World Congress 2025

Bullet-Proof APIs: The OWASP API Security Top Ten

July 10, 2025 10:10 – 10:40 Β· 30 min Stage 4
compliance cybersecurity privacy

What this session covers

The OWASP Top Ten as a list of the ten biggest security risks for web applications has been a de facto standard for over ten years. Somewhat out of the limelight, however, there are other lists. The OWASP API Security Top Ten was last updated in 2023 and highlights risks for APIs. Since arguably almost every web application relies on APIs these days, it’s imperative that we address them. In the talk, we’ll take a look at how the list came about and then go through all the points, showcasing common attacks. In particular, we are interested in what this means for modern stacks. Which points are relevant, and how can we take technology-specific countermeasures?

Related talks at this congress

Open session

World Congress 2025

July 11, 2025 Β· 13:40–14:10

Stage 5

Lessons learned from observing a billion API requests

Pratim Bhosale

Senior Developer Experience Engineer

Pratim Bhosale
Open session

World Congress 2025

July 11, 2025 Β· 16:20–16:50

Stage 1

Lessons from Our API Past: Evolving to a Resilient API Future

Yousaf Nabi

Yousaf, Developer Advocate at SmartBear Software.

Yousaf Nabi
Open session

World Congress 2025

July 10, 2025 Β· 10:30–12:30

M7 (18 Seats)

Code Red: When Your Tools Turn Against You

Aaron Bray, Julian Totzek-Hallhuber

Aaron Bray
Julian Totzek-Hallhuber
Open session

World Congress 2025

July 10, 2025 Β· 13:30–14:00

Stage 9

REST in Peace? What does the API protocol of the future look like? Or do we have it already?

Simon Auer

Organizer of flutter vienna meetup and CEO of marqably

Simon Auer
All sessions at this congress