# General

**URL:** https://threatmodelingconnect.discourse.group/c/general/31.md

[Latest](https://threatmodelingconnect.discourse.group/latest.md) · [Categories](https://threatmodelingconnect.discourse.group/categories.md) · [Tags](https://threatmodelingconnect.discourse.group/tags.md)

---

## [About the General category](https://threatmodelingconnect.discourse.group/t/about-the-general-category/968)

<div class="topic-metadata">

**Author:** [@system](https://threatmodelingconnect.discourse.group/u/system)\
**Replies:** 0\
**Last updated:** [May 20, 2025, 4:39am UTC](https://threatmodelingconnect.discourse.group/t/about-the-general-category/968 "2025-05-20T04:39:05Z")

</div>

Got questions or ideas about threat modeling or secure by design? This is the place to chat, share, and explore with fellow TMC members.

---

## [Introduce yourself! 👋](https://threatmodelingconnect.discourse.group/t/introduce-yourself/111)

<div class="topic-metadata">

**Author:** [@shuning](https://threatmodelingconnect.discourse.group/u/shuning)\
**Replies:** 22\
**Last updated:** [January 6, 2026, 11:35am UTC](https://threatmodelingconnect.discourse.group/t/introduce-yourself/111 "2026-01-06T11:35:06Z")

</div>

Welcome to the TMC forum! We want to get to know you. Threat modeling, like any craft, is a journey. We all started somewhere, and no two paths look the same. Use this thread to introduce yourself and share your story: …

---

## [CyberSec Game Challenge 2026](https://threatmodelingconnect.discourse.group/t/cybersec-game-challenge-2026/1273)

<div class="topic-metadata">

**Author:** [@sjgibbs](https://threatmodelingconnect.discourse.group/u/sjgibbs)\
**Replies:** 2\
**Last updated:** [September 20, 2026, 11:11am UTC](https://threatmodelingconnect.discourse.group/t/cybersec-game-challenge-2026/1273 "2026-09-20T11:11:10Z")

</div>

Hello again everyone, CyberSec Games’ summer competition for anyone with an idea for a physical cybersecurity game is back for it’s second year and you have just under 20 days to enter. We are looking for board games, …

---

## [The Secure Code Review Challenge — Solution #5: Notekeeper (Insecure Deserialization)](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-5-notekeeper-insecure-deserialization/1272)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [September 18, 2026, 7:37pm UTC](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-5-notekeeper-insecure-deserialization/1272 "2026-09-18T19:37:58Z")

</div>

Hi all, The solution of challenge #5 of the secure code review challenge, and its video walkthrough are both live. Also, challenge #6 is also live. Video Walkthorugh: https://youtu.be/r3or6Yig\_t0 Solution #5: the-secur…

---

## [The Secure Code Review Challenge — Solution #4: File Converter (A Guessable ID Is an Accessible ID)](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-4-file-converter-a-guessable-id-is-an-accessible-id/1270)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [September 3, 2026, 9:21pm UTC](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-4-file-converter-a-guessable-id-is-an-accessible-id/1270 "2026-09-03T21:21:20Z")

</div>

:loudspeaker: The solution to Secure Code Review Challenge #4: File Converter is live! This one’s a reminder that authentication is not authorization. The app does a lot right: bcrypt password hashing, express-mongo-san…

---

## [The Secure Code Review Challenge — Solution #3: Dice (When Input Sanitization Is Not Enough)](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-3-dice-when-input-sanitization-is-not-enough/1269)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [August 21, 2026, 10:31am UTC](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-3-dice-when-input-sanitization-is-not-enough/1269 "2026-08-21T10:31:09Z")

</div>

:loudspeaker: The solution to Secure Code Review Challenge #3: Dice is live! This one’s a reminder that individually “correct” security controls can still combine into a vulnerability. The app sanitizes user input with …

---

## [ThreatModCon 2026 SanFrancisco](https://threatmodelingconnect.discourse.group/t/threatmodcon-2026-sanfrancisco/1267)

<div class="topic-metadata">

**Author:** [@Guillem\_Bentue\_Marti](https://threatmodelingconnect.discourse.group/u/Guillem_Bentue_Marti)\
**Replies:** 0\
**Last updated:** [August 18, 2026, 1:47pm UTC](https://threatmodelingconnect.discourse.group/t/threatmodcon-2026-sanfrancisco/1267 "2026-08-18T13:47:49Z")

</div>

Heading to OWASP Global AppSec US this November? Don’t forget to join us at threatmodcon San Francisco immediately after! On November 6-7th, we’re bringing together the threat modeling and AppSec community for two days …

---

## [Secure Code Review Challenge #2: Professional — Solution (Clean Code Can Still Be Vulnerable)](https://threatmodelingconnect.discourse.group/t/secure-code-review-challenge-2-professional-solution-clean-code-can-still-be-vulnerable/1265)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [August 6, 2026, 5:48pm UTC](https://threatmodelingconnect.discourse.group/t/secure-code-review-challenge-2-professional-solution-clean-code-can-still-be-vulnerable/1265 "2026-08-06T17:48:05Z")

</div>

:loudspeaker: The solution to Secure Code Review Challenge #2: Professional is live! Quick recap: the Secure Code Review Challenge is a free biweekly series of full, realistic applications with vulnerabilities based on …

---

## [The Secure Code Review Challenge — Solution #1: Schooled](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-1-schooled/1263)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [July 23, 2026, 7:30pm UTC](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-1-schooled/1263 "2026-07-23T19:30:51Z")

</div>

:loudspeaker: The solution to Challenge #1: Schooled is live. Quick recap: the Secure Code Review Challenge is a free biweekly series of full, realistic applications with vulnerabilities based on real-world CVEs — you r…

---

## [Introducing the Secure Code Review Challenge (Practice Real-World Reviews)](https://threatmodelingconnect.discourse.group/t/introducing-the-secure-code-review-challenge-practice-real-world-reviews/1254)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [July 6, 2026, 11:43pm UTC](https://threatmodelingconnect.discourse.group/t/introducing-the-secure-code-review-challenge-practice-real-world-reviews/1254 "2026-07-06T23:43:28Z")

</div>

:loudspeaker: I’m launching a new series: the “Secure Code Review Challenge”. A free biweekly series of full, realistic applications with vulnerabilities based on real-world vulnerabilities, you identify and exploit them…

---

## [New video: Clinejection - One Misconfigured GitHub Action Can Compromise Your App (Deep Dive & Lessons Learned)](https://threatmodelingconnect.discourse.group/t/new-video-clinejection-one-misconfigured-github-action-can-compromise-your-app-deep-dive-lessons-learned/1251)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [June 10, 2026, 10:04pm UTC](https://threatmodelingconnect.discourse.group/t/new-video-clinejection-one-misconfigured-github-action-can-compromise-your-app-deep-dive-lessons-learned/1251 "2026-06-10T22:04:19Z")

</div>

New video is live: “Clinejection: One Misconfigured GitHub Action Can Compromise Your App (Deep Dive & Lessons Learned)”. In this deep dive, I break down how a single misconfigured GitHub Action, combined with prompt in…

---

## [New Video: Let "Claude Code" do your Pentesting!](https://threatmodelingconnect.discourse.group/t/new-video-let-claude-code-do-your-pentesting/1249)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [June 5, 2026, 1:19pm UTC](https://threatmodelingconnect.discourse.group/t/new-video-let-claude-code-do-your-pentesting/1249 "2026-06-05T13:19:09Z")

</div>

:speaker\_high\_volume: New video on the AppSec Untangled channel: a live demo of using Claude Code for pentesting, integrated with Burp Suite via MCP and Playwright as a browser agent. The demo covers IDOR, authenticati…

---

## [New Video: deep dive into CVE-2026–3854 — a critical RCE in GitHub](https://threatmodelingconnect.discourse.group/t/new-video-deep-dive-into-cve-2026-3854-a-critical-rce-in-github/1244)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 1\
**Last updated:** [May 31, 2026, 7:15am UTC](https://threatmodelingconnect.discourse.group/t/new-video-deep-dive-into-cve-2026-3854-a-critical-rce-in-github/1244 "2026-05-31T07:15:56Z")

</div>

:loudspeaker: New video on the “AppSec Untangled” YouTube channel! In this video, I do a deep dive into CVE-2026–3854 — a critical RCE in GitHub where a single git push command with a carefully crafted option was enough…

---

## [How to Use "AI" For Security Code Reviews](https://threatmodelingconnect.discourse.group/t/how-to-use-ai-for-security-code-reviews/1243)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [May 11, 2026, 3:30pm UTC](https://threatmodelingconnect.discourse.group/t/how-to-use-ai-for-security-code-reviews/1243 "2026-05-11T15:30:49Z")

</div>

:loudspeaker: Hi all, check this new video added to the “AppSec Untangled” YouTube channel. In this video, I go through a demo showing how to use AI (Claude Code in this demo) to perform security code review in a way tha…

---

## [Introducing a OWASP Game for threat modeling Agentic AI, Cloud, Devops, Frontend, LLM, Automation, and Web](https://threatmodelingconnect.discourse.group/t/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-and-web/1242)

<div class="topic-metadata">

**Author:** [@Johan\_Sydseter](https://threatmodelingconnect.discourse.group/u/Johan_Sydseter)\
**Replies:** 0\
**Last updated:** [May 11, 2026, 4:55am UTC](https://threatmodelingconnect.discourse.group/t/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-and-web/1242 "2026-05-11T04:55:34Z")

</div>

Shift-left doesn’t start with scanning the code for security vulnerabilities; it begins with designing for security. Too often, the shift-left mantra consists of implementing (AI-powered) code scanning and applying AI-p…

---

## [New Article: What AppSec Engineers Actually Do (and Why It Matters)](https://threatmodelingconnect.discourse.group/t/new-article-what-appsec-engineers-actually-do-and-why-it-matters/1236)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 5\
**Last updated:** [May 6, 2026, 6:49pm UTC](https://threatmodelingconnect.discourse.group/t/new-article-what-appsec-engineers-actually-do-and-why-it-matters/1236 "2026-05-06T18:49:27Z")

</div>

:man\_technologist:t2: Hi all, I’ve added a new post to my blog “AppSec Untangled.” This post breaks down what AppSec engineers actually do, the value they add, and how they help teams define what “secure” means for the s…

---

## [What’s your definition of ‘trust boundary’?](https://threatmodelingconnect.discourse.group/t/what-s-your-definition-of-trust-boundary/1163)

<div class="topic-metadata">

**Author:** [@shuning](https://threatmodelingconnect.discourse.group/u/shuning)\
**Replies:** 5\
**Last updated:** [April 14, 2026, 11:56am UTC](https://threatmodelingconnect.discourse.group/t/what-s-your-definition-of-trust-boundary/1163 "2026-04-14T11:56:41Z")

</div>

Hey friend! This week in the community, we want to talk about trust boundary and its definition. According to SOTM 2024-2025, 72% of orgs use trust boundaries in their modeling. The most common definition: “a groupin…

---

## [Submitting Open Source Projects for ThreatModCon, Vienna 2026](https://threatmodelingconnect.discourse.group/t/submitting-open-source-projects-for-threatmodcon-vienna-2026/1220)

<div class="topic-metadata">

**Author:** [@Vikram\_N](https://threatmodelingconnect.discourse.group/u/Vikram_N)\
**Replies:** 2\
**Last updated:** [March 4, 2026, 3:24pm UTC](https://threatmodelingconnect.discourse.group/t/submitting-open-source-projects-for-threatmodcon-vienna-2026/1220 "2026-03-04T15:24:17Z")

</div>

Hello Folks, I’m wondering if any of you folks building open source tooling are submitting for the upcoming Vienna ThreatModCon … and if you have answers to the following situation: In Sessionize, the following is ment…

---

## [State of Security Champions Survey](https://threatmodelingconnect.discourse.group/t/state-of-security-champions-survey/1216)

<div class="topic-metadata">

**Author:** [@ClaireAA](https://threatmodelingconnect.discourse.group/u/ClaireAA)\
**Replies:** 0\
**Last updated:** [February 6, 2026, 4:09pm UTC](https://threatmodelingconnect.discourse.group/t/state-of-security-champions-survey/1216 "2026-02-06T16:09:26Z")

</div>

Are you an AppSec program owner, or security leader? Do you own, operate, or lead a Security Champion program within your organisation? Then check out this \<15 minute survey and have your say, for the 2nd year runnin…

---

## [How threat modeling is practiced in modern organizations?](https://threatmodelingconnect.discourse.group/t/how-threat-modeling-is-practiced-in-modern-organizations/1207)

<div class="topic-metadata">

**Author:** [@mik0w](https://threatmodelingconnect.discourse.group/u/mik0w)\
**Replies:** 0\
**Last updated:** [January 2, 2026, 4:51pm UTC](https://threatmodelingconnect.discourse.group/t/how-threat-modeling-is-practiced-in-modern-organizations/1207 "2026-01-02T16:51:42Z")

</div>

Hi everyone, I am reposting from Reddit after zeroXten suggested I might search for help here :slight\_smile: I’m conducting a short academic survey as part of my diploma thesis in a Cybersecurity Management program. Th…

---

## [What Is Your Ideal Threat Modeling Lifecycle?](https://threatmodelingconnect.discourse.group/t/what-is-your-ideal-threat-modeling-lifecycle/1191)

<div class="topic-metadata">

**Author:** [@Vikram\_N](https://threatmodelingconnect.discourse.group/u/Vikram_N)\
**Replies:** 1\
**Last updated:** [October 31, 2025, 12:46pm UTC](https://threatmodelingconnect.discourse.group/t/what-is-your-ideal-threat-modeling-lifecycle/1191 "2025-10-31T12:46:31Z")

</div>

So when I started learning about Threat Modeling, the threat modeling process seemed pretty straight-forward to me with Adam Shostack’s 4 question framework. But the deeper I get into threat modeling, the more I realize…

---

## [How do you tackle these top 3 challenges in threat modeling?](https://threatmodelingconnect.discourse.group/t/how-do-you-tackle-these-top-3-challenges-in-threat-modeling/1165)

<div class="topic-metadata">

**Author:** [@shuning](https://threatmodelingconnect.discourse.group/u/shuning)\
**Replies:** 0\
**Last updated:** [October 12, 2025, 7:00pm UTC](https://threatmodelingconnect.discourse.group/t/how-do-you-tackle-these-top-3-challenges-in-threat-modeling/1165 "2025-10-12T19:00:14Z")

</div>

Hello friends, last week we discussed one of the toughest roadblocks in our field, reporting. This week, let’s zoom out to challenges overall. On average, companies in the SOTM survey reported a minimum of 10 recurri…

---

## [Are AI Agents the Ultimate Confused Deputy? How AI Agents' Capabilities Are Being Abused](https://threatmodelingconnect.discourse.group/t/are-ai-agents-the-ultimate-confused-deputy-how-ai-agents-capabilities-are-being-abused/1186)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 1\
**Last updated:** [October 12, 2025, 2:17pm UTC](https://threatmodelingconnect.discourse.group/t/are-ai-agents-the-ultimate-confused-deputy-how-ai-agents-capabilities-are-being-abused/1186 "2025-10-12T14:17:58Z")

</div>

:man\_technologist:t2: Hi all, I’ve added a new post to my blog “AppSec Untangled”. This post discusses how AI agents’ :robot: capabilities are being abused (aka the “Confused Deputy” :thinking: problem) by showing some r…

---

## [Reporting is hard, it really is. Any ideas?](https://threatmodelingconnect.discourse.group/t/reporting-is-hard-it-really-is-any-ideas/1164)

<div class="topic-metadata">

**Author:** [@shuning](https://threatmodelingconnect.discourse.group/u/shuning)\
**Replies:** 2\
**Last updated:** [October 6, 2025, 11:04pm UTC](https://threatmodelingconnect.discourse.group/t/reporting-is-hard-it-really-is-any-ideas/1164 "2025-10-06T23:04:00Z")

</div>

Hey friends, this week’s topic is a tricky one - reporting. The SOTM Report 2024-2025 found that 52% of companies don’t produce regular reports, and for many, reporting remains the least clear part of the process. A…

---

## [How do you get your dev team to shift security left?](https://threatmodelingconnect.discourse.group/t/how-do-you-get-your-dev-team-to-shift-security-left/1182)

<div class="topic-metadata">

**Author:** [@Johan\_Sydseter](https://threatmodelingconnect.discourse.group/u/Johan_Sydseter)\
**Replies:** 0\
**Last updated:** [October 3, 2025, 8:16am UTC](https://threatmodelingconnect.discourse.group/t/how-do-you-get-your-dev-team-to-shift-security-left/1182 "2025-10-03T08:16:57Z")

</div>

How do you get your dev team to shift security left? In your organization, does shift-left mean scanning code for security vulnerabilities, or does it begin with designing it? Can threat modeling be part of an organ…

---

## [How many threat models does your team create in a year?](https://threatmodelingconnect.discourse.group/t/how-many-threat-models-does-your-team-create-in-a-year/1162)

<div class="topic-metadata">

**Author:** [@shuning](https://threatmodelingconnect.discourse.group/u/shuning)\
**Replies:** 0\
**Last updated:** [September 22, 2025, 2:01pm UTC](https://threatmodelingconnect.discourse.group/t/how-many-threat-models-does-your-team-create-in-a-year/1162 "2025-09-22T14:01:10Z")

</div>

Hey friends, this week we’re diving into threat model counts. According to State of Threat Modeling 2024-2025, most companies create 10-100 models per year, regardless of company size, security team size, or the numb…

---

## [To DFD or not to DFD? 🤔](https://threatmodelingconnect.discourse.group/t/to-dfd-or-not-to-dfd/1161)

<div class="topic-metadata">

**Author:** [@shuning](https://threatmodelingconnect.discourse.group/u/shuning)\
**Replies:** 5\
**Last updated:** [September 19, 2025, 2:00pm UTC](https://threatmodelingconnect.discourse.group/t/to-dfd-or-not-to-dfd/1161 "2025-09-19T14:00:51Z")

</div>

Hello again, friends! The SOTM report shows that diagrams remain central in most threat modeling processes - but their accuracy and purpose vary widely. So we’re curious: You (probably) use DFDs, but how do you make t…

---

## [Want to talk about Threat Modelling or Secure by Design?](https://threatmodelingconnect.discourse.group/t/want-to-talk-about-threat-modelling-or-secure-by-design/1171)

<div class="topic-metadata">

**Author:** [@PaulSpruce](https://threatmodelingconnect.discourse.group/u/PaulSpruce)\
**Replies:** 0\
**Last updated:** [September 11, 2025, 10:11pm UTC](https://threatmodelingconnect.discourse.group/t/want-to-talk-about-threat-modelling-or-secure-by-design/1171 "2025-09-11T22:11:00Z")

</div>

Hi All :waving\_hand: Sharing is caring :grin: If anyone is looking for a speaker to chat about Secure by Design methodologies or threat modelling I’m available from Oct onwards, as this awesome community are global it …

---

## [Threat modeling and risk management](https://threatmodelingconnect.discourse.group/t/threat-modeling-and-risk-management/1088)

<div class="topic-metadata">

**Author:** [@adamshostack](https://threatmodelingconnect.discourse.group/u/adamshostack)\
**Replies:** 24\
**Last updated:** [September 4, 2025, 1:54pm UTC](https://threatmodelingconnect.discourse.group/t/threat-modeling-and-risk-management/1088 "2025-09-04T13:54:49Z")

</div>

I have a new, longish post on the topic, Shostack + Associates \> Shostack + Friends Blog \> Risk Management and Threat Modeling. Eager for your feedback.

---

## [OWASP® Cornucopia 2.2 & Copi - A Game Engine for OWASP® Cornucopia Threat Modeling](https://threatmodelingconnect.discourse.group/t/owasp-cornucopia-2-2-copi-a-game-engine-for-owasp-cornucopia-threat-modeling/970)

<div class="topic-metadata">

**Author:** [@Johan\_Sydseter](https://threatmodelingconnect.discourse.group/u/Johan_Sydseter)\
**Replies:** 1\
**Last updated:** [August 19, 2025, 9:35pm UTC](https://threatmodelingconnect.discourse.group/t/owasp-cornucopia-2-2-copi-a-game-engine-for-owasp-cornucopia-threat-modeling/970 "2025-08-19T21:35:44Z")

</div>

Do you feel like yelling at the world for not doing threat modeling? No need to yell, the tools are free! Copi - The OWASP® Cornucopia Game Engine - Is free to use and perfect for distributed teams. We have release…

[Next page](https://threatmodelingconnect.discourse.group/c/general/31.md?page=1)
