
Lessons from Threat Modeling Intensive With AI
Actionable lessons from delivering Threat Modeling with AI, and using AI more generally.

Actionable lessons from delivering Threat Modeling with AI, and using AI more generally.

Shostack + Associates COO Kymberlee Price shares her experience measuring the impact of secure design engineering practices on security outcomes

Adam finally caught his breath and sat down to reflect on BSides SF and RSAC 2026.

One week left to take advantage of Early Bird pricing for our new Threat Modeling AI Systems course.

Some thoughts on Artemis

On First Contact Day, we dive into the lessons that security engineers can learn from the crew.

Security engineers in a DevSecOps world can learn a few things from Star Trek.

This month kicks off with Donald Knuth being shocked by LLMs, then goes into the threat modeling impact of right to repair, and how to TM MCP, and a whole lot more!

Some of the best parts of BSidesSF and RSAC 2026 don't make it into session recordings...

Cybersecurity should learn lessons from industries that are transparent about failure.

Announcing a new course from the Shostack + Associates team.

BlackHat invites human factors work


This month's roundup starts with losing oneself, continues with cool new threat modeling tools and applications, and continues into appsec, AI and regulation.

How do we use models to help us answer what are we going to do?