What Changed in the OWASP LLM and Agentic Top 10 (2026 Update)

In December 2025, OWASP released its first Top 10 for Agentic AI Applications, defining risks like goal hijacking, tool misuse, supply-chain attacks, and rogue agents — threats that real incidents quickly validated in 2026.

Content

Make Your Applications Secure Today

Sign up for a personalized demo to see how DerScanner can meet your Application Security needs

For two years, teams building on large language models had one OWASP reference point: the Top 10 for LLM Applications, with prompt injection sitting at number one. In December 2025 that map got a second sheet. The OWASP GenAI Security Project released the Top 10 for Agentic Applications, announced at Black Hat Europe 2025, and it is the first standards-grade taxonomy for systems where the model does things: calls tools, executes code, moves data, coordinates with other agents.

A chatbot or RAG system stays covered by the LLM list. The moment the system gains tools and autonomy, ten new risk categories apply, labeled ASI01 through ASI10. Within six months of publication, 2026 had already supplied a real incident for the categories that matter most.

 

OWASP Top 10 for Agentic Applications

  1. Agent Goal Hijack (ASI01)

  2. Tool Misuse and Exploitation (ASI02)

  3. Identity and Privilege Abuse (ASI03)

  4. Agentic Supply Chain Vulnerabilities (ASI04)

  5. Unexpected Code Execution (ASI05)

  6. Memory and Context Poisoning (ASI06)

  7. Insecure Inter-Agent Communication (ASI07)

  8. Cascading Failures (ASI08)

  9. Human-Agent Trust Exploitation (ASI09)

  10. Rogue Agents (ASI10).

The framework now treats supply chain as a runtime problem: ASI04 covers agents that discover and integrate tools during execution, where the classic LLM supply chain entry stopped at pre-deployment components. 

Three categories (inter-agent communication, cascading failures, rogue agents) describe risks that simply have no equivalent in single-model applications. OWASP grounded each entry in documented incidents: EchoLeak for goal hijack, the Amazon Q incident for tool misuse, a GitHub MCP exploit for the supply chain entry.

 

ASI01 in the wild: when the agent is the operator's weapon

The category OWASP put first, Agent Goal Hijack, covers an attacker seizing control of an agent's decision-making. The most consequential agent-driven incident of early 2026 shows why the framework's authors were in a hurry, even though it arrived through a different door: the attacker owned the agent from the start.

Between late January and February 2026, a single operator used AI coding agents to breach nine Mexican government agencies, including the federal tax authority and the civil registry. By the time Gambit Security found the operator's session logs exposed online in late February, the tally reported by SecurityWeek and subsequent analyses stood at more than 150 GB exfiltrated, including 195 million taxpayer records and 220 million civil records, with 37 database servers compromised in the state of Jalisco alone. The operator convinced the model it was working an authorized bug bounty, fed it a custom playbook, and received structured reports naming the next internal targets and the credentials to use.

The incident is a jailbreak and social engineering story as much as a hijack story, and honest taxonomy matters here. What it demonstrates beyond argument is the amplification: one person with agentic tooling ran a campaign that previously required a team. Every ASI category inherits that multiplier. A hijacked goal, a misused tool, or a poisoned context now executes at machine speed.

 

ASI04 in the wild: the Mastra compromise

For Agentic Supply Chain Vulnerabilities, 2026 delivered a textbook case in one afternoon. On June 17, an attacker who had hijacked a maintainer account republished more than 140 packages of the Mastra AI framework, the npm ecosystem developers use to build AI agents, in an automated 88-minute campaign. The package code itself was untouched; each version gained one new dependency, easy-day-js, a typosquat of the dayjs date library whose postinstall hook dropped a cross-platform infostealer. Combined weekly downloads across the affected scope exceeded 1.1 million, and Microsoft later attributed the operation to Sapphire Sleet, a North Korean state actor.

The target was the agent development stack itself. Environments that install Mastra hold LLM API keys, cloud credentials, and CI/CD tokens, which is precisely why a state actor bothered. The dependency graph of an agent framework is now a critical attack surface, the same lesson the Miasma campaign taught in the Red Hat namespace two weeks earlier.

 

What SAST and SCA cover and what don't

Application security testing covers roughly half of the agentic Top 10: the risks that live in code and dependencies. The other half happens at runtime and needs separate controls. 

ASI04 is largely an SCA problem. The Mastra attack shows up as a suspicious new dependency with a fresh install hook, and flagging packages like that is what SCA does. ASI05, Unexpected Code Execution, usually comes down to ordinary bugs in the glue code: MCP servers and tool wrappers with command injection paths, unvalidated fetch destinations, hardcoded tokens. SAST analyzes this code like any other code, as we show in Agentjacking article. Mapping what an agent's codebase can reach through its dependencies and tool definitions is static work too.

The runtime half of the list is a different discipline. Goal hijack, memory poisoning, inter-agent spoofing, and cascading failures happen in live inference, shaped by inputs no scanner saw at build time. Those need runtime controls: approval gates, context isolation, behavioral monitoring, identity boundaries between agents. No static tool observes a conversation, and vendors implying otherwise are selling the label rather than the control.

The workable posture treats the two halves as a stack. Scan the agent's code and dependencies with the same rigor as the rest of the application surface, then add runtime governance for the behaviors static analysis cannot see. Teams starting on the first half can walk through their agent integration code in a DerScanner demo; for the historical arc of how supply chain attacks reached this point, 11 Examples of Supply Chain Attacks is the background reading.

Loading blogs...
Get Started

Ready to Reduce Technical Debt and
Improve Security?

Clean code. Fewer risks. Stronger software

dashboard