OWASP has released the Subtractive Security Top 10 Project, a new security engineering framework that prioritizes removing attacker pathways over adding more detection tooling. The project defines a defense hierarchy of Delete > Constrain > Monitor, urging organizations to eliminate unnecessary access, services, trust relationships, privileges, protocols, and exposed systems before relying on monitoring for residual risk. OWASP says the approach is designed to reduce opportunities for initial access, lateral movement, privilege escalation, and persistence across enterprise environments.
The project also introduces Path Erasure Rate (PER), a metric intended to measure how many adversary-accessible attack paths have been structurally removed. OWASP has published the guidance in a public GitHub repository under the Apache 2.0 license, with platform-specific hardening standards covering environments including Windows, Linux, Active Directory, AWS, Microsoft 365, networks, IoT, macOS, applications, data stores, CI/CD pipelines, HPC, and AI infrastructure, and says additional standards are planned.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
OWASP made the Subtractive Security Top 10 Project available in a public GitHub repository as an open-source initiative under the Apache License 2.0. The project introduces a framework centered on eliminating or constraining attack paths and defines the Path Erasure Rate (PER) as its measurement model.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.