Threat Modeling and Security by Design
Threat modeling tooling: Use our tool to start threat modeling within minutes.
Solve your threat modeling problems: We can help you to implement threat modeling and security by design.
Learn about threat modeling: We have lots of content to teach you about threat modeling.
Our Threat Modeling Tool Helps you to Perform Structured Threat Modeling at Scale
It’s easy to get started with threat modeling and gain initial security value from it. However, rolling out structured threat modeling at scale is a different matter. Our threat modeling tool helps you to get the most of threat modeling, in order to apply security by design and default.
- Powerful assessment engine to understand potential threats and security weakness.
- Flexible Diagram engine to visualize components and communication flows in play.
- Clear reporting and metrics for compliance demonstration.
Try our threat modeling tool and get started within minutes!
Tooling
We have a full list of threat modeling tools that can help to perform threat modeling. Including our own threat modeling tool.
Templates
Templates can help to kickstart the process. We have lots of free templates available.
Examples
We believe that you learn best from practical and real-world examples. We have lots of example cases and threat models available.
Threat Modeling ARTICLES
Threat Modeling Tooling
Explanation of the Threat Modeling Tool
STRIDE Threat Modeling
The Ultimate List of STRIDE Threat Examples
STRIDE Threat Modeling Example for Better Understanding and Learning
STRIDE Threat Modeling in DevOps: A Perfect Fit
What is STRIDE Threat Modeling
STRIDE Threat Modeling Frequently Asked Questions and Answers (FAQs)
Threat Modeling
How to use Data Flow Diagrams in Threat Modeling
Threat Modeling Versus Vulnerability Management
CAPEC Threat Modeling
Threat Modeling Framework
Why Threat Modeling is Overly Complex and How We Can Simplify It
CIS Controls
CIS Controls (CIS Critical Security Controls)
OWASP Top 10
PASTA Threat Modeling
PASTA Threat Modeling and DevOps
A PASTA Threat Modeling Example
TRIKE Threat Modeling
NIST
LINDDUN Threat Modeling
DREAD Threat Modeling
CISO Security Mind Map
AI Security
Adding AI to Applications: What You Need to Know for Safety and Security
Critical Vulnerability — CVSS 9.8 CVE-2026-8935 is a critical-severity unauthenticated AJAX vulnerability in the WP MAPS PRO WordPress plugin. CVSS Score: 9.8 (Critical) | Attack Complexity: Low | Privileges Required: None Exploitation is trivial. A valid nonce is exposed on every frontend page, allowing any unauthenticated visitor to execute privileged AJAX actions remotely. CVE-2026-8935 is a critical-severity unauthenticated AJAX vulnerability affecting the WP MAPS…
CISA Known Exploited Vulnerability CVE-2026-20262 has been added to the CISA Known Exploited Vulnerabilities (KEV) Catalog. Date Added: June 15, 2026 | Due Date: June 29, 2026 Federal agencies and organisations following CISA Binding Operational Directive (BOD) 22-01 must remediate this vulnerability by the due date. This vulnerability is being actively exploited in the wild. CVE-2026-20262 is a high-severity path traversal vulnerability in Cisco…
OptinMonster, the popular lead-generation and conversion optimization WordPress plugin with over 1.4 million active installations, has been compromised in a CDN supply-chain attack that also affected sibling products TrustPulse and PushEngage. The attack, discovered by e-commerce security firm Sansec over the weekend of June 13-14, 2026, allowed threat actors to inject malicious JavaScript into websites by compromising the parent company Awesome Motive’s content distribution…
Continue Reading OptinMonster WordPress Plugin CDN Supply-Chain Attack: 1.4 Million Sites Affected
SummaryA critical vulnerability has been disclosed in the SimpleHelp remote support platform that allows unauthenticated attackers to create rogue administrator accounts. This flaw enables complete takeover of the SimpleHelp server and all connected client machines.Affected ProductSimpleHelp – Remote support and remote access platform (all versions prior to the patched release)Vulnerability DetailsThe vulnerability resides in the administrator account creation mechanism. Due to insufficient access controls,…
Vulnerability Intelligence Report — June 16, 2026 Coverage: June 1–16, 2026 | Total CISA KEV additions (period): 14 | New KEVs yesterday: 2 | Oracle PeopleSoft deadline passed (June 15) | Next KEV deadline: LiteSpeed cPanel (June 18) | Overdue KEVs: 7 Previous reports: June 15, 2026 | June 14, 2026 Today — Tuesday, June 16, 2026 — marks the start of a new…
Continue Reading Vulnerability Intelligence Report — June 16, 2026
Overview CVE-2026-12191 is a high-severity insecure deserialization vulnerability in Comma AI Openpilot, an open-source autonomous driving research platform. The vulnerability exists in the modeld.py module, which uses Python’s pickle.load() and pickle.loads() to deserialize untrusted data without any validation or sanitization. A local attacker with access to the system can craft a malicious pickle payload to achieve arbitrary code execution in the context of the…