
Threat Modeling AI Systems: Finding the Line Between Application Security and AI Security
Announcing a new course from the Shostack + Associates team.

Announcing a new course from the Shostack + Associates team.

BlackHat invites human factors work


This month's roundup starts with losing oneself, continues with cool new threat modeling tools and applications, and continues into appsec, AI and regulation.

How do we use models to help us answer what are we going to do?

We’re pleased to share that Kymberlee Price has joined Shostack + Associates as our Chief Operating Officer.

LLM-driven vuln finding has reached an inflection

The 2026 Hackers Almanack is out!

Learn more about threat modeling and the Four Question Framework

The normalization of deviance, exciting threat modeling news, and a question of do regulatory threats change ‘the threat model’ as much as GPS attacks? Not yet.

Adam will be the featured speaker at the ISC2 Seattle Chapter meeting in February.

NIST 800-218 wants you!

What can the Bitlocker story tell us about risk?

GPS attacks trigger revisiting threat models

In 2026, it’s more important than ever to take control of what you read