home.social

#threatmodeling — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatmodeling, aggregated by home.social.

  1. "Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.

    CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.

    postquantum.com/post-quantum/c

    #threatmodeling #CRQC #infosec #PQC

  2. "Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.

    CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.

    postquantum.com/post-quantum/c

    #threatmodeling #CRQC #infosec #PQC

  3. Spend a half-day learning about threat modeling with AI at TechBash 2026! 4-day attendees choose their workshop track. Check out this year's options at techbash.com/

    Save 12% on standard registration thru 7/31 with code SUMMERSALE

    #ai #security #threatmodeling #workshops #devconf #poconos

  4. Spend a half-day learning about threat modeling with AI at TechBash 2026! 4-day attendees choose their workshop track. Check out this year's options at techbash.com/

    Save 12% on standard registration thru 7/31 with code SUMMERSALE

    #ai #security #threatmodeling #workshops #devconf #poconos

  5. For parents in the digital age, physical security protocols require a threat-modeling update.

    Legacy "stranger danger" paradigms fail against modern social engineering tactics. We must teach children to recognize behavioral anomalies rather than physical profiles.

    Implement an offline, zero-knowledge family verification token (code word) to secure pick-up vectors.

    Full documentation and actionable framework: securelylife.com/modern-strang

    #FamilySafety #InfoSec #ThreatModeling #ParentingTips

  6. The OWASP Cornucopia Web App Companion Set, which celebrates 25 years of the Open Web/World Application Security Project (OWASP), can be bought as a high-quality printed duplex deck from cybersecgames.com/collections/

    My name appears in a few places. Being open source, all the data, code and source files are available free online cornucopia.owasp.org

    @owasp #owasp #appsec #threatmodeling #infosec #devsecops #devops #ai #automation #cloud #webapps #cornucopia #threatmodelling #cybersecurity

  7. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  8. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  9. OWASP Cornucopia just released v3.2.2 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for adding DBD Cornucopia to copi.owasp.org and for providing various bugfixes for the project. Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

    Release Release v3.2.2 · OWASP...

  10. OWASP Cornucopia just released v3.2.2 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for adding DBD Cornucopia to copi.owasp.org and for providing various bugfixes for the project. Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

    Release Release v3.2.2 · OWASP...

  11. OWASP Cornucopia just released v3.2.3 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for adding DBD Cornucopia to cooi.owasp.org and for providing various bugfixes for the project. Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

    Release Release v3.2.2 · OWASP...

  12. OWASP Cornucopia just released v3.2.3 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for adding DBD Cornucopia to cooi.owasp.org and for providing various bugfixes for the project. Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

    Release Release v3.2.2 · OWASP...

  13. The risk in AI skill managers isn't theoretical. A compromised skill file could instruct an agent to exfiltrate credentials or execute shell commands under the user's own permissions. Yet most managers treat skills like inert config rather than executable intent. The threat model needs to shift. implicator.ai/ai-agent-skill-m #AI #threatmodeling #infosec

  14. The risk in AI skill managers isn't theoretical. A compromised skill file could instruct an agent to exfiltrate credentials or execute shell commands under the user's own permissions. Yet most managers treat skills like inert config rather than executable intent. The threat model needs to shift. implicator.ai/ai-agent-skill-m #AI #threatmodeling #infosec

  15. 🎥 Watch this short video to learn more about Vikramaditya Narayan's talk: AI and the Threat Modeling Manifesto: Conflicts, Failure Modes, and Better Patterns, taking place on Thursday, 25 June at OWASP Global AppSec Vienna.

    owaspglobalappseceuvienna20.sc

    #OWASPVienna26 #GlobalAppSec26 #threatmodeling

  16. 🎥 Watch this short video to learn more about Vikramaditya Narayan's talk: AI and the Threat Modeling Manifesto: Conflicts, Failure Modes, and Better Patterns, taking place on Thursday, 25 June at OWASP Global AppSec Vienna.

    owaspglobalappseceuvienna20.sc

    #OWASPVienna26 #GlobalAppSec26 #threatmodeling

  17. OWASP Cornucopia just released v3.1.6 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for doing a redesign of the OWASP Cornucopia website (cornucopia.owasp.org). It looks really cool! Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

  18. OWASP Cornucopia just released v3.1.6 github.com/OWASP/cornuc... A Special thanks to Adarsh Kumar for doing a redesign of the OWASP Cornucopia website (cornucopia.owasp.org). It looks really cool! Thank you so much for all your help! #cornucopia #website #threatmodeling #appsec #games #security

  19. It's done. Just gave a talk about Threat Modeling at the SoCraTes Day Franken.

    Thank you for your feedback, finding my typos and being my test audience 🙏

    You can find most and more information in this recent article blog.maschmi.net/threat-modeli.

    The PDFs for the slides are here: codeberg.org/maschmi/talk-thre

    #SoCraTesFranken #threatmodeling #softwareengineering

  20. It's done. Just gave a talk about Threat Modeling at the SoCraTes Day Franken.

    Thank you for your feedback, finding my typos and being my test audience 🙏

    You can find most and more information in this recent article blog.maschmi.net/threat-modeli.

    The PDFs for the slides are here: codeberg.org/maschmi/talk-thre

    #SoCraTesFranken #threatmodeling #softwareengineering

  21. It's done. Just gave a talk about Threat Modeling at the SoCraTes Day Franken.

    Thank you all for the for feedback and finding my typos :) And also for being my test audience.

    Find me if you want to discuss it, give feedback or talk a bit more.

    You can find most and more information in this recent article blog.maschmi.net/threat-modeli.

    The PDFs for the slides are here: codeberg.org/maschmi/talk-thre

    #SoCraTesFranken #threatmodeling #softwareengineering

  22. It's done. Just gave a talk about Threat Modeling at the SoCraTes Day Franken.

    Thank you all for the for feedback and finding my typos :) And also for being my test audience.

    Find me if you want to discuss it, give feedback or talk a bit more.

    You can find most and more information in this recent article blog.maschmi.net/threat-modeli.

    The PDFs for the slides are here: codeberg.org/maschmi/talk-thre

    #SoCraTesFranken #threatmodeling #softwareengineering

  23. @adamshostack Always interesting and thought provoking. Isn't 2026-1999 = 27 (not 20 even rounding)? It feels that long ago o me.
    Thanks for the mention too.
    I'd be very interested to learn more about:
    --> "No one knew what quality looked like." [quality software or quality threat models?]
    --> "When we had experts like Mike Howard, Dave LeBlanc or Window Snyder in the room, threat modeling worked great." [what are you implying?]
    Also, assuming you were in these rooms observing, you definitely count as an expert in the room!
    #threatmodeling

  24. @adamshostack Always interesting and thought provoking. Isn't 2026-1999 = 27 (not 20 even rounding)? It feels that long ago o me.
    Thanks for the mention too.
    I'd be very interested to learn more about:
    --> "No one knew what quality looked like." [quality software or quality threat models?]
    --> "When we had experts like Mike Howard, Dave LeBlanc or Window Snyder in the room, threat modeling worked great." [what are you implying?]
    Also, assuming you were in these rooms observing, you definitely count as an expert in the room!
    #threatmodeling

  25. I had to structure my knowledge and my thoughts. So I did write an article on Threat Modeling.

    Maybe you find that helpful.

    blog.maschmi.net/threat-modeli

    If you attend the SoCraTes Day Franken tomorrow, you might have the experience of me giving a non-rehearsed talk about this. (Depending on my energy levels). Might be 30 to 120 minutes long 😅

    #threatmodeling #blog #security #softwaredevelopment

  26. I had to structure my knowledge and my thoughts. So I did write an article on Threat Modeling.

    Maybe you find that helpful.

    blog.maschmi.net/threat-modeli

    If you attend the SoCraTes Day Franken tomorrow, you might have the experience of me giving a non-rehearsed talk about this. (Depending on my energy levels). Might be 30 to 120 minutes long 😅

    #threatmodeling #blog #security #softwaredevelopment

  27. Would you like to try out the 25th Anniversary Edition of OWASP Cornucopia? If you do, you may have a chance at winning one. If so, you should get tickets to OWASP Global AppSec 2026 in Vienna: owasp.glueup.com/event/owasp-... #appsec #security #threatmodeling #owasp #games #cornucopia

  28. Would you like to try out the 25th Anniversary Edition of OWASP Cornucopia? If you do, you may have a chance at winning one. If so, you should get tickets to OWASP Global AppSec 2026 in Vienna: owasp.glueup.com/event/owasp-... #appsec #security #threatmodeling #owasp #games #cornucopia

  29. Someone sent me this package; guess what was inside... Yes, just what you'd expect. The first custom-printed OWASP Cornucopia Website App Edition v3 and Companion Edition v1 decks. youtu.be/dM1J72FY1JQ?... #appsec #owasp #security #games #threatmodeling #cornucopia

    Unboxing OWAPS Cornucopia Webs...

  30. New preprint: AI_Bleeding — inference cost amplification via OOD linguistic payload

    TL;DR: send queries in Grecanico or Farsi to an LLM endpoint → TTFT +59.8%, compute cost +2.8%, statistically significant. No vuln, no volumetric signature, evades all standard detection.

    Worst case: exposed unauthenticated Ollama instance with num_predict=4096 + keep_alive=300s → Amplification Factor 17.56 Wh/KB. 3KB of attacker bandwidth → enough energy to charge a phone 5%.

    Especially nasty for:
    - PA/judicial chatbots on fixed budgets
    - Pay-per-use API deployments with client-side exposed keys
    - PNRR-funded public sector AI with zero inference monitoring

    Four scenarios: EDoS, browser JS distribution, Ollama open-proxy relay, frontier providers as involuntary relays.

    All tests on self-hosted Ollama, no commercial endpoints touched.

    Paper (CC BY 4.0): doi.org/10.13140/RG.2.2.26767.

    #llmsecurity #infosec #threatmodeling #ollama #ood #AI #AIResearch #aisecurity

  31. Yes! It’s time to party! The OWASP Foundation is celebrating 25 incredible years of open source security. That’s why OWASP Cornucopia is launching its 25th anniversary edition. #appsec #security #owasp #cornucopia #llm #agentic_ai #devops #cloud #frontend #threatmodeling

  32. Yes! It’s time to party! The OWASP Foundation is celebrating 25 incredible years of open source security. That’s why OWASP Cornucopia is launching its 25th anniversary edition. #appsec #security #owasp #cornucopia #llm #agentic_ai #devops #cloud #frontend #threatmodeling

  33. AI service reliability incident.
    Anthropic confirmed elevated error rates across Claude platforms, including API workloads, with repeated fix-and-monitor cycles.

    Operational impact:
    • Request failures
    • Increased latency
    • Model instability
    • Recurrent degradation events
    Third-party AI concentration risk is now a measurable availability threat vector.

    Key architectural considerations:
    Multi-provider abstraction layers
    Graceful degradation modes
    SLA-backed enterprise contracts
    On-prem or hybrid inference models
    Real-time outage monitoring integration
    Is AI dependency now part of your business continuity and disaster recovery planning?
    Engage below.

    Follow TechNadu for AI operations, resilience engineering, and cybersecurity reporting.

    Source: bleepingcomputer.com/news/arti

    Repost to inform your network.

    #Infosec #AIOps #LLMReliability #CloudRisk #ServiceResilience #DisasterRecovery #APIManagement #EnterpriseAI #CyberResilience #TechInfrastructure #ThreatModeling

  34. AI service reliability incident.
    Anthropic confirmed elevated error rates across Claude platforms, including API workloads, with repeated fix-and-monitor cycles.

    Operational impact:
    • Request failures
    • Increased latency
    • Model instability
    • Recurrent degradation events
    Third-party AI concentration risk is now a measurable availability threat vector.

    Key architectural considerations:
    Multi-provider abstraction layers
    Graceful degradation modes
    SLA-backed enterprise contracts
    On-prem or hybrid inference models
    Real-time outage monitoring integration
    Is AI dependency now part of your business continuity and disaster recovery planning?
    Engage below.

    Follow TechNadu for AI operations, resilience engineering, and cybersecurity reporting.

    Source: bleepingcomputer.com/news/arti

    Repost to inform your network.

    #Infosec #AIOps #LLMReliability #CloudRisk #ServiceResilience #DisasterRecovery #APIManagement #EnterpriseAI #CyberResilience #TechInfrastructure #ThreatModeling

  35. AI service reliability incident.
    Anthropic confirmed elevated error rates across Claude platforms, including API workloads, with repeated fix-and-monitor cycles.

    Operational impact:
    • Request failures
    • Increased latency
    • Model instability
    • Recurrent degradation events
    Third-party AI concentration risk is now a measurable availability threat vector.

    Key architectural considerations:
    Multi-provider abstraction layers
    Graceful degradation modes
    SLA-backed enterprise contracts
    On-prem or hybrid inference models
    Real-time outage monitoring integration
    Is AI dependency now part of your business continuity and disaster recovery planning?
    Engage below.

    Follow TechNadu for AI operations, resilience engineering, and cybersecurity reporting.

    Source: bleepingcomputer.com/news/arti

    Repost to inform your network.

    #Infosec #AIOps #LLMReliability #CloudRisk #ServiceResilience #DisasterRecovery #APIManagement #EnterpriseAI #CyberResilience #TechInfrastructure #ThreatModeling

  36. AI service reliability incident.
    Anthropic confirmed elevated error rates across Claude platforms, including API workloads, with repeated fix-and-monitor cycles.

    Operational impact:
    • Request failures
    • Increased latency
    • Model instability
    • Recurrent degradation events
    Third-party AI concentration risk is now a measurable availability threat vector.

    Key architectural considerations:
    Multi-provider abstraction layers
    Graceful degradation modes
    SLA-backed enterprise contracts
    On-prem or hybrid inference models
    Real-time outage monitoring integration
    Is AI dependency now part of your business continuity and disaster recovery planning?
    Engage below.

    Follow TechNadu for AI operations, resilience engineering, and cybersecurity reporting.

    Source: bleepingcomputer.com/news/arti

    Repost to inform your network.

    #Infosec #AIOps #LLMReliability #CloudRisk #ServiceResilience #DisasterRecovery #APIManagement #EnterpriseAI #CyberResilience #TechInfrastructure #ThreatModeling

  37. Policy development with cybersecurity implications.

    Florida’s proposed HB 945 would establish a state-level operational intelligence unit with authority extending into threat identification and counterintelligence.

    Risk dimensions:
    • Expansion of state-run surveillance infrastructure
    • Ideology-based scrutiny concerns
    • Potential inter-state policy replication
    • Oversight ambiguity and governance design challenges
    • Broader digital monitoring implications
    Security professionals understand that surveillance architecture, once normalized, rarely contracts.

    From a risk modeling perspective:
    What controls, auditability mechanisms, and transparency frameworks would be required to prevent mission creep?

    Source: theguardian.com/commentisfree/

    Engage below.
    Follow TechNadu for cybersecurity law, digital rights, and governance analysis.
    Repost to elevate the discussion within the security community.

    #Infosec #CyberPolicy #SurveillanceRisk #Governance #PrivacyEngineering #SecurityArchitecture #DigitalRights #FirstAmendment #NationalSecurity #Compliance #ThreatModeling #PublicSectorSecurity

  38. Policy development with cybersecurity implications.

    Florida’s proposed HB 945 would establish a state-level operational intelligence unit with authority extending into threat identification and counterintelligence.

    Risk dimensions:
    • Expansion of state-run surveillance infrastructure
    • Ideology-based scrutiny concerns
    • Potential inter-state policy replication
    • Oversight ambiguity and governance design challenges
    • Broader digital monitoring implications
    Security professionals understand that surveillance architecture, once normalized, rarely contracts.

    From a risk modeling perspective:
    What controls, auditability mechanisms, and transparency frameworks would be required to prevent mission creep?

    Source: theguardian.com/commentisfree/

    Engage below.
    Follow TechNadu for cybersecurity law, digital rights, and governance analysis.
    Repost to elevate the discussion within the security community.

    #Infosec #CyberPolicy #SurveillanceRisk #Governance #PrivacyEngineering #SecurityArchitecture #DigitalRights #FirstAmendment #NationalSecurity #Compliance #ThreatModeling #PublicSectorSecurity

  39. Policy development with cybersecurity implications.

    Florida’s proposed HB 945 would establish a state-level operational intelligence unit with authority extending into threat identification and counterintelligence.

    Risk dimensions:
    • Expansion of state-run surveillance infrastructure
    • Ideology-based scrutiny concerns
    • Potential inter-state policy replication
    • Oversight ambiguity and governance design challenges
    • Broader digital monitoring implications
    Security professionals understand that surveillance architecture, once normalized, rarely contracts.

    From a risk modeling perspective:
    What controls, auditability mechanisms, and transparency frameworks would be required to prevent mission creep?

    Source: theguardian.com/commentisfree/

    Engage below.
    Follow TechNadu for cybersecurity law, digital rights, and governance analysis.
    Repost to elevate the discussion within the security community.

    #Infosec #CyberPolicy #SurveillanceRisk #Governance #PrivacyEngineering #SecurityArchitecture #DigitalRights #FirstAmendment #NationalSecurity #Compliance #ThreatModeling #PublicSectorSecurity

  40. Policy development with cybersecurity implications.

    Florida’s proposed HB 945 would establish a state-level operational intelligence unit with authority extending into threat identification and counterintelligence.

    Risk dimensions:
    • Expansion of state-run surveillance infrastructure
    • Ideology-based scrutiny concerns
    • Potential inter-state policy replication
    • Oversight ambiguity and governance design challenges
    • Broader digital monitoring implications
    Security professionals understand that surveillance architecture, once normalized, rarely contracts.

    From a risk modeling perspective:
    What controls, auditability mechanisms, and transparency frameworks would be required to prevent mission creep?

    Source: theguardian.com/commentisfree/

    Engage below.
    Follow TechNadu for cybersecurity law, digital rights, and governance analysis.
    Repost to elevate the discussion within the security community.

    #Infosec #CyberPolicy #SurveillanceRisk #Governance #PrivacyEngineering #SecurityArchitecture #DigitalRights #FirstAmendment #NationalSecurity #Compliance #ThreatModeling #PublicSectorSecurity

  41. CVE-2026-21902 represents a high-impact infrastructure exposure.

    Affected platform: Junos OS Evolved on PTX series routers.

    Attack vector: Unauthenticated network access.
    Privilege level: Root execution.
    Service: On-Box Anomaly Detection, enabled by default.

    Strategic risk:
    • Traffic interception capability
    • Policy manipulation
    • Controller redirection
    • Lateral pivoting
    • Long-term foothold persistence
    Although no exploitation has been observed, historically, high-performance routing infrastructure is a prime target due to its control-plane visibility and network centrality.

    Recommended actions:
    – Immediate patch validation
    – Control-plane traffic monitoring
    – Service exposure review
    – Network segmentation validation
    – Threat hunting for anomalous routing behavior
    Are infrastructure devices integrated into your continuous detection engineering pipeline?

    Source: securityweek.com/juniper-netwo

    Engage below.
    Follow TechNadu for high-signal vulnerability intelligence.
    Repost to strengthen security awareness.

    #Infosec #CVE2026 #Juniper #RouterSecurity #CriticalInfrastructure #ThreatModeling #DetectionEngineering #NetworkDefense #ZeroTrustArchitecture #CyberRisk #SecurityOperations #VulnerabilityManagement