Threat Modeling and Security by Design

Threat modeling tooling: Use our tool to start threat modeling within minutes.

Solve your threat modeling problems: We can help you to implement threat modeling and security by design.

Learn about threat modeling: We have lots of content to teach you about threat modeling.

Our Threat Modeling Tool Helps you to Perform Structured Threat Modeling at Scale

It’s easy to get started with threat modeling and gain initial security value from it. However, rolling out structured threat modeling at scale is a different matter. Our threat modeling tool helps you to get the most of threat modeling, in order to apply security by design and default.

  • Powerful assessment engine to understand potential threats and security weakness.
  • Flexible Diagram engine to visualize components and communication flows in play.
  • Clear reporting and metrics for compliance demonstration.

Try our threat modeling tool and get started within minutes!

Methods

Learn about the various threat modeling methods such as STRIDE, PASTA, LINDDUN, and Persona non Grata.

Tooling

We have a full list of threat modeling tools that can help to perform threat modeling. Including our own threat modeling tool.

Templates

Templates can help to kickstart the process. We have lots of free templates available.

Examples

We believe that you learn best from practical and real-world examples. We have lots of example cases and threat models available.

FortiBleed: Fortinet VPN Credentials Exposed for 73,000 Devices

What Happened On June 17, 2026, security researchers disclosed a massive credential leak affecting Fortinet VPN devices, dubbed “FortiBleed.” A publicly exposed database containing VPN credentials from over 73,000 Fortinet devices worldwide was discovered on an unsecured cloud storage bucket. The exposure appears to stem from a combination of misconfigured logging and a vulnerability chain that allowed attackers to exfiltrate authentication data from FortiOS-based…

Continue Reading FortiBleed: Fortinet VPN Credentials Exposed for 73,000 Devices

Oracle July 2026 Critical Patch Update: 5 CRITICAL and 12+ HIGH Severity Vulnerabilities Across WebLogic, PeopleSoft, Identity Manager, and WebCenter

Date: July 15, 2026 | TLP: CLEAR | Severity: CRITICAL Overview Oracle’s July 2026 Critical Patch Update (CPU) addresses 5 CRITICAL (CVSS ≥ 9.0) and over 12 HIGH severity vulnerabilities across its flagship product suite. The affected products include Oracle WebLogic Server, Oracle PeopleSoft, Oracle Identity Manager, Oracle WebCenter, WebCenter Capture, and Oracle VirtualBox. Remote, unauthenticated attackers can exploit several of these flaws to…

Continue Reading Oracle July 2026 Critical Patch Update: 5 CRITICAL and 12+ HIGH Severity Vulnerabilities Across WebLogic, PeopleSoft, Identity Manager, and WebCenter

CVE-2026-6933: Premmerce Dev Tools WordPress Plugin Remote Code Execution Vulnerability (CVSS 8.8)

High Severity Vulnerability — CVSS 8.8 CVE-2026-6933 is a high-severity missing authorization vulnerability in the Premmerce Dev Tools WordPress plugin leading to unauthenticated remote code execution. CVSS Score: 8.8 (High) | Attack Complexity: Low | Privileges Required: None The plugin exposes privileged AJAX/REST API endpoints without authorization checks, allowing any unauthenticated attacker to execute arbitrary code on the WordPress server. CVE-2026-6933 is a high-severity…

Continue Reading CVE-2026-6933: Premmerce Dev Tools WordPress Plugin Remote Code Execution Vulnerability (CVSS 8.8)

Ransomware Gangs Abusing Microsoft Teams Relays to Hide Command-and-Control Traffic

What HappenedSecurity researchers have identified a concerning trend among ransomware gangs who are exploiting Microsoft Teams relay infrastructure to conceal their command-and-control (C2) traffic. By routing malicious communications through legitimate Microsoft 365 and Teams infrastructure, attackers can make their C2 traffic blend seamlessly with normal enterprise collaboration activity, evading traditional network-based detection mechanisms. This technique was first observed in the wild in June 2026…

Continue Reading Ransomware Gangs Abusing Microsoft Teams Relays to Hide Command-and-Control Traffic