🔍 Kennst du die Angriffspfade deines Systems?
Threat Modeling hilft dir, Vertrauensgrenzen, Abhängigkeiten und Risiken früh sichtbar zu machen und passende Security Controls abzuleiten.
🎓 Jetzt im neuen Kurs lernen:
https://f.mtr.cool/7rovitj1x1

[THREAT] Identified threat: Finance pays invoices on emailed PDFs without out-of-band confirmation [RESPONSE] Dev/management: CVSS is only 6.8. We focus on 9+. #threatmodeling #infosec
[THREAT] Identified threat: Session ID is not rotated after login, enabling fixation attacks [RESPONSE] Dev/management: If something breaks, we'll do a blameless post-mortem. #threatmodeling #infosec
🔍 Kennst du die Angriffspfade deines Systems?
Threat Modeling hilft dir, Vertrauensgrenzen, Abhängigkeiten und Risiken früh sichtbar zu machen und passende Security Controls abzuleiten.
🎓 Jetzt im neuen Kurs lernen:
https://f.mtr.cool/7rovitj1x1
[THREAT] Identified threat: Backups have not been test-restored since the runbook was written [RESPONSE] Dev/management: If something breaks, we'll do a blameless post-mortem. #threatmodeling #infosec
[THREAT] Identified threat: Multifunction printer stores scanned documents on an open SMB share [RESPONSE] Dev/management: We have a PR firm on retainer for that scenario. #threatmodeling #infosec
El lado del mal - SANS x Cloudflare Lisboa: 28 de Octubre www.elladodelmal.com/2026/10/sans... #Cloudflare #SANS #AI #IA #ThreatModeling #ArtificialIntelligence #Hacking #Lisboa #Event ¿Tenías ganas de visitar Lisboa? Ven a vernos a Cloudflare Portugal.
A multi-agent framework uses an LLM to perform design-time security review from requirements and architecture inputs, producing attack trees and mitigation recommendations without retrieving from CWE databases…
#AIsecurity #LLMagents #ThreatModeling #CyberDefense
https://arxiv.org/abs/2610.03820
[THREAT] Identified threat: MQTT broker accepts anonymous connections to all device topics [RESPONSE] Dev/management: We've discussed it with leadership and accepted the risk. #threatmodeling #infosec
Researchers propose CVE2AP, an LLM-based method that automatically generates PDDL-encoded attack paths from natural-language CVE descriptions, aiming to scale up formal cybersecurity analysis.
#cybersecurity #AIsecurity #threatmodeling #LLM
https://arxiv.org/abs/2610.03383
[THREAT] Identified threat: Bastion allows SSH password auth as root from anywhere on the internet [RESPONSE] Dev/management: Traffic is low enough that no one will notice. #threatmodeling #infosec
[THREAT] Identified threat: TLS 1.0 still enabled on the customer login endpoint [RESPONSE] Dev/management: Works on my machine. #threatmodeling #infosec
#OWASP #Ottawa is proud to announce Farshad Abasi founder of Forward Security will be speaking at #OWASPOttawa2026.
"Your Threat Model is Lying to You: Why Modeling the design Isn't Enough in 2026"
📅 Oct 17
📍 UofO- STEM 117
ℹ️ tinyurl.com/87j33b82
🎟️ tinyurl.com/mr2z6z8r
[THREAT] Identified threat: Backups have not been test-restored since the runbook was written [RESPONSE] Dev/management: We're not interesting enough for nation-state attackers. #threatmodeling #infosec
[THREAT] Identified threat: Password policy permits 'password1' and has done since 2014 [RESPONSE] Dev/management: TOTP in Slack is fine, the channel is private. #threatmodeling #infosec
Threat Modeling erst nach Launch? Das kostet Zeit und Geld. Sicherheit muss in der Planung anfangen – mit echten Checklisten nach BSI und OWASP. Praxis statt Theorie für 2026.
#ITSicherheit #ThreatModeling
(KI-generiertes Bild)
[THREAT] Identified threat: Sensitive Android activity is exported with no permission declared [RESPONSE] Dev/management: Legacy system. We're sunsetting it next quarter. #threatmodeling #infosec
[THREAT] Identified threat: Vendor binary is downloaded at build time with no checksum verification [RESPONSE] Dev/management: Traffic is low enough that no one will notice. #threatmodeling #infosec
[THREAT] Identified threat: Endpoint feeds user input into yaml.load() without SafeLoader [RESPONSE] Dev/management: Traffic is low enough that no one will notice. #threatmodeling #infosec
[THREAT] Identified threat: /export.csv returns the entire user table without authentication [RESPONSE] Dev/management: Marketing is technically a partner, not a vendor. #threatmodeling #infosec
We're only 16 days away from workshop day at TechBash 2026! We have five workshop tracks to choose from when you register for 4 days. More info at techbash.com
#devconference #techevent #ai #dotnet #kubernetes #webdev #threatmodeling #communication #poconos #kalahari