frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: TMDD – continuous threat modelling that makes your code more secure

https://github.com/attasec/tmdd
2•attasec•1h ago
My name is Mikolaj and I built tmdd tool, a CLI that keeps an up-to-date threat model of your app (in YAML format) in your repo and generates security-aware prompts for AI coding agents. Here's why:

I am a security engineer. Oftentimes I observed situations where "technical" security levels were pretty high, but the business logic and authorization related issues made the apps pretty vulnerable. In my experience, no SAST or DAST is able to spot this kind of issues; some of them might be captured during the pentests, but the pentests are time-boxed, so you never have the guarantee that everything was thoroughly analysed.

That's why I decided to build this framework (name TMDD is a shortcut for Threat Modeling Driven Development, but it's more than that).

How it works: 1. you init the threat model with <code>tmdd init</code> command - the yaml files that describe the threat model are created in your repo (either empty or from the template). 2. you load threat modeling skill into your coding agent - I tested with Cursor and Claude Code 3. The agent does the threat modeling and updates yaml files 4. IF you want to add a new feature, you can use <code>tmdd feature "feature name"</code> command, that will update the YAML and generate security-focused development prompt, that you can then feed to agent 5. You can generate complete threat model report with diagram using tmdd-report

E.g. without TMDD, you ask Cursor to build a password reset flow and it might ship it without rate limiting or token expiration. With TMDD, the agent gets a prompt that lists those as required controls because they're in the threat model.

And even without the AI workflow, you get a structured, version-controlled threat model - which many appsec teams don't have today :)

Why is matters: 1. It takes Threat Modeling closer to the code - instead of using whiteboard, you do threat modeling with help from AI Agent can refer to exact lines in your codebase. You can also track mitigations and who's reviewed mitigations for the last time 2. It's similar to Claude Code Security in some ways, but works with any agent that has terminal access - no vendor lock-in ;) 3. Threat Model documentation lives alongside your repo and is stored in YAML, so you can version control it, etc. 4. you can build custom <code>catalog.yaml</code> file, and use a catalog of threats for threat modeling of all products at your company

Let me know what do you think about it. Repo is here: https://github.com/attasec/tmdd

We are also working on SaaS version (core remains open-source, but additional features, collaboration tools and UI will be available), you can learn more here: https://attasec.com

Show HN: Go-GATE – Database-grade safety for AI agents

https://github.com/billyxp74/go-gate
1•billyxp74•27s ago•0 comments

Analyzing Latency Hiding and Parallelism in an MLIR-Based AI Kernel Compiler

https://arxiv.org/abs/2602.20204
1•matt_d•1m ago•0 comments

Show HN: A site only LLM can access

https://anti-human.vercel.app/
1•aniketsauravv•1m ago•0 comments

JetStream NATS.io C#: Example primitive for composite learning, reading data

https://github.com/nats-io/nats.net/blob/main/examples/Example.JetStream.PullConsumer/Program.cs
1•northlondoner•2m ago•1 comments

What NIH Staff Can't Tell You–and Why That Matters

https://substack.com/home/post/p-188153795
1•SubiculumCode•2m ago•1 comments

Sub-Scheduler Support Could Be the Most Exciting Features to Come for Linux 7.1

https://www.phoronix.com/news/cgroup-sub-scheduler-sched-ext
1•rbanffy•2m ago•0 comments

Show HN: Ing-switch – migrate from ingress-Nginx to Traefik or Gateway API

https://github.com/saiyam1814/ing-switch
1•saiyampathak•3m ago•0 comments

Accelerated FOMO in the Age of AI

https://www.0xsid.com/blog/accelerated-ai-fomo
1•ntnbr•3m ago•0 comments

SpokedPy – Polyglot visual IDE with Universal IR, live execution (17 languages)

1•mdifrancesco•3m ago•0 comments

Douglas Rushkoff: The End of Employment (and Why It Could Free Us) [video]

https://www.youtube.com/watch?v=0Q62CxA4ikw
1•wilsonfiifi•3m ago•0 comments

xs

https://cryptm.org/xs/
2•tosh•3m ago•0 comments

Hegseth threatens to blacklist Anthropic over 'woke AI' concerns

https://www.npr.org/2026/02/24/nx-s1-5725327/pentagon-anthropic-hegseth-safety
2•e12e•3m ago•0 comments

A Man Who Stole Infinity

https://www.quantamagazine.org/the-man-who-stole-infinity-20260225/
1•rbanffy•4m ago•0 comments

Practical Decentralization

https://www.pfrazee.com/blog/practical-decentralization
1•chokolad•5m ago•0 comments

Show HN: A speed reading app to help you finish books in < half the time

https://speed-read-black.vercel.app/
1•Ronyisonline•6m ago•1 comments

Bay Area tech company who 'precisely allocates every human resource' has layoffs

https://www.sfgate.com/tech/article/c3-ai-layoffs-21939617.php
2•randycupertino•6m ago•1 comments

Show HN: Tic-Tac-Toe

https://ultimattt.com/
1•ArneVogel•6m ago•1 comments

Show HN: GPU multi-agent war simulation

https://github.com/ayushdnb/Neural-Siege/tree/combat_first_tick
1•luthor190397•7m ago•0 comments

Migrate from Akamai Identity Cloud

https://fusionauth.io/docs/lifecycle/migrate-users/provider-specific/akamai
1•mooreds•7m ago•0 comments

Six Months of Rust

https://kittygiraudel.com/2026/02/25/six-months-of-rust/
1•speckx•7m ago•0 comments

Show HN: Google Maps Email Lead Scraper (Real-Time)

https://leadscraper-tool.web.app/
1•faalbane•10m ago•0 comments

Kinases regulate leptin action and weight reducing effect of HDAC6 inhibition

https://www.nature.com/articles/s41467-026-69008-9
1•PaulHoule•10m ago•0 comments

Bcachefs creator insists his custom LLM is female and 'fully conscious'

https://www.theregister.com/2026/02/25/bcachefs_creator_ai/
2•Bender•11m ago•0 comments

Orbital datacenters are a pie-in-the-sky idea: Gartner

https://www.theregister.com/2026/02/25/gartner_orbiting_datacenter_peak_insanity/
1•Bender•11m ago•0 comments

Meta is planning stablecoin comeback in the second half of this year

https://www.coindesk.com/business/2026/02/24/mark-zuckerberg-s-meta-is-planning-stablecoin-comeba...
1•wslh•13m ago•0 comments

Claude Status – Elevated error rates across multiple models

https://status.claude.com/incidents/bdxgsy48hp00
7•StanAngeloff•13m ago•7 comments

Google Wants to Control Your Device

https://blog.jmp.chat/b/2026-google-wants-to-control-your-device
2•upofadown•14m ago•0 comments

The Password That Lets Caterpillars Hide in an Ant's Lair

https://www.nytimes.com/2026/02/25/science/caterpillar-ant-language.html
1•marojejian•14m ago•1 comments

Anthropic ditches its core safety promise

https://www.cnn.com/2026/02/25/tech/anthropic-safety-policy-change
2•thewebguyd•14m ago•1 comments

NOVO Was Europe's Most Valuable Company

https://philippdubach.com/posts/novo-was-europes-most-valuable-company/
1•7777777phil•16m ago•0 comments