This document summarizes a presentation on web application security given on January 29th, 2014. The presentation covered common web application vulnerabilities like injection flaws, broken authentication, insecure direct object references, cross-site scripting, and more. It also discussed the OWASP Top 10 risks and how to address them through practices like following the OWASP Application Security Verification Standard (ASVS) and implementing a secure software development lifecycle with security testing throughout. Attendees were given an assignment to participate in an "ASVS Bingo" verification exercise of the OWASP requirements.