
DevSecOps: Lessons from the ST:TNG Crew
On First Contact Day, we dive into the lessons that security engineers can learn from the crew.

On First Contact Day, we dive into the lessons that security engineers can learn from the crew.

Security engineers in a DevSecOps world can learn a few things from Star Trek.


Some of the best parts of BSidesSF and RSAC 2026 don't make it into session recordings...

Cybersecurity should learn lessons from industries that are transparent about failure.

Announcing a new course from the Shostack + Associates team.

BlackHat invites human factors work


This month's roundup starts with losing oneself, continues with cool new threat modeling tools and applications, and continues into appsec, AI and regulation.

How do we use models to help us answer what are we going to do?

We’re pleased to share that Kymberlee Price has joined Shostack + Associates as our Chief Operating Officer.

LLM-driven vuln finding has reached an inflection

The 2026 Hackers Almanack is out!

Learn more about threat modeling and the Four Question Framework

The normalization of deviance, exciting threat modeling news, and a question of do regulatory threats change ‘the threat model’ as much as GPS attacks? Not yet.