Threat Modeling for LLM Applications: Where to Start
LLM applications need threat models that cover more than prompts: trust boundaries, RAG, agents, tools, identity, data flows, provider boundaries and audit evidence.
Read article →Application security notes about secure-by-design software, security headers, deployment hardening and AI-assisted development risks.
4 articles tagged AppSec on vesely.sk.
LLM applications need threat models that cover more than prompts: trust boundaries, RAG, agents, tools, identity, data flows, provider boundaries and audit evidence.
Read article →AI can generate working applications quickly, but functionality is not the same as security. The next challenge is proving that AI-generated systems are hardened, compliant and trustworthy enough for production.
Read article →Every piece of software contains weaknesses. The real question is not whether a bug exists, but whether we find it first or an attacker does.
Read article →AI makes it easier than ever to build and deploy software. That also means basic web security, AppSec and DevSecOps checks must happen before publishing, not after deployment.
Read article →