Loading…
OWASP 25th Anniversary Virtual Conference (September)
Tuesday September 22, 2026 11:00am - 11:55am PDT
Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with design.
Too often, the shift-left mantra consists of implementing (AI-powered) code scanning and applying AI-powered security fixes for remediation. Also, don't forget to implement the AI-powered benchmark for AI-powered Security Fixes. Now, to be clear, I am not actually telling you to stop using these tools — if they work for you — instead, we should ask ourselves:

What are we working on?
What can go wrong?
What are we going to do about it?
Did we do a good job?

In order to support that second question in particular, we have created the next version of OWASP Cornucopia (see: https://cornucopia.owasp.org/card/webapp/AZ2/3.0/en).

OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams in identifying security requirements in Agile, conventional, and formal development processes. It is language, platform, and technology-agnostic.
The formerly titled “Cornucopia — Ecommerce Website Edition” is now “Cornucopia — Website App Edition”. This edition was originally created in August 2012, released as v1.0 in February 2013, and has undergone several minor updates/releases over the following ten to fifteen years. This has been substantially updated in v2.0, in which the most noticeable change was an update of the OWASP ASVS mapping from ASVS v3.0 to v4.0, together with the creation of translations into six languages (EN, ES, FR, NL, NO-NB, and PT-BR) due to the efforts of past and current volunteers.

The new version, available in 10 languages (EN, ES, FR, HI, NL, NO-NB, PT-PT, PT-BR, RU, UK), will include all new cards and text that cover all OWASP ASVS 5.0 requirements and connect them to more than 200 unique common attack patterns (CAPEC). Each of the common attack patterns will have a unique set of ASVS requirements, which means that you never need to stop playing the game! You will always be able to return to the same card to discover new threats and security requirements to consider when building your software. Additionally, we are publishing the OWASP Cornucopia Companion Edition (see: https://cornucopia.owasp.org/edition/companion/AAIA/1.0/en that comes with 6 companion suits (see: https://cornucopia.owasp.org/edition/companion ) covering new topics: Agentic AI (AAI), Automated Threats (BOT), Cloud (CLD), Frontend (FRE), Large Language Models (LLM), and DevOps (DVO). A suit in the companion deck may replace (or be used in addition to) suites in the existing Website Edition so that the players can add a specific focus to their threat modeling: For example, say you are building an LLM application and want to perform threat modeling specifically for LLM. You would then use the OWASP Cornucopia Website Edition and the LLM companion suite as your elected OWASP Cornucopia focus area.

What’s more, it is now possible to create your OWASP Cornucopia Threat Model in OWASP Threat Dragon using their brand new EoP Games diagram (see: https://www.threatdragon.com/
Speakers
avatar for Johan Sydseter

Johan Sydseter

co-leader of OWASP Cornucopia, Johan (Uncle Joe) Sydseter - The guy with the long hair, not the beard
Johan Sydseter is one of the co-leaders of OWASP Cornucopia and the co-creator of the OWASP Cornucopia Mobile App Edition. he is a living AppSec Pokémon, application security engineer, developer, architect and DevOps practitioner. He has 15 years of experience building and designing... Read More →
Tuesday September 22, 2026 11:00am - 11:55am PDT

Attendees (1)


Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link