Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
The OWASP Top 10 for Large Language Model (LLM) Applications: An Overview

The OWASP Top 10 for Large Language Model (LLM) Applications: An Overview

1h 39mIntermediate2025-08-07

Authors

Reet Kaur

Reet Kaur

Course details

As artificial intelligence reshapes how we interact with technology, securing Large Language Models (LLMs) and their surrounding ecosystems has become a mission-critical task. In this course, Reet Kaur—the Former CISO and Former Executive director of IT Security and Risk Management—guides you through the latest version of OWASP Top 10 for LLMs (2025), a community-curated guide to understanding the most pressing vulnerabilities in LLM systems. Explore each risk, including prompt injection, data poisoning, misinformation, and excessive agency, and examine practical mitigation strategies. Learn how to apply threat modeling specifically for LLM applications and align LLM security risks with standard frameworks. When you complete this course, you’ll have the skills to implement LLM security best practices in real-world deployments.

Learning objectives
Identify and explain the OWASP Top 10 vulnerabilities specific to Large Language Models (LLMs) for 2025.
Perform threat modeling for LLM-powered applications and systems.
Recognize and mitigate real-world LLM-specific security risks such as prompt injection, data poisoning, and excessive agency.
Map LLM vulnerabilities to established frameworks to align with enterprise security practices and compliance standards.
Understand real-world attack scenarios on LLMs and apply security controls to prevent such incidents.

Skills covered

Application SecurityGenerative AICybersecurityArtificial Intelligence (AI)One-Off

Concepts

0. Introduction

  • 01 - Introducing the 2025 OWASP Top 10 for LLMs
  • 02 - What is the OWASP Top 10 list
  • 03 - How to threat model LLM applications

1. OWASP Top 10 for LLMs

  • 04 - What is a prompt
  • 05 - What is prompt injection
  • 06 - What is jailbreaking How does it differ from prompt injection
  • 07 - OWASP recommendations to defend against prompt injection

2. Sensitive Information Disclosure

  • 08 - What is sensitive information disclosure
  • 09 - How to prevent sensitive information disclosure

3. Supply Chain

  • 10 - Supply chain risks
  • 11 - Securing the LLM supply chain

4. Data and Model Poisoning

  • 12 - What is data and model poisoning
  • 13 - How to stop data and model poisoning

5. Improper Output Handling

  • 14 - Insecure output handling
  • 15 - Preventing improper output handling

6. Excessive Agency

  • 16 - Excessive agency
  • 17 - Excessive agency mitigations

7. System Prompt Leakage

  • 18 - System prompt leakage
  • 19 - System prompt leakage - Mitigations

8. Vector and Embedding Weaknesses

  • 20 - Vector and embedding vulnerabilities
  • 21 - Vector and embedding vulnerabilities mitigations

9. Misinformation

  • 22 - Misinformation
  • 23 - Misinformation mitigations

10. Unbounded Consumption

  • 24 - Unbounded consumption
  • 25 - Unbounded consumption mitigations

Conclusion

  • 26 - Final thoughts and next steps

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal