Security Control Framework
OWASP Top 10 2025: What's changed and why it matters

OWASP Top 10 2025: What's changed and why it matters

1/7/2026 · Fernando Diaz

What this post added

This post details the OWASP Top 10 2025 list, highlighting new categories like 'Software Supply Chain Failures' and 'Mishandling of Exceptional Conditions', and explains how GitLab Ultimate's security scanning features (SAST, IaC scanning, Dependency Scanning, DAST, API Security Testing, Web API Fuzz Testing) map to these risks, enabling detection and management of vulnerabilities within the CI/CD pipeline and vulnerability reports.

Read the original post ↗