as agent goal hijack and tool misuse, providing organizations with actionable mitigation recommendations and practical tools to secure their AI deployments.
These efforts come as industries, particularly financial services, face increasing threats from generative and agentic AI, which can accelerate attack timelines and introduce new vectors such as deepfake-driven fraud and rapid ransomware campaigns. The OWASP initiative aims to equip security teams with the necessary resources to proactively address these evolving risks, emphasizing the importance of embedding security into AI systems from the outset and keeping pace with the rapidly changing threat landscape.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks published guidance highlighting the growing AI-cybersecurity risks facing financial services and advocating a Secure AI by Design approach. The roadmap covers securing external AI tools, infrastructure, applications, and agents, while emphasizing governance and board oversight.
The OWASP Foundation released a new set of AI security resources focused on agentic and autonomous AI systems, including the Top 10 for Agentic Applications 2026, an AI Testing Guide, and the AI Vulnerability Scoring System (AIVSS). The materials aim to standardize how organizations identify, test, and prioritize AI-specific security risks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.