Business Wire

VerSprite Launches Fork and Knife: AI-Driven Threat Modeling and Adversarial Testing Built for the Speed of Modern Software

26.6.2026 23:28:00 CEST | Business Wire | Press Release

Share

VerSprite, a global leader in risk-based threat modeling and the firm behind the PASTA (Process for Attack Simulation and Threat Analysis) methodology, today announced the general availability of Fork (www.forktm.com), a continuous application threat modeling platform, alongside Knife, an AI-led, human-on-the-loop adversarial testing platform for web applications and web API endpoints. Together, the two products operationalize a new model for product security—one where applications are securely designed, continuously modeled, and actively tested as part of the build process itself.

The launch addresses a problem every security leader knows but few tools have solved: threat modeling is essential, never more so than in an AI-driven era, yet it has remained slow, manual, and anchored to frameworks designed for a different threat landscape.

The problem: threat modeling matters more than ever—and most tools are stuck in 2005

For two decades, application threat modeling has leaned heavily on STRIDE—a categorization mnemonic for spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. STRIDE is useful for sorting threats into buckets, but it was never a methodology. It does not ingest real-time threat intelligence, it does not weigh business impact, and its static categories say nothing about the adversary behaviors defining risk today—persistence, extortion, double-extortion ransomware, supply-chain compromise, and the novel attack surfaces introduced by AI-enabled applications.

The result is a familiar bottleneck. Threat modeling gets treated as a one-time, document-heavy exercise that lands too late in the lifecycle, goes stale the moment an application changes, and rarely connects to the testing that would actually validate whether a threat is real. As organizations ship faster and adopt AI across the stack, the gap between how quickly software evolves and how slowly it gets modeled has become a material risk.

The solution: risk-centric threat modeling at sprint speed

Fork is a practical, software-driven implementation of PASTA—the only risk-centric, business-aligned threat modeling methodology, co-authored by VerSprite founder and CEO Tony UcedaVelez. Rather than categorizing threats in the abstract, PASTA’s seven stages move from business objectives through attack surface, application decomposition, threat analysis, weakness and vulnerability analysis, attack modeling, and finally risk and impact analysis—so the threats that surface are the ones most likely to happen and most damaging if they do.

Fork brings that rigor to the cadence of modern development, enabling teams to produce a defensible, risk-prioritized threat model in under two hours and keep it current from Sprint 1 onward. Key capabilities include:

  • AI-accelerated attack trees. Fork’s AI capabilities intelligently trim the attack tree for an application, removing noise and focusing analysts on viable, high-impact paths instead of exhaustive theoretical ones.
  • Contextualized, threat-informed models. Fork enriches every model with live cyber threat intelligence, the latest vulnerability data across a product’s full technology stack, and viable attack vectors substantiated through real adversarial testing.
  • Industry-aligned taxonomies. The platform automatically correlates findings with trusted MITRE and OWASP frameworks—including CWE, CVE with EPSS scoring, CAPEC, ATT&CK, D3FEND, and ASVS—to drive targeted, defensible mitigations.
  • A proprietary residual risk formula. As tests complete and conditions change, Fork recalculates residual risk so leaders always have an accurate, current view of exposure.
  • A single pane of glass. Industry threats, an application’s attack surface, and threat intelligence converge into one unified, collaborative view for security, engineering, product, and business stakeholders.

From blueprint to proof: introducing Knife

A threat model defines which attack paths matter most. Knife proves them.

VerSprite is debuting Knife, an AI-led, human-on-the-loop adversarial platform for web applications and web API endpoints, trained on more than 20 years of accredited, industry-recognized offensive security work from VerSprite’s BREAKERS OffSec team. Where Fork serves as the blueprint for adversarial testing, Knife executes against that blueprint—pairing the scale and speed of AI with expert human oversight to validate exploitability with real-world fidelity.

The integration closes the loop that has long separated threat modeling from testing. From within a Fork threat model, teams can request targeted, on-demand testing of specific weaknesses and attack patterns. Knife runs the assessment; results flow back into the model; and Fork updates the residual risk of the product automatically. Threat modeling and adversarial testing stop being sequential, disconnected events and become a continuous, self-updating system.

A new operating model: AI SecOps

“The future of product and software security is an integrated model of AI SecOps—where products are securely designed and tested as part of the functional build process, not bolted on afterward. STRIDE gave the industry a vocabulary. PASTA gave it a methodology. Fork and Knife now give it operational speed—continuous threat modeling and integrated, AI-led testing that keeps pace with how software is actually built and how adversaries actually behave.”

— Tony UcedaVelez, CEO and founder of VerSprite and co-author of the PASTA methodology

Operationalized visibility through deep integrations

Fork is designed to supercharge, not replace, the security tooling enterprises already run. Through integrations across the AppSec ecosystem—spanning SAST, DAST, and software composition analysis, vulnerability scanning, cloud security posture, attack surface management (CASM), penetration testing platforms, and IT service management—Fork turns scattered findings into a living risk picture. Connected and roadmapped integrations include ServiceNow, Veracode, Snyk, Semgrep, Checkmarx, OpenCTI, Qualys, Tenable, Mandiant, and Archer, among others.

The payoff is real-time visibility, operationalized: as continuous and on-demand tests complete and report back, a product’s threat model and residual risk update at the speed of delivery—giving security and product leaders an always-current understanding of what could go wrong, how likely it is, and what it would cost the business.

Availability

Fork is available today. A free Fork Community edition supports a single application threat model with vulnerability ingestion via SBOM or OVAL, while Fork Enterprise unlocks unlimited applications and teams, all integrations, SSO, granular access controls, and audit logging. Fork Enterprise PT extends the platform with on-demand adversarial testing—powered by Knife and VerSprite’s BREAKERS team—requested directly from within a threat model. VerSprite also offers Threat Modeling as a Service for organizations seeking expert-led training and managed delivery.

To learn more, request a demo, or start for free, visit www.forktm.com.

About VerSprite

VerSprite is a global cybersecurity firm specializing in risk-based threat modeling, offensive security, and managed security services. Founded in 2007 and headquartered in Atlanta, Georgia, VerSprite is the originator of the PASTA (Process for Attack Simulation and Threat Analysis) methodology and partners with Fortune 500 enterprises and product organizations worldwide to reduce cyber risk through a structured, data-driven, adversary-informed approach. Learn more at www.versprite.com.

About Fork

Fork is VerSprite’s continuous application threat modeling platform. Built on the PASTA methodology and accelerated by AI, Fork enables security, engineering, and product teams to produce risk-centric threat models in under two hours, contextualize them with live threat intelligence and full-stack vulnerability data, and keep them continuously aligned with how applications evolve—now with integrated, AI-led adversarial testing through Knife.

View source version on businesswire.com: https://www.businesswire.com/news/home/20260626289581/en/

Contacts

Tim Deleon
beetle@versprite.com
7079278611

www.versprite.com -
https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.versprite.
com&esheet=54561295&newsitemid=20260626289581&lan=en-US&anchor=www.versprite.com
&index=5&md5=1cf2d58268829a642f6b28c8ca8e0c4c

(c) 2024 Business Wire, Inc., All rights reserved.

Business Wire, a Berkshire Hathaway company, is the global leader in multiplatform press release distribution.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Venture Global Announces Closing of $1.5 Billion Senior Secured Vessel Financing Facility26.6.2026 22:30:00 CEST | Press Release

Venture Global, Inc. (NYSE: VG) announced today that its wholly-owned subsidiary, Venture Global Shipping Holdings, LLC (“VGSH”), has entered into a Credit and Guaranty Agreement providing for a senior secured term loan facility (the “Facility”) in an aggregate principal amount of up to $1,500,000,000. The Facility will mature on June 26, 2032. Deutsche Bank and ING acted as coordinating lead arrangers for the Facility. ING also serves as facility agent and security trustee. VGSH intends to use the net proceeds from the Facility for general corporate purposes, including to reimburse Venture Global LNG, Inc. for payments previously made by it or its affiliates in connection with the acquisition of nine LNG carriers, funding certain reserve accounts, and paying transaction fees and expenses. About Venture Global Venture Global is an American producer and exporter of low-cost U.S. liquefied natural gas (“LNG”) with over 100 MTPA of capacity in production, construction, or development. Ven

Capco Recognized by OpenAI for Innovation and Responsible AI Leadership26.6.2026 20:00:00 CEST | Press Release

Global management and technology consultancy Capco, a Wipro company,has been recognized by OpenAI for both AI innovation and responsible AI leadership. Capco received the AI Governance & Risk Excellence Award at the recent OpenAI Partner Summit 2026 in San Francisco, highlighting Capco’s ability to deliver enterprise-grade AI outcomes in highly regulated environments. The award recognizes Capco’s expert advantage when helping financial services and energy organizations to scale AI with confidence, balancing innovation with strong governance to reduce risk, strengthen compliance and improve customer outcomes. This award follows Capco winning the OpenAI Codex Hackathon, where its UK AI Lab competed against more than 30 teams and over 100 participants from across the OpenAI partner ecosystem. Capco's winning entry Sentra – a consulting-led, AI-powered retail banking solution – uses digital twin technology to identify vulnerable customers and recommend explainable next-best actions for fro

Incyte Announces Positive CHMP Opinion for Opzelura ® (ruxolitinib) Cream for the Treatment of Adults with Moderate Atopic Dermatitis26.6.2026 13:30:00 CEST | Press Release

Incyte (Nasdaq: INCY) today announced that the Committee for Medicinal Products for Human Use (CHMP) of the European Medicines Agency (EMA) has issued a positive opinion recommending the approval of Opzelura® (ruxolitinib) cream for the treatment of moderate atopic dermatitis (AD) in adult patients for whom topical corticosteroids (TCSs) and topical calcineurin inhibitors (TCIs) are inadequate or inappropriate. “AD is a chronic skin condition that can have a significant impact on daily life. The positive CHMP opinion for Opzelura marks meaningful progress toward bringing the first non-steroidal topical JAK treatment option to adults in Europe with moderate AD for whom standard topical therapies have failed,” said Lee Heeson, Executive Vice President and Head of Incyte International. “If approved by the European Commission, Opzelura could help address an important gap for patients who have limited treatment options when TCSs and TCIs are inadequate or inappropriate.” The positive CHMP o

Datroway ® Recommended for Approval in the EU by CHMP as First-Line Treatment for Patients with Metastatic Triple Negative Breast Cancer Who Are Not Candidates for Immunotherapy26.6.2026 13:00:00 CEST | Press Release

Datroway® (datopotamab deruxtecan) has been recommended for approval in the European Union (EU) as monotherapy for the first-line treatment of adult patients with unresectable or metastatic triple negative breast cancer (TNBC) who are not candidates for PD-1/PD-L1 inhibitor therapy. Datroway is a specifically engineered TROP2 directed DXd antibody drug conjugate (ADC) discovered by Daiichi Sankyo (TSE: 4568) and being jointly developed and commercialized by Daiichi Sankyo and AstraZeneca (LSE/STO/NYSE: AZN). The Committee for Medicinal Products for Human Use (CHMP) of the European Medicines Agency (EMA) based its positive opinion on results from the TROPION-Breast02phase 3 trial, which werepresented at the 2025 European Society for Medical Oncology Congress and published in Annals of Oncology. The recommendation will now be reviewed by the European Commission, which has the authority to grant marketing authorizations for medicines in the EU. In TROPION-Breast02, Datroway demonstrated a

DAYBU ® (trofinetide) Recommended for Approval in the European Union by CHMP26.6.2026 12:49:00 CEST | Press Release

Acadia Pharmaceuticals Inc. (Nasdaq: ACAD) today announced that the Committee for Medicinal Products for Human Use (CHMP) of the European Medicines Agency (EMA) has adopted a positive opinion following a re-examination procedure, recommending the granting of a marketing authorization for DAYBU® (trofinetide) for the treatment of neurobehavioral symptoms of Rett syndrome in adults and pediatric patients aged five years and older. If granted marketing authorization by the European Commission, DAYBU® would be the first therapy approved for this indication in the European Union (EU). “The CHMP’s positive opinion for DAYBU® is an important milestone in our mission to bring this innovative therapy to the EU, where there are no therapies specifically approved for the neurobehavioral symptoms of this devastating condition," said Catherine Owen Adams, Acadia’s Chief Executive Officer. “Our commitment is to make a meaningful difference in the lives of patients, caregivers, and the wider Rett com

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye