41554 blogs · [ { "id": "01a087e0-315a-7052-85fb-abbb839fbff0", "title": "LLMs as Compilers", "url": "https://shostack.org/blog/llms-as-compilers/", "published_at": "2025-07-29T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb83021637", "title": "Blackhat and Defcon 2025", "url": "https://shostack.org/blog/blackhat-defcon-25/", "published_at": "2025-07-24T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb8268300e", "title": "Risk Management and Threat Modeling", "url": "https://shostack.org/blog/risk-management-and-threat-modeling/", "published_at": "2025-07-21T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb8260da0e", "title": "The Cyber Resilience Act (CRA)!", "url": "https://shostack.org/blog/the-cyber-resilience-act/", "published_at": "2025-07-15T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb81adbb79", "title": "Threat modeling as a dial, not a switch", "url": "https://shostack.org/blog/threat-modeling-as-a-dial-not-a-switch/", "published_at": "2025-07-09T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb80c8f7b6", "title": "Voting Twice for Secession Would be More Fair", "url": "https://shostack.org/blog/voting-for-secession/", "published_at": "2025-07-05T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb8054ce79", "title": "The Unanimous Declaration of the Thirteen United States of America", "url": "https://shostack.org/blog/the-unanimous-declaration-of-the-thirteen-united-states-of-america-2025/", "published_at": "2025-07-04T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb80291bd1", "title": "Appsec Roundup - June 2025", "url": "https://shostack.org/blog/appsec-roundup-june-2025/", "published_at": "2025-07-01T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb7fe83001", "title": "Google’s approach to AI Agents -- Threat Model Thursday", "url": "https://shostack.org/blog/google-approach-to-ai-agents-threat-model-thursday/", "published_at": "2025-06-27T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb7fb085c8", "title": "Publish your threat model!", "url": "https://shostack.org/blog/publish-your-threat-model/", "published_at": "2025-06-16T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb7f222545", "title": "The Essence and Beauty of Threat Modeling", "url": "https://shostack.org/blog/essence-and-beauty-of-threat-modeling/", "published_at": "2025-06-13T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb7e1916f7", "title": "Andor: Insider Threats", "url": "https://shostack.org/blog/andor-insider-threat/", "published_at": "2025-06-02T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb7ec5547d", "title": "Appsec Roundup - May 2025", "url": "https://shostack.org/blog/appsec-roundup-may-2025/", "published_at": "2025-06-02T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb7d30d372", "title": "Free Threat Modeling Training for Displaced Federal Workers", "url": "https://shostack.org/blog/threat-modeling-training-for-federal-workers/", "published_at": "2025-05-20T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb7c342be0", "title": "Blackhat Earlybird Prices End Friday", "url": "https://shostack.org/blog/blackhat-earlybird-pricing-25/", "published_at": "2025-05-19T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb7ba3da38", "title": "Cyber Hard Problems Report", "url": "https://shostack.org/blog/cyber-hard-problems-review/", "published_at": "2025-05-14T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb7abd5b13", "title": "Andor: Think like a leader", "url": "https://shostack.org/blog/think-like-a-leader/", "published_at": "2025-05-13T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb7a0d3ee8", "title": "Andor Threats: Information Disclosure", "url": "https://shostack.org/blog/andor-threats-information-disclosure/", "published_at": "2025-05-03T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb797d1ef0", "title": "The Empire’s Threat Modeling", "url": "https://shostack.org/blog/the-empires-threat-modeling/", "published_at": "2025-05-02T00:00:00+00:00" }, { "id": "01a087e0-315a-7052-85fb-abbb78d0050f", "title": "Appsec Roundup - April 2025", "url": "https://shostack.org/blog/appsec-roundup-april/", "published_at": "2025-04-27T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f9b8c545", "title": "Threat Informed Defense Series", "url": "https://shostack.org/blog/threat-informed-defense/", "published_at": "2025-04-25T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f985c9b6", "title": "CVE Futures", "url": "https://shostack.org/blog/cve-futures/", "published_at": "2025-04-24T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f8ca1a3f", "title": "Andor, Season 2", "url": "https://shostack.org/blog/andor-season-2/", "published_at": "2025-04-22T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f7e203d1", "title": "Free Threats", "url": "https://shostack.org/blog/free-threats/", "published_at": "2025-04-21T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f78ed5c2", "title": "A few thoughts on CVE", "url": "https://shostack.org/blog/thoughts-on-cve/", "published_at": "2025-04-15T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f71171bf", "title": "Assets, Again", "url": "https://shostack.org/blog/assets-again/", "published_at": "2025-04-10T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f61c3252", "title": "Learning from Troy Hunt’s Sneaky Phish", "url": "https://shostack.org/blog/learning-from-troy-hunts-sneaky-phish/", "published_at": "2025-04-05T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f5428f51", "title": "Appsec Roundup - March 2025", "url": "https://shostack.org/blog/appsec-roundup-march-2025/", "published_at": "2025-04-02T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f4745fa1", "title": "Introducing the DEF CON 32 Hackers' Almanack", "url": "https://shostack.org/blog/def-con-almanack/", "published_at": "2025-03-26T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f45f14da", "title": "Security Researcher Comments on HIPAA Security Rule", "url": "https://shostack.org/blog/security-researcher-comment-on-hipaa-security-rules/", "published_at": "2025-03-20T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f436ed14", "title": "OWASP Training in Barcelona", "url": "https://shostack.org/blog/owasp-announcement/", "published_at": "2025-03-15T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f3e13a47", "title": "The Covid pandemic, 5 years on", "url": "https://shostack.org/blog/covid-5-years-on/", "published_at": "2025-03-11T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f2e48411", "title": "The First Constitutional Crisis of 2025", "url": "https://shostack.org/blog/the-first-constitutional-crisis-of-2025/", "published_at": "2025-03-09T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f26c7a49", "title": "Strategy for threat modeling AI", "url": "https://shostack.org/blog/strategy-for-threat-modeling-ai/", "published_at": "2025-03-06T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f1d54243", "title": "RSAC Webinar: Building Resilient Systems", "url": "https://shostack.org/blog/rsa-webinar/", "published_at": "2025-03-04T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f0ff7db2", "title": "Appsec Roundup - Feb 2025", "url": "https://shostack.org/blog/appsec-roundup-feb-2025/", "published_at": "2025-03-03T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f09c77ec", "title": "Inside Man", "url": "https://shostack.org/blog/inside-man/", "published_at": "2025-03-01T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84f013e92c", "title": "How to Threat Model Medical Devices, on The Medical Device Cybersecurity Podcast", "url": "https://shostack.org/blog/medical-device-cybersecurity/", "published_at": "2025-02-20T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84efcc094a", "title": "A New Hope for Threat Modeling, on The CyberTuesday Podcast", "url": "https://shostack.org/blog/cybertuesday-podcast/", "published_at": "2025-02-18T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ef89425b", "title": "Blackhat and Human Factors", "url": "https://shostack.org/blog/blackhat-and-human-factors-2025/", "published_at": "2025-02-14T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ef64e8e0", "title": "Threat Modeling the Genomic Data Sequencing Workflow (Threat Model Thursday)", "url": "https://shostack.org/blog/threat-modeling-the-genetic-sequencing-workflow/", "published_at": "2025-02-13T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ef3e9462", "title": "Appsec Roundup - Jan 2025", "url": "https://shostack.org/blog/appsec-roundup-jan-2025/", "published_at": "2025-02-12T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ee451a17", "title": "Talk at CERIAS", "url": "https://shostack.org/blog/risk-talk-cerias/", "published_at": "2025-02-11T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ede9384d", "title": "The Birth of the CVE System, on Hackers To Founders", "url": "https://shostack.org/blog/hackers-to-founders/", "published_at": "2025-01-30T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ee3ac5a2", "title": "Hoarding, Debt and Threat Modeling", "url": "https://shostack.org/blog/hoarding-debt-and-threat-modeling/", "published_at": "2025-01-30T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84eddeda2c", "title": "National Cyber Incident Response Plan comments", "url": "https://shostack.org/blog/national-cyber-incident-response-plan/", "published_at": "2025-01-28T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ed2a95c3", "title": "Spatial Reasoning and Threat Modeling", "url": "https://shostack.org/blog/spatial-reasoning-and-threat-modeing/", "published_at": "2025-01-27T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ecee6345", "title": "Handling Pandemic-Scale Cyber Threats: Lessons from COVID-19", "url": "https://shostack.org/blog/pandemic-scale/", "published_at": "2025-01-21T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ecbc1f5c", "title": "Lessons for Cybersecurity from the American Public Health System", "url": "https://shostack.org/blog/lessons-for-cyber-from-the-public-health-system/", "published_at": "2025-01-16T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ec742407", "title": "Who Are 'We?' Power Centers in Threat Modeling", "url": "https://shostack.org/blog/who-are-we/", "published_at": "2025-01-05T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ec1df2f4", "title": "Appsec Roundup - Dec 2024", "url": "https://shostack.org/blog/appsec-roundup-dec-2024/", "published_at": "2024-12-31T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ebadb3f9", "title": "A Different Hackathon Design?", "url": "https://shostack.org/blog/a-different-hackathon-design/", "published_at": "2024-12-23T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84eac5de6b", "title": "Stocking stuffers for security nerds", "url": "https://shostack.org/blog/stocking-stuffers-for-security-nerds/", "published_at": "2024-12-16T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ea5ed9d9", "title": "Gavle Goat Endures", "url": "https://shostack.org/blog/gavle-goat-2024/", "published_at": "2024-12-11T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84ea156bfb", "title": "Human Centered Security", "url": "https://shostack.org/blog/human-centered-security/", "published_at": "2024-12-09T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84e92ed5e3", "title": "Appsec Roundup - Nov 2024", "url": "https://shostack.org/blog/appsec-roundup-nov-2024/", "published_at": "2024-12-05T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84e924adca", "title": "Risk Talk at JPL", "url": "https://shostack.org/blog/risk-talk-at-JPL/", "published_at": "2024-11-29T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84e8b37e58", "title": "The Four Question Framework for Threat Modeling", "url": "https://shostack.org/blog/four-question-frame/", "published_at": "2024-11-27T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84e82b235e", "title": "Black Friday Sale", "url": "https://shostack.org/blog/black-friday-sale/", "published_at": "2024-11-26T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84e809c582", "title": "Is Cybersecurity Awareness Month Worth the Money?", "url": "https://shostack.org/blog/is-cybersecurity-awareness-month-worth-the-money/", "published_at": "2024-11-18T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84e739ced6", "title": "Car Safety Factoids", "url": "https://shostack.org/blog/car-safety/", "published_at": "2024-11-16T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84e646a733", "title": "Purple States", "url": "https://shostack.org/blog/purple-states/", "published_at": "2024-11-13T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84e61054e4", "title": "Why do we call them trust boundaries?", "url": "https://shostack.org/blog/trust-and-security-boundaries/", "published_at": "2024-11-06T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84e5966232", "title": "Election Prediction", "url": "https://shostack.org/blog/election-prediction/", "published_at": "2024-11-04T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84e498841d", "title": "Patching in 2024", "url": "https://shostack.org/blog/patching-in-2024/", "published_at": "2024-11-02T00:00:00+00:00" }, { "id": "01a087e0-3159-73af-a758-da84e3f91991", "title": "The Economy", "url": "https://shostack.org/blog/the-economy/", "published_at": "2024-11-01T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879d9d093d", "title": "Appsec Roundup - Oct 2024", "url": "https://shostack.org/blog/appsec-roundup-oct-2024/", "published_at": "2024-10-30T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879d2505d7", "title": "On policy", "url": "https://shostack.org/blog/policy/", "published_at": "2024-10-29T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879c6f1313", "title": "Russia", "url": "https://shostack.org/blog/russia/", "published_at": "2024-10-26T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879bf59fb6", "title": "25 Years of CVE", "url": "https://shostack.org/blog/25-years-of-cve/", "published_at": "2024-10-25T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879be7752f", "title": "Scaling Threat Modeling", "url": "https://shostack.org/blog/scaling-threat-modeling/", "published_at": "2024-10-22T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879bb2dc50", "title": "The people who served under Trump", "url": "https://shostack.org/blog/the-people-who-served-under-trump/", "published_at": "2024-10-20T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879b2da14a", "title": "MITRE ATT&CK: Threat Model Thursday", "url": "https://shostack.org/blog/mitre-attack-threat-modeling-threat-model-thursday/", "published_at": "2024-10-17T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879a3940e6", "title": "OWASP Board 2024", "url": "https://shostack.org/blog/owasp-board-2024/", "published_at": "2024-10-15T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879a373c5d", "title": "Party over country", "url": "https://shostack.org/blog/party-over-country/", "published_at": "2024-10-13T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879957a125", "title": "Coaching", "url": "https://shostack.org/blog/coaching/", "published_at": "2024-10-10T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-2387986781bb", "title": "A Tale of Two Addresses", "url": "https://shostack.org/blog/a-tale-of-two-addresses/", "published_at": "2024-10-07T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-238797803ad6", "title": "On Democracy", "url": "https://shostack.org/blog/on-democracy/", "published_at": "2024-10-06T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879767531e", "title": "ThreatModCon San Francisco", "url": "https://shostack.org/blog/threatmodcon-sf/", "published_at": "2024-10-03T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-238796f7a4a1", "title": "Our back to school sale is ending", "url": "https://shostack.org/blog/back-to-school-ends-today/", "published_at": "2024-09-30T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-238796b10d1d", "title": "Appsec Roundup - September 2024", "url": "https://shostack.org/blog/appsec-roundup-sept-2024/", "published_at": "2024-09-25T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-2387965717d5", "title": "Secure Boot and Liability", "url": "https://shostack.org/blog/secure-boot-and-liability/", "published_at": "2024-09-17T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-2387961f4c35", "title": "Our back to school sale", "url": "https://shostack.org/blog/back-to-school/", "published_at": "2024-09-11T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-238795f11c4c", "title": "Google Health Symposium", "url": "https://shostack.org/blog/google-health-symposium-2024/", "published_at": "2024-09-05T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-2387955375a5", "title": "Appsec Roundup - August 2024", "url": "https://shostack.org/blog/appsec-roundup-august-2024/", "published_at": "2024-09-02T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879516ac79", "title": "Secure Boot and Secure by Design", "url": "https://shostack.org/blog/secure-boot-and-secure-by-design/", "published_at": "2024-08-22T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-238794acea9a", "title": "Handling Pandemic-Scale Cyber Threats (preprint)", "url": "https://shostack.org/blog/handling-pandemic-scale-cyber-threats/", "published_at": "2024-08-19T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879485d6f7", "title": "Office Hours after training", "url": "https://shostack.org/blog/office-hours-training/", "published_at": "2024-08-14T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-238794736c02", "title": "Threat Modeling Gameplay with Eop", "url": "https://shostack.org/blog/threat-modeling-gameplay/", "published_at": "2024-08-12T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-2387937b4964", "title": "Appsec Roundup - July 2024", "url": "https://shostack.org/blog/appsec-roundup-july-2024/", "published_at": "2024-08-02T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879356110f", "title": "Threat Modeling and GenAI with Venkat Ramakrishnan", "url": "https://shostack.org/blog/venkat-podcast/", "published_at": "2024-08-01T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-238792702ae4", "title": "Your Turn! by Scott Rogers", "url": "https://shostack.org/blog/your-turn/", "published_at": "2024-07-31T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-238791cc0754", "title": "The Goals of Cyber Public Health", "url": "https://shostack.org/blog/goals-of-cyber-public-health/", "published_at": "2024-07-28T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23879135177b", "title": "Hard Problems + Cyber Public Health", "url": "https://shostack.org/blog/hard-problems-cyber-public-health-video/", "published_at": "2024-07-25T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-238790d253d9", "title": "Google on Cyber Public Health", "url": "https://shostack.org/blog/google-on-cyberpublichealth/", "published_at": "2024-07-22T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-238790c84e3b", "title": "Hard Problems + Cyber Public Health", "url": "https://shostack.org/blog/hard-problems-cyber-public-health/", "published_at": "2024-07-18T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-238790464742", "title": "Appsec Roundup - June 2024", "url": "https://shostack.org/blog/appsec-roundup-june-2024/", "published_at": "2024-07-10T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-2387902c1ff5", "title": "The Unanimous Declaration of the Thirteen United States of America", "url": "https://shostack.org/blog/the-unanimous-declaration-of-the-thirteen-united-states-of-america-2024/", "published_at": "2024-07-04T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-2387900b54e8", "title": "Inherent threats talk (ThreatModCon)", "url": "https://shostack.org/blog/inherent-threats-threatmodcon/", "published_at": "2024-07-03T00:00:00+00:00" }, { "id": "01a087e0-3158-7293-868a-23878f4aeab8", "title": "Worthwhile Books 1H 2024", "url": "https://shostack.org/blog/worthwhile-books-2024/", "published_at": "2024-06-27T00:00:00+00:00" } ] posts Claim your blog
Back to shostack.org
Blog · corpus.blog/blogs/shostack.org/posts

shostack.org

shostack.org

2025

2024