
Michael at OWASP: Why interactive learning sticks in cybersecurity
Why are we big fans of using games as a learning tool? Michael makes the case for experience-driven learning.

Why are we big fans of using games as a learning tool? Michael makes the case for experience-driven learning.

A look at what's happening in the Threat Modeling Intensive session this week in Vienna

Exploring what it means for an AI to explain itself, and why “it gave a reason” is not the same as accountability.

A roundup of where you'll find us over the next couple of months

Reflecting on 20 years of work to scale threat modeling

New repudiation threats, fascinating results from rewriting code in rust, a new strategic plan for OWASP, AIs love their own slop, two new books, and more!

Slides for today's talk

It’s easy to think prioritization is an easy problem, but it’s one deserving careful consideration.

Understanding the numbers from Anthropic and the system that surrounds Glasswing gives us new possibilities for effective defense.

Peter Neumann helped define the field, and my career. He'll be missed terribly.

A busy Black Hat: A new talk, a new practical tool, and a deadline you should know about

HIPAA reform seems to lead to published threat models, and that’s going to be a hard change.

LLMs are great at providing credible answers to questions. And those answers are worth looking at closely.
All about the upcoming Threat Modeling Intensive with Complete AI at Black Hat and why you should be the early bird

The importance of slow time in work is a theme for April, along with how Claude optimized away its own security rules. Also fun games collected at RSA!