frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: TITO – Automated threat modeling from code (open source)

https://github.com/Leathal1/TITO
2•xxmrlnxx•1h ago
I built TITO because threat modeling is broken. It either requires drawing diagrams by hand, hiring consultants, or buying tools that start at $50K/year. Most teams skip it entirely.

TITO reads your code and builds the threat model for you:

    go install github.com/Leathal1/TITO/v2/cmd/tito@latest
    tito scan --repo .
What you get in ~60 seconds:

- STRIDE-LM classification — threats categorized by Spoofing, Tampering, Info Disclosure, DoS, Elevation of Privilege, Lateral Movement - MITRE ATT&CK mapping — every finding linked to real-world attack techniques - Attack path analysis — how individual findings chain into realistic breach scenarios (think BloodHound for app-layer threats) - MAESTRO analysis — maps threats across agentic AI security layers (if your code uses LLMs/agents) - Compliance mapping — PCI DSS v4.0, SOC 2, ISO 27001, NIST 800-53, HIPAA - Interactive 3D visualization — explorable data flow diagrams with attack path overlays - PR threat diffing — catch security regressions on every pull request

Under the hood it runs Semgrep for static analysis, detects your architecture (monolith, microservices, serverless, AI/ML), and layers threat intelligence on top.

Single binary. No config files. No accounts. No data leaves your machine.

The Cloud Security Alliance is listing TITO as a community implementation of their MAESTRO framework for agentic AI security.

CI/CD integration:

    - uses: Leathal1/TITO@v2
      with:
        maestro: true
        fail-on: critical
Technical details: written in Go, ~15K LOC, MIT licensed. GitHub Action on the Marketplace. Docker images available.

I'd love feedback — especially from folks doing AppSec or building AI agents. What frameworks or compliance mappings would be most useful to add?

GitHub: https://github.com/Leathal1/TITO

Student Loans May Get Discharged, Refunded for 200k as Key Deadline Passes

https://www.forbes.com/sites/adamminsky/2026/01/30/student-loans-may-get-discharged-and-refunded-...
1•toomuchtodo•1m ago•1 comments

I, Integrated Circuit

https://hackaday.com/2026/02/04/__trashed-28/
1•jnord•1m ago•0 comments

The Iron Heel

https://en.wikipedia.org/wiki/The_Iron_Heel
1•d_silin•2m ago•0 comments

Monolith OS Devblog for January 2026

https://monolith-project.org/blog/january-2026-update/
1•mrunix•3m ago•0 comments

The missing metric: Spec Coverage

https://benhouston3d.com/blog/spec-coverage
1•bhouston•4m ago•0 comments

From building client websites to launching my own SaaS

1•CheckAnalytic•4m ago•0 comments

A sandbox-safe macOS gateway for AI agents

https://github.com/ericblue/mac-agent-gateway
1•ericblue•5m ago•1 comments

Show HN: The Last Worm – Visualizing guinea worm eradication, from 3.5M to 10

https://echomoltinsson.github.io/last-worm/
1•onyx_writes•5m ago•0 comments

Everyone Is Stealing TV

https://www.theverge.com/streaming/873416/piracy-streaming-boxes
1•jnord•5m ago•0 comments

Paul Graham's Essays

https://paulgraham.com/articles.html
1•Brysonbw•6m ago•0 comments

Smart AI Policy Means Examing Its Real Harms and Benefits

https://www.eff.org/deeplinks/2026/02/smart-ai-policy-means-understanding-its-real-harms-and-bene...
1•hn_acker•6m ago•1 comments

From Anki to Kickstarter: The Making of Kanjideck

https://alt-romes.github.io/posts/2026-01-30-from-side-project-to-kickstarter-a-walkthrough.html
1•romes•6m ago•0 comments

Thought-Terminating Cliché

https://en.wikipedia.org/wiki/Thought-terminating_clich%C3%A9
1•walterbell•8m ago•0 comments

Lopaka: Create pixel-perfect graphics for embedded devices

https://lopaka.app/
1•flexagoon•9m ago•0 comments

Alphabet Q4 Earnings

https://blog.google/company-news/inside-google/message-ceo/alphabet-earnings-q4-2025/
2•aresant•10m ago•0 comments

The Internet of Babel

https://dolphinmade.com/blog/internet-of-babel/
1•rprend•11m ago•1 comments

As Rocks May Think

https://evjang.com/2026/02/04/rocks.html
2•modeless•13m ago•0 comments

School

https://bcanuntoldhistory.knowledge.ca
1•haileymmm•14m ago•0 comments

Claude Code patches to make it use less CPU

https://github.com/denysvitali/claude-code-patches
3•denysvitali•15m ago•0 comments

DeepAgents – A virtual filesystem abstraction for AI agents (S3, SQLite, disk) [video]

https://www.youtube.com/watch?v=5oI_G8WL6rU
1•cbromann•15m ago•0 comments

I've created a tool to make your Discord server indexable on Google and AI

https://silver-concept-375343.framer.app/
1•jackota•17m ago•1 comments

AI Mirror

https://mirror.syshuman.com
1•KadirErturk•17m ago•0 comments

Striking a Balance: Working Remote for Nearly a Decade

https://rion.io/2025/12/30/striking-a-balance-working-fully-remote-for-nearly-a-decade/
2•rionmonster•18m ago•0 comments

Ask HN: chat agent for n8n development?

1•realityfactchex•19m ago•0 comments

Epstein asked Chomsky for advice over 'putrid' media coverage, files show

https://www.bbc.com/news/articles/ce9ykjlyv50o
3•tartoran•19m ago•0 comments

I Am Not a Functional Programmer

https://blog.daniel-beskin.com/2026-01-28-i-am-not-a-functional-programmer
4•birdculture•23m ago•0 comments

Sam Altman: I wonder why Anthropic would go for something so clearly dishonest

https://twitter.com/sama/status/2019139174339928189
3•doener•24m ago•2 comments

METR estimates that GPT-5.2 has a 50%-time-horizon of around 6.6 hrs

https://twitter.com/METR_Evals/status/2019169900317798857
2•tedsanders•25m ago•0 comments

Epistemological Fault Lines Between Human and Artificial Intelligence

https://arxiv.org/abs/2512.19466
2•DyslexicAtheist•26m ago•0 comments

Debian's Challenge When Its Developers Drift Away

https://www.phoronix.com/news/Debian-Developers-Quiet-Away
2•cuechan•29m ago•0 comments