logo

OWASP tackles AI security with new NHI Top 10: What you need to know

ID: 8a8de3dd-070c-5591-a14a-c43165382520

STIX ID: report--8a8de3dd-070c-5591-a14a-c43165382520

Feed Name: ReversingLabs Blog

Date Published: 2025-01-29

Date Updated: 2026-04-29

Author: [email protected] (John P. Mello Jr.)

...
...

This article examines OWASP’s new Non‑Human Identities (NHI) Top 10, emphasizing how machine identities (service accounts, API keys, CI/CD tokens) in AI-driven, microservice, and ephemeral environments expand the attack surface and demand standardized governance, least privilege, monitoring, and attestation. Experts spotlight common weaknesses (hardcoded credentials, excessive permissions, poor logging/observability), note the list is a strong but non-exhaustive starting point, and call for future focus on workload identities, emerging AI risks, and growing compliance requirements.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.