home.social

#threatmodeling — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatmodeling, aggregated by home.social.

fetched live
  1. OWASP v3: With EoP and PHANTOM-B

    We’re thrilled to bring you v3.4 with an update that expands how we identify threats, whether you're mapping out traditional applications or diving into AI architectures.

    Read more: dev.to/owasp/owasp-...

    #ai #games #security #appsec #threatmodeling #cornucopia

    OWASP Cornucopia v3.4: With Eo...

  2. OWASP v3: With EoP and PHANTOM-B

    We’re thrilled to bring you v3.4 with an update that expands how we identify threats, whether you're mapping out traditional applications or diving into AI architectures.

    Read more: dev.to/owasp/owasp-...

    #ai #games #security #appsec #threatmodeling #cornucopia

    OWASP Cornucopia v3.4: With Eo...

  3. "Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.

    CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.

    postquantum.com/post-quantum/c

    #threatmodeling #CRQC #infosec #PQC

  4. "Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.

    CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.

    postquantum.com/post-quantum/c

    #threatmodeling #CRQC #infosec #PQC

  5. Spend a half-day learning about threat modeling with AI at TechBash 2026! 4-day attendees choose their workshop track. Check out this year's options at techbash.com/

    Save 12% on standard registration thru 7/31 with code SUMMERSALE

    #ai #security #threatmodeling #workshops #devconf #poconos

  6. Spend a half-day learning about threat modeling with AI at TechBash 2026! 4-day attendees choose their workshop track. Check out this year's options at techbash.com/

    Save 12% on standard registration thru 7/31 with code SUMMERSALE

    #ai #security #threatmodeling #workshops #devconf #poconos

  7. For parents in the digital age, physical security protocols require a threat-modeling update.

    Legacy "stranger danger" paradigms fail against modern social engineering tactics. We must teach children to recognize behavioral anomalies rather than physical profiles.

    Implement an offline, zero-knowledge family verification token (code word) to secure pick-up vectors.

    Full documentation and actionable framework: securelylife.com/modern-strang

    #FamilySafety #InfoSec #ThreatModeling #ParentingTips

  8. The OWASP Cornucopia Web App Companion Set, which celebrates 25 years of the Open Web/World Application Security Project (OWASP), can be bought as a high-quality printed duplex deck from cybersecgames.com/collections/

    My name appears in a few places. Being open source, all the data, code and source files are available free online cornucopia.owasp.org

    @owasp #owasp #appsec #threatmodeling #infosec #devsecops #devops #ai #automation #cloud #webapps #cornucopia #threatmodelling #cybersecurity

  9. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  10. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  11. OWASP Cornucopia just released v3.2.2 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for adding DBD Cornucopia to copi.owasp.org and for providing various bugfixes for the project. Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

    Release Release v3.2.2 · OWASP...

  12. OWASP Cornucopia just released v3.2.2 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for adding DBD Cornucopia to copi.owasp.org and for providing various bugfixes for the project. Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

    Release Release v3.2.2 · OWASP...

  13. OWASP Cornucopia just released v3.2.3 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for adding DBD Cornucopia to cooi.owasp.org and for providing various bugfixes for the project. Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

    Release Release v3.2.2 · OWASP...

  14. OWASP Cornucopia just released v3.2.3 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for adding DBD Cornucopia to cooi.owasp.org and for providing various bugfixes for the project. Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

    Release Release v3.2.2 · OWASP...

  15. The risk in AI skill managers isn't theoretical. A compromised skill file could instruct an agent to exfiltrate credentials or execute shell commands under the user's own permissions. Yet most managers treat skills like inert config rather than executable intent. The threat model needs to shift. implicator.ai/ai-agent-skill-m #AI #threatmodeling #infosec

  16. The risk in AI skill managers isn't theoretical. A compromised skill file could instruct an agent to exfiltrate credentials or execute shell commands under the user's own permissions. Yet most managers treat skills like inert config rather than executable intent. The threat model needs to shift. implicator.ai/ai-agent-skill-m #AI #threatmodeling #infosec

  17. 🎥 Watch this short video to learn more about Vikramaditya Narayan's talk: AI and the Threat Modeling Manifesto: Conflicts, Failure Modes, and Better Patterns, taking place on Thursday, 25 June at OWASP Global AppSec Vienna.

    owaspglobalappseceuvienna20.sc

    #OWASPVienna26 #GlobalAppSec26 #threatmodeling

  18. 🎥 Watch this short video to learn more about Vikramaditya Narayan's talk: AI and the Threat Modeling Manifesto: Conflicts, Failure Modes, and Better Patterns, taking place on Thursday, 25 June at OWASP Global AppSec Vienna.

    owaspglobalappseceuvienna20.sc

    #OWASPVienna26 #GlobalAppSec26 #threatmodeling

  19. OWASP Cornucopia just released v3.1.6 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for doing a redesign of the OWASP Cornucopia website (cornucopia.owasp.org). It looks really cool! Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

  20. OWASP Cornucopia just released v3.1.6 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for doing a redesign of the OWASP Cornucopia website (cornucopia.owasp.org). It looks really cool! Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

  21. It's done. Just gave a talk about Threat Modeling at the SoCraTes Day Franken.

    Thank you for your feedback, finding my typos and being my test audience 🙏

    You can find most and more information in this recent article blog.maschmi.net/threat-modeli.

    The PDFs for the slides are here: codeberg.org/maschmi/talk-thre

    #SoCraTesFranken #threatmodeling #softwareengineering

  22. It's done. Just gave a talk about Threat Modeling at the SoCraTes Day Franken.

    Thank you for your feedback, finding my typos and being my test audience 🙏

    You can find most and more information in this recent article blog.maschmi.net/threat-modeli.

    The PDFs for the slides are here: codeberg.org/maschmi/talk-thre

    #SoCraTesFranken #threatmodeling #softwareengineering

  23. It's done. Just gave a talk about Threat Modeling at the SoCraTes Day Franken.

    Thank you all for the for feedback and finding my typos :) And also for being my test audience.

    Find me if you want to discuss it, give feedback or talk a bit more.

    You can find most and more information in this recent article blog.maschmi.net/threat-modeli.

    The PDFs for the slides are here: codeberg.org/maschmi/talk-thre

    #SoCraTesFranken #threatmodeling #softwareengineering

  24. It's done. Just gave a talk about Threat Modeling at the SoCraTes Day Franken.

    Thank you all for the for feedback and finding my typos :) And also for being my test audience.

    Find me if you want to discuss it, give feedback or talk a bit more.

    You can find most and more information in this recent article blog.maschmi.net/threat-modeli.

    The PDFs for the slides are here: codeberg.org/maschmi/talk-thre

    #SoCraTesFranken #threatmodeling #softwareengineering

  25. @adamshostack Always interesting and thought provoking. Isn't 2026-1999 = 27 (not 20 even rounding)? It feels that long ago o me.
    Thanks for the mention too.
    I'd be very interested to learn more about:
    --> "No one knew what quality looked like." [quality software or quality threat models?]
    --> "When we had experts like Mike Howard, Dave LeBlanc or Window Snyder in the room, threat modeling worked great." [what are you implying?]
    Also, assuming you were in these rooms observing, you definitely count as an expert in the room!
    #threatmodeling

  26. @adamshostack Always interesting and thought provoking. Isn't 2026-1999 = 27 (not 20 even rounding)? It feels that long ago o me.
    Thanks for the mention too.
    I'd be very interested to learn more about:
    --> "No one knew what quality looked like." [quality software or quality threat models?]
    --> "When we had experts like Mike Howard, Dave LeBlanc or Window Snyder in the room, threat modeling worked great." [what are you implying?]
    Also, assuming you were in these rooms observing, you definitely count as an expert in the room!
    #threatmodeling

  27. I had to structure my knowledge and my thoughts. So I did write an article on Threat Modeling.

    Maybe you find that helpful.

    blog.maschmi.net/threat-modeli

    If you attend the SoCraTes Day Franken tomorrow, you might have the experience of me giving a non-rehearsed talk about this. (Depending on my energy levels). Might be 30 to 120 minutes long 😅

    #threatmodeling #blog #security #softwaredevelopment

  28. I had to structure my knowledge and my thoughts. So I did write an article on Threat Modeling.

    Maybe you find that helpful.

    blog.maschmi.net/threat-modeli

    If you attend the SoCraTes Day Franken tomorrow, you might have the experience of me giving a non-rehearsed talk about this. (Depending on my energy levels). Might be 30 to 120 minutes long 😅

    #threatmodeling #blog #security #softwaredevelopment

  29. Would you like to try out the 25th Anniversary Edition of OWASP Cornucopia? If you do, you may have a chance at winning one. If so, you should get tickets to OWASP Global AppSec 2026 in Vienna: owasp.glueup.com/event/owasp-... #appsec #security #threatmodeling #owasp #games #cornucopia

  30. Someone sent me this package; guess what was inside... Yes, just what you'd expect. The first custom-printed OWASP Cornucopia Website App Edition v3 and Companion Edition v1 decks. youtu.be/dM1J72FY1JQ?... #appsec #owasp #security #games #threatmodeling #cornucopia

    Unboxing OWAPS Cornucopia Webs...

  31. New preprint: AI_Bleeding — inference cost amplification via OOD linguistic payload

    TL;DR: send queries in Grecanico or Farsi to an LLM endpoint → TTFT +59.8%, compute cost +2.8%, statistically significant. No vuln, no volumetric signature, evades all standard detection.

    Worst case: exposed unauthenticated Ollama instance with num_predict=4096 + keep_alive=300s → Amplification Factor 17.56 Wh/KB. 3KB of attacker bandwidth → enough energy to charge a phone 5%.

    Especially nasty for:
    - PA/judicial chatbots on fixed budgets
    - Pay-per-use API deployments with client-side exposed keys
    - PNRR-funded public sector AI with zero inference monitoring

    Four scenarios: EDoS, browser JS distribution, Ollama open-proxy relay, frontier providers as involuntary relays.

    All tests on self-hosted Ollama, no commercial endpoints touched.

    Paper (CC BY 4.0): doi.org/10.13140/RG.2.2.26767.

    #llmsecurity #infosec #threatmodeling #ollama #ood #AI #AIResearch #aisecurity