@kaoudis politely skewering a platitude. #threatmodeling #tmcon
Get Ready for OWASP Global AppSec USA 2025!
This event is built for everyone in the CyberSec community, whether you want to expand your skills or discover new solutions, this is the event for you.
Register now: https://owasp.glueup.com/event/131624/register/
i know SMBs are a bit more hand-holdy than enterprise customers, but that doesn't really bother me when it comes to #threatmodeling or this #ransomwareRemediation thing i'm talking about lately. i genuinely like learning how people work. i have a somewhat unusual philosophy on #tech which is i don't solve every problem by throwing bigger computers at it unless that person is like "it would be life changing to have a bigger computer" (bigger = higher performance not literal size, Amelia Bedelia.
Attackers are more regularly targeting industrial control systems (ICS) on Operational Technology (OT), which have led to devistating real world consequences
Trace attack paths in ICS with Gilberto "Gil" Garcia's #BSidesBoulder25 talk "Attack Path Modeling for Securing ICS/OT Systems"! Attendees will learn how to visualize adversary movements, focus on crown jewels, and turn free tools and threat intel into actionable defense strategies through understanding attacker workflows.
Garcia's session will also delve into frameworks, modeling techniques, and the integration of intelligence-driven security measures to strengthen ICS/OT resilience - because in critical infrastructure, guesswork isn’t a good option!
Tickets are available for purchase for our 13 June event here: https://www.eventbrite.com/e/bsides-boulder-2025-registration-1290129274389
I have seen a lot of efforts to use an #LLM to create a #ThreatModel. I have some insights.
Attempts at #AI #ThreatModeling tend to do 3 things wrong:
1/n
My #Appsec roundup for April is live. No blow by blow masto post this time because i have to head to the airport soon for #rsac
Lots of #threatmodeling, important improvements to #llm #security and more
I've updated the illuminated security #threatmodeling workbook, designed for either pen&paper or #reMarkable2 use. It's now a lot more detailed and with hyperlinked sections. At some point I'll get around to documenting how to use it, but if you've read @adamshostack 's book it should be self-explanatory. Entirely free to download, use etc - CC-BY-SA licensed.
https://illuminated-security.com/threat-modelling-workbook-2/
The full agenda is now live on our website, and we're kicking things off in Barcelona with an incredible first day! Join in on training sessions on AI Whiteboard Hacking, Full-Stack Pentesting, and iOS and Andriod App Security on day 1.
https://owasp.glueup.com/event/owasp-global-appsec-eu-2025-123983/home.html
The Full Agenda for OWASP Global AppSec EU 2025 is LIVE!
Get ready for an unparalleled lineup of security experts, cutting-edge talks, and hands-on training sessions in Barcelona! Whether you specialize in DevSecOps, threat modeling, AI security, or AppSec automation, there’s something for everyone.
Check out the full agenda and secure your spot today! https://owasp.glueup.com/event/owasp-global-appsec-eu-2025-123983/home.html
Exciting news #OWASP! The full agenda for Global #AppSec EU (#Barcelona) is now live!
Dive into the incredible sessions we've lined up just for you, and don’t wait—register now to secure your spot! https://owasp.glueup.com/event/owasp-global-appsec-eu-2025-123983/
Master Threat Modeling at OWASP Global AppSec 2025 Barcelona!
2-Day Training | May 27-28, 2025
Trainer: Adam Shostack
Led by industry expert Adam Shostack, this course will refine your skills through guided exercises and real-world scenarios, ensuring you leave with practical, actionable expertise.
Master Threat Modeling at OWASP Global AppSec 2025 Barcelona!
Led by industry expert Adam Shostack, this course will refine your skills through guided exercises and real-world scenarios, ensuring you leave with practical, actionable expertise.
Calling all cybersecurity pros, developers, DevSecOps engineers, ethical hackers, and AppSec leaders!
OWASP Global AppSec EU 2025 Early Bird Pricing ends TODAY!
Register NOW: https://owasp.glueup.com/event/123983/register/
Digital Security Introduction in Under 2 Minutes. There's much more to come.
Consider donating so we can produce more in-depth instructional content for at-risk folks. #securityculture #digitalsecurity #threatmodeling #surveillance #opensource #encryption #antifascist
Digital Security Introduction in Under 2 Minutes. There's much more to come. Consider donating so we can produce more in-depth instructional content for at-risk folks. #securityculture #digitalsecurity #threatmodeling #surveillance #opensource #encryption #antifascist #antidoge #enshitify
https://youtube.com/shorts/iZG2eXps6gw?si=CAZdqf80mEMQGkQI
2m
Startups & Security Innovators: Fuel innovation & security!
Global AppSec EU 2025 is the place for AppSec leaders & startups to connect.
Early bird tickets gone after Feb 28!
Sign up now: https://owasp.glueup.com/event/123983/register/
Developers & Engineers Focused on Secure Coding: Join the best in AppSec at OWASP Global AppSec EU 2025!
Early bird discounts end February 28!
Save your seat now! https://owasp.glueup.com/event/123983/register/
Hi @elizayer,
Here's a good write-up about #ThreatModeling by @privacyguides:
https://www.privacyguides.org/en/basics/threat-modeling/
Also, these are the VPN they recommend - and why:
**VPN Services**
https://www.privacyguides.org/en/vpn/
[Spoiler: NordVPN is **not** on the list, for good reasons]
Hope this helps.
@krusynth