# Latest

**URL:** https://threatmodelingconnect.discourse.group/latest.md

[Latest](https://threatmodelingconnect.discourse.group/latest.md) · [Categories](https://threatmodelingconnect.discourse.group/categories.md) · [Tags](https://threatmodelingconnect.discourse.group/tags.md)

---

## [CyberSec Game Challenge 2026](https://threatmodelingconnect.discourse.group/t/cybersec-game-challenge-2026/1273)

<div class="topic-metadata">

**Author:** [@sjgibbs](https://threatmodelingconnect.discourse.group/u/sjgibbs)\
**Replies:** 2\
**Last updated:** [September 20, 2026, 11:11am UTC](https://threatmodelingconnect.discourse.group/t/cybersec-game-challenge-2026/1273 "2026-09-20T11:11:10Z")

</div>

Hello again everyone, CyberSec Games’ summer competition for anyone with an idea for a physical cybersecurity game is back for it’s second year and you have just under 20 days to enter. We are looking for board games, …

---

## [The Secure Code Review Challenge — Solution #5: Notekeeper (Insecure Deserialization)](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-5-notekeeper-insecure-deserialization/1272)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [September 18, 2026, 7:37pm UTC](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-5-notekeeper-insecure-deserialization/1272 "2026-09-18T19:37:58Z")

</div>

Hi all, The solution of challenge #5 of the secure code review challenge, and its video walkthrough are both live. Also, challenge #6 is also live. Video Walkthorugh: https://youtu.be/r3or6Yig\_t0 Solution #5: the-secur…

---

## [🇩🇪 TMC DACH Neues/News](https://threatmodelingconnect.discourse.group/t/tmc-dach-neues-news/843)

<div class="topic-metadata">

**Author:** [@RonMK](https://threatmodelingconnect.discourse.group/u/RonMK)\
**Replies:** 15\
**Last updated:** [September 4, 2026, 7:24pm UTC](https://threatmodelingconnect.discourse.group/t/tmc-dach-neues-news/843 "2026-09-04T19:24:04Z")

</div>

:de: :switzerland: :austria: \[lang:de\] Am 04. März 2025 17:30 war es endlich soweit – das Gründungstreffen der deutschsprachigen Zweigstelle von Threat Modelling Connect fand statt. Zusammen mit 35 Teilnehmenden führten …

---

## [Threat Modeling Mental Health + Stress](https://threatmodelingconnect.discourse.group/t/threat-modeling-mental-health-stress/1271)

<div class="topic-metadata">

**Author:** [@hewerlin](https://threatmodelingconnect.discourse.group/u/hewerlin)\
**Replies:** 1\
**Last updated:** [September 4, 2026, 7:14pm UTC](https://threatmodelingconnect.discourse.group/t/threat-modeling-mental-health-stress/1271 "2026-09-04T19:14:37Z")

</div>

(:de: folgt | :gb: next post) Du schützt Systeme… Wer schützt eigentlich dich?! Unter diesem Motto trafen sich am 27.08.2026 22 Bedrohungsmodellierungsbegeisterte für einen Perspektivwechsel. Alice Hajjar, Gründerin …

---

## [The Secure Code Review Challenge — Solution #4: File Converter (A Guessable ID Is an Accessible ID)](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-4-file-converter-a-guessable-id-is-an-accessible-id/1270)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [September 3, 2026, 9:21pm UTC](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-4-file-converter-a-guessable-id-is-an-accessible-id/1270 "2026-09-03T21:21:20Z")

</div>

:loudspeaker: The solution to Secure Code Review Challenge #4: File Converter is live! This one’s a reminder that authentication is not authorization. The app does a lot right: bcrypt password hashing, express-mongo-san…

---

## [The Secure Code Review Challenge — Solution #3: Dice (When Input Sanitization Is Not Enough)](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-3-dice-when-input-sanitization-is-not-enough/1269)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [August 21, 2026, 10:31am UTC](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-3-dice-when-input-sanitization-is-not-enough/1269 "2026-08-21T10:31:09Z")

</div>

:loudspeaker: The solution to Secure Code Review Challenge #3: Dice is live! This one’s a reminder that individually “correct” security controls can still combine into a vulnerability. The app sanitizes user input with …

---

## [ThreatModCon 2026 SanFrancisco](https://threatmodelingconnect.discourse.group/t/threatmodcon-2026-sanfrancisco/1267)

<div class="topic-metadata">

**Author:** [@Guillem\_Bentue\_Marti](https://threatmodelingconnect.discourse.group/u/Guillem_Bentue_Marti)\
**Replies:** 0\
**Last updated:** [August 18, 2026, 1:47pm UTC](https://threatmodelingconnect.discourse.group/t/threatmodcon-2026-sanfrancisco/1267 "2026-08-18T13:47:49Z")

</div>

Heading to OWASP Global AppSec US this November? Don’t forget to join us at threatmodcon San Francisco immediately after! On November 6-7th, we’re bringing together the threat modeling and AppSec community for two days …

---

## [Secure Code Review Challenge #2: Professional — Solution (Clean Code Can Still Be Vulnerable)](https://threatmodelingconnect.discourse.group/t/secure-code-review-challenge-2-professional-solution-clean-code-can-still-be-vulnerable/1265)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [August 6, 2026, 5:48pm UTC](https://threatmodelingconnect.discourse.group/t/secure-code-review-challenge-2-professional-solution-clean-code-can-still-be-vulnerable/1265 "2026-08-06T17:48:05Z")

</div>

:loudspeaker: The solution to Secure Code Review Challenge #2: Professional is live! Quick recap: the Secure Code Review Challenge is a free biweekly series of full, realistic applications with vulnerabilities based on …

---

## [Quantitative Risk with Risquanter - TMC DACH](https://threatmodelingconnect.discourse.group/t/quantitative-risk-with-risquanter-tmc-dach/1264)

<div class="topic-metadata">

**Author:** [@hewerlin](https://threatmodelingconnect.discourse.group/u/hewerlin)\
**Replies:** 1\
**Last updated:** [August 3, 2026, 8:26am UTC](https://threatmodelingconnect.discourse.group/t/quantitative-risk-with-risquanter-tmc-dach/1264 "2026-08-03T08:26:39Z")

</div>

:de: Folgt. :us: Next post. Am 14.07.2026 trafen sich 15 Bedrohungsmodellierungsbegeisterte, um in die Welt des quantitativen Risikos einzutauchen: Daniel Agota und TMC DACH hatten zu einer Werkzeugschau seines Werkzeug…

---

## [PHANTOM-B: A STRIDE analog for LLMs](https://threatmodelingconnect.discourse.group/t/phantom-b-a-stride-analog-for-llms/1261)

<div class="topic-metadata">

**Author:** [@adamshostack](https://threatmodelingconnect.discourse.group/u/adamshostack)\
**Replies:** 4\
**Last updated:** [July 25, 2026, 6:28pm UTC](https://threatmodelingconnect.discourse.group/t/phantom-b-a-stride-analog-for-llms/1261 "2026-07-25T18:28:51Z")

</div>

Hi! I’m really excited that we released PHANTOM-B for threat modeling LLMs. Why PHANTOM-B? | Shostack + Associates Blog Free whitepaper. Would love your feedback + thoughts.

---

## [The Secure Code Review Challenge — Solution #1: Schooled](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-1-schooled/1263)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [July 23, 2026, 7:30pm UTC](https://threatmodelingconnect.discourse.group/t/the-secure-code-review-challenge-solution-1-schooled/1263 "2026-07-23T19:30:51Z")

</div>

:loudspeaker: The solution to Challenge #1: Schooled is live. Quick recap: the Secure Code Review Challenge is a free biweekly series of full, realistic applications with vulnerabilities based on real-world CVEs — you r…

---

## [Call for papers: ThreatModCon 2026 San Francisco](https://threatmodelingconnect.discourse.group/t/call-for-papers-threatmodcon-2026-san-francisco/1256)

<div class="topic-metadata">

**Author:** [@Guillem\_Bentue\_Marti](https://threatmodelingconnect.discourse.group/u/Guillem_Bentue_Marti)\
**Replies:** 0\
**Last updated:** [July 13, 2026, 12:15pm UTC](https://threatmodelingconnect.discourse.group/t/call-for-papers-threatmodcon-2026-san-francisco/1256 "2026-07-13T12:15:06Z")

</div>

Call for papers: ThreatModCon 2026 San Francisco. The CFP for ThreatModCon is officially open through July 31. We are looking for the “doers” who practice threat modeling. If you have a technical story to tell or a proc…

---

## [Good Questions in Threat Modeling?](https://threatmodelingconnect.discourse.group/t/good-questions-in-threat-modeling/1253)

<div class="topic-metadata">

**Author:** [@hewerlin](https://threatmodelingconnect.discourse.group/u/hewerlin)\
**Replies:** 3\
**Last updated:** [July 8, 2026, 4:58am UTC](https://threatmodelingconnect.discourse.group/t/good-questions-in-threat-modeling/1253 "2026-07-08T04:58:53Z")

</div>

I am designing a Threat Modeling tool. It is good at (many to many) relationships! At it’s heart, it has a set of rules with source type, question/prompt and target type. I can configure this really flexible. A simple …

---

## [Introducing the Secure Code Review Challenge (Practice Real-World Reviews)](https://threatmodelingconnect.discourse.group/t/introducing-the-secure-code-review-challenge-practice-real-world-reviews/1254)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [July 6, 2026, 11:43pm UTC](https://threatmodelingconnect.discourse.group/t/introducing-the-secure-code-review-challenge-practice-real-world-reviews/1254 "2026-07-06T23:43:28Z")

</div>

:loudspeaker: I’m launching a new series: the “Secure Code Review Challenge”. A free biweekly series of full, realistic applications with vulnerabilities based on real-world vulnerabilities, you identify and exploit them…

---

## [Help me design coverage metrics](https://threatmodelingconnect.discourse.group/t/help-me-design-coverage-metrics/1246)

<div class="topic-metadata">

**Author:** [@hewerlin](https://threatmodelingconnect.discourse.group/u/hewerlin)\
**Replies:** 11\
**Last updated:** [June 23, 2026, 5:39pm UTC](https://threatmodelingconnect.discourse.group/t/help-me-design-coverage-metrics/1246 "2026-06-23T17:39:53Z")

</div>

I’m building a Threat Modeling Tool and I am facing the following problem: There are a bunch of threat models (:gift:). Each has threats (:cloud\_with\_lightning:). Threats have their associated mitigations (:umbrella:). …

---

## [TMC New York City meetup - Live workshop on secure coding with Claude Code and Codex](https://threatmodelingconnect.discourse.group/t/tmc-new-york-city-meetup-live-workshop-on-secure-coding-with-claude-code-and-codex/1252)

<div class="topic-metadata">

**Author:** [@zbraiterman](https://threatmodelingconnect.discourse.group/u/zbraiterman)\
**Replies:** 0\
**Last updated:** [June 14, 2026, 2:54pm UTC](https://threatmodelingconnect.discourse.group/t/tmc-new-york-city-meetup-live-workshop-on-secure-coding-with-claude-code-and-codex/1252 "2026-06-14T14:54:22Z")

</div>

During our last meetup, threat modeling trailblazer, Brook Schoenfield, shared expert insights on the intersection of threat modeling in AI. His talk included warnings about the abundance of buggy, AI generated code. …

---

## [New video: Clinejection - One Misconfigured GitHub Action Can Compromise Your App (Deep Dive & Lessons Learned)](https://threatmodelingconnect.discourse.group/t/new-video-clinejection-one-misconfigured-github-action-can-compromise-your-app-deep-dive-lessons-learned/1251)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [June 10, 2026, 10:04pm UTC](https://threatmodelingconnect.discourse.group/t/new-video-clinejection-one-misconfigured-github-action-can-compromise-your-app-deep-dive-lessons-learned/1251 "2026-06-10T22:04:19Z")

</div>

New video is live: “Clinejection: One Misconfigured GitHub Action Can Compromise Your App (Deep Dive & Lessons Learned)”. In this deep dive, I break down how a single misconfigured GitHub Action, combined with prompt in…

---

## ["Did we do a good job?" TMC DACH virtual meetup recap](https://threatmodelingconnect.discourse.group/t/did-we-do-a-good-job-tmc-dach-virtual-meetup-recap/1250)

<div class="topic-metadata">

**Author:** [@Laxarella](https://threatmodelingconnect.discourse.group/u/Laxarella)\
**Replies:** 1\
**Last updated:** [June 6, 2026, 8:16pm UTC](https://threatmodelingconnect.discourse.group/t/did-we-do-a-good-job-tmc-dach-virtual-meetup-recap/1250 "2026-06-06T20:16:49Z")

</div>

:de: :austria: :switzerland:? =\> Nächster Eintrag. :us: :gb:? =\> Ahead: On June 3 2026, eleven threat modeling enthusiasts from TMC DACH gathered in an informal setting to explore the fourth question of the four-questio…

---

## [New Video: Let "Claude Code" do your Pentesting!](https://threatmodelingconnect.discourse.group/t/new-video-let-claude-code-do-your-pentesting/1249)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [June 5, 2026, 1:19pm UTC](https://threatmodelingconnect.discourse.group/t/new-video-let-claude-code-do-your-pentesting/1249 "2026-06-05T13:19:09Z")

</div>

:speaker\_high\_volume: New video on the AppSec Untangled channel: a live demo of using Claude Code for pentesting, integrated with Burp Suite via MCP and Playwright as a browser agent. The demo covers IDOR, authenticati…

---

## [TMI newsletter #53 on threat modeling enforcement, community feedback on ENISA TM playbook, and much more](https://threatmodelingconnect.discourse.group/t/tmi-newsletter-53-on-threat-modeling-enforcement-community-feedback-on-enisa-tm-playbook-and-much-more/1248)

<div class="topic-metadata">

**Author:** [@SebaDele](https://threatmodelingconnect.discourse.group/u/SebaDele)\
**Replies:** 0\
**Last updated:** [June 5, 2026, 6:43am UTC](https://threatmodelingconnect.discourse.group/t/tmi-newsletter-53-on-threat-modeling-enforcement-community-feedback-on-enisa-tm-playbook-and-much-more/1248 "2026-06-05T06:43:57Z")

</div>

We released our Toreon threat modeling insider newsletter #53 this week, covering: Amir Kavousian: Why threat modelers need to focus less on static documents and more on code. I wrote an article on the proposed ENISA d…

---

## [New Video: deep dive into CVE-2026–3854 — a critical RCE in GitHub](https://threatmodelingconnect.discourse.group/t/new-video-deep-dive-into-cve-2026-3854-a-critical-rce-in-github/1244)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 1\
**Last updated:** [May 31, 2026, 7:15am UTC](https://threatmodelingconnect.discourse.group/t/new-video-deep-dive-into-cve-2026-3854-a-critical-rce-in-github/1244 "2026-05-31T07:15:56Z")

</div>

:loudspeaker: New video on the “AppSec Untangled” YouTube channel! In this video, I do a deep dive into CVE-2026–3854 — a critical RCE in GitHub where a single git push command with a carefully crafted option was enough…

---

## [Luanch of the first TMC BeNeLux Chapter](https://threatmodelingconnect.discourse.group/t/luanch-of-the-first-tmc-benelux-chapter/1237)

<div class="topic-metadata">

**Author:** [@Simon\_monteyne](https://threatmodelingconnect.discourse.group/u/Simon_monteyne)\
**Replies:** 4\
**Last updated:** [May 14, 2026, 8:49am UTC](https://threatmodelingconnect.discourse.group/t/luanch-of-the-first-tmc-benelux-chapter/1237 "2026-05-14T08:49:14Z")

</div>

This week, the first ever Threat Modeling Connect BeNeLux meetup turned out to be a great success. We had a strong turnout, a very mixed audience, and a fantastic venue with a beautiful view over Brussels …

---

## [How to Use "AI" For Security Code Reviews](https://threatmodelingconnect.discourse.group/t/how-to-use-ai-for-security-code-reviews/1243)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 0\
**Last updated:** [May 11, 2026, 3:30pm UTC](https://threatmodelingconnect.discourse.group/t/how-to-use-ai-for-security-code-reviews/1243 "2026-05-11T15:30:49Z")

</div>

:loudspeaker: Hi all, check this new video added to the “AppSec Untangled” YouTube channel. In this video, I go through a demo showing how to use AI (Claude Code in this demo) to perform security code review in a way tha…

---

## [Introducing a OWASP Game for threat modeling Agentic AI, Cloud, Devops, Frontend, LLM, Automation, and Web](https://threatmodelingconnect.discourse.group/t/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-and-web/1242)

<div class="topic-metadata">

**Author:** [@Johan\_Sydseter](https://threatmodelingconnect.discourse.group/u/Johan_Sydseter)\
**Replies:** 0\
**Last updated:** [May 11, 2026, 4:55am UTC](https://threatmodelingconnect.discourse.group/t/introducing-a-owasp-game-for-threat-modeling-agentic-ai-cloud-devops-frontend-llm-automation-and-web/1242 "2026-05-11T04:55:34Z")

</div>

Shift-left doesn’t start with scanning the code for security vulnerabilities; it begins with designing for security. Too often, the shift-left mantra consists of implementing (AI-powered) code scanning and applying AI-p…

---

## [New Article: What AppSec Engineers Actually Do (and Why It Matters)](https://threatmodelingconnect.discourse.group/t/new-article-what-appsec-engineers-actually-do-and-why-it-matters/1236)

<div class="topic-metadata">

**Author:** [@Mohamed\_AboElKheir](https://threatmodelingconnect.discourse.group/u/Mohamed_AboElKheir)\
**Replies:** 5\
**Last updated:** [May 6, 2026, 6:49pm UTC](https://threatmodelingconnect.discourse.group/t/new-article-what-appsec-engineers-actually-do-and-why-it-matters/1236 "2026-05-06T18:49:27Z")

</div>

:man\_technologist:t2: Hi all, I’ve added a new post to my blog “AppSec Untangled.” This post breaks down what AppSec engineers actually do, the value they add, and how they help teams define what “secure” means for the s…

---

## [VICAR: Bridging the Gap Between Threat Modeling and Remediation](https://threatmodelingconnect.discourse.group/t/vicar-bridging-the-gap-between-threat-modeling-and-remediation/1003)

<div class="topic-metadata">

**Author:** [@LFB](https://threatmodelingconnect.discourse.group/u/LFB)\
**Replies:** 11\
**Last updated:** [April 27, 2026, 11:14am UTC](https://threatmodelingconnect.discourse.group/t/vicar-bridging-the-gap-between-threat-modeling-and-remediation/1003 "2026-04-27T11:14:34Z")

</div>

VICAR: Bridging the Gap Between Threat Modeling and Remediation Sharing an approach that helped our internal threat modeling team have more impact. This article introduces VICAR, a structure for documenting and communi…

---

## [Have you met AttackTree.online?](https://threatmodelingconnect.discourse.group/t/have-you-met-attacktree-online/1234)

<div class="topic-metadata">

**Author:** [@hewerlin](https://threatmodelingconnect.discourse.group/u/hewerlin)\
**Replies:** 1\
**Last updated:** [April 15, 2026, 8:02pm UTC](https://threatmodelingconnect.discourse.group/t/have-you-met-attacktree-online/1234 "2026-04-15T20:02:39Z")

</div>

:us: :gb:? =\> Next post. :de: :austria: :switzerland:? =\> Folgt: Am 14.04.2026 trafen sich 34 Bedrohungsmodellierungsbegeisterte zur ersten TMC DACH :hammer\_and\_wrench: Werkzeugschau! Das ist ein neuer Besuchsrekord! C…

---

## [What’s your definition of ‘trust boundary’?](https://threatmodelingconnect.discourse.group/t/what-s-your-definition-of-trust-boundary/1163)

<div class="topic-metadata">

**Author:** [@shuning](https://threatmodelingconnect.discourse.group/u/shuning)\
**Replies:** 5\
**Last updated:** [April 14, 2026, 11:56am UTC](https://threatmodelingconnect.discourse.group/t/what-s-your-definition-of-trust-boundary/1163 "2026-04-14T11:56:41Z")

</div>

Hey friend! This week in the community, we want to talk about trust boundary and its definition. According to SOTM 2024-2025, 72% of orgs use trust boundaries in their modeling. The most common definition: “a groupin…

---

## [Say Hi to Precogly :)](https://threatmodelingconnect.discourse.group/t/say-hi-to-precogly/1232)

<div class="topic-metadata">

**Author:** [@Vikram\_N](https://threatmodelingconnect.discourse.group/u/Vikram_N)\
**Replies:** 3\
**Last updated:** [April 3, 2026, 12:51am UTC](https://threatmodelingconnect.discourse.group/t/say-hi-to-precogly/1232 "2026-04-03T00:51:52Z")

</div>

A number of awesome folks here have given feedback on Precogly - an open-source alternative to commercial threat modeling tools. I’m very appreciative of those of you who have helped shaped the product. Thank you! I rel…

---

## [Threat Modelling Hackaton - 1st place 2026 (group 47)](https://threatmodelingconnect.discourse.group/t/threat-modelling-hackaton-1st-place-2026-group-47/1231)

<div class="topic-metadata">

**Author:** [@maxw07](https://threatmodelingconnect.discourse.group/u/maxw07)\
**Replies:** 1\
**Last updated:** [March 28, 2026, 8:50am UTC](https://threatmodelingconnect.discourse.group/t/threat-modelling-hackaton-1st-place-2026-group-47/1231 "2026-03-28T08:50:19Z")

</div>

Hello everyone, we are happy to announce that group 47 (Avi, Sully, Engin, Max) won this year’s ThreatModCon Hackaton! A big shoutout to our mentor Dragan too! :slight\_smile: In this post I will not go into much detail,…

[Next page](https://threatmodelingconnect.discourse.group/latest.md?page=1)
