The annual review of web security research, titled the Top 10 Web Hacking Techniques of 2025, showcases significant contributions from the security community. This year, 63 research pieces were nominated, a notable decrease from 121 submissions in the previous year, likely influenced by the increasing focus on AI technologies.
The selection process involved community nominations, a voting phase to shortlist 15 candidates, and a final decision made by an expert panel, including notable figures such as Nicolas Grégoire and Soroush Dalili. The results will culminate in an award ceremony at DEF CON, with further details yet to be announced.
Among the top ten techniques, the presentation titled Parser Differentials: When Interpretation Becomes a Vulnerability, presented by @joernchen, takes the tenth spot, highlighting vulnerabilities across various programming languages. Other techniques include innovative work on HTTP/2 and XSS-Leak, emphasizing a continued exploration of web vulnerabilities.