OWASP tackles AI security with new NHI Top 10: What you need to know
ID: 8a8de3dd-070c-5591-a14a-c43165382520
STIX ID: report--8a8de3dd-070c-5591-a14a-c43165382520
Feed Name: ReversingLabs Blog
Date Published: 2025-01-29
Date Updated: 2026-04-29
Author: [email protected] (John P. Mello Jr.)
This article examines OWASP’s new Non‑Human Identities (NHI) Top 10, emphasizing how machine identities (service accounts, API keys, CI/CD tokens) in AI-driven, microservice, and ephemeral environments expand the attack surface and demand standardized governance, least privilege, monitoring, and attestation. Experts spotlight common weaknesses (hardcoded credentials, excessive permissions, poor logging/observability), note the list is a strong but non-exhaustive starting point, and call for future focus on workload identities, emerging AI risks, and growing compliance requirements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
