#threatmodeling

11 posts · Last used 6d

Back to Timeline
eteryu @eteryu@infosec.exchange · 6d ago
Cześć! Jak tam Wasze niedzielne poranki? Ja kończę śniadanie i zaraz biorę się za pisanie tekstu na bloga o tym, od czego w ogóle zacząć własne modelowanie zagrożeń (threat modeling). Jeżeli macie jakieś swoje ulubione podejścia albo pytania w tym temacie, dajcie znać! #cyberbezpieczeństwo #infosec #threatmodeling #security
1
1
3
eteryu @eteryu@infosec.exchange · Aug 08, 2026
W nawiązaniu do wczorajszego tekstu o tym, że prywatność prosto z pudełka nie istnieje, przypominam moją serię o cyfrowej higienie. Pokazuję tam w praktyce, że bezpieczeństwo to codzienne nawyki. Część pierwsza o odzyskiwaniu kontroli: https://eteryu.space/cyfrowa-higiena-podczas-przerwy-na-kawe-jak-atwo-odzyskac-kontrole-nad-telefonem/ Część druga o izolacji toksycznych aplikacji: https://eteryu.space/cyfrowa-higiena-bez-kompromisow-jak-atwo-odizolowac-toksyczne-aplikacje/ Część trzecia o odcinaniu algorytmów: https://eteryu.space/cyfrowa-higiena-bez-podgladaczy-jak-atwo-odciac-algorytmy-i-zabezpieczyc-zdjecia/ Ta seria będzie kontynuowana. W kolejnych tekstach weźmiemy na warsztat bezpieczne zarządzanie hasłami oraz dywersyfikację danych. Zanim to jednak nastąpi, na blogu pojawi się bardzo ważny wpis tłumaczący od podstaw modelowanie zagrożeń. Zanim go opublikuję, mam dla Was zadanie na start. Zastanówcie się i odpowiedzcie sobie szczerze na jedno pytanie: przed kim dokładnie chronicie swoje informacje? Sprecyzowanie przeciwnika to absolutny fundament, od którego musicie zacząć budowę własnego modelu bezpieczeństwa. #infosec #cyberbezpieczenstwo #prywatnosc #bezpieczenstwo #opsec #higienacyfrowa #threatmodeling #cybersec
0
0
0
Simon Roses Femerling @simonroses@infosec.exchange · Aug 03, 2026
🛡️ USecVisLib — open-source Universal Security Visualization Library. Attack trees, attack graphs, STRIDE threat models, MAESTRO AI-agent threat modeling, binary viz & more. Python + FastAPI + Vue 3. Apache 2.0. https://github.com/vulnex/usecvislib #infosec #threatmodeling #opensource #redteam #blueteam
0
0
0
Open Security Conference @OSCo@infosec.exchange · Jul 31, 2026
The next one in the #peoplebehindosco series is Felix. Hi @Gronner@infosec.exchange 👋 Felix is a software engineer with more than 10 years experience in the automotive and medical industry. Working at XITASO he focuses on building secure and safe systems. Besides that he provides trainings on security, safety, software architecture and Rust. To learn in and with a community he organises the SWEC and is a member of the iSAQB. He loves learning by exploring: building small embedded system or tools, mostly in Rust. In his spare time he enjoys playing pen & paper games, miniature figure painting and playing the drums. His Tags: #AppSec, #Embedded, #Rust, #ThreatModeling Thank you very much for your work as a volunteer and your support in organizing the Open Security conference. Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.
0
0
0
Prof Hernan Huwyler, MBA CPA @hewyler@infosec.exchange · Jul 30, 2026
Most AI security audits miss 70% of the attack surface. Training data, prompt pipelines, model weights, and agentic tool calls are #AI's real battleground. Free open-source #threatmodeling toolkit for engineers and architects: https://github.com/hwyler/ai-threat-modeling-toolkit https://hernanhuwyler.wordpress.com/2026/07/30/a-practical-guide-for-engineers-architects-and-governance-teams-who-need-to-get-it-right/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Shostack + Associates @shostackassociates@infosec.exchange · Jul 14, 2026
AI won't replace threat modeling fundamentals, but it will change how you work. Join Adam Shostack for our 4-day Threat Modeling Intensive with Complete AI at Black Hat USA 2026, Aug 1-4 in Las Vegas. See where LLMs help, where they fail, and where human judgment still wins. Regular pricing ends July 17. 🔗 https://shorturl.at/CmBtW Read more: https://shorturl.at/aPqVP #ThreatModeling #BlackHat2026 #InfoSec #AI
0
0
0
arcticbison @arcticbison@infosec.exchange · Jul 10, 2026
Replying to @arcticbison@infosec.exchange
Full argument — including historical cases and what "nothing to compel" looks like in production: @arcticbison@paragraph.com If you're building for threat models that include hostile state actors or legal compellability, I'd like to hear how you're approaching it. #infosec #privacy #opsec #threatmodeling #cloudinfrastructure
0
0
0
Shostack + Associates @shostackassociates@infosec.exchange · Jul 09, 2026
The S+A team had a blast in Vienna at OWASP Global AppSec EU 2026 🇦🇹 From leading our Threat Modeling Intensive to meeting fellow members of the AppSec community, we loved the turnout and the lively discussions. Thanks to everyone who showed up with intention, dove deep, and learned by doing! We shared some reflections on the training in our blog post 👇 https://shostack.org/blog/owasp-to-blackhat-recap/ #ThreatModeling #AppSec #OWASP
0
1
0
Shostack + Associates @shostackassociates@infosec.exchange · Jul 09, 2026
Replying to @shostackassociates@infosec.exchange
Missed OWASP Global AppSec EU? No worries — the S + A team is heading to Black Hat USA 2026 next! Join our new 4-day Threat Modeling Intensive with Complete AI (Aug 1–4). We cover threat modeling fundamentals plus how to use LLMs in your workflow, where things go wrong, and AI-specific threat modeling skills. Prices go up after July 17 — register now: https://blackhat.com/us-26/training/schedule/index.html#adam-shostacks-threat-modeling-intensive-with-complete-ai-51473 #BlackHat2026 #ThreatModeling #AI
0
0
0
Tanya Janca | SheHacksPurple :verified: :verified: @SheHacksPurple@infosec.exchange · Jul 02, 2026
Replying to @SheHacksPurple@infosec.exchange
📩 Send me a message or visit shehackspurple.ca to learn more about training, workshops, and speaking opportunities. tanya AT shehackspurple DOT ca #SecurityAwarenessMonth #AppSec #SecureCoding #ThreatModeling #AISecurity #CyberSecurity 4/4
2
0
1
Caria Giovanni - Harpocrates @Harpocrates@infosec.exchange · Jun 02, 2026
Boosted by disregard Joe Groff @joe@f.duriansoftware.com

New preprint: AI_Bleeding — inference cost amplification via OOD linguistic payload

TL;DR: send queries in Grecanico or Farsi to an LLM endpoint → TTFT +59.8%, compute cost +2.8%, statistically significant. No vuln, no volumetric signature, evades all standard detection.

Worst case: exposed unauthenticated Ollama instance with num_predict=4096 + keep_alive=300s → Amplification Factor 17.56 Wh/KB. 3KB of attacker bandwidth → enough energy to charge a phone 5%.

Especially nasty for:

  • PA/judicial chatbots on fixed budgets
  • Pay-per-use API deployments with client-side exposed keys
  • PNRR-funded public sector AI with zero inference monitoring

Four scenarios: EDoS, browser JS distribution, Ollama open-proxy relay, frontier providers as involuntary relays.

All tests on self-hosted Ollama, no commercial endpoints touched.

Paper (CC BY 4.0): https://doi.org/10.13140/RG.2.2.26767.96166

#llmsecurity #infosec #threatmodeling #ollama #ood #AI #AIResearch #aisecurity

8
0
6

You've seen all posts