The Advances in Teaching and Learning for Cyber Security Education (AiTLCE) is the annual conference of CSE Connect. The 2026 conference will be held on 23rd and 24th July at Abertay University in Dundee. This is a free event.
foundation that works to improve the security of software through its community-led open source software projects, hundreds of chapters worldwide, tens of thousands of community members, and by hosting local and global conferences. Open Source Tools, Guidelines, Standards, Frameworks, Books Community Chapters Worldwide owasp.org Global Application Security Conferences: USA, Europe, Asia @securestep9
developers and web application security practitioners • A broad consensus about the most critical security risks to web applications • The 1st step towards changing the application development culture within your organization into one that produces more secure code • A Whitepaper Not a “Standard”! (However OWASP ASVS is) • 2025 is the latest version owasp.org @securestep9
catalogue of testable security requirements for AI-enabled systems. NEW!!! It gives developers, architects, security engineers, and auditors a structured framework to design, build, test, and verify the security of AI applications throughout their lifecycle owasp.org @securestep9
Hijack Attackers can manipulate an agent’s objectives, task selection, or decision pathways through a variety of techniques - including, but not limited to prompt-based manipulation, deceptive tool outputs, malicious artefacts, forged agent-to-agent messages, or poisoned external data. Because agents rely on untyped natural-language inputs and loosely governed orchestration logic, they cannot reliably distinguish legitimate instructions from attacker -controlled content. owasp.org @securestep9
Rogue Agents are malicious or compromised AI Agents that deviate from their intended function or authorized scope, acting harmfully, deceptively, or parasitically within multi-agent or human-agent ecosystems. owasp.org @securestep9
received: “These are not considered security vulnerabilities:” ➢ ➢ ➢ ➢ generation of inappropriate text/visual content with the model getting inappropriate suggestions from the model malicious code generation by the model any issues or actions which are result of model hallucinations are out scope of bug bounty and vulnerability disclosure programs owasp.org @securestep9