# appsec

Published articles for appsec.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Researchers link the RubyHack campaign to alleged OpenAI-connected agents, while RubyGems disputes key claims

DevFeed: [Researchers link the RubyHack campaign to alleged OpenAI-connected agents, while RubyGems disputes key claims](<https://devfeed.tech/articles/rubygems-openai-40878.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/codescoring/news/1083068/>)

Author: amaksimovv (CodeScoring)

Published: 2026-09-16T15:08:49Z

Content type: news

Language: ru

Sources: [Tagir Valeev](<https://devfeed.tech/sources/tagir-valeev.md>)

Topics: [rubygems](<https://devfeed.tech/topics/rubygems.md>), [Ruby](<https://devfeed.tech/topics/ruby.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [legacy](<https://devfeed.tech/topics/legacy.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [appsec](<https://devfeed.tech/tags/appsec.md>), [cdn](<https://devfeed.tech/tags/cdn.md>), [gemstuffer](<https://devfeed.tech/tags/gemstuffer.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [load](<https://devfeed.tech/tags/load.md>), [openai](<https://devfeed.tech/tags/openai.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [rubydoc](<https://devfeed.tech/tags/rubydoc.md>), [rubygems](<https://devfeed.tech/tags/rubygems.md>), [rubyhack](<https://devfeed.tech/tags/rubyhack.md>), [tag-070ecaaf0eda](<https://devfeed.tech/tags/tag-070ecaaf0eda.md>), [tag-64251c106897](<https://devfeed.tech/tags/tag-64251c106897.md>), [yard](<https://devfeed.tech/tags/yard.md>)

### AI overview

Researchers from Nightingale Collective linked the RubyHack campaign in RubyGems to alleged internal OpenAI agents. The article describes malicious code executed during RubyDoc documentation builds, data collection from British municipal websites, attempts to obtain RubyGems API keys, and a caching flaw involving legacy keys. RubyGems said it could not independently identify the package creators and found no evidence that чужие keys were successfully obtained.

### Source excerpt

11 сентября исследователи Nightingale Collective опубликовали разбор RubyHack и связали майскую кампанию в RubyGems с внутренними агентами OpenAI. По их версии, скрипты внутри пакетов запускали код в инфраструктуре RubyDoc, собирали открытые данные с сайтов британских муниципалитетов и публиковали результаты обратно в реестр. В нескольких образцах исследователи также обнаружили попытки получить чужие API-ключи RubyGems. Команда RubyGems не смогла независимо установить, кем именно были созданы пакеты, и не нашла доказательств успешного получения чужих ключей. Во время майской кампании она отозвала вредоносные пакеты и на четыре дня остановила регистрацию новых пользователей. Одной из точек входа стала обычная сборка документации. В пакет добавляли .yardopts - файл параметров генератора YARD - с указанием загрузить Ruby-скрипт. Когда для пакета запрашивали документацию на RubyDoc, сборщик обрабатывал этот файл и запускал вложенный код. Такое поведение соответствует механике самого YARD: параметр --load загружает указанный Ruby-файл перед выполнением команды. Запущенный скрипт обращался к муниципальным сайтам, сохранял ответы, собирал из них новый .gem-архив и отправлял его в RubyGems со встроенным ключом. В результате реестр использовался как канал передачи и хранения собранных данных. Установка такого пакета множеством разработчиков для работы этой схемы не требовалась: достаточно было исполнения кода в сервисе сборки документации. Отдельные пакеты обращались к старому endpoint выдачи API-ключей. В нём действовала ошибка кэширования: при определённых условиях CDN мог сохранить ответ с legacy-ключом и до часа отдавать его следующим запросам на том же узле. RubyGems исправил проблему 9 июля, очистил кэш, отозвал legacy-ключи и затем отключил старый endpoint. Читать далее

## Application and AI roundup - October

DevFeed: [Application and AI roundup - October](<https://devfeed.tech/articles/application-and-ai-roundup-october-36684.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-oct-2023/>)

Author: Adam

Published: 2023-11-09T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Adversarial attacks](<https://devfeed.tech/topics/adversarial-attacks.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [browser](<https://devfeed.tech/topics/browser.md>), [okta](<https://devfeed.tech/topics/okta.md>), [solarwinds](<https://devfeed.tech/topics/solarwinds.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [appsec](<https://devfeed.tech/tags/appsec.md>), [article](<https://devfeed.tech/tags/article.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [browser](<https://devfeed.tech/tags/browser.md>), [large-language-models](<https://devfeed.tech/tags/large-language-models.md>), [okta](<https://devfeed.tech/tags/okta.md>), [security](<https://devfeed.tech/tags/security.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

An October roundup covering the SEC's case against SolarWinds and its CISO, research on vulnerabilities in large language models and adversarial attacks, AI policy and model behavior, and threat-modeling issues involving browser privacy, Okta's support system, and bug hunting.

### Source excerpt

Exciting news from the SEC, lots of AI, and lots of threat modeling.

## Application and AI roundup - September

DevFeed: [Application and AI roundup - September](<https://devfeed.tech/articles/application-and-ai-roundup-september-36687.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-september/>)

Author: Adam

Published: 2023-10-04T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Memory Safety](<https://devfeed.tech/topics/memory-safety.md>), [c/c++](<https://devfeed.tech/topics/c-c-plus-plus.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Zig](<https://devfeed.tech/topics/zig.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [c-c-plus-plus](<https://devfeed.tech/tags/c-c-plus-plus.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [development](<https://devfeed.tech/tags/development.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>)

### AI overview

A September roundup covering application security developments involving memory safety, C and C++, Zig, hardware memory tagging, secure-by-design AI guidance, cybersecurity policy for medical devices, and open-source software security.

### Source excerpt

September was a big month in appsec for both memory safety and policy

## AI-assisted programming can speed development while increasing abstraction and technical debt

DevFeed: [AI-assisted programming can speed development while increasing abstraction and technical debt](<https://devfeed.tech/articles/ai-will-be-the-high-interest-credit-card-of-2023-36663.md>)

Original publisher: [Read original article](<https://shostack.org/blog/ai-high-interest-credit-card/>)

Author: Adam

Published: 2023-06-16T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [jupyter notebooks](<https://devfeed.tech/topics/jupyter-notebooks.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Python](<https://devfeed.tech/topics/python.md>), [pair\_programming](<https://devfeed.tech/topics/pair-programming.md>), [Programming](<https://devfeed.tech/topics/programming.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [appsec](<https://devfeed.tech/tags/appsec.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [jupyter-notebooks](<https://devfeed.tech/tags/jupyter-notebooks.md>), [pair-programming](<https://devfeed.tech/tags/pair-programming.md>), [programming](<https://devfeed.tech/tags/programming.md>), [python](<https://devfeed.tech/tags/python.md>)

### AI overview

The author reflects on using ChatGPT, GitHub Copilot, pair programming, and Jupyter Notebooks while learning Python and producing graphs. The experience accelerated development and debugging, but raised concerns about code quality, application security, abstraction, and the faster accumulation of technical debt.

### Source excerpt

AI will be the high interest credit card of 2023 I haven't done a lot of work in Python, and I've never used it to produce graphs. But after an hour of pair programming and then using Chatgpt and Github Copilot got me quite far in writing a set of Jupyter Notebooks, and dramatically shrunk the effort to use and debug a new tool. I wanted to record some thoughts on the experience, and what it means for programming and for application security.

## AppSecPNW 2023

DevFeed: [AppSecPNW 2023](<https://devfeed.tech/articles/appsecpnw-2023-36688.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsecpnw2023/>)

Author: Adam

Published: 2023-06-12T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [event](<https://devfeed.tech/tags/event.md>), [keynote](<https://devfeed.tech/tags/keynote.md>)

### AI overview

The author reports delivering the opening keynote at OWASP's AppSec PNW 2023 in Portland and provides the presentation slides.

### Source excerpt

Adam's AppSecPNW 2023 keynote

## The Appsec Landscape in 2023

DevFeed: [The Appsec Landscape in 2023](<https://devfeed.tech/articles/the-appsec-landscape-in-2023-36998.md>)

Original publisher: [Read original article](<https://shostack.org/blog/the-appsec-landscape-in-2023/>)

Author: Adam

Published: 2023-01-05T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [changes](<https://devfeed.tech/tags/changes.md>), [circleci](<https://devfeed.tech/tags/circleci.md>), [driving](<https://devfeed.tech/tags/driving.md>), [external](<https://devfeed.tech/tags/external.md>), [government](<https://devfeed.tech/tags/government.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article examines how economic conditions, new regulations, and engineering considerations may shape application security decisions in 2023. It emphasizes threat modeling, secure software development requirements, legacy code, and software supply-chain concerns.

### Source excerpt

External changes will be driving appsec in 2023. It's time to frame the decisions in front of you.

## Application Security Roundup - September

DevFeed: [Application Security Roundup - September](<https://devfeed.tech/articles/application-security-roundup-september-36686.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-sept/>)

Author: Adam

Published: 2022-09-30T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [pip](<https://devfeed.tech/topics/pip.md>), [PyPI](<https://devfeed.tech/topics/pypi.md>), [Python](<https://devfeed.tech/topics/python.md>), [PyTorch](<https://devfeed.tech/topics/pytorch.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [appsec](<https://devfeed.tech/tags/appsec.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [python](<https://devfeed.tech/tags/python.md>), [pytorch](<https://devfeed.tech/tags/pytorch.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

A monthly application security roundup covering access-control failures, STRIDE, DevSecOps, attack trees, software supply-chain attacks, customer-service risks, PyPI package installation behavior, PyTorch loading behavior, and cryptography.

### Source excerpt

Interesting appsec posts: machine learning, performance, and C4

## Application Security Roundup - July

DevFeed: [Application Security Roundup - July](<https://devfeed.tech/articles/application-security-roundup-july-36679.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-july/>)

Author: Adam

Published: 2022-07-30T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [appsec](<https://devfeed.tech/tags/appsec.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [performance](<https://devfeed.tech/tags/performance.md>)

### AI overview

A July roundup of application security posts covering attacks on machine learning systems, Spotify's adaptation of the C4 model for understanding system architecture, and the relationship between performance and security.

### Source excerpt

Interesting appsec posts: machine learning, performance, and C4

## Application Security Roundup - May

DevFeed: [Application Security Roundup - May](<https://devfeed.tech/articles/application-security-roundup-may-36683.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-may/>)

Author: Adam

Published: 2022-05-12T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [appsec](<https://devfeed.tech/tags/appsec.md>), [development](<https://devfeed.tech/tags/development.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A roundup of appsec posts and related reading covering security practitioners, scaling application security, systems thinking, cybersecurity disclosures, threat modeling, threat modeling careers, and UK NCSC technology assurance principles.

### Source excerpt

A collection of interesting appsec posts.

## Future of Appsec podcast

DevFeed: [Future of Appsec podcast](<https://devfeed.tech/articles/future-of-appsec-podcast-36802.md>)

Original publisher: [Read original article](<https://shostack.org/blog/future-of-appsec/>)

Author: Adam

Published: 2022-04-21T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [appsec](<https://devfeed.tech/tags/appsec.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

An episode of Tromzo's Future of Appsec podcast discusses making threat modeling more accessible, bridging security and development teams, training developers, prioritizing threat modeling, and recognizing its broader benefits.

### Source excerpt

A really fun episode with Adam joining Harshill Parikh of Tromzo's Future of Appsec podcast.

## 25 Years in AppSec: Looking Back, Looking Forward

DevFeed: [25 Years in AppSec: Looking Back, Looking Forward](<https://devfeed.tech/articles/25-years-in-appsec-looking-back-looking-forward-36643.md>)

Original publisher: [Read original article](<https://shostack.org/blog/25-years-appsec-keynote/>)

Author: Adam

Published: 2022-01-10T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [global](<https://devfeed.tech/tags/global.md>), [keynote](<https://devfeed.tech/tags/keynote.md>)

### AI overview

The author shares an opening keynote from OWASP AppSec Global 2021 reflecting on 25 years in application security and its future. The keynote is now publicly available.

### Source excerpt

My opening keynote from Appsec Global 2021

## 25 Years of Appsec - Appsec Global

DevFeed: [25 Years of Appsec - Appsec Global](<https://devfeed.tech/articles/25-years-of-appsec-appsec-global-36645.md>)

Original publisher: [Read original article](<https://shostack.org/blog/25-years-of-appsec-owasp/>)

Author: Adam

Published: 2021-11-11T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Code review](<https://devfeed.tech/topics/code-review.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [code-review](<https://devfeed.tech/tags/code-review.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A retrospective on 25 years of application security, presented through an OWASP Global AppSec 2021 keynote. It covers the author's early source code security review work, later experience with the Microsoft SDL team, and questions about the future of application security.

### Source excerpt

Adam is delivering the opening keynote for OWASP Global Appsec 2021 with a 25 year restrospective on the history of appsec and a look into its future.

## Trainings at Global Appsec 2021

DevFeed: [Trainings at Global Appsec 2021](<https://devfeed.tech/articles/trainings-at-global-appsec-2021-37096.md>)

Original publisher: [Read original article](<https://shostack.org/blog/trainings-global-appsec-2021/>)

Author: Adam

Published: 2021-10-20T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Python](<https://devfeed.tech/topics/python.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [global](<https://devfeed.tech/tags/global.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [training](<https://devfeed.tech/tags/training.md>), [web-apps](<https://devfeed.tech/tags/web-apps.md>)

### AI overview

The article announces training opportunities at OWASP AppSec Global 2021, highlighting several threat modeling courses and additional sessions on secure coding, DevSecOps, web application hacking, bug bounty, Kubernetes security, and Python-related vulnerability research.

### Source excerpt

Tremendous training opportunities in threat modeling and other topics at Appsec Global 2021

## 25 Years in AppSec: Looking Back

DevFeed: [25 Years in AppSec: Looking Back](<https://devfeed.tech/articles/25-years-in-appsec-looking-back-36644.md>)

Original publisher: [Read original article](<https://shostack.org/blog/25-years-in-appsec-looking-back/>)

Author: Adam

Published: 2021-08-09T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Code review](<https://devfeed.tech/topics/code-review.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Memory safety verification](<https://devfeed.tech/topics/memory-safety-verification.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [code-review](<https://devfeed.tech/tags/code-review.md>), [compiler](<https://devfeed.tech/tags/compiler.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [tooling](<https://devfeed.tech/tags/tooling.md>)

### AI overview

A retrospective on the growth of application security, beginning with code review guidelines published 25 years ago and describing how practices and tooling evolved from firewall-group reviews, linting, and compiler warnings toward broader security approaches.

### Source excerpt

Time flies and things change... A look back on the growth of this industry.

## Pacific Northwest Appsec Conference

DevFeed: [Pacific Northwest Appsec Conference](<https://devfeed.tech/articles/pacific-northwest-appsec-conference-36925.md>)

Original publisher: [Read original article](<https://shostack.org/blog/pacific-northwest-appsec-conference/>)

Author: Adam

Published: 2021-05-14T00:00:00Z

Content type: news

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [appsec](<https://devfeed.tech/tags/appsec.md>), [conference](<https://devfeed.tech/tags/conference.md>), [event](<https://devfeed.tech/tags/event.md>), [free](<https://devfeed.tech/tags/free.md>), [security-conference](<https://devfeed.tech/tags/security-conference.md>), [sponsored](<https://devfeed.tech/tags/sponsored.md>), [virtual](<https://devfeed.tech/tags/virtual.md>)

### AI overview

The AppSec Pacific Northwest Conference is a free virtual application security event scheduled for Saturday, June 19th. Sponsored by OWASP chapters in Portland, Vancouver, and Victoria, it is accepting presentation proposals from both new and experienced speakers.

### Source excerpt

AppSec Pacific Northwest Conference is a free application security conference that will be held Saturday, June 19th. It is a virtual, online event sponsored by the OWASP chapters of Portland, Vancouver, and Victoria.

## Better OKRs Through Threat Modeling

DevFeed: [Better OKRs Through Threat Modeling](<https://devfeed.tech/articles/better-okrs-through-threat-modeling-36697.md>)

Original publisher: [Read original article](<https://shostack.org/blog/better-oks-through-threat-modeling/>)

Author: Adam

Published: 2021-02-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [okrs](<https://devfeed.tech/tags/okrs.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This commentary argues that effective threat modeling can improve application security OKRs and help define a strategic AppSec roadmap. It proposes sample objectives involving current threat-model documents, system resilience, security testing, and reducing security debt.

### Source excerpt

Effective Threat Modeling by itself can ensure that your OKRs and AppSec Program are not only in great tactical shape, but also help define a strategic roadmap for your AppSec Program.

## When to Threat Model

DevFeed: [When to Threat Model](<https://devfeed.tech/articles/when-to-threat-model-37121.md>)

Original publisher: [Read original article](<https://shostack.org/blog/when-to-threat-model/>)

Author: Adam

Published: 2020-08-12T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [.NET Conf](<https://devfeed.tech/topics/net-conf.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [defcon](<https://devfeed.tech/tags/defcon.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [talk](<https://devfeed.tech/tags/talk.md>)

### AI overview

The article discusses when organizations should perform threat modeling. It notes that practices such as doing it every sprint or aligning it with waterfall development are not universal, particularly when considering software supply chains, and highlights organizational discipline factors from a Biohacking Village talk at DefCon.

### Source excerpt

A talk from the Biohacking Village at DefCon brought up a good point.

## Threat Modeling with Questionnaires

DevFeed: [Threat Modeling with Questionnaires](<https://devfeed.tech/articles/threat-modeling-with-questionnaires-37055.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threat-modeling-with-questionnaires/>)

Author: Adam

Published: 2020-03-19T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [self-service](<https://devfeed.tech/topics/self-service.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [security](<https://devfeed.tech/tags/security.md>), [self-service](<https://devfeed.tech/tags/self-service.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

The article examines lightweight threat modeling through self-service security questionnaires. It argues that developers or scrum masters can identify what they are building, what could go wrong, and whether security engineers should focus on the feature based on its risk.

### Source excerpt

This post comes from a conversation I had on Linkedin with Clint Gibler.

## Threat Model Thursday: Games

DevFeed: [Threat Model Thursday: Games](<https://devfeed.tech/articles/threat-model-thursday-games-37076.md>)

Original publisher: [Read original article](<https://shostack.org/blog/tmt-games/>)

Author: Adam

Published: 2020-02-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [games](<https://devfeed.tech/tags/games.md>), [security-and-privacy](<https://devfeed.tech/tags/security-and-privacy.md>)

### AI overview

A Threat Model Thursday post announces transcriptions of a talk about using card gaming to help teams model security and privacy threats. It links to parts one and two and notes that part three will be posted later.

### Source excerpt

For reasons I can't quite talk about yet, this has been a super busy time, and I look forward to sharing the exciting developments that have kept me occupied.

## Threat Modeling at Layer 8

DevFeed: [Threat Modeling at Layer 8](<https://devfeed.tech/articles/threat-modeling-at-layer-8-37030.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threat-modeling-at-layer-8/>)

Author: Adam

Published: 2019-07-12T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [layer](<https://devfeed.tech/tags/layer.md>), [podcast](<https://devfeed.tech/tags/podcast.md>)

### AI overview

A discussion of online conflict, including bullying, trolling, and threats, on the AppSec Podcast. The speakers consider how to engineer responses to these problems and invite collaboration.

### Source excerpt

Discussing online conflict on the AppSec Podcast

## Threat Modeling Panel at APPSEC Cali 2018

DevFeed: [Threat Modeling Panel at APPSEC Cali 2018](<https://devfeed.tech/articles/threat-modeling-panel-at-appsec-cali-2018-37046.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threat-modeling-panel-at-appsec-cali-2018/>)

Author: Adam

Published: 2018-03-20T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [blog](<https://devfeed.tech/tags/blog.md>), [experience](<https://devfeed.tech/tags/experience.md>), [panel](<https://devfeed.tech/tags/panel.md>)

### AI overview

The author reflects on participating in a threat modeling panel at APPSEC Cali 2018, describing the panel as having a good mix of experience and interesting conversations.

### Source excerpt

[no description provided]

## AppSec Cali 2018: Izar Tarandach

DevFeed: [AppSec Cali 2018: Izar Tarandach](<https://devfeed.tech/articles/appsec-cali-2018-izar-tarandach-36674.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-cali-2018-izar-tarandach/>)

Author: Adam

Published: 2018-01-30T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Learning](<https://devfeed.tech/topics/learning.md>), [legacy](<https://devfeed.tech/topics/legacy.md>), [MySQL](<https://devfeed.tech/topics/mysql.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [development](<https://devfeed.tech/tags/development.md>), [experiment](<https://devfeed.tech/tags/experiment.md>), [learning](<https://devfeed.tech/tags/learning.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security](<https://devfeed.tech/tags/security.md>), [sql](<https://devfeed.tech/tags/sql.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

Notes from Izar Tarandach's AppSec Cali 2018 talk describe recurring development security failures, including incomplete requirements, insecure design, weak security awareness, and insecure code. The talk advocates integrating security expertise into development, using concise event-based guidance, training, checklists, and clearly defined responsibilities.

### Source excerpt

[no description provided]

## Jonathan Marcil's Threat Modeling Toolkit talk

DevFeed: [Jonathan Marcil's Threat Modeling Toolkit talk](<https://devfeed.tech/articles/jonathan-marcil-s-threat-modeling-toolkit-talk-36857.md>)

Original publisher: [Read original article](<https://shostack.org/blog/jonathan-marcils-threat-modeling-toolkit-talk/>)

Author: Adam

Published: 2018-01-30T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [plantuml](<https://devfeed.tech/topics/plantuml.md>), [version-control](<https://devfeed.tech/topics/version-control.md>), [trust](<https://devfeed.tech/topics/trust.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [blog](<https://devfeed.tech/tags/blog.md>), [diagram](<https://devfeed.tech/tags/diagram.md>), [github](<https://devfeed.tech/tags/github.md>), [plantuml](<https://devfeed.tech/tags/plantuml.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security](<https://devfeed.tech/tags/security.md>), [talk](<https://devfeed.tech/tags/talk.md>), [trust](<https://devfeed.tech/tags/trust.md>), [version-control](<https://devfeed.tech/tags/version-control.md>)

### AI overview

A report on Jonathan Marcil's threat modeling toolkit talk, covering collaborative threat modeling, data flow diagrams, attack trees, controls checklists, and system models. The talk includes an Electrum example in which investigations driven by a system model found a real JSON-RPC vulnerability, and discusses using PlantUML and version control for attack trees.

### Source excerpt

[no description provided]

## AppSec California TM Panel

DevFeed: [AppSec California TM Panel](<https://devfeed.tech/articles/appsec-california-tm-panel-36675.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-california-tm-panel/>)

Author: Adam

Published: 2018-01-23T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [panel](<https://devfeed.tech/tags/panel.md>), [survey](<https://devfeed.tech/tags/survey.md>)

### AI overview

The author is participating in a threat modeling panel at AppSec California and invites attendees to complete a three-question survey to help shape the discussion.

### Source excerpt

[no description provided]

[Next page](<https://devfeed.tech/tags/appsec.md?cursor=WyIyMDE4LTAxLTIzVDAwOjAwOjAwKzAwOjAwIiwgIjNhNGMwNGVlLWIyODItNDQ0Ni1iNzhlLTA1YjZmODZmMzE5NiJd>)