
Shostack + Friends Blog
Recent Blog Posts


Secure By Design roundup - October 2025
Phil Venables is releasing a masterclass; new guidance from SAFECode, a new paper from JPMorganChase on their tools, how Facebook uses “waves”, a new AI shared responsibility model and more!

Stop Trying to Manage Risk!
Risk doesn’t do what we hope. We need to talk.

October Adam's New Thing!
Read up on Adam's New Thing from October

The Moonwalkers
Go see The Moonwalkers

OWASP Board Thoughts 2025
Please vote for the OWASP 2025 board

LeanAppSec Announcement
Watch a masterclass in effective security processes


AI Insurance Won't Save You
LLM Insurance is, and will remain, a great source of insurer profits.

Secure By Design roundup - September 2025
The secret service, the CSRB, the CMMC, Sept was pretty busy in government. Plus Apple's Memory Integrity and a nice short paper on prompt-based attacks.

Adam Featured on Inside MedTech Innovation
Learn from the past and advance your threat modeling skills!

Lunar Rover Vehicle, Redux
What can the moon buggy teach us about modeling?

Apollo 15 Lunar Rover Vehicle
What can a signed Apollo 15 print teach us about modern threat modeling and risk management?

New Adventure! CyberSec Game Challenge 2025
Register for CyberSec Game Challenge 2025!

How could LLMs change threat modeling
LLMs will change threat modeling. Will it be for the better?