OWASP® Foundation’s cover photo
OWASP® Foundation

OWASP® Foundation

Software Development

Wilmington, Delaware 302,187 followers

Every vibrant technology marketplace needs an unbiased source of information. OWASP is synonymous with AppSec.

About us

The Open Worldwide Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of software. Our mission is to make application security "visible," so that people and organizations can make informed decisions about application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license. The OWASP Foundation is a 501c3 not-for-profit charitable organization that ensures the ongoing availability and support for our work.

Website
http://owasp.org
Industry
Software Development
Company size
2-10 employees
Headquarters
Wilmington, Delaware
Type
Nonprofit
Founded
2001

Locations

  • Primary

    300 Delaware Ave

    Suite 210 # 384

    Wilmington, Delaware 19801, US

    Get directions

Employees at OWASP® Foundation

Updates

  • What if HAL 9000 were a modern agentic AI system? Join us at #DEFCON34 for “2001: Agentic Odyssey in Threat Modeling,” a hands-on, drop-in workshop where we’ll map trust boundaries, build attack trees, analyze failure paths, and turn threats into practical security tests. Whether you contribute for 10 minutes or stay for the full session, come help answer the classic question: What could possibly go wrong? 📅 August 9 | 10:30 a.m.–12:30 p.m. PT 📍 Las Vegas Convention Center, OWASP Community Village W4 / 1415 🎟️ Free registration: https://luma.com/l3j6ecg5 #OWASP #ThreatModeling #AgenticAI #AISecurity #Cybersecurity

    • What if HAL 9000 were a modern agentic AI system? 

Join us at #DEFCON34 for “2001: Agentic Odyssey in Threat Modeling,” a hands-on, drop-in workshop where we’ll map trust boundaries, build attack...
  • How do you move beyond AI security theory and verify that an AI system is actually secure? Join OWASP AI Security Verification Standard \(AISVS\) Project Leader @jmanico at DEF CON 34 for “Practical AI Security Assessments Using OWASP AISVS.” This hands-on workshop will explore real AISVS requirements and practical assessment scenarios involving: 🔹 Prompt injection defenses 🔹 Agentic action security 🔹 RAG and vector database hardening 🔹 Output safety controls 🔹 LLM applications, autonomous agents, and MCP-connected tools Participants will learn how to scope an AI security assessment, select the appropriate verification level, and apply AISVS requirements to running systems. 📅 August 8, 2026 🕓 4:00–6:00 p.m. PT 📍 Las Vegas Convention Center, OWASP Community Village W4 / 1415 💻 Bring a laptop to follow along 🎟️ Free registration: https://luma.com/3jqf6wrg #OWASP #DEFCON34 #AISVS #AISecurity #ApplicationSecurity #Cybersecurity

  • How do you move beyond AI security theory and verify that an AI system is actually secure? Join OWASP AI Security Verification Standard \(AISVS\) Project Leader @jmanico at DEF CON 34 for “Practical AI Security Assessments Using OWASP AISVS.” This hands-on workshop will explore real AISVS requirements and practical assessment scenarios involving: 🔹 Prompt injection defenses 🔹 Agentic action security 🔹 RAG and vector database hardening 🔹 Output safety controls 🔹 LLM applications, autonomous agents, and MCP-connected tools Participants will learn how to scope an AI security assessment, select the appropriate verification level, and apply AISVS requirements to running systems. 📅 August 8, 2026 🕓 4:00–6:00 p.m. PT 📍 Las Vegas Convention Center, OWASP Community Village W4 / 1415 💻 Bring a laptop to follow along 🎟️ Free registration: https://luma.com/3jqf6wrg #OWASP #DEFCON34 #AISVS #AISecurity #ApplicationSecurity #Cybersecurity

  • What happens when you give an AI agent a shell, a browser, and a vulnerable application to hack? Join @phildour at DEF CON 34 for “Agents & Exploits: Hacking OWASP VWAD,” a hands-on workshop where you’ll build an AI-powered security agent from the ground up and explore the fundamentals of agentic penetration testing. You’ll learn how to: 🛠️ Equip an agent with shell and browser access 🎯 Discover, exploit, and document vulnerabilities in OWASP applications 🧠 Work with agent architecture, memory, tool integration, and orchestration 🔒 Apply safe execution practices 📊 Evaluate missed vulnerabilities and iteratively improve the agent’s performance By the end of the session, you’ll have a functional security agent and practical techniques for improving AI-assisted security testing through systematic evaluation and feedback. 📍 OWASP Community Village, Las Vegas Convention Center, W4/1415, Level 1 🎟️ Register: https://luma.com/yw0xkarr #OWASP #DEFCON34 #AISecurity #AppSec #AgenticAI #PenTesting #Cybersecurity

    • What happens when you give an AI agent a shell, a browser, and a vulnerable application to hack?

Join @phildour at DEF CON 34 for “Agents & Exploits: Hacking OWASP VWAD,” a hands-on workshop...
  • Discover the future of OSINT automation and attack-surface intelligence at the OWASP Amass Workshop during DEF CON 34! Led by Amass founder and longtime maintainer Jeff Foley, this two-hour, hands-on workshop offers a first look at Amass v5.0 and its new Open Asset Model—a structured graph for storing, analyzing, and querying Internet-facing assets and their relationships. Participants will learn how to: 🔎 Perform deep asset and subdomain discovery 🌐 Collect intelligence from DNS, WHOIS/RDAP, TLS certificates, and other sources 📊 Visualize relationships between discovered assets 🧩 Write advanced association queries using the new assoc tool 🛠️ Integrate Amass data into security tools and pipelines Bring a laptop and follow along with support from Amass project contributors. Some OSINT, command-line, or network-security experience is helpful, but the workshop is designed to be self-contained and accessible. 📍 OWASP Communtiy Village, Las Vegas Convention Center, W4/1415, Level 1 🎟️ Register: https://luma.com/n6t7cuqm #OWASP #DEFCON34 #Amass #OSINT #AttackSurfaceManagement #Cybersecurity

    • Discover the future of OSINT automation and attack-surface intelligence at the OWASP Amass Workshop during DEF CON 34!

Led by Amass founder and longtime maintainer Jeff Foley, this two-hour,...
  • 🦖 Life finds a way—and so do vulnerabilities. Join us at #DEFCON34 for “Life Finds a Way: Secure Coding with OWASP ASVS.” You’ll identify and patch vulnerabilities in a lab application, use rigorous code review to bring Apex Island’s facilities back online, and hopefully prevent a containment failure…with teeth. Bring a Docker-capable laptop with GitHub access and get ready for a hands-on secure coding adventure, only in the OWASP Community Village 📍 Las Vegas Convention Center, W4/1415 🎟️ Register: https://luma.com/5geigcgf #OWASP #ASVS #SecureCoding #AppSec #Cybersecurity

    • 🦖 Life finds a way—and so do vulnerabilities.

Join us at #DEFCON34 for “Life Finds a Way: Secure Coding with OWASP ASVS.” You’ll identify and patch vulnerabilities in a lab application, use...
  • Did you know OWASP members get exclusive access to a reserved instance of SecureFlag’s Secure-by-Design Enablement Platform? From secure design to secure code, the platform is built to help you ship safer features, faster. SecureFlag delivers:  📚 Secure Coding Training: Learn by doing with hands-on labs that mirror real projects, in live development environments. 🤖  AI-Powered Threat Modeling: Visualize and identify risks in seconds with ThreatCanvas.  📈 Measurable Impact: Spend 24% less time performing frustrating security reworks. Join engineers across 30+ countries who are building a secure-by-design culture. Claim your exclusive member benefit to the SecureFlag platform here:  https://lnkd.in/exZc84xE Not an OWASP member? Join the community today! https://lnkd.in/evGuHnfc #OWASP #SecureFlag #SecureCodingTraining #ThreatModeling #SoftwareEngineering

    SecureFlag x OWASP

    SecureFlag x OWASP

    secureflag.com

Similar pages

Browse jobs