Shostack + Friends Blog

 

Secure By Design roundup - October 2025

Phil Venables is releasing a masterclass; new guidance from SAFECode, a new paper from JPMorganChase on their tools, how Facebook uses “waves”, a new AI shared responsibility model and more!

Phil Venables, CSO for Goldman Sachs and then Google cloud has kicked off a series, Security Leadership Master Class. Even if you’re not a CISO, understanding the leadership principles he lays out is helpful to you.

Threat Modeling

Appsec

  • Allan Reyes has a longish article, Keeping Secrets Out of Logs, which is quite good, and has nice easter eggs.
  • Facebook describes how they use monthly “waves” of activity to help teams engage with their privacy work in a blog post, Federation Platform and Privacy Waves. Key concept: “Tasks are sent in Privacy Waves, which are batches of privacy-related work distributed at a predefined, predictable cadence.”
  • Also on the subject of scaling, Ryan Hurst has an article Compliance at the Speed of Code. It starts out a little obvious to set the scene, but then gets quite thought provoking. I can see starting to reject stories that don’t contain at least a line like “no security implications.”
  • From CVE Entries to Verifiable Exploits: An Automated Multi-Agent Framework for Reproducing CVEs (Arxiv) is interesting both for they can produce exploits for half of the small subset of CVEs where their tools can set up an environment, and for the complexity of the LLM setup to deliver those results.

AI

Regulation

  • There are no regulatory updates because the United States of America is unable to fund its ongoing operations and shut down. 2025 United States federal government shutdown (Wikipedia)
  • Despite that, the FCC deems it essential to reconsider a set of security actions. The letter from Wiley Rein referenced in crucial footnotes is here.

Shostack + Associates News