
NIST 800-218 revision
NIST 800-218 wants you!

NIST 800-218 wants you!

What can the Bitlocker story tell us about risk?

GPS attacks trigger revisiting threat models
Threat Modeling Essentials, led by Adam Shostack, is a standout offering at Archimedes 2026 Healthcare Security Week, Feb 18 in Las Vegas.

In 2026, it’s more important than ever to take control of what you read

Congratulations to all involved!

Prompted by participants, a few closing thoughts for 2025

Important news about current events

The best decorations ever

Watch Adam's keynote 'Stop Trying to 'Manage Risk'' From OWASP 2025

The first-ever, community-powered report on threat modeling

Some dialogs can harm the viewer

Perspective on CISOs as facilitators, a deep dive into the types of diagrams for medical devices, poetry, Chinese LLMs, Chinese drones and Chinese routers. Do any of them contain secrets?

Accessibility is an ongoing process. Learn about some recent updates to the Shostack + Associates website that increase accessibility and usability.

Get in, we’re rebooting the OWASP Threat Modeling project!