⚠️ Malware / Trojaner / VirenYou don't want this Sleepwalker backdoor on your Windows machine(24.08.2026 um 23:39 Uhr)
⚠️ Malware / Trojaner / VirenCrooks push Mac malware through fake OpenAI Codex ads(25.08.2026 um 11:15 Uhr)
🔧 AI Nachrichten OpenAI explains how its naughty AI agents attacked Hugging Face(27.08.2026 um 01:45 Uhr)
⚠️ Malware / Trojaner / VirenATF responds to 'major' cybersecurity incident after ransomware gang's claims(27.08.2026 um 17:25 Uhr)
🔧 AI Nachrichten Industry that built the problem offers to sell you the solution(28.08.2026 um 13:01 Uhr)
🕵️ SicherheitslückenCISA: Most exploited vulnerabilities should have been eradicated decades ago(28.08.2026 um 13:29 Uhr)
⚠️ Malware / Trojaner / VirenAnthropic cracks down on hijacked user accounts mining AI tokens(31.08.2026 um 18:03 Uhr)
⚠️ Malware / Trojaner / VirenYou don't want this Sleepwalker backdoor on your Windows machine(24.08.2026 um 23:39 Uhr)
⚠️ Malware / Trojaner / VirenCrooks push Mac malware through fake OpenAI Codex ads(25.08.2026 um 11:15 Uhr)
🔧 AI Nachrichten OpenAI explains how its naughty AI agents attacked Hugging Face(27.08.2026 um 01:45 Uhr)
⚠️ Malware / Trojaner / VirenATF responds to 'major' cybersecurity incident after ransomware gang's claims(27.08.2026 um 17:25 Uhr)
🔧 AI Nachrichten Industry that built the problem offers to sell you the solution(28.08.2026 um 13:01 Uhr)
🕵️ SicherheitslückenCISA: Most exploited vulnerabilities should have been eradicated decades ago(28.08.2026 um 13:29 Uhr)
⚠️ Malware / Trojaner / VirenAnthropic cracks down on hijacked user accounts mining AI tokens(31.08.2026 um 18:03 Uhr)

26 🕛 kürzlich 10 Min Lesezeit
0

Introducing a OWASP Game for threat modeling Agentic AI, Cloud, Devops, Frontend, LLM, Automation, and Web

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with designing for security.



Too often, the shift-left mantra consists of implementing (AI-powered) code scanning and applying AI-powered security fixes for remediation. Also, don't forget to implement the AI-powered benchmark for AI-powered Security Fixes. Now, to be clear, I am not actually telling you to stop using these tools — if they work for you — instead, we should ask ourselves:




  • What are we working on?

  • What can go wrong?

  • What are we going to do about it?

  • Did we do a good job?






OWASP Cornucopia v3.0



.

If you would like to buy a professional physical copy of v3.0, you can do so at



. Each of the common attack patterns will have a unique set of ASVS 5.0 requirements, which means that you never need to stop playing the game! You will always be able to return to the same card to discover new threats and security requirements to consider when building your software; that's the Cornucopia way.



We have also "





OWASP Cornucopia Companion Edition v1.0



to complement the existing two editions. The and for sale at .



To commemorate the OWASP Foundation's 25th anniversary, we have also designed the case, leaflet, and cards specifically to celebrate the anniversary and OWASP's achievements within the field of application security and software engineering. We will also be attending the OWASP Global AppSec 2026 in Vienna, where we will be demoing the game for anyone who wants to come and play with us.



We feel this is only the start; each year, OWASP Cornucopia resellers distribute 1,000 games to teams worldwide. At copi.owasp.org, more than 500 users conduct threat modeling for mobile applications, agentic AI, automated threats, cloud, identity management, large language models, and SDL processes every month. In the coming time, we at OWASP Cornucopia will work towards promoting threat modeling and games to change the security culture at software companies worldwide.





The time when development teams could focus only on web development is long gone. Modern software development and sprint planning often include implementing integrations towards large language models, AI agents, and DevOps pipelines through full-stack development. In such an environment, security requirements are constantly shifting from sprint to sprint. Therefore, the only possibility is choosing an agile and collaborative approach to threat modeling that supports including a large number of people with various backgrounds, experiences, and knowledge.

The OWASP Cornucopia Companion Edition was created to accommodate this. A big, beautiful Excel document can never replace a collaborative approach to threat modeling that includes the opinions of everyone on the development team. To avoid having the threat modeling and security design processes become an exercise in superficial ISO compliance, you need to empower your development teams to work together to come up with a secure design. Such a process requires ingenuity, to think out of the box, and to make unpopular decisions that may affect the delivery schedule of a development project. Neither an Excel document nor an ISO 27001 policy will ever get a development team to do that.



Failing to regularly assess your security isn't only costly; it can leave you vulnerable to threats. Several companies have implemented OWASP Cornucopia as part of their SDLC and use it for security requirements analysis, threat modeling, and secure design for every sprint and every user story. You should do the same! Don't let your business spiral out of control; consciously assess how you are doing by continuously threat-modeling your applications and infrastructure. To get started scaling your threat modeling efforts, OWASP Cornucopia and its companion edition are the perfect tools.



We want to thank all project leaders and contributors to the OWASP projects who have provided valuable input and guidance on the OWASP Top 10, OWASP AISVS, OWASP MAS, OWASP Cumulus, OWASP Threat Dragon and the OWASP GenAI Security project. It's thanks to these projects, and many more, that we can deliver to you the OWASP gamified approach to threat modeling and requirement analysis.

We also want to thank the people and contributors to Mitre's Common Attack Pattern Enumeration and Classification (CAPEC™) and Atlas, together with CSA Cloud Controls Matrix, which are all used in the cross-references provided.





Walk that walk, talk that talk



With this latest version of OWASP Cornucopia, we are making it more than a game; it has become a fully fledged threat modeling tool. It doesn’t just feed into your threat modeling process; it drives it, and it doesn’t just work; it scales! A long-time project contributor, previously working at Banco de Crédito BCP, used OWASP Cornucopia to train hundreds of people in using .



"Continuous Gamified threat modeling", done the OWASP way, has been tested and proven to work and is generally welcomed by ISO auditors. Not only is it welcomed, but auditors also love to hear about how it can be used to create engagement and change the culture of the companies that make use of it. This, according to Admincontrol, which has been audited 4 times using all 97 controls from ISO 27001/27002 as part of their information security management system. "Continuous Gamified Threat Modeling" is about assisting software development teams in identifying security requirements in Agile, conventional, and formal development processes through continuous gamification and threat modeling for every feature and every release. Don't apologize for designing before coding, it's called thinking!





.



"Continuous Threat Modeling", a term described in "!



Admincontrol used threat modeling to design its applications. They have large sessions that they run once a year and several smaller sessions for each sprint. They define Jira issues to mitigate these threats and assign them directly to the development team's backlog. Then they have security backlog grooming once a month with the product owners, where they discuss directly with them how they can resolve these issues.

The first graph shows the resolution time for Jira issues created during the annual threat modeling session. The second graph shows the resolution of Jira issues for the threat modeling they do each sprint.





As shown in the first graph, the resolution time is increasing. This is because they had Jira issues that were defined but never resolved. Some of the issues had taken nearly 3 years to resolve.

The second graph shows an increase in resolution time. This is because Admincontrol had a component that didn't get finalized. It stayed on the drawing board, but the threat modeling was done, so the resolution time spiked. There are no data prior to 2023, as they didn't keep this form of statistics before then. On average, the resolution time for the short threat modeling sessions were ca. 3 months. This usually coincided with the frequency of their minor releases, which included new features.



If you do long, large sessions, you run the risk of doing threat modeling irregularly, meaning you will have issues you will never be able to solve, and issues meant to improve security will stay in the development team's backlog forever, never to see the light of day. If you think technical debt is scary, wait until you see your security debt.



, share your feedback, and, if appropriate, give us a star⭐️.










OWASP is a non-profit foundation that envisions a world with no more insecure software. Our mission is to be the global open community that powers secure software through education, tools, and collaboration. We maintain hundreds of open source projects, run industry-leading educational and training conferences, and meet through over 340 chapters worldwide.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 48%
🟡 In Evaluierung 31%
🟢 Keine Auswirkung 17%
Spannende Innovation 5%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
OpenAI launches GPT-6 Astra
1 Quelle
AWS Adds GPT-5.6 Terra and Luna to Amazon Bedrock in India
1 Quelle
ChatGPT, Claude, Grok, and Gemini Hit by Rare Overlapping Outages
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Introducing a OWASP Game for threat modeling Agentic AI, Cloud, Devops, Frontend, LLM, Automation, and Web

Thematisch verwandte Begriffe: Introducing, OWASP, Game, threat · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...