Threat Modeling LLMs: Adam’s talk at Black Hat USA
PHANTOM-B is a practical tool built for threat modeling AI systems
Security, privacy, economics and unrelated topics since 2005
PHANTOM-B is a practical tool built for threat modeling AI systems
How can we shape a business strategy in an ‘AI world?’
The big takeaways from the OpenAI incident are over-reliance on benchmarks, anthropomorphization and volume.
Kymberlee's list of must-see talks at Black Hat this year
Kymberlee on the Threat Modeling AI Systems community meetup at Black Hat
The things I'm looking forward to at Black Hat this year.
Our newest whitepaper introduces a new threat elicitation tool engineered specifically for LLMs.
Learn what goes into our Threat Modeling Intensive with Complete AI
Reflecting on the S+A team's adventures in Vienna and excitement for BlackHat 2026
From near misses to a new book on the C4 model and fundamental work by NIST showing the limits of today’s AI Guardrails, lots of exciting news about Application security.
When was the last time you read the Declaration? It remains an amazing document.
It's a trap. (The trap being: can five Threat Modeling Manifesto working group members sit on the ThreatModCon EU Unkeynote stage together and agree on how AI requires them to amend their own work?)
Why are we big fans of using games as a learning tool? Michael makes the case for experience-driven learning.
A look at what's happening in the Threat Modeling Intensive session this week in Vienna
Exploring what it means for an AI to explain itself, and why “it gave a reason” is not the same as accountability.
A roundup of where you'll find us over the next couple of months
Reflecting on 20 years of work to scale threat modeling
New repudiation threats, fascinating results from rewriting code in rust, a new strategic plan for OWASP, AIs love their own slop, two new books, and more!
Slides for today's talk
It’s easy to think prioritization is an easy problem, but it’s one deserving careful consideration.
Understanding the numbers from Anthropic and the system that surrounds Glasswing gives us new possibilities for effective defense.
Peter Neumann helped define the field, and my career. He'll be missed terribly.
A busy Black Hat: A new talk, a new practical tool, and a deadline you should know about
HIPAA reform seems to lead to published threat models, and that’s going to be a hard change.
LLMs are great at providing credible answers to questions. And those answers are worth looking at closely.
All about the upcoming Threat Modeling Intensive with Complete AI at Black Hat and why you should be the early bird
The importance of slow time in work is a theme for April, along with how Claude optimized away its own security rules. Also fun games collected at RSA!
Showcasing some Star Wars art to celebrate Revenge of the Fifth
Celebrating Star Wars Day with a look at what Darth Maul’s training can teach you.
Exploring the fun in LLM threat modeling, and how it’s both an interface choice and a possibly ‘dark pattern’
Actionable lessons from delivering Threat Modeling Using LLMs, and using AI more generally.
Shostack + Associates COO Kymberlee Price shares her experience measuring the impact of secure design engineering practices on security outcomes
Adam finally caught his breath and sat down to reflect on BSides SF and RSAC 2026.
Some thoughts on Artemis
One week left to take advantage of Early Bird pricing for our new Threat Modeling AI Systems course.
On First Contact Day, we dive into the lessons that security engineers can learn from the crew.
Security engineers in a DevSecOps world can learn a few things from Star Trek.
This month kicks off with Donald Knuth being shocked by LLMs, then goes into the threat modeling impact of right to repair, and how to TM MCP, and a whole lot more!
Some of the best parts of BSidesSF and RSAC 2026 don't make it into session recordings...
Cybersecurity should learn lessons from industries that are transparent about failure.
Announcing a new course from the Shostack + Associates team.
BlackHat invites human factors work
This is a really funny story, and then a thought-provoking one. It starts: Why Hyundai Has To Recall Only Silver Cars Over A Serious Safety Defect : For vehicles in the Savile Silver exterior color, the front corner radar signals may reflect off the aluminum content in the silver bumper cover paint and pass through the front bumper beam. These signals may be registered as an object in the opposing…
This month's roundup starts with losing oneself, continues with cool new threat modeling tools and applications, and continues into appsec, AI and regulation.
How do we use models to help us answer what are we going to do?
We’re pleased to share that Kymberlee Price has joined Shostack + Associates as our Chief Operating Officer.
LLM-driven vuln finding has reached an inflection
The 2026 Hackers Almanack is out!
Learn more about threat modeling and the Four Question Framework
The normalization of deviance, exciting threat modeling news, and a question of do regulatory threats change ‘the threat model’ as much as GPS attacks? Not yet.