home.social

#threatmodelling — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatmodelling, aggregated by home.social.

fetched live
  1. "Back in September 2025, we announced an investment in Open Web Docs by the Sovereign Tech Agency to create developer documentation on web security and privacy. This month we've completed the biggest section of the commissioned work: to update the web security documentation on MDN. In this post we'll have a look at what we've added, and what's coming up next.

    The docs we've written for MDN consist of four main pillars: Attacks, Defenses, Threat modeling, and Authentication."

    openwebdocs.org/content/posts/

    #CyberSecurity #WebSecurity #WebDevelopment #ThreatModelling #Authentication

  2. "Back in September 2025, we announced an investment in Open Web Docs by the Sovereign Tech Agency to create developer documentation on web security and privacy. This month we've completed the biggest section of the commissioned work: to update the web security documentation on MDN. In this post we'll have a look at what we've added, and what's coming up next.

    The docs we've written for MDN consist of four main pillars: Attacks, Defenses, Threat modeling, and Authentication."

    openwebdocs.org/content/posts/

    #CyberSecurity #WebSecurity #WebDevelopment #ThreatModelling #Authentication

  3. "Back in September 2025, we announced an investment in Open Web Docs by the Sovereign Tech Agency to create developer documentation on web security and privacy. This month we've completed the biggest section of the commissioned work: to update the web security documentation on MDN. In this post we'll have a look at what we've added, and what's coming up next.

    The docs we've written for MDN consist of four main pillars: Attacks, Defenses, Threat modeling, and Authentication."

    openwebdocs.org/content/posts/

    #CyberSecurity #WebSecurity #WebDevelopment #ThreatModelling #Authentication

  4. "Back in September 2025, we announced an investment in Open Web Docs by the Sovereign Tech Agency to create developer documentation on web security and privacy. This month we've completed the biggest section of the commissioned work: to update the web security documentation on MDN. In this post we'll have a look at what we've added, and what's coming up next.

    The docs we've written for MDN consist of four main pillars: Attacks, Defenses, Threat modeling, and Authentication."

    openwebdocs.org/content/posts/

    #CyberSecurity #WebSecurity #WebDevelopment #ThreatModelling #Authentication

  5. "Back in September 2025, we announced an investment in Open Web Docs by the Sovereign Tech Agency to create developer documentation on web security and privacy. This month we've completed the biggest section of the commissioned work: to update the web security documentation on MDN. In this post we'll have a look at what we've added, and what's coming up next.

    The docs we've written for MDN consist of four main pillars: Attacks, Defenses, Threat modeling, and Authentication."

    openwebdocs.org/content/posts/

    #CyberSecurity #WebSecurity #WebDevelopment #ThreatModelling #Authentication

  6. The OWASP Cornucopia Web App Companion Set, which celebrates 25 years of the Open Web/World Application Security Project (OWASP), can be bought as a high-quality printed duplex deck from cybersecgames.com/collections/

    My name appears in a few places. Being open source, all the data, code and source files are available free online cornucopia.owasp.org

    @owasp #owasp #appsec #threatmodeling #infosec #devsecops #devops #ai #automation #cloud #webapps #cornucopia #threatmodelling #cybersecurity

  7. The OWASP Cornucopia Web App Companion Set, which celebrates 25 years of the Open Web/World Application Security Project (OWASP), can be bought as a high-quality printed duplex deck from cybersecgames.com/collections/

    My name appears in a few places. Being open source, all the data, code and source files are available free online cornucopia.owasp.org

    @owasp #owasp #appsec #threatmodeling #infosec #devsecops #devops #ai #automation #cloud #webapps #cornucopia #threatmodelling #cybersecurity

  8. The OWASP Cornucopia Web App Companion Set, which celebrates 25 years of the Open Web/World Application Security Project (OWASP), can be bought as a high-quality printed duplex deck from cybersecgames.com/collections/

    My name appears in a few places. Being open source, all the data, code and source files are available free online cornucopia.owasp.org

    @owasp #owasp #appsec #threatmodeling #infosec #devsecops #devops #ai #automation #cloud #webapps #cornucopia #threatmodelling #cybersecurity

  9. The OWASP Cornucopia Web App Companion Set, which celebrates 25 years of the Open Web/World Application Security Project (OWASP), can be bought as a high-quality printed duplex deck from cybersecgames.com/collections/

    My name appears in a few places. Being open source, all the data, code and source files are available free online cornucopia.owasp.org

    @owasp #owasp #appsec #threatmodeling #infosec #devsecops #devops #ai #automation #cloud #webapps #cornucopia #threatmodelling #cybersecurity

  10. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  11. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  12. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  13. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  14. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  15. Just received 4 copies of OWASP Cornucopia Web App Companion Set, which celebrates 25 years of The Open Web/World Application Security Project (OWASP). The duplex pack contains a deck of Website App Edition, a deck of the new Companion Edition, and specially-written booklet. All the data, code and source files are available free online cornucopia.owasp.org

    Well done CyberSec Games for doing such a great job printing (and selling) this unique pack.

    #owasp #threatmodelling #appsec @owasp

  16. Just received 4 copies of OWASP Cornucopia Web App Companion Set, which celebrates 25 years of The Open Web/World Application Security Project (OWASP). The duplex pack contains a deck of Website App Edition, a deck of the new Companion Edition, and specially-written booklet. All the data, code and source files are available free online cornucopia.owasp.org

    Well done CyberSec Games for doing such a great job printing (and selling) this unique pack.

    #owasp #threatmodelling #appsec @owasp

  17. Just received 4 copies of OWASP Cornucopia Web App Companion Set, which celebrates 25 years of The Open Web/World Application Security Project (OWASP). The duplex pack contains a deck of Website App Edition, a deck of the new Companion Edition, and specially-written booklet. All the data, code and source files are available free online cornucopia.owasp.org

    Well done CyberSec Games for doing such a great job printing (and selling) this unique pack.

    #owasp #threatmodelling #appsec @owasp

  18. Just received 4 copies of OWASP Cornucopia Web App Companion Set, which celebrates 25 years of The Open Web/World Application Security Project (OWASP). The duplex pack contains a deck of Website App Edition, a deck of the new Companion Edition, and specially-written booklet. All the data, code and source files are available free online cornucopia.owasp.org

    Well done CyberSec Games for doing such a great job printing (and selling) this unique pack.

    #owasp #threatmodelling #appsec @owasp

  19. After five years, The Digital Identity Event Horizon is published in full today: three problem statements, ten key findings, and dozens of recommendations across policy, protocol, legal, and social contexts.

    It's the largest research study in New Design Congress' eight-year history: eight case studies, hundreds of citations, dozens of participants from government, intelligence, civil society, technology, and the field itself.

    It is also, without exaggeration, the most alarming body of work we have ever produced.

    The argument is straightforward and difficult to reckon with: Digital identity makes societies brittle. In 2026, we find ourselves in an era of digital identity fetishism: flawed age verification schemes, biometric and facial-recognition authenticators, and fragile state-backed identity programmes are rolling out at an unprecedented rate. And every one of them, whether current or emerging, remains vulnerable to social engineering. The success rate for a non-technical attack on a user is now three out of four. These attacks cost US companies an estimated $1.6 billion in the five years to 2017 alone; by 2024, fraud runs to hundreds of billions worldwide.

    READ IT HERE newdesigncongress.org/en/repor

    #digitalidentity #privacy #eupol #did #politics #threatmodelling

  20. After five years, The Digital Identity Event Horizon is published in full today: three problem statements, ten key findings, and dozens of recommendations across policy, protocol, legal, and social contexts.

    It's the largest research study in New Design Congress' eight-year history: eight case studies, hundreds of citations, dozens of participants from government, intelligence, civil society, technology, and the field itself.

    It is also, without exaggeration, the most alarming body of work we have ever produced.

    The argument is straightforward and difficult to reckon with: Digital identity makes societies brittle. In 2026, we find ourselves in an era of digital identity fetishism: flawed age verification schemes, biometric and facial-recognition authenticators, and fragile state-backed identity programmes are rolling out at an unprecedented rate. And every one of them, whether current or emerging, remains vulnerable to social engineering. The success rate for a non-technical attack on a user is now three out of four. These attacks cost US companies an estimated $1.6 billion in the five years to 2017 alone; by 2024, fraud runs to hundreds of billions worldwide.

    READ IT HERE newdesigncongress.org/en/repor

    #digitalidentity #privacy #eupol #did #politics #threatmodelling

  21. After five years, The Digital Identity Event Horizon is published in full today: three problem statements, ten key findings, and dozens of recommendations across policy, protocol, legal, and social contexts.

    It's the largest research study in New Design Congress' eight-year history: eight case studies, hundreds of citations, dozens of participants from government, intelligence, civil society, technology, and the field itself.

    It is also, without exaggeration, the most alarming body of work we have ever produced.

    The argument is straightforward and difficult to reckon with: Digital identity makes societies brittle. In 2026, we find ourselves in an era of digital identity fetishism: flawed age verification schemes, biometric and facial-recognition authenticators, and fragile state-backed identity programmes are rolling out at an unprecedented rate. And every one of them, whether current or emerging, remains vulnerable to social engineering. The success rate for a non-technical attack on a user is now three out of four. These attacks cost US companies an estimated $1.6 billion in the five years to 2017 alone; by 2024, fraud runs to hundreds of billions worldwide.

    READ IT HERE newdesigncongress.org/en/repor

    #digitalidentity #privacy #eupol #did #politics #threatmodelling

  22. After five years, The Digital Identity Event Horizon is published in full today: three problem statements, ten key findings, and dozens of recommendations across policy, protocol, legal, and social contexts.

    It's the largest research study in New Design Congress' eight-year history: eight case studies, hundreds of citations, dozens of participants from government, intelligence, civil society, technology, and the field itself.

    It is also, without exaggeration, the most alarming body of work we have ever produced.

    The argument is straightforward and difficult to reckon with: Digital identity makes societies brittle. In 2026, we find ourselves in an era of digital identity fetishism: flawed age verification schemes, biometric and facial-recognition authenticators, and fragile state-backed identity programmes are rolling out at an unprecedented rate. And every one of them, whether current or emerging, remains vulnerable to social engineering. The success rate for a non-technical attack on a user is now three out of four. These attacks cost US companies an estimated $1.6 billion in the five years to 2017 alone; by 2024, fraud runs to hundreds of billions worldwide.

    READ IT HERE newdesigncongress.org/en/repor

    #digitalidentity #privacy #eupol #did #politics #threatmodelling

  23. After five years, The Digital Identity Event Horizon is published in full today: three problem statements, ten key findings, and dozens of recommendations across policy, protocol, legal, and social contexts.

    It's the largest research study in New Design Congress' eight-year history: eight case studies, hundreds of citations, dozens of participants from government, intelligence, civil society, technology, and the field itself.

    It is also, without exaggeration, the most alarming body of work we have ever produced.

    The argument is straightforward and difficult to reckon with: Digital identity makes societies brittle. In 2026, we find ourselves in an era of digital identity fetishism: flawed age verification schemes, biometric and facial-recognition authenticators, and fragile state-backed identity programmes are rolling out at an unprecedented rate. And every one of them, whether current or emerging, remains vulnerable to social engineering. The success rate for a non-technical attack on a user is now three out of four. These attacks cost US companies an estimated $1.6 billion in the five years to 2017 alone; by 2024, fraud runs to hundreds of billions worldwide.

    READ IT HERE newdesigncongress.org/en/repor

    #digitalidentity #privacy #eupol #did #politics #threatmodelling

  24. DBD Cornucopia is now available for teams to play online. Free to use, no registration, no tracking.

    Thank you Adarsh Kumar @Adarshkumar0509 from OWASP Cornucopia (open source security threat modelling of software) for adding Digital Benefits and Disbenefits Cornucopia to their Copi online gaming engine.

    copi.owasp.org/

    #welfarebenefits #socialprotection #egovernment #servicedesign #threatmodelling #harms #hci

  25. DBD Cornucopia is now available for teams to play online. Free to use, no registration, no tracking.

    Thank you Adarsh Kumar @Adarshkumar0509 from OWASP Cornucopia (open source security threat modelling of software) for adding Digital Benefits and Disbenefits Cornucopia to their Copi online gaming engine.

    copi.owasp.org/

    #welfarebenefits #socialprotection #egovernment #servicedesign #threatmodelling #harms #hci

  26. DBD Cornucopia is now available for teams to play online. Free to use, no registration, no tracking.

    Thank you Adarsh Kumar @Adarshkumar0509 from OWASP Cornucopia (open source security threat modelling of software) for adding Digital Benefits and Disbenefits Cornucopia to their Copi online gaming engine.

    copi.owasp.org/

    #welfarebenefits #socialprotection #egovernment #servicedesign #threatmodelling #harms #hci

  27. 📆 15-17 June 2026

    As part of the @webhackfest, W3C has proposed a breakout session to collaboratively map the Web Security Model, including components, assumptions, trust boundaries, and responsibilities of the Web Platform, with the output feeding the Threat Model for the Web and future security-by-design boilerplate for Web APIs.
    w3.org/events/talks/2026/web-s
    #WebHackfest #WebStandards #WebSecurity #ThreatModelling

  28. 📆 15-17 June 2026

    As part of the @webhackfest, W3C has proposed a breakout session to collaboratively map the Web Security Model, including components, assumptions, trust boundaries, and responsibilities of the Web Platform, with the output feeding the Threat Model for the Web and future security-by-design boilerplate for Web APIs.
    w3.org/events/talks/2026/web-s
    #WebHackfest #WebStandards #WebSecurity #ThreatModelling

  29. 📆 15-17 June 2026

    As part of the @webhackfest, W3C has proposed a breakout session to collaboratively map the Web Security Model, including components, assumptions, trust boundaries, and responsibilities of the Web Platform, with the output feeding the Threat Model for the Web and future security-by-design boilerplate for Web APIs.
    w3.org/events/talks/2026/web-s
    #WebHackfest #WebStandards #WebSecurity #ThreatModelling

  30. 📆 15-17 June 2026

    As part of the @webhackfest, W3C has proposed a breakout session to collaboratively map the Web Security Model, including components, assumptions, trust boundaries, and responsibilities of the Web Platform, with the output feeding the Threat Model for the Web and future security-by-design boilerplate for Web APIs.
    w3.org/events/talks/2026/web-s
    #WebHackfest #WebStandards #WebSecurity #ThreatModelling

  31. 📆 15-17 June 2026

    As part of the @webhackfest, W3C has proposed a breakout session to collaboratively map the Web Security Model, including components, assumptions, trust boundaries, and responsibilities of the Web Platform, with the output feeding the Threat Model for the Web and future security-by-design boilerplate for Web APIs.
    w3.org/events/talks/2026/web-s
    #WebHackfest #WebStandards #WebSecurity #ThreatModelling

  32. Very pleased to see the way the new OWASP Cornucopia Companion Edition software threat-modelling game deck looks in print. Thanks to all the volunteers who created it, and made this release happen.

    Source data and print-ready files available for free in the project repository // Play for free online // Print your own decks // Buy professionally-printed decks.

    cornucopia.owasp.org/news/2026

    #owasp #threatmodelling #appsec #devops #software #devsecops @owasp

    OWASP Cornucopia, first created in 2012

  33. Very pleased to see the way the new OWASP Cornucopia Companion Edition software threat-modelling game deck looks in print. Thanks to all the volunteers who created it, and made this release happen.

    Source data and print-ready files available for free in the project repository // Play for free online // Print your own decks // Buy professionally-printed decks.

    cornucopia.owasp.org/news/2026

    #owasp #threatmodelling #appsec #devops #software #devsecops @owasp

    OWASP Cornucopia, first created in 2012

  34. Very pleased to see the way the new OWASP Cornucopia Companion Edition software threat-modelling game deck looks in print. Thanks to all the volunteers who created it, and made this release happen.

    Source data and print-ready files available for free in the project repository // Play for free online // Print your own decks // Buy professionally-printed decks.

    cornucopia.owasp.org/news/2026

    #owasp #threatmodelling #appsec #devops #software #devsecops @owasp

    OWASP Cornucopia, first created in 2012

  35. Very pleased to see the way the new OWASP Cornucopia Companion Edition software threat-modelling game deck looks in print. Thanks to all the volunteers who created it, and made this release happen.

    Source data and print-ready files available for free in the project repository // Play for free online // Print your own decks // Buy professionally-printed decks.

    cornucopia.owasp.org/news/2026

    #owasp #threatmodelling #appsec #devops #software #devsecops @owasp

    OWASP Cornucopia, first created in 2012

  36. Very pleased to see the way the new OWASP Cornucopia Companion Edition software threat-modelling game deck looks in print. Thanks to all the volunteers who created it, and made this release happen.

    Source data and print-ready files available for free in the project repository // Play for free online // Print your own decks // Buy professionally-printed decks.

    cornucopia.owasp.org/news/2026

    #owasp #threatmodelling #appsec #devops #software #devsecops @owasp

    OWASP Cornucopia, first created in 2012

  37. Could something be skipping though the "customer interaction" points in your application?

    BOT3 from the OWASP Cornucopia Companion illustrates how automation at scale can be used on gambling sites to make bets fast & furiously, skipping past all the checks and balances, warnings, up-selling and regulatory information.

    Read the whole scenario at cornucopia.owasp.org/edition/c

    Details of new release at cornucopia.owasp.org/news/2026

    @owasp #appsec #devops #devsecops #threatmodelling #eop #owasp #cornucopia

  38. Could something be skipping though the "customer interaction" points in your application?

    BOT3 from the OWASP Cornucopia Companion illustrates how automation at scale can be used on gambling sites to make bets fast & furiously, skipping past all the checks and balances, warnings, up-selling and regulatory information.

    Read the whole scenario at cornucopia.owasp.org/edition/c

    Details of new release at cornucopia.owasp.org/news/2026

    @owasp #appsec #devops #devsecops #threatmodelling #eop #owasp #cornucopia

  39. Could something be skipping though the "customer interaction" points in your application?

    BOT3 from the OWASP Cornucopia Companion illustrates how automation at scale can be used on gambling sites to make bets fast & furiously, skipping past all the checks and balances, warnings, up-selling and regulatory information.

    Read the whole scenario at cornucopia.owasp.org/edition/c

    Details of new release at cornucopia.owasp.org/news/2026

    @owasp #appsec #devops #devsecops #threatmodelling #eop #owasp #cornucopia

  40. Could something be skipping though the "customer interaction" points in your application?

    BOT3 from the OWASP Cornucopia Companion illustrates how automation at scale can be used on gambling sites to make bets fast & furiously, skipping past all the checks and balances, warnings, up-selling and regulatory information.

    Read the whole scenario at cornucopia.owasp.org/edition/c

    Details of new release at cornucopia.owasp.org/news/2026

    @owasp #appsec #devops #devsecops #threatmodelling #eop #owasp #cornucopia

  41. Could something be skipping though the "customer interaction" points in your application?

    BOT3 from the OWASP Cornucopia Companion illustrates how automation at scale can be used on gambling sites to make bets fast & furiously, skipping past all the checks and balances, warnings, up-selling and regulatory information.

    Read the whole scenario at cornucopia.owasp.org/edition/c

    Details of new release at cornucopia.owasp.org/news/2026

    @owasp #appsec #devops #devsecops #threatmodelling #eop #owasp #cornucopia

  42. Open source and free. Download print-ready files and play Cornucopia together, browse the cards online, or play games online with remote team members.

    cornucopia.owasp.org

    copi.owasp.org

    If you prefer, printed decks are available to purchase from a vendor as a dual-packaged Website App Edition x Companion Edition combination set:

    cybersecgames.com/pages/owasp-

    @owasp #owasp #cornucopia #eop #stride #threatmodelling #devops #devopsec #appsec #infosec

    2/2

  43. Open source and free. Download print-ready files and play Cornucopia together, browse the cards online, or play games online with remote team members.

    cornucopia.owasp.org

    copi.owasp.org

    If you prefer, printed decks are available to purchase from a vendor as a dual-packaged Website App Edition x Companion Edition combination set:

    cybersecgames.com/pages/owasp-

    @owasp #owasp #cornucopia #eop #stride #threatmodelling #devops #devopsec #appsec #infosec

    2/2

  44. Open source and free. Download print-ready files and play Cornucopia together, browse the cards online, or play games online with remote team members.

    cornucopia.owasp.org

    copi.owasp.org

    If you prefer, printed decks are available to purchase from a vendor as a dual-packaged Website App Edition x Companion Edition combination set:

    cybersecgames.com/pages/owasp-

    @owasp #owasp #cornucopia #eop #stride #threatmodelling #devops #devopsec #appsec #infosec

    2/2

  45. Open source and free. Download print-ready files and play Cornucopia together, browse the cards online, or play games online with remote team members.

    cornucopia.owasp.org

    copi.owasp.org

    If you prefer, printed decks are available to purchase from a vendor as a dual-packaged Website App Edition x Companion Edition combination set:

    cybersecgames.com/pages/owasp-

    @owasp #owasp #cornucopia #eop #stride #threatmodelling #devops #devopsec #appsec #infosec

    2/2

  46. Open source and free. Download print-ready files and play Cornucopia together, browse the cards online, or play games online with remote team members.

    cornucopia.owasp.org

    copi.owasp.org

    If you prefer, printed decks are available to purchase from a vendor as a dual-packaged Website App Edition x Companion Edition combination set:

    cybersecgames.com/pages/owasp-

    @owasp #owasp #cornucopia #eop #stride #threatmodelling #devops #devopsec #appsec #infosec

    2/2

  47. The new Companion Deck for OWASP Cornucopia includes six novel suits to assist threat modelling of Agentic AI, Cloud, DevOps, Frontend, LLM and Automation. The suits can be used alone or in combination with suits from either existing Cornucopia decks: the Website App Edition or Mobile App Edition. My main contribution to this is the Automated Threats (BOT) suit.

    cornucopia.owasp.org/news/2026

    @owasp #owasp #cornucopia #eop #stride #threatmodelling #devops #devopsec #appsec #infosec

    1/2

  48. The new Companion Deck for OWASP Cornucopia includes six novel suits to assist threat modelling of Agentic AI, Cloud, DevOps, Frontend, LLM and Automation. The suits can be used alone or in combination with suits from either existing Cornucopia decks: the Website App Edition or Mobile App Edition. My main contribution to this is the Automated Threats (BOT) suit.

    cornucopia.owasp.org/news/2026

    @owasp #owasp #cornucopia #eop #stride #threatmodelling #devops #devopsec #appsec #infosec

    1/2

  49. The new Companion Deck for OWASP Cornucopia includes six novel suits to assist threat modelling of Agentic AI, Cloud, DevOps, Frontend, LLM and Automation. The suits can be used alone or in combination with suits from either existing Cornucopia decks: the Website App Edition or Mobile App Edition. My main contribution to this is the Automated Threats (BOT) suit.

    cornucopia.owasp.org/news/2026

    @owasp #owasp #cornucopia #eop #stride #threatmodelling #devops #devopsec #appsec #infosec

    1/2

  50. The new Companion Deck for OWASP Cornucopia includes six novel suits to assist threat modelling of Agentic AI, Cloud, DevOps, Frontend, LLM and Automation. The suits can be used alone or in combination with suits from either existing Cornucopia decks: the Website App Edition or Mobile App Edition. My main contribution to this is the Automated Threats (BOT) suit.

    cornucopia.owasp.org/news/2026

    @owasp #owasp #cornucopia #eop #stride #threatmodelling #devops #devopsec #appsec #infosec

    1/2

  51. The new Companion Deck for OWASP Cornucopia includes six novel suits to assist threat modelling of Agentic AI, Cloud, DevOps, Frontend, LLM and Automation. The suits can be used alone or in combination with suits from either existing Cornucopia decks: the Website App Edition or Mobile App Edition. My main contribution to this is the Automated Threats (BOT) suit.

    cornucopia.owasp.org/news/2026

    @owasp #owasp #cornucopia #eop #stride #threatmodelling #devops #devopsec #appsec #infosec

    1/2

  52. Great to see the new Companion Edition released by the OWASP Cornucopia project. A year in the making, project leader Johan Sydseter has organised a whole group of volunteers to build out a new deck of playing cards for the application security threat modelling card game.

    The new deck with six new suits also celebrates the 25th anniversary of the Open Worldwide Application Security Project (OWASP).

    cornucopia.owasp.org/news/2026

    @owasp @sydseter #appsec #devops #devsecops #threatmodelling #owasp

  53. Great to see the new Companion Edition released by the OWASP Cornucopia project. A year in the making, project leader Johan Sydseter has organised a whole group of volunteers to build out a new deck of playing cards for the application security threat modelling card game.

    The new deck with six new suits also celebrates the 25th anniversary of the Open Worldwide Application Security Project (OWASP).

    cornucopia.owasp.org/news/2026

    @owasp @sydseter #appsec #devops #devsecops #threatmodelling #owasp

  54. Great to see the new Companion Edition released by the OWASP Cornucopia project. A year in the making, project leader Johan Sydseter has organised a whole group of volunteers to build out a new deck of playing cards for the application security threat modelling card game.

    The new deck with six new suits also celebrates the 25th anniversary of the Open Worldwide Application Security Project (OWASP).

    cornucopia.owasp.org/news/2026

    @owasp @sydseter #appsec #devops #devsecops #threatmodelling #owasp

  55. Great to see the new Companion Edition released by the OWASP Cornucopia project. A year in the making, project leader Johan Sydseter has organised a whole group of volunteers to build out a new deck of playing cards for the application security threat modelling card game.

    The new deck with six new suits also celebrates the 25th anniversary of the Open Worldwide Application Security Project (OWASP).

    cornucopia.owasp.org/news/2026

    @owasp @sydseter #appsec #devops #devsecops #threatmodelling #owasp

  56. Great to see the new Companion Edition released by the OWASP Cornucopia project. A year in the making, project leader Johan Sydseter has organised a whole group of volunteers to build out a new deck of playing cards for the application security threat modelling card game.

    The new deck with six new suits also celebrates the 25th anniversary of the Open Worldwide Application Security Project (OWASP).

    cornucopia.owasp.org/news/2026

    @owasp @sydseter #appsec #devops #devsecops #threatmodelling #owasp