OWASP Top 10

Welcome to the Rootsec blog — your source for in-depth cybersecurity insights. Explore our articles and reports to stay on top of the latest industry news, deep technical analysis and expert views on emerging trends and technologies. Stay one step ahead with content written for professionals and cybersecurity enthusiasts alike.

Filter by category

post image
What Is Cross-Site Scripting (XSS)? | Rootsec

Cross-site scripting, or XSS, is a type of attack where injection plays the leading role. Attackers inject malicious scripts into websites and...

post image
Vulnerable and Outdated Components Explained | Rootsec

That is quite a mouthful for a single category of weakness, but it earns its place. In the original OWASP Top 10 (2017) this risk was listed as A9:...

post image
Logging & Monitoring Failures Explained | Rootsec

This is the tenth and final stop in our walk through the OWASP Top 10. Looking back, it might have made more sense to begin here and work upwards,...

post image
What Is Insecure Deserialization? | Rootsec

In this series of articles, we walk you through the OWASP Top 10 — the most common and most damaging types of cyber attack. These topics have a...

post image
What Is Security Misconfiguration? | Rootsec

In this series of articles, we walk you through the OWASP Top 10 — the ten most common, and most dangerous, types of cyber attack. There’s...

post image
What Is Broken Access Control? | Rootsec

We’re at the halfway point in our series on the OWASP Top 10 — the ten most common and most damaging categories of web application weakness....

post image
What Are XML External Entities (XXE)? | Rootsec

In this series, we walk you through the OWASP Top 10 — the ten most common and most dangerous types of cyber attack. There’s still a lot of...

post image
What Is Sensitive Data Exposure? | Rootsec

In this series of articles, we take you through the OWASP Top 10 — the ten most common, and most damaging, categories of cyber attack. There is...