惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
P
Proofpoint News Feed
G
Google Developers Blog
B
Blog
Engineering at Meta
Engineering at Meta
阮一峰的网络日志
阮一峰的网络日志
The Register - Security
The Register - Security
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 叶小钗
The Cloudflare Blog
The Hacker News
The Hacker News
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
雷峰网
雷峰网
F
Fortinet All Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Hackread – Cybersecurity News, Data Breaches, AI and More
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
T
Threat Research - Cisco Blogs
A
About on SuperTechFans
量子位
Recorded Future
Recorded Future
博客园 - 三生石上(FineUI控件)
H
Help Net Security
Help Net Security
Help Net Security
P
Palo Alto Networks Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
T
Troy Hunt's Blog
W
WeLiveSecurity
V
Vulnerabilities – Threatpost
T
The Exploit Database - CXSecurity.com
Know Your Adversary
Know Your Adversary
Apple Machine Learning Research
Apple Machine Learning Research
Scott Helme
Scott Helme
N
News | PayPal Newsroom
AWS News Blog
AWS News Blog
D
DataBreaches.Net
Blog — PlanetScale
Blog — PlanetScale
MongoDB | Blog
MongoDB | Blog
B
Blog RSS Feed
腾讯CDC
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog
TaoSecurity Blog
TaoSecurity Blog
GbyAI
GbyAI
Y
Y Combinator Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
D
Docker

OWASP Gen AI Security Project

Memory Is a Feature. It Is Also an Attack Surface Memory Is a Feature. It Is Also an Attack Surface FinBot CTF Is Live: A Hands-On Companion to the OWASP GenAI Security Project OWASP GenAI Exploit Round-up Report Q1 2026 OWASP GenAI Exploit Round-up Report Q1 2026 OWASP GenAI Security Project Expands AI Security Frameworks Ahead of RSA 2026, Celebrates Continued Sponsor Support OWASP GenAI Security Project Expands AI Security Frameworks Ahead of RSA 2026, Celebrates Continued Sponsor Support Evolving AI Transparency: The Journey of the AIBOM Generator and Its New Home at OWASP Evolving AI Transparency: The Journey of the AIBOM Generator and Its New Home at OWASP OWASP Top 10 for Agentic Applications – The Benchmark for Agentic Security in the Age of Autonomous AI OWASP Top 10 for Agentic Applications – The Benchmark for Agentic Security in the Age of Autonomous AI OWASP GenAI Security Project Releases Top 10 Risks and Mitigations for Agentic AI Security OWASP GenAI Security Project Releases Top 10 Risks and Mitigations for Agentic AI Security OWASP Agentic AI Taxonomy in Action: From Theory to Tools OWASP Agentic AI Taxonomy in Action: From Theory to Tools OWASP Gen AI Incident & Exploit Round-up, Q2’25 OWASP Gen AI Incident & Exploit Round-up, Q2’25 CyberRisk Alliance and OWASP Join Forces to Advance Application Security and AI Education Across the Cyber Ecosystem CyberRisk Alliance and OWASP Join Forces to Advance Application Security and AI Education Across the Cyber Ecosystem
FinBot CTF Is Live: A Hands-On Companion to the OWASP GenAI Security Project
Helen Oakley and Venkata (Sai) Kishore Modalavalasa · 2026-04-15 · via OWASP Gen AI Security Project

At RSAC 2026, the community got an early look at FinBot through the OWASP GenAI Security Summit and Open Workshop, including the session “FinBot: An Agentic AI Capture-The-Flag Deep Dive.” FinBot was also showcased at AppSec Village in “AI Risks Through the OWASP GenAI Security Project & FinBot CTF,” where it was used to demonstrate how agentic AI systems can fail in practice through a live walkthrough and audience participation. 

Now that the platform is live, it is a good time to formally describe what FinBot is and how it fits into the broader OWASP effort. FinBot is part of the OWASP GenAI Security Project’s Agentic Security Initiative and is designed to help builders and defenders better understand and mitigate agentic AI risks through a hands-on environment. The OWASP GenAI project describes it as an interactive Agentic Security CTF built around a simulated financial-services-focused application and designed as the “Juice Shop for Agentic AI.”

That role is best understood as complementary to the parent project. The OWASP Top 10 for Agentic Applications for 2026 is a globally peer-reviewed framework developed with contributions from more than 100 experts, researchers, and practitioners, and it provides practical guidance for securing AI agents that plan, act, and make decisions across complex workflows. FinBot complements that guidance by giving practitioners a place to interact with agentic risk directly and see how those patterns emerge in a live system. 

FinBot simulates a multi-agent vendor management platform with autonomous onboarding, fraud detection, invoice processing, and communications, all powered by LLMs with real tool access. Its challenges cover prompt injection, tool misuse, policy bypass, data exfiltration, privilege escalation, and remote code execution, with mappings to the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, CWE, and MITRE ATLAS. 

The platform also reflects an important reality about agentic AI security: the risk is not limited to a single chatbot interaction. In FinBot, malicious vendor data can flow upstream into administrative AI workflows and laterally into other tenants through shared context. On the administrative side, participants configure MCP tool servers (to simulate supply chain attacks) that agents rely on and can observe how tampered MCP tool descriptions or compromised external tool servers can influence trusted agents – threats can come from other vendors, the supply chain, and the tools themselves. 

FinBot is therefore best viewed as a hands-on companion to the OWASP GenAI Security Project and the Agentic Security Initiative. The parent project provides the shared guidance, taxonomy, and direction. The Agentic Top 10 provides the framework. FinBot helps bring those ideas to life in a way that is practical, interactive, and grounded in how agentic systems actually operate. 

Finally, FinBot would not exist without the energy and contributions of the broader community. We want to thank the contributors, workstream leads, and OWASP GenAI Security Project leadership who have helped shape the platform, strengthen its quality, and move the work forward. FinBot is very much a community-built effort, and we are excited to continue growing it with practitioners, builders, and defenders across the ecosystem. To meet the people behind the project, visit the About page

Explore the platform: OWASP FinBot CTF
Learn the framework: OWASP Top 10 for Agentic Applications 2026
Learn more about the platform: How FinBot Works
Get involved: Contribute ideas, feedback, and future challenges through the OWASP GenAI community here.