Issue 284: OWASP Top 10 2025, ChatGPT’s API Flaw, BOLA at Mercury Energy NZ, Leaky AI Companies
Brief
This week, we’re sharing some AI-related security news, with several reports highlighting vulnerabilities in trusted AI platforms. We also review a blog post claiming an API BOLA vulnerability at Mercury Energy New Zealand and cover a recent interview exploring a range of API security topics. First up though, news of a new OWASP Top 10 list just released.
Industry News: OWASP Top 10 2025 now available
A release candidate for the new OWASP Top 10:2025 vulnerability list is available from the OWASP website. This is the general OWASP Top 10 list, not the API-specific one. But there are a couple of notable trends that I think could also influence the next API vulnerability list.
First, Security Misconfigurations has been bumped up from #5 to #2, signaling that insecure or unexpected application behavior is increasingly caused by configuration issues rather than just coding flaws.
