OWASP Launches Subtractive Security Top 10 to Combat Cyber Threats

OWASP Launches Subtractive Security Top 10 to Combat Cyber Threats

First seen 4 Aug 2026, 12:18 UTC Feeds2.FeedburnerFeeds.4SysopsGbhackersCybersecuritynews 83% similarity 27.8

Article Content

Browse articles
ThreatCluster

OWASP has introduced the Subtractive Security Top 10 project, aimed at eliminating attack paths to reduce cyber risks. Led by Christopher Frenz, the initiative focuses on removing unnecessary capabilities and permissions that attackers could exploit. The project includes a new standard called Path Erasure Rate, which quantifies the effectiveness of these removals. This approach shifts the emphasis from detection to prevention, advocating for a proactive stance in cybersecurity. Organizations are encouraged to adopt this methodology to enhance their security posture and minimize potential vulnerabilities. The project is part of OWASP's ongoing efforts to support secure software development and architecture.

Key Points: • OWASP's Subtractive Security Top 10 focuses on removing attack paths rather than adding detection. • The initiative introduces the Path Erasure Rate standard to measure security improvements. • Organizations are encouraged to eliminate unnecessary permissions to reduce cyber risks.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
OWASP Subtractive Security Top 10 Project launched
OWASP introduced a new initiative to eliminate attack paths, shifting focus from detection to prevention in cybersecurity.
Feeds.4Sysops
2026-08-04
Path Erasure Rate standard introduced
The new standard quantifies the removal of unnecessary capabilities and permissions to enhance security.
Feeds2.Feedburner
2026-08-04
Christopher Frenz leads the initiative
Frenz emphasizes the importance of deleting exploitable capabilities before they can be detected.
Gbhackers
2026-08-04
Focus on proactive cybersecurity measures
The project encourages organizations to adopt a proactive approach by removing vulnerabilities rather than just detecting them.
Cybersecuritynews

Community

Browse all →