# AppSec Newsletter 0028

### Links

* \[tool\] [threatcl/threatcl: Documenting your Threat Models with HCL](https://github.com/threatcl/threatcl)
    
* \[tool\] [aquasecurity/chain-bench: An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.](https://github.com/aquasecurity/chain-bench)
    
* \[video\] [Webinar: Rapid Threat Modeling with GenAI and LLMs](https://www.linkedin.com/events/7175751572528766976/comments/)
    
* \[artigo\] [Product Security Plans: What They Are and Why They Matter](https://thenewstack.io/product-security-plans-what-they-are-and-why-they-matter/)
    
* \[video\] [Secure LLM Architecture - Testing LLM Guard](https://www.youtube.com/watch?v=C_5KRqQrGD4)
    
* \[wiki\] [Risk Based Prioritization](https://riskbasedprioritization.github.io/)
    
* \[tool\] [sonatype SBOM manager](https://www.sonatype.com/products/sonatype-sbom-manager?utm_campaign=organic+social&utm_source=linkedin&utm_medium=social)
    
* \[artigo\] [Jit | The Essential Components of a DevSecOps Pipeline](https://www.jit.io/blog/the-essential-components-of-a-devsecops-pipeline)
    

### Vagas

* [Loggi - Senior Cybersecurity Manager (App Sec & SOC)](https://www.linkedin.com/jobs/view/3872562173/)
    
* [Compass UOL - Security Champion | Senior](https://www.linkedin.com/jobs/view/3872417355/)
