Izar Tarandach's Avatar

Izar Tarandach

@threatmodeling.dev.bsky.social

Threat model and prosper! πŸ–– OWASP pytm Leader | OWASP Events Committee Chair (2024)

518 Followers  |  62 Following  |  14 Posts  |  Joined: 15.01.2024  |  2.1338

Latest posts by threatmodeling.dev on Bluesky

Post image Post image Post image Post image

🚨 Register now for OWASP Global AppSec US 2025, coming up next month!

owasp.glueup.com/eve...

Kick off your cybersecurity journey before the main conference with 3 days of hands-on training.

#OWASP #AppSec #Pentesting #Infosec #WashingtonDC #Cybersec

15.10.2025 13:04 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
A Dragon and a Python walk into an OWASP card game... | Izar Tarandach πŸŽ—οΈ A short post celebrating some of the Threat Modeling tools that OWASP makes available to the community. Give them a spin - no AI (yet!) but that shouldn't keep you away...

A little appreciation post to the OWASP threat modeling tools.

www.linkedin.com/posts/izarta...

19.09.2025 14:04 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Exciting opportunity alert! πŸš€ Become a mentor at the Meet the Mentor event at #OWASP Global #AppSec USA this November. Share your knowledge, empower future AppSec leaders, and connect with an incredible community.

Claim your spot now: owasp.wufoo.com/form...

11.09.2025 17:32 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image Post image

Join us in Washington, D.C., Nov 3–5, 2025 for immersive, hands-on 3-day sessions at OWASP Global AppSec USA!

Register: owasp.glueup.com/eve...

#AppSec #Cybersec #AISecurity #CloudSecurity #Pentesting #DevSecOps #WashingtonDC

06.08.2025 15:02 β€” πŸ‘ 3    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

I'm giving a 1-Day paid, live Training at OWASP Global AppSec in Washington DC, November 5th, 2025: API Security: Hands-On Secure API Design & Hardening

Learn more here! https://twp.ai/9PTEfL

#OWASP #OWASPGLOBALAPPSEC

18.07.2025 23:23 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
Threat Modeling: A Practical Guide for Development Teams Amazon.com: Threat Modeling: A Practical Guide for Development Teams: 9781492056553: Tarandach, Izar, Coles, Matthew J.: Books

And if you are serious about doing continuous threat modeling, I recommend @threatmodeling.dev's and Matthew Coles's book "Threat Modeling: A Practical Guide for Development Teams": www.amazon.com/Threat-Model...

26.06.2025 10:54 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Privacy time at Threat Modeling Con with @sec_tigger and @Wuytski ! (Check out that definition - ever wondered what a good, modern definition of privacy might be?)

31.05.2025 10:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

It took us a long time but it is still a sweet achievement. Just up for ThreatMod Con 25-a, OWASP pytm has reached the milestone of 1k stars on Github!

We're niche, we don't move very fast, but we shine bright. Thanks everyone who has taken a minute to star us up!

30.05.2025 22:32 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

The Security Table S3E06: "Threat Modeling or Threat Intelligence, Are they the Same".

No. Connected, yes. The same, no.

Now how do they connect ...

21.05.2025 12:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Shostack + Associates updates

We’re sponsoring the Threat Modeling Connect #hackathon, going on now.
Adam will be keynoting BSides Seattle (April 18/19, Seattle).
Adam will be co-presenting with Tanya Janca at RSA: Red Teaming AI: 50 Years of Failure, But […]

[Original post on infosec.exchange]

03.04.2025 14:56 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Hey, "Vibe Threat Modeling" demands a mention or there will be no more vibing!

03.04.2025 15:13 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 1

Presenters PLEASE read the CfP before submitting to avoid any issues!

20.03.2025 19:21 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Threat modeling sessions. If they feel like falling asleep during the afterparty, you're doing it wrong.

Threat modeling sessions. If they feel like falling asleep during the afterparty, you're doing it wrong.

Are your people falling asleep during your sessions?
Mine were, Play OWASP Cornucopia!

OWASP Cornucopia Website App 2.1 & Mobile App 1.1 have been released! See: dev.to/owasp/owaspr...
Thanks to all contributors: cornucopia.owasp.org/about#Acknowledgements

#appsec #threatmodeling #cybersec #owasp

17.02.2025 13:23 β€” πŸ‘ 13    πŸ” 7    πŸ’¬ 0    πŸ“Œ 0

Is it a faux pas to wish people a happy Data Privacy Day (Jan/28) on social media ?

Also can we call it DPD, create a convoluted process around it and sell training for its proper enjoyment ?

27.01.2025 21:53 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
The Cyber Trust Mark Debate Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

Today at The Security Table Podcast we dive into the complexities of the Cyber Trust Mark and its implications for IoT security. Are you ready to question everything you thought you knew about regulation and innovation? Check it out here: buff.ly/4anEpKR
#CyberSecurity #IoT #Innovation

22.01.2025 18:32 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Uncle Joe's cybersec book author's starter pack

A must have for all new bee cybersec reading horses starting out in Bluesky town.

Perfect for those cold and dark winter nights after the security audits finally are over.

Mention @sydseter.com to be added.

go.bsky.app/2EtvRPP

22.01.2025 12:10 β€” πŸ‘ 11    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0

1!

21.01.2025 17:04 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Working Groups | CycloneDX OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. The specification supports Software Bill of Materials (SBOM), Software-as-a-Service Bill of Materials (SaaSBOM), Hardware Bill of Materials (HBOM), Operations Bill of Materials (OBOM), Vulnerability Disclosure Reports (VDR), and Vulnerability Exploitability eXchange (VEX).

We even have a very nice, very small, very interested working group around...Threat Modeling BOM. Come join us. There's plenty of work to be done, and you get to help build some potentially very cool stuff. cyclonedx.org/partic...
2/2

08.01.2025 16:21 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
CycloneDX Bill of Materials Standard | CycloneDX OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. The specification supports Software Bill of Materials (SBOM), Software-as-a-Service Bill of Materials (SaaSBOM), Hardware Bill of Materials (HBOM), Operations Bill of Materials (OBOM), Vulnerability Disclosure Reports (VDR), and Vulnerability Exploitability eXchange (VEX).

Do you, like me, scratch your head and think "SBOMs, what are they good for?" ? If you do, why not join one of the working groups on CycloneDX - now even easier to do by checking out the new site at https://cyclonedx.org !
1/2

08.01.2025 16:21 β€” πŸ‘ 5    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

2025 is going to be the Year Of The Agent. If it is going to be 007 or 86 remains to be seen.

06.01.2025 20:55 β€” πŸ‘ 7    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

We may not be the most tech-y, not the funniest, but we definitely are the fun-nest. We have fun doing it and it shows. Pull a chair and sit with us at The Security Table as we go on a break before we start Season 3!

17.12.2024 14:46 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Hey @swiftonsecurity.com Here is a good joke:

If you receive email from owaspfoundation.org it's not spam.
A faulty Microsoft AI is blocking @owasp.org .
Read: owasp.org/blog/2024/10...

Perhaps they have gone tired of following best security practices?

#appsec #microsoft #ai #owasp

11.12.2024 10:04 β€” πŸ‘ 59    πŸ” 10    πŸ’¬ 2    πŸ“Œ 1
Post image

Calling all Speakers! πŸš€ Big news alert! Ready to make a mark? Submit your paper for the 2025 #OWASP Global #AppSec EU Call for Presentations. Join the #cybersecurity community, flaunt your expertise, and show off your skills. Don't let this chance slip away! Take action now!
sessionize.com/owasp...

09.12.2024 21:55 β€” πŸ‘ 8    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸš€ Don't miss out on this thrilling update! Grab your SUPER Early Bird Tickets for the 2025 #OWASP Global #AppSec EU happening in Barcelona. Seize your spot at a special rate for the May conference. Hurry, these fantastic prices are limited! Register now to secure your spot: owasp.glueup.com/eve...

06.12.2024 18:31 β€” πŸ‘ 7    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

Hey folks! A friend of mine is looking for a tutor for a cyber security university program. Does anyone do that or know someone they can recommend?

06.12.2024 20:45 β€” πŸ‘ 11    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0

Definitely check this out if you haven't already. Besides Tanya's chapter you'll find one from @adamshostack.bsky.social and @izart.bsky.social too.

03.12.2024 05:11 β€” πŸ‘ 11    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0
Threat Modeling - Bluesky Starter Pack Threat modeling members of the community, including folks who worked on the Threat Modeling Manifesto and Capabilities. There are more to add but a bug in selecting users persists. Seeking recommendations for additional threat modeling folks to add.

Just going to leave here a cool thing Matt Coles made - the Threat Modeling Starter Pack: blueskystarterpack.c...

03.12.2024 02:28 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Threat Modeling Whitepapers from Shostack + Associates

For Cyber Monday, Shostack + Associates has released a free white paper on my Four Question Framework on Threat Modeling. shostack.org/whitepapers

02.12.2024 16:31 β€” πŸ‘ 4    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸš€ Calling all Speakers! πŸš€ Don't miss out on this thrilling opportunity to submit your paper for the 2025 #OWASP Global #AppSec EU Call for Presentations. Share your knowledge with the #cybersecurity community and shine a light on your skills. Take action now!
sessionize.com/owasp...

02.12.2024 19:28 β€” πŸ‘ 11    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

OWASP has a social media presence wherever our community is. We regularly monitor our social media posts for engagement and trends. We have no plans to withdraw from any social media platform. If you have any suggestions on how we can improve our posts, please let us know!

26.11.2024 17:32 β€” πŸ‘ 12    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0

@threatmodeling.dev is following 20 prominent accounts