Threat Modeling and Security by Design

Threat modeling tooling: Use our tool to start threat modeling within minutes.

Solve your threat modeling problems: We can help you to implement threat modeling and security by design.

Learn about threat modeling: We have lots of content to teach you about threat modeling.

Our Threat Modeling Tool Helps you to Perform Structured Threat Modeling at Scale

It’s easy to get started with threat modeling and gain initial security value from it. However, rolling out structured threat modeling at scale is a different matter. Our threat modeling tool helps you to get the most of threat modeling, in order to apply security by design and default.

  • Powerful assessment engine to understand potential threats and security weakness.
  • Flexible Diagram engine to visualize components and communication flows in play.
  • Clear reporting and metrics for compliance demonstration.

Try our threat modeling tool and get started within minutes!

Methods

Learn about the various threat modeling methods such as STRIDE, PASTA, LINDDUN, and Persona non Grata.

Tooling

We have a full list of threat modeling tools that can help to perform threat modeling. Including our own threat modeling tool.

Templates

Templates can help to kickstart the process. We have lots of free templates available.

Examples

We believe that you learn best from practical and real-world examples. We have lots of example cases and threat models available.

Microsoft Copilot Vulnerabilities (CVE-2026-47644, CVE-2026-45497): Injection and Command Execution

Two vulnerabilities in Microsoft Copilot have been disclosed: an injection vulnerability in Copilot Chat for Microsoft Edge (CVE-2026-47644, CVSS 6.5) and a command injection vulnerability in Microsoft Copilot (CVE-2026-45497, CVSS 7.7). Both allow an authorised attacker to execute code or disclose information over a network. What Are the Vulnerabilities? CVE-2026-47644 — Copilot Chat Injection (CVSS 6.5, CWE-74): An improper neutralisation of special elements in…

Continue Reading Microsoft Copilot Vulnerabilities (CVE-2026-47644, CVE-2026-45497): Injection and Command Execution

Microsoft Graph Information Disclosure (CVE-2026-47655): Unauthorized Data Access via Microsoft 365 API Platform

An information disclosure vulnerability in Microsoft Graph, tracked as CVE-2026-47655 (CVSS 6.5), allows an authorised attacker to disclose information over a network. Microsoft Graph is the unified API endpoint for accessing data across Microsoft 365 services — including Exchange Online, SharePoint, Teams, and OneDrive. What Is the Vulnerability? CVE-2026-47655 is an exposure of sensitive information vulnerability in Microsoft Graph (CWE-200). The vulnerability allows an…

Continue Reading Microsoft Graph Information Disclosure (CVE-2026-47655): Unauthorized Data Access via Microsoft 365 API Platform

Microsoft Defender Vulnerabilities (CVE-2026-45584, CVE-2026-45498): Heap-Based Buffer Overflow and Denial of Service

Two vulnerabilities in Microsoft Defender have been disclosed: a heap-based buffer overflow (CVE-2026-45584, CVSS 8.1) enabling unauthorised remote code execution, and a denial-of-service vulnerability (CVE-2026-45498, CVSS 4.0). Both were covered extensively in the May 22, 2026 Vulnerability Intelligence Report and had a CISA KEV remediation deadline of June 3, 2026 — now passed. The fix is delivered through the Malware Protection Engine update to…

Continue Reading Microsoft Defender Vulnerabilities (CVE-2026-45584, CVE-2026-45498): Heap-Based Buffer Overflow and Denial of Service

Windows BitLocker Security Feature Bypass — YellowKey (CVE-2026-45585): PoC Publicly Released, Mitigation Available

Microsoft has acknowledged a security feature bypass vulnerability in Windows BitLocker, publicly known as “YellowKey” and tracked as CVE-2026-45585. The vulnerability affects Windows 11 (24H2, 25H2, 26H1) and Windows Server 2025. A proof-of-concept has been publicly released, and Microsoft has published mitigation guidance while working on a permanent security update. What Is the Vulnerability? CVE-2026-45585 (YellowKey) is a security feature bypass in Windows BitLocker…

Continue Reading Windows BitLocker Security Feature Bypass — YellowKey (CVE-2026-45585): PoC Publicly Released, Mitigation Available

Microsoft SharePoint Deserialization Vulnerabilities (CVE-2026-47294, CVE-2026-45659): Authenticated Remote Code Execution

Two deserialization vulnerabilities in Microsoft SharePoint Server, tracked as CVE-2026-47294 (CVSS 8.0) and CVE-2026-45659 (CVSS 8.8), allow authenticated attackers to execute arbitrary code over a network. Both affect SharePoint Server Subscription Edition, 2016, and 2019, and are fixed in build 16.0.19725.20280 for the Subscription Edition. What Are the Vulnerabilities? Both vulnerabilities involve deserialization of untrusted data — a well-known and frequently exploited vulnerability class…

Continue Reading Microsoft SharePoint Deserialization Vulnerabilities (CVE-2026-47294, CVE-2026-45659): Authenticated Remote Code Execution

Azure Resource Manager Authentication Bypass (CVE-2026-47280): CVSS 10.0 Privilege Escalation in Azure Management Platform

An improper authentication vulnerability in Azure Resource Manager (ARM), tracked as CVE-2026-47280, allows an unauthorised attacker to elevate privileges over a network. The vulnerability carries a CVSS score of 10.0 — the maximum possible severity — and affects Azure’s core management and deployment platform. Microsoft has released a security update. What Is the Vulnerability? CVE-2026-47280 is an authentication bypass vulnerability in Azure Resource Manager…

Continue Reading Azure Resource Manager Authentication Bypass (CVE-2026-47280): CVSS 10.0 Privilege Escalation in Azure Management Platform