
The Nazgul of Threat Modeling
(no description available)

(no description available)


A threat modeling conference, lots of government appsec guidance, and some updates from Shostack + Associates

What can we learn from the C2PA security considerations document?

What can we learn from Gunnar Peterson’s Threat Model for Thanksgiving?

Exciting news from the SEC, lots of AI, and lots of threat modeling.

Principles are lovely, but do they lead us to actionable results?

Thinking about adversarial thinking

Best price ever for Threat Modeling

September was a big month in appsec for both memory safety and policy

The FDA has released their new guidance, which will be broadly impactful.

We can learn a lot from comparing retrospectives

Seats are available in our October training

Lots of interesting work in LLMs (again)

Thoughts on an article on near misses