The OWASP Top 10 for Large Language Model (LLM) Applications: An Overview

The OWASP Top 10 for Large Language Model (LLM) Applications: An Overview

1h 39mIntermediate2025-08-07

Authors

Reet Kaur

Reet Kaur

Course details

As artificial intelligence reshapes how we interact with technology, securing Large Language Models (LLMs) and their surrounding ecosystems has become a mission-critical task. In this course, Reet Kaur—the Former CISO and Former Executive director of IT Security and Risk Management—guides you through the latest version of OWASP Top 10 for LLMs (2025), a community-curated guide to understanding the most pressing vulnerabilities in LLM systems. Explore each risk, including prompt injection, data poisoning, misinformation, and excessive agency, and examine practical mitigation strategies. Learn how to apply threat modeling specifically for LLM applications and align LLM security risks with standard frameworks. When you complete this course, you’ll have the skills to implement LLM security best practices in real-world deployments.

Learning objectives
Identify and explain the OWASP Top 10 vulnerabilities specific to Large Language Models (LLMs) for 2025.
Perform threat modeling for LLM-powered applications and systems.
Recognize and mitigate real-world LLM-specific security risks such as prompt injection, data poisoning, and excessive agency.
Map LLM vulnerabilities to established frameworks to align with enterprise security practices and compliance standards.
Understand real-world attack scenarios on LLMs and apply security controls to prevent such incidents.

Skills covered

Application SecurityMachine Learning FundamentalsTraditional AI and Machine LearningArtificial Intelligence (AI)CybersecurityOne-Off

Concepts

Introduction

  • Introducing the 2025 OWASP Top 10 for LLMs
  • What is the OWASP Top 10 list
  • How to threat model LLM applications

OWASP Top 10 for LLMs

  • What is a prompt
  • What is prompt injection
  • What is jailbreaking How does it differ from prompt injection
  • OWASP recommendations to defend against prompt injection

Sensitive Information Disclosure

  • What is sensitive information disclosure
  • How to prevent sensitive information disclosure

Supply Chain

  • Supply chain risks
  • Securing the LLM supply chain

Data and Model Poisoning

  • What is data and model poisoning
  • How to stop data and model poisoning

Improper Output Handling

  • Insecure output handling
  • Preventing improper output handling

Excessive Agency

  • Excessive agency
  • Excessive agency mitigations

System Prompt Leakage

  • System prompt leakage
  • System prompt leakage - Mitigations

Vector and Embedding Weaknesses

  • Vector and embedding vulnerabilities
  • Vector and embedding vulnerabilities mitigations

Misinformation

  • Misinformation
  • Misinformation mitigations

Unbounded Consumption

  • Unbounded consumption
  • Unbounded consumption mitigations

Conclusion

  • Final thoughts and next steps
40,000 Toman