About this talk
This talk features Farshad Abasi discussing the shortcomings of traditional threat modeling approaches that focus on intended designs rather than actual deployments. The speaker highlights the critical blind spot this creates and presents strategies to enhance threat modeling by integrating real findings from Static Application Security Testing (SAST), Software Composition Analysis (SCA), Dynamic Application Security Testing (DAST), Infrastructure as Code (IaC), and cloud security assessments. Attendees will gain insights into evolving their threat modeling practices to better align with real-world conditions and vulnerabilities.
More from this event
See all 91 talks →
BSidesSF 2026 - Opening Remarks (Sunday) (Reed Loden)
14:36
BSidesSF 2026 - Follow the data to learn the secret (Dylan Ayrey)
35:17
BSidesSF 2026 - Not My Vibe: When AI Coding Agents Go Off the Rails (Aonan Guan, Zhengyu Liu)
45:56
BSidesSF 2026 - "Ask the EFF" Panel (Panel)
45:30