OWASP Top 10 — 2021
The most common root causes of real-world web breaches. Each card maps to a hands-on module where it exists, or a reference summary otherwise.
Broken Access Control
Facebook 2018 — access-token bug enabled account takeover of 50M users.
Cryptographic Failures
Equifax 2017 — 147M records leaked due to TLS / patching failure.
Injection
British Airways 2018 — Magecart skimmer (XSS) leaked 380K cards.
Insecure Design
Snapchat 2014 — find-friends API enumerable; 4.6M numbers leaked.
Security Misconfiguration
Capital One 2019 — SSRF + over-permissioned IAM exposed 100M records.
Vulnerable Components
Log4Shell 2021 — single dep enabled mass RCE across the internet.
Identification & Auth Failures
Dunkin' 2019 — credential stuffing exposed thousands of accounts.
Software & Data Integrity
SolarWinds 2020 — signed but tampered update reached 18K orgs.
Security Logging & Monitoring
Most breaches are discovered by external parties first.
Server-Side Request Forgery
Capital One 2019 — SSRF read cloud metadata, escalated to S3.