
Shostack + Friends Blog
Recent Blog Posts, Page 6


Cyber Hard Problems Report
The Cyber Hard Problems report is coming out

Andor: Think like a leader
Think like a what??!

Andor Threats: Information Disclosure
What Andor can teach us about Information disclosure threats

The Empire’s Threat Modeling
Get one fourth off for May the fourth!

Appsec Roundup - April 2025
Threat modeling. So much threat modeling, and so much more, including foreshadowing of new rules from FDA.

Threat Informed Defense Series
A great, in depth series on threat modeling with ATTACK

CVE Futures
What’s next for the CVE program?

Andor, Season 2
Excited for Star Wars: Andor Season 2

Free Threats
Pray they don’t alter the price any further

A few thoughts on CVE
Thoughts on the CVE funding crisis

Assets, Again
What's wrong with this process?


Appsec Roundup - March 2025
Big news for LLMs in threat modeling!

Introducing the DEF CON 32 Hackers' Almanack
Grateful to introduce the Hackers' Almanack!