live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
newsSECURITY

Red Hat turns six threat-modeling methods into a portable coding-agent module

The open-source Lola module runs in Claude Code, Cursor and Gemini CLI, tying proposed attack scenarios to files and lines while keeping human review in the loop.

Manual threat modeling versus agentic threat modeling.
Side by side: what changed
By The News Desk· Sep 21, 2026the quick take — two AI hosts go live when you do

Red Hat Product Security has open-sourced an AI-assisted threat-modeling module that developers can run from Claude Code, Cursor or Gemini CLI. The project is intended to move an initial security review closer to the engineer and the code, without treating model output as an authoritative security verdict.

What changed

The agentic-threat-modeling module profiles likely attackers, analyzes a selected feature or service and generates narrative attack scenarios grounded in the repository. Red Hat says it checks the code through six structured approaches, including STRIDE, PASTA, LINDDUN and attack trees, then connects findings to particular files and lines.

The module runs on Lola, an open-source package manager for reusable AI context. That packaging is consequential for platform teams: one module can be installed across the three supported coding-agent environments rather than maintaining separate prompt files for each tool.

Users can choose a guided /threat-model workflow or a faster /threat-model-quick pass. Red Hat’s example analyzes an unauthenticated file-upload handler and identifies a path-traversal scenario, naming the affected line and a proposed mitigation.

Who should care

Development teams adopting coding agents are the immediate audience, especially where a centralized product-security group cannot review every change before it ships. The module offers a repeatable first pass that is more structured than asking a general chatbot whether a file is secure.

Security teams may also care about the output format. Red Hat is positioning a structured threat model as a possible future input to vulnerability triage: an SBOM can show that a component contains a CVE, while a threat model may help determine whether the affected path appears reachable or protected by a compensating control. That triage pipeline is explicitly future work, not a current capability.

What to do

Teams can install Lola with uv, add Red Hat Product Security’s Lola marketplace and install the module for Cursor, Claude Code or Gemini CLI. Before putting it into a delivery workflow, they should evaluate how source code and prompts are handled by the selected agent and model, and establish a review process for generated findings.

The project should be treated as a diagnostic aid, not an approval gate. Red Hat itself says the output does not replace human judgment. A useful pilot would compare the quick and guided modes against a service with an existing human-written threat model, measuring missed attack paths, false positives and whether file-and-line references remain accurate as the code changes.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.