OWASP GenAI LLM Top 10 2026: What the New Rankings Mean for Security Teams

The OWASP GenAI LLM Top 10 2026 was published on August 3, 2026. I am still learning my way around AI security, and I read OWASP Top 10 lists because they are the closest thing the industry has to a consensus map. They are not academic papers. They become the basis for threat models, security review checklists, and procurement questions. The GenAI edition specifically maps the risks that matter when you build applications around large language models. ...

August 5, 2026 · 6 min · 1111 words · Matteo Bisi

Shadow AI in CI/CD: Threat-Modelling Laptop to Kubernetes

Artificial intelligence is becoming part of daily software delivery, often before it becomes part of the organisation’s security architecture. This creates Shadow AI: AI tools, models, agents, extensions, or integrations used without formal approval, ownership, risk assessment, or monitoring. For executives, Shadow AI is not primarily a “developers using ChatGPT” issue. It is an enterprise-risk issue: ungoverned AI can gain access to source code, intellectual property, credentials, customer data, cloud environments, and deployment workflows. When AI systems are allowed to call tools or take actions, they must be treated as new non-human identities with access rights, not simply as productivity software. ...

July 27, 2026 · 13 min · 2597 words · Matteo Bisi

Zero Trust for AI Agents: Why Anthropic's New eBook Should Be on Your Reading List

Attackers Now Run at Machine Speed If you have been following this blog, you know that 2026 has not been a quiet year for the security community. The Trivy supply chain attack in March was the wake up call: a trusted security scanner turned into a credential harvesting machine, followed by the CanisterWorm escalation that propagated itself through the npm ecosystem at a speed no human operator could match. In the weeks after, we saw several other serious and successful exploitations following the same pattern: automation turned against the defenders, with exploits appearing within hours of a patch instead of months. ...

June 10, 2026 · 7 min · 1384 words · Matteo Bisi