ostering.com
  • Posts
  • Talks
  • Privacy
Brett Crawley

Author: Brett Crawley (46)

Brett Crawley is a principal application security engineer and the author of Threat Modeling Gameplay with EoP (Packt, 2024). He created SBOM-Graph and the Elevation of Autonomy card deck for threat modelling AI, LLM and agentic systems, contributes to OWASP, and writes The Blast Radius newsletter on supply chain security, AI security and EU regulation.

SLSA and Provenance: Your SBOM Says What's Inside, This Says Where It Came From

The Blast Radius runs on one conviction: prefer...

July 20, 2026
Threat Modeling MCP

Threat Modeling MCP

Threat Modeling the Model Context Protocol: Your Agent...

July 7, 2026
Data Protection and Data Privacy Part 2 of 2

Data Protection and Data Privacy - Part 2 of 2

From Principle to Practice: Privacy in the Real...

June 23, 2026
Untangling the Confusion

Data Protection and Data Privacy - Part 1 of 2

Untangling the Confusion People often confuse these two...

June 9, 2026
PQC Part 2: The Plan, the Order, and the Bill

Get PQC Ready PDQ - Part 2

The Plan, the Order, and the Bill In...

May 26, 2026

Get PQC Ready PDQ - Part 1

Quantum, AI, and the Window That’s Already Closing...

May 13, 2026

Threat Modeling AI Systems: A Complete Playbook for Practitioners

The Blast Radius - Edition [4] Over the...

April 28, 2026

Sparse or Dense? Claude Mythos, Dan Geer, and Where We Should Actually Be Spending Our Effort

Last week, Anthropic announced Claude Mythos Preview and...

April 15, 2026

Software Engineering Has Regressed 50+ Years Since AI

Bear with me on this train of thought....

April 1, 2026

Dependency Pruning and Tree Shaking

Cutting the Dead Wood from Your Dependency Graph...

March 31, 2026

Threat Modeling Your Dependencies - Part 2

Mitigating Third-Party Component Risk: Swapping the Cancer for...

March 22, 2026

Threat Modeling Your Dependencies - Part 1

How One Bad Library Can Poison Your Entire...

March 18, 2026

Your SBOM Data Has Been Gathering Dust - Until Now

I’ve been talking about graphs for dependency analysis...

March 9, 2026

SAST vs Claude Code Security: A Deep Dive

SAST vs Claude Code Security: A Deep Dive...

February 23, 2026

Why SAST is Broken!

Why SAST is broken, and how it could...

February 22, 2026

Cursor as your Secure Dev Team

Cursor as your Secure Dev Team What I...

February 21, 2026
See the older articles

Browse all Topics

  • Agentic AI
  • AI Security
  • Application Security
  • Auth
  • CAPEC
  • Change
  • Claude Code Security
  • Compliance
  • Cryptography
  • Culture
  • Cursor AI
  • Cybersecurity
  • Dark Patterns
  • DevSecOps
  • Elevation of Privilege
  • Games
  • Graph Analysis
  • Inner-Source
  • Java
  • JavaScript
  • languages
  • learning
  • Miro
  • Mitre
  • Model Context Protocol
  • Origins
  • Osteria
  • OWASP
  • Post Quantum Cryptography
  • Privacy
  • Privacy by Design
  • Python
  • Risk
  • Running
  • SAST
  • SBOM
  • Secure by Design
  • Security
  • Security by Design
  • Security Culture
  • Security Maturity
  • SLSA
  • Social Engineering
  • Software Architecture
  • Software Design
  • Software Development
  • Software Engineering
  • Strategy
  • STRIDE
  • Supply Chain Security
  • Threat Modeling
  • TRIM
ostering.com

{Osteria}{Running}

Copyright 2026 Brett Crawley

Β 

This website uses cookies
Select which cookies to opt-in to via the checkboxes below; our website uses cookies to examine site traffic and user activity while on our site, and to provide social media functionality. Privacy Policy
Cookie settings
We use cookies to enhance your browsing experience, serve content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Privacy Policy
  • Required

    These cookies are used to enhance your browsing experience, and serve content.

  • analytics

    Our site anonymizes all of its tracking data, making it fully GDPR-compliant