Threat Modeling and Security by Design

Threat modeling tooling: Use our tool to start threat modeling within minutes.

Solve your threat modeling problems: We can help you to implement threat modeling and security by design.

Learn about threat modeling: We have lots of content to teach you about threat modeling.

Our Threat Modeling Tool Helps you to Perform Structured Threat Modeling at Scale

It’s easy to get started with threat modeling and gain initial security value from it. However, rolling out structured threat modeling at scale is a different matter. Our threat modeling tool helps you to get the most of threat modeling, in order to apply security by design and default.

  • Powerful assessment engine to understand potential threats and security weakness.
  • Flexible Diagram engine to visualize components and communication flows in play.
  • Clear reporting and metrics for compliance demonstration.

Try our threat modeling tool and get started within minutes!

Methods

Learn about the various threat modeling methods such as STRIDE, PASTA, LINDDUN, and Persona non Grata.

Tooling

We have a full list of threat modeling tools that can help to perform threat modeling. Including our own threat modeling tool.

Templates

Templates can help to kickstart the process. We have lots of free templates available.

Examples

We believe that you learn best from practical and real-world examples. We have lots of example cases and threat models available.

CVE-2026-8935: WP MAPS PRO WordPress Plugin Unauthenticated AJAX Vulnerability (CVSS 9.8)

Critical Vulnerability — CVSS 9.8 CVE-2026-8935 is a critical-severity unauthenticated AJAX vulnerability in the WP MAPS PRO WordPress plugin. CVSS Score: 9.8 (Critical) | Attack Complexity: Low | Privileges Required: None Exploitation is trivial. A valid nonce is exposed on every frontend page, allowing any unauthenticated visitor to execute privileged AJAX actions remotely. CVE-2026-8935 is a critical-severity unauthenticated AJAX vulnerability affecting the WP MAPS…

Continue Reading CVE-2026-8935: WP MAPS PRO WordPress Plugin Unauthenticated AJAX Vulnerability (CVSS 9.8)

CVE-2026-20262: Cisco Catalyst SD-WAN Manager Path Traversal Vulnerability (CISA KEV)

CISA Known Exploited Vulnerability CVE-2026-20262 has been added to the CISA Known Exploited Vulnerabilities (KEV) Catalog. Date Added: June 15, 2026 | Due Date: June 29, 2026 Federal agencies and organisations following CISA Binding Operational Directive (BOD) 22-01 must remediate this vulnerability by the due date. This vulnerability is being actively exploited in the wild. CVE-2026-20262 is a high-severity path traversal vulnerability in Cisco…

Continue Reading CVE-2026-20262: Cisco Catalyst SD-WAN Manager Path Traversal Vulnerability (CISA KEV)

OptinMonster WordPress Plugin CDN Supply-Chain Attack: 1.4 Million Sites Affected

OptinMonster, the popular lead-generation and conversion optimization WordPress plugin with over 1.4 million active installations, has been compromised in a CDN supply-chain attack that also affected sibling products TrustPulse and PushEngage. The attack, discovered by e-commerce security firm Sansec over the weekend of June 13-14, 2026, allowed threat actors to inject malicious JavaScript into websites by compromising the parent company Awesome Motive’s content distribution…

Continue Reading OptinMonster WordPress Plugin CDN Supply-Chain Attack: 1.4 Million Sites Affected

SimpleHelp Remote Support Platform: Unauthorized Administrator Account Creation Vulnerability

SummaryA critical vulnerability has been disclosed in the SimpleHelp remote support platform that allows unauthenticated attackers to create rogue administrator accounts. This flaw enables complete takeover of the SimpleHelp server and all connected client machines.Affected ProductSimpleHelp – Remote support and remote access platform (all versions prior to the patched release)Vulnerability DetailsThe vulnerability resides in the administrator account creation mechanism. Due to insufficient access controls,…

Continue Reading SimpleHelp Remote Support Platform: Unauthorized Administrator Account Creation Vulnerability

CVE-2026-12191: Comma AI Openpilot Unsafe Pickle Deserialization Vulnerability (CVSS 7.8)

Overview CVE-2026-12191 is a high-severity insecure deserialization vulnerability in Comma AI Openpilot, an open-source autonomous driving research platform. The vulnerability exists in the modeld.py module, which uses Python’s pickle.load() and pickle.loads() to deserialize untrusted data without any validation or sanitization. A local attacker with access to the system can craft a malicious pickle payload to achieve arbitrary code execution in the context of the…

Continue Reading CVE-2026-12191: Comma AI Openpilot Unsafe Pickle Deserialization Vulnerability (CVSS 7.8)