NewsOWASP Top 10 Agentic Applications 2026 Least Agency PrincipleOWASP·high signalXBlueskyLinkedInCopy linkDefinitive agent risk framework introducing Least Agency principle. Top risks: Agent Goal Hijack, Tool Misuse, Identity Abuse, Supply Chain.SourceSource pageOWASP↳ Follow the threadPolicy dependency / Stack layerOrdewell uses a read-only coding agent as planner, then spawns per-task agent sessions gated by a marker-based verdict engineGitHubPolicy dependency / Stack layer'Do this as quickly as possible' repeatedly got a Claude session flagged by a corporate security directorr/ClaudeAIPolicy dependency / Stack layerCognitive Admission Control makes an agent produce a witness certificate before it is allowed to mutate infrastructurearXiv 2609.16313Stack layer / Threat patternSpain's Data Protection Agency Logs the First Breach Where an AI Agent Chained the Whole Attack ItselfSecurityWeekStack layer / Threat patternPentestChain keeps a 7B local model off the critical path behind a deterministic exploit map and runs an eleven-tool MCP pentest pipeline at zero paid-API costarXiv 2609.18120Stack layer / ContrastHierarchos-Native trains 143 Transformer architectures on Rust and Vulkan with no CUDA or PyTorchGitHub / necat101 (via r/LocalLLaMA)Policy dependency / Update threadVercel's Is Agentic audit now scores sites by type, with an opt-in meta tag for docs, business, app or commerceVercel ChangelogStack layer / Update threadTwo Tool-Level Defenses Drive Prompt Injection and Memory Poisoning to 0% Attack Success in Many SettingsarXiv 2609.16098