Appsec roundup - July + August 2026
The CRA, how AI is showing up in security requirements, threat modeling, bug fixing and inventing biases in its spare time. Also, a lot of cool books by other authors.
This end of summer edition leads off with the EU’s release of 83 pages of guidance for the CRA:
Article 26(1) of the CRA requires the Commission to publish guidance to assist economic operators in applying the Regulation, with a particular focus on facilitating compliance by microenterprises and small and medium-sized enterprises (SMEs). Article 26(2) sets out minimum aspects that should be addressed in the guidance. These include: (i) the scope of the CRA (particularly remote data processing solutions and free and open-source software); (ii) the notion of ‘support periods’; (iii) the interplay between the CRA and other EU legislation; and (iv) the concept of ‘substantial modification.’
Threat Modeling
- In Trust Boundary Semantic Gaps: A Multi-dimensional Analysis and Mitigation for Security-by-Design, Doyeon Kim, Jin-Young Choi, Junghee Lee propose a set of analyses modules, including Identity, Spatial, Temporal, and Interpretation. The work is thought provoking. (I would have liked for them to have stayed away from the math long enough to distinguish the types of artifacts they mention, including software packages which are not like inputs, messages or tokens, none of which are expected to be executed.)
- In An Empirical Evaluation of Generative AI in Security Requirements Engineering and Threat Modeling, F. Martins and Elaine Venson discuss how to use generative AI to support requirements engineering.
Appsec
- Google released a blog post How we’re making Chrome and the web safer in the AI Era, which includes, but isn’t limited to threat modeling, still done by humans and recorded in security.md files.
- In Overhead of Recording Feature Locations with Embedded Annotations, Johan Martinson, Kevin Hermann, and Thorsten Berger show that lightweight annotations that define where features are help find feature-related code. (There’s security relevance in knowing where your security features show up in the code.)
AI
- In AI is more likely than humans to form biases when hiring, Michelle Kim reports on a study that shows LLM hiring agents can literally invent new biases.
- In an April pre-print, Nicholas Sofroniew and colleagues of Anthropic report on Emotion Concepts and their Function in a Large Language Model. Do you really want to spend the tokens they sell you on that, or have your outputs impacted by it?
- Dan Goodin has a story, Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission. Key facts include 60 hours of work and $100,000 of tokens. (It's unclear if that was the only work that was done, or if there were other, unsuccessful experiments, which would change the token cost, perhaps dramatically.) Cryptographer Matt Green has good analysis in Some thoughts about Anthropic’s new cryptanalysis results.
- Axel Mierczuk, Spencer Michaels and Keith Hoodlet of 1Password’s new Off-by-1 Labs released Frontier Models’ Vulnerability Patches are Often F.L.A.W.E.D.. This study is pretty devastating to the hope that LLMs can fix the deluge of vulns they discover. Adrian Sanabria has a great summary in Reviewing initial research on using AI for vulnerability remediation. Contrast with Google’s opinion in Stronger with every update: How we’re making Chrome and the web safer in the AI Era, and note the important words “At this point, we have LLMs generating candidate fixes for most vulnerabilities, dramatically increasing the rate of security fixes in recent Chrome releases” (emphasis added).
- I covered the OpenAI/HuggingFace incident separately.
Operations
- In Disasters for Small Teams, Dr. Greg Wilson presents reasonably compact advice on disaster planning.
Regulation
- Christian Espinosa has a good article Your Penetration Test Can Pass And Still Fail FDA Review on the importance of testing the right things for FDA review. I think his points will generalize to other testing such as CRA.
Books and Games Received

- The C4 Model: Visualizing Software Architecture by Simon Brown
- The Psychology of Software Teams by Cat Hicks
- Building Safer Technology: A Field Guide to Failing Well by Yonatan Zunger, Lea Kissner, Neil Coles, Juan Hernandez, Harmony Mabrey, and Phillip Misner.
- Threat-Driven Software Development: Defending online services from modern threat actors by Michael Howard, Lee Holmes, Sherrod DeGrippo, and Shawn Hernan. (Purchased as ebook).
- The vCISO Playbook: How Virtual CISOs Deliver Enterprise-Grade Cybersecurity to Small and Medium Businesses (SMBs) by Peter Green and Jan Ross.
- Cards Against Vulnerabilities by Patrick Smyth of Chainguard.
- The second version of Bob Lord’s Secure by Design storycards.
Shostack + Associates News
- The second edition of the threat modeling bible, Threat Modeling: Designing for Security in an AI World was announced!
- Registration is open for our three-day course, Threat Modeling Intensive Using LLMs, in person in San Francisco in association with OWASP’s Global Appsec Conference.
- It's that time of year! We're kicking off our Back to School Sale to help engineering teams and practitioners gear up for the upcoming training season. Get 20% off our self-paced courses by using code SECURE101 at checkout.
Image by midjourney: ”a photograph of a robot, sitting in a library, working on a jigsaw puzzle. The robot is spotlighted by light streaming in through a small window, through which you can it's snowing.” I appreciate how this one is holding up the jigsaw and it’s snowing inside, both demonstrating AI is bad at concepts.