When the new OWASP Top 10 came out in December 2017, I was somewhat enthusiastic about one of the items dropping off: Cross-Site Request Forgery (CSRF). From malicious actors changing Netflix DVD queues to attackers taking over someone’s rewards accounts, there have been plenty of exploitations of CSRF over the years.