OWASP Introduces Subtractive Security Top 10 to Mitigate Attack Paths

OWASP Introduces Subtractive Security Top 10 to Mitigate Attack Paths

First seen 4 Aug 2026, 12:18 UTC Feeds2.FeedburnerFeeds.4Sysops 79% similarity 24.9

Article Content

Browse articles
ThreatCluster

OWASP has launched its Subtractive Security Top 10, focusing on removing attack paths before they can be exploited. This initiative, led by Christopher Frenz, emphasizes the importance of erasing unnecessary capabilities and permissions from systems. The Path Erasure Rate standard quantifies the effectiveness of these removals, aiming to enhance overall security. Organizations are encouraged to adopt this framework to minimize potential vulnerabilities. The project includes nine lists detailing various attack paths that should be eliminated. This proactive approach seeks to prevent attackers from leveraging existing permissions and routes. The initiative is part of OWASP's broader mission to improve software security practices across industries.

Key Points: • OWASP's Subtractive Security Top 10 aims to remove attack paths before exploitation. • The Path Erasure Rate standard quantifies the effectiveness of capability removals. • Organizations are encouraged to adopt this proactive security framework.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
OWASP Subtractive Security Top 10 launched
OWASP introduced its Subtractive Security Top 10, focusing on erasing attack paths to enhance security.
Feeds.4Sysops
2026-08-04
Path Erasure Rate standard published
Alongside the Subtractive Security Top 10, OWASP released the Path Erasure Rate standard to measure security improvements.
Feeds2.Feedburner

Community

Browse all →