u/Neat-Long-460

Community votes for OWASP Top 10 LLM 2026

Hey guys , I'm an entry lead for Owasp top 10 LLM for the new 2026 edition

Currently we are in sprint 2, Basically this sprint is about community voting

We are a week into voting for top 10 llm for 2026 community votes

We have only received 24 votes which is quite short for smtg this big

Your vote can help us reshape and strengthen LLM Security

Google form : https://docs.google.com/document/d/17NnFXGlVYmBslWbG\_6ug8totwziXgTC2DyCRAfPTy8Y/edit?tab=t.0

Linkedin post: https://www.linkedin.com/posts/rocklambros\_owasp-llmsecurity-aisecurity-activity-7457476594241011712-0EzC?utm\_source=share&utm\_medium=member\_desktop&rcm=ACoAAFcmwXkBV3xIyoq0I8IaYBBna3xA\_h\_bN-U

reddit.com
u/Neat-Long-460 — 1 day ago
▲ 8 r/gsoc_2027+1 crossposts

Few months i had built https://github.com/S3DFX-CYBER/GSoC-Org-Finder- which runs on https://findmygsoc.vercel.app/

a free tool that helps students find GSoC orgs by language, domain, and competition level. It's been used by 244+ students

Now that 2026 results are out, I want to build features specifically for people planning their 2027 application

A few ideas I'm considering:

- Proposal analyzer — upload your draft proposal, get AI feedback comparing it against accepted 2026 proposals from the same org

- Org match quiz — answer a few questions about your skills and goals, get a ranked list of orgs that fit you

- Contribution tracker — log your pre-GSoC contributions per org as you build your profile over the year

- Mentor finder — surfaces mentor contact info and communication channels from org idea pages in one place

My questions for you'll:

  1. Which of these would you actually use?

  2. What's the #1 thing that made (or would make) your GSoC application process harder?

  3. Is there something you wished existed that none of the above covers?

u/Neat-Long-460 — 14 days ago

Hey community, I’m currently working on security research around RAG (Retrieval-Augmented Generation) systems, focusing on issues in embeddings, vector databases, and retrieval pipelines.

Most discussions online are theoretical, so I’m trying to collect real-world experiences from people who’ve actually built or deployed RAG systems.

I’ve put together a short anonymous survey (2–3 minutes):
[https://docs.google.com/forms/d/e/1FAIpQLSeqczLiCYv6A1ihiIpbAqpnebxBc5eSshcs3Dcd826BBNQddg/viewform?usp=dialog]

Looking for things like:

  • data leakage or access control issues
  • prompt injection via retrieved data
  • poisoning or low-quality data affecting outputs
  • retrieval manipulation / weird query behavior
  • issues in agentic or multi-step RAG systems

Even small issues are useful—trying to understand what actually breaks in practice.

Happy to share results back with the community.

u/Neat-Long-460 — 27 days ago