RSSAmplifier

Blog

Shostack & Friends Blog

Security, privacy, economics and unrelated topics since 2005

shostack.orgRSS feed ↗737 posts

Latest posts

Threat Modeling LLMs: Adam’s talk at Black Hat USA

PHANTOM-B is a practical tool built for threat modeling AI systems

AI and Business Strategy

How can we shape a business strategy in an ‘AI world?’

Lessons from the OpenAI/HuggingFace AI Security Incident

The big takeaways from the OpenAI incident are over-reliance on benchmarks, anthropomorphization and volume.

Black Hat Talks I'm Excited to Attend This Year (Kymberlee's version)

Kymberlee's list of must-see talks at Black Hat this year

Come think out loud with us: Threat Modeling AI Systems

Kymberlee on the Threat Modeling AI Systems community meetup at Black Hat

The Sessions I'm Genuinely Excited About at Black Hat 2026 (Adam's version)

The things I'm looking forward to at Black Hat this year.

Why PHANTOM-B?

Our newest whitepaper introduces a new threat elicitation tool engineered specifically for LLMs.

What to Expect: Threat Modeling Intensive with Complete AI

Learn what goes into our Threat Modeling Intensive with Complete AI

OWASP Global AppSec EU 2026 Recap (Next up, BlackHat!)

Reflecting on the S+A team's adventures in Vienna and excitement for BlackHat 2026

Appsec roundup - June 2026

From near misses to a new book on the C4 model and fundamental work by NIST showing the limits of today’s AI Guardrails, lots of exciting news about Application security.

The Unanimous Declaration of the Thirteen United States of America

When was the last time you read the Declaration? It remains an amazing document.

The Unkeynote: challenging the Threat Modeling Manifesto in Vienna

It's a trap. (The trap being: can five Threat Modeling Manifesto working group members sit on the ThreatModCon EU Unkeynote stage together and agree on how AI requires them to amend their own work?)

Michael at OWASP: Why interactive learning sticks in cybersecurity

Why are we big fans of using games as a learning tool? Michael makes the case for experience-driven learning.

From the training room: real security starts on the whiteboard

A look at what's happening in the Threat Modeling Intensive session this week in Vienna

Why “The AI Explained It” Isn't Good Enough: Introducing the SCORE Framework

Exploring what it means for an AI to explain itself, and why “it gave a reason” is not the same as accountability.

Summer Plans: Vienna, then Las Vegas

A roundup of where you'll find us over the next couple of months

Twenty Years of Scaling Threat Modeling

Reflecting on 20 years of work to scale threat modeling

Appsec roundup - May 2026

New repudiation threats, fascinating results from rewriting code in rust, a new strategic plan for OWASP, AIs love their own slop, two new books, and more!

UW Cyberday: Threat Modeling in the Age of AI

Slides for today's talk

Focus on high priority threats(?)

It’s easy to think prioritization is an easy problem, but it’s one deserving careful consideration.

Vulnerability Finding: Two Inflection Points

Understanding the numbers from Anthropic and the system that surrounds Glasswing gives us new possibilities for effective defense.

Remembering Peter Neumann

Peter Neumann helped define the field, and my career. He'll be missed terribly.

PHANTOM-B goes to Black Hat

A busy Black Hat: A new talk, a new practical tool, and a deadline you should know about

HIPAA Updates and Threat Models

HIPAA reform seems to lead to published threat models, and that’s going to be a hard change.

Claude Opus 4.7 and Threat Modeling

LLMs are great at providing credible answers to questions. And those answers are worth looking at closely.

Black Hat training earlybird pricing ends soon

All about the upcoming Threat Modeling Intensive with Complete AI at Black Hat and why you should be the early bird

Appsec roundup - April 2026

The importance of slow time in work is a theme for April, along with how Claude optimized away its own security rules. Also fun games collected at RSA!

Clever Clippings Star Wars Art

Showcasing some Star Wars art to celebrate Revenge of the Fifth

May the Fourth Be With You!

Celebrating Star Wars Day with a look at what Darth Maul’s training can teach you.

LLM Threat Modeling Is Fun

Exploring the fun in LLM threat modeling, and how it’s both an interface choice and a possibly ‘dark pattern’

Lessons from Threat Modeling Intensive Using LLMs

Actionable lessons from delivering Threat Modeling Using LLMs, and using AI more generally.

Measuring the ROI of threat modeling: moving from activity to impact

Shostack + Associates COO Kymberlee Price shares her experience measuring the impact of secure design engineering practices on security outcomes

Adam reflects on BSides SF and RSAC

Adam finally caught his breath and sat down to reflect on BSides SF and RSAC 2026.

Artemis and Cybersecurity

Some thoughts on Artemis

One week left for Threat Modeling AI Systems Early Bird pricing

One week left to take advantage of Early Bird pricing for our new Threat Modeling AI Systems course.

DevSecOps: Lessons from the ST:TNG Crew

On First Contact Day, we dive into the lessons that security engineers can learn from the crew.

DevSecOps: What Every Security Engineer Should Learn from Star Trek

Security engineers in a DevSecOps world can learn a few things from Star Trek.

Appsec roundup - March 2026

This month kicks off with Donald Knuth being shocked by LLMs, then goes into the threat modeling impact of right to repair, and how to TM MCP, and a whole lot more!

Sunshine and Security – Kymberlee’s week at BSides SF and RSAC 2026

Some of the best parts of BSidesSF and RSAC 2026 don't make it into session recordings...

Wasting Failures at RSAC™ 2026 Conference

Cybersecurity should learn lessons from industries that are transparent about failure.

Threat Modeling AI Systems: Finding the Line Between Application Security and AI Security

Announcing a new course from the Shostack + Associates team.

Blackhat and Human Factors

BlackHat invites human factors work

Silver Hyundais Recalled

This is a really funny story, and then a thought-provoking one. It starts: Why Hyundai Has To Recall Only Silver Cars Over A Serious Safety Defect : For vehicles in the Savile Silver exterior color, the front corner radar signals may reflect off the aluminum content in the silver bumper cover paint and pass through the front bumper beam. These signals may be registered as an object in the opposing…

Appsec roundup - Feb 2026

This month's roundup starts with losing oneself, continues with cool new threat modeling tools and applications, and continues into appsec, AI and regulation.

Layered Defenses at BSides Seattle

How do we use models to help us answer what are we going to do?

Welcoming Kymberlee Price to Shostack + Associates

We’re pleased to share that Kymberlee Price has joined Shostack + Associates as our Chief Operating Officer.

Vulnerability Finding: An Inflection Point

LLM-driven vuln finding has reached an inflection

The DEF CON 33 Hackers Almanack

The 2026 Hackers Almanack is out!

Adam Featured on the AppSec Weekly Podcast

Learn more about threat modeling and the Four Question Framework

Secure By Design roundup - Dec/Jan 2026

The normalization of deviance, exciting threat modeling news, and a question of do regulatory threats change ‘the threat model’ as much as GPS attacks? Not yet.