<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Threat-Modeling on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
    <link>https://www.msbiro.net/tags/threat-modeling/</link>
    <description>Recent content in Threat-Modeling on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</description>
    <image>
      <title>Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
      <url>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</url>
      <link>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</link>
    </image>
    <generator>Hugo -- 0.164.0</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 09 Aug 2026 09:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.msbiro.net/tags/threat-modeling/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SCTPhantom (CVE-2026-64564): Threat-Modeling a High-Impact SCTP Kernel Flaw Without Panic</title>
      <link>https://www.msbiro.net/posts/sctphantom-cve-2026-64564-threat-modeling/</link>
      <pubDate>Sun, 09 Aug 2026 09:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/sctphantom-cve-2026-64564-threat-modeling/</guid>
      <description>CVE-2026-64564 (SCTPhantom) is a critical Linux kernel use-after-free in SCTP ASCONF with a high CVSS score and a demonstrated container escape. A DevSecOps threat-modeling walkthrough of when to care, who is actually at risk, and how to prioritize patching without panic, accounting for attacker-creatable SCTP associations.</description>
    </item>
    <item>
      <title>OWASP GenAI LLM Top 10 2026: What the New Rankings Mean for Security Teams</title>
      <link>https://www.msbiro.net/posts/owasp-genai-llm-top-10-2026/</link>
      <pubDate>Wed, 05 Aug 2026 07:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/owasp-genai-llm-top-10-2026/</guid>
      <description>OWASP released the GenAI LLM Top 10 2026, the first edition grounded in 7,714 real AI security incidents. Prompt Injection stays at number one. Excessive Agency climbs. Misinformation is the widest gap between what practitioners fear and what the evidence shows.</description>
    </item>
    <item>
      <title>When Your Update System Becomes the Attack Vector: The Notepad&#43;&#43; Supply Chain Compromise</title>
      <link>https://www.msbiro.net/posts/notepad-plusplus-sdlc-compromise-2026/</link>
      <pubDate>Tue, 03 Feb 2026 22:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/notepad-plusplus-sdlc-compromise-2026/</guid>
      <description>Deep dive into the Notepad&#43;&#43; supply chain attack: how state-sponsored hackers compromised the hosting provider, hijacked updates, and what we can learn about SDLC security.</description>
    </item>
  </channel>
</rss>
