Threat-Aware Engineering: A Hands-On Cybersecurity Guide to Modern Software and AI Agents
Every threat modeling book on the market was written before AI agents could call APIs, poison their own memory, or manipulate each other into leaking data. This book closes that gap.
If you build software today, you're not just defending against SQL injection and misconfigured cloud storage. You're defending against prompt injection, tool poisoning, and AI agents that can be socially engineered. Most security books cover one side of this or the other. This one covers both, so you're not stitching together a strategy from books that don't talk to each other.
What makes this different
Readers of the current bestsellers in this space consistently say the same thing: too theoretical, not enough hands-on guidance, and threat models that go stale the moment the system ships. This book fixes that. Every chapter pairs a concept with a real, applied example, what it looks like in an actual codebase or pipeline, and what you'd do differently because of it. It references real incidents: Equifax, Capital One, SolarWinds, and Log4Shell, so you're learning from what actually happened.
What you'll learn
You'll start with foundations: thinking like an attacker, mapping your real attack surface, and building a threat model that doesn't collect dust the moment you ship. From there, the book moves through the layers that matter most in production:
Secure architecture and least privilege, and why it's the highest-leverage decision most teams get wrong. Identity, authentication, and access control, including the authorization mistake ranked among the most damaging findings in real-world API assessments. Input handling, injection attacks, and API security, with validation patterns that eliminate entire vulnerability classes by design. Dependency and supply chain risk, covering what happened with Log4Shell and why most organizations couldn't answer "are we affected" fast enough. Cloud, container, and infrastructure security, including the mistakes that turn a contained breach into a headline. Secure coding, testing, logging, monitoring, and incident response, the operational backbone that decides whether a compromise stays a non-event or becomes a disaster.
Then the book covers what almost nothing else in the market does: securing AI-integrated software and autonomous agents. How prompt injection actually works, how indirect injection through documents and web content creates a new attack surface, how to design agents with genuinely limited authority instead of trusting a model's judgment, and how to secure agent tools, memory, and external connections.
Who this is for
Written for software engineers, architects, DevSecOps practitioners, and technical leads responsible for building systems that withstand real-world pressure, not just pass a compliance checklist. Whether you're securing a traditional web application or your team's first AI agent deployment, this book gives you a working method: identify what could go wrong, understand why, and turn that understanding into a concrete, verified engineering decision.
What you'll walk away with
A practical, repeatable threat modeling process you can run on a real sprint schedule. A concrete understanding of the vulnerability classes behind most real-world breaches, and the specific fixes for each. A framework for securing AI agents built around independent authorization checks, limited authority, and layered defense, not hoping the model behaves. A mindset shift: security stops being a phase bolted onto development and becomes a normal part of how you already build software.
Software will keep getting attacked. This book makes sure yours is ready for it.
"synopsis" may belong to another edition of this title.
Seller: California Books, Miami, FL, U.S.A.
Condition: New. Print on Demand. Seller Inventory # I-9798193859277