Threat Modeling and Security by Design

Threat modeling tooling: Use our tool to start threat modeling within minutes.

Solve your threat modeling problems: We can help you to implement threat modeling and security by design.

Learn about threat modeling: We have lots of content to teach you about threat modeling.

Our Threat Modeling Tool Helps you to Perform Structured Threat Modeling at Scale

It’s easy to get started with threat modeling and gain initial security value from it. However, rolling out structured threat modeling at scale is a different matter. Our threat modeling tool helps you to get the most of threat modeling, in order to apply security by design and default.

  • Powerful assessment engine to understand potential threats and security weakness.
  • Flexible Diagram engine to visualize components and communication flows in play.
  • Clear reporting and metrics for compliance demonstration.

Try our threat modeling tool and get started within minutes!

Methods

Learn about the various threat modeling methods such as STRIDE, PASTA, LINDDUN, and Persona non Grata.

Tooling

We have a full list of threat modeling tools that can help to perform threat modeling. Including our own threat modeling tool.

Templates

Templates can help to kickstart the process. We have lots of free templates available.

Examples

We believe that you learn best from practical and real-world examples. We have lots of example cases and threat models available.

Arch Linux AUR Supply Chain Compromise: 400+ Packages Distributing Rootkit and Infostealer

Arch Linux AUR Supply Chain Compromise — A massive supply chain attack has compromised over 400 packages in the Arch User Repository (AUR), distributing a Linux rootkit combined with infostealer malware. The malware targets sensitive credentials, access tokens, and SSH keys from compromised systems. All organizations and individuals using Arch-based systems with AUR packages should audit their environments immediately. What Happened In June 2026,…

Continue Reading Arch Linux AUR Supply Chain Compromise: 400+ Packages Distributing Rootkit and Infostealer

Spring Ecosystem Security Advisory: 8 New Vulnerabilities Across Spring Integration, Web Services, Web Flow, and Boot (June 2026)

VMware Tanzu has published a coordinated security advisory covering eight new vulnerabilities across multiple Spring ecosystem modules. The affected projects include Spring Integration (1 CVE), Spring Web Services (4 CVEs), Spring Web Flow (2 CVEs), and Spring Boot (1 CVE). The vulnerabilities span arbitrary file writes, authentication and signature bypasses, expression language injection, cross-site scripting, hostname verification weaknesses, weak cryptographic defaults, and replay attack…

Continue Reading Spring Ecosystem Security Advisory: 8 New Vulnerabilities Across Spring Integration, Web Services, Web Flow, and Boot (June 2026)

GitLab Security Advisory: 4 New Vulnerabilities — SSRF, DoS, Email Injection, and Service Desk Impersonation (June 2026)

GitLab Security Advisory — June 2026 (Second Release) 4 New CVEs | CVSS Range: 5.3 – 7.5 | All fixed in GitLab 18.10.8, 18.11.5, and 19.0.2 This is the second GitLab security release this period, following the June 11 advisory covering 8 CVEs. The combined total now stands at 12 CVEs for this release cycle. GitLab has published a supplemental security advisory addressing 4…

Continue Reading GitLab Security Advisory: 4 New Vulnerabilities — SSRF, DoS, Email Injection, and Service Desk Impersonation (June 2026)

CVE-2026-8464: Golem OEE MES Unauthenticated Path Traversal Vulnerability

CVE: CVE-2026-8464 | CVSS 4.0: 8.3 (HIGH) | CWE: CWE-22 | Vendor: Golem | Product: Golem OEE MES | Affected versions: < 11.6.0 What Is the Vulnerability CVE-2026-8464 is a high-severity path traversal vulnerability in the Golem OEE MES (Overall Equipment Effectiveness Manufacturing Execution System) that allows unauthenticated attackers on the local network to read arbitrary files from the server operating system. The vulnerability…

Continue Reading CVE-2026-8464: Golem OEE MES Unauthenticated Path Traversal Vulnerability

CVE-2026-10795: UpdraftPlus WordPress Plugin Authentication Bypass Leading to Remote Code Execution

CVE: CVE-2026-10795 | CVSS 3.1: 8.1 (HIGH) | CWE: CWE-306 | Vendor: UpdraftPlus | Product: UpdraftPlus: WP Backup & Migration Plugin | Affected versions: ≤ 1.26.4 | Installations: 3+ million What Is the Vulnerability UpdraftPlus includes a remote communications (RPC) protocol that allows authenticated remote control of the plugin’s backup, restore, and migration functions. This protocol relies on cryptographic signature verification to authenticate incoming…

Continue Reading CVE-2026-10795: UpdraftPlus WordPress Plugin Authentication Bypass Leading to Remote Code Execution

CVE-2026-11561: Apinizer Expression Language Injection Vulnerability (CVSS 9.8)

CVE-2026-11561 is a critical vulnerability in Soagen Apinizer, an API management platform, with a CVSS score of 9.8 (CRITICAL). Classified under CWE-917: Expression Language Injection, this flaw affects Apinizer versions 2026.04.0 through 2026.04.5. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code on the Apinizer server, leading to complete system compromise. What Is the Vulnerability This is an Expression Language (EL) injection…

Continue Reading CVE-2026-11561: Apinizer Expression Language Injection Vulnerability (CVSS 9.8)