41554 blogs · [ { "id": "01a087e0-3156-7011-bc81-bc855059a2db", "title": "Threats, To The Supply Chain", "url": "https://shostack.org/blog/threats-to-the-supply-chain/", "published_at": "2023-01-22T00:00:00+00:00" }, { "id": "01a087e0-3156-7011-bc81-bc854fb58505", "title": "Friday Star Wars: Presidents Daily Brief", "url": "https://shostack.org/blog/friday-star-wars-jan-2023/", "published_at": "2023-01-20T00:00:00+00:00" }, { "id": "01a087e0-3156-7011-bc81-bc854f4639ac", "title": "Threats Book Launch Party", "url": "https://shostack.org/blog/threats-book-launch-seattle/", "published_at": "2023-01-19T00:00:00+00:00" }, { "id": "01a087e0-3156-7011-bc81-bc854f410dd8", "title": "Threats Book is Complete", "url": "https://shostack.org/blog/threats-books-complete/", "published_at": "2023-01-17T00:00:00+00:00" }, { "id": "01a087e0-3156-7011-bc81-bc854f36c203", "title": "Threats: The Table of Contents", "url": "https://shostack.org/blog/threats-table-of-contents/", "published_at": "2023-01-16T00:00:00+00:00" }, { "id": "01a087e0-3156-7011-bc81-bc854ee66cda", "title": "Threat Modeling is Measure Twice, Cut Once", "url": "https://shostack.org/blog/threat-modeling-is-measure-twice-cut-once-for-software/", "published_at": "2023-01-12T00:00:00+00:00" }, { "id": "01a087e0-3156-7011-bc81-bc854de95eb0", "title": "The Appsec Landscape in 2023", "url": "https://shostack.org/blog/the-appsec-landscape-in-2023/", "published_at": "2023-01-05T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d9d5e82f", "title": "The Last 747", "url": "https://shostack.org/blog/747/", "published_at": "2022-12-30T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d92eefeb", "title": "Threat Model Thursday: curl", "url": "https://shostack.org/blog/threat-model-thursday-curl/", "published_at": "2022-12-29T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d9008913", "title": "Fast, Cheap and Good, Redux", "url": "https://shostack.org/blog/fast-cheap-good-redux/", "published_at": "2022-12-28T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d800a605", "title": "Gavle Goat", "url": "https://shostack.org/blog/gavle/", "published_at": "2022-12-25T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d872bf15", "title": "More on GPT-3 and threat modeling", "url": "https://shostack.org/blog/more-on-gpt3/", "published_at": "2022-12-25T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d77944f4", "title": "What do you get the person who has everything?", "url": "https://shostack.org/blog/spacepostcards/", "published_at": "2022-12-23T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d76d5d1d", "title": "Darkreading: Threat Modeling in the Age of OpenAI's Chatbot", "url": "https://shostack.org/blog/gpt3-threatmodeling-darkreading/", "published_at": "2022-12-22T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d7078660", "title": "Usable Security Matters", "url": "https://shostack.org/blog/security-alerts/", "published_at": "2022-12-21T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d6313956", "title": "Worthwhile Books Q4 2022", "url": "https://shostack.org/blog/worthwhile-books-q4/", "published_at": "2022-12-19T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d5678fc9", "title": "Space News", "url": "https://shostack.org/blog/spacenews/", "published_at": "2022-12-18T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d4ab79e8", "title": "Liability for the Second Death Star", "url": "https://shostack.org/blog/death-star-liability/", "published_at": "2022-12-16T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d3f29e74", "title": "Human-Centered Security", "url": "https://shostack.org/blog/human-centered-podcast/", "published_at": "2022-12-14T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d38a7acf", "title": "GPT-3", "url": "https://shostack.org/blog/gpt-3-threat-modeling/", "published_at": "2022-12-09T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d3a37d49", "title": "GPT-3", "url": "https://shostack.org/blog/gpt-3/", "published_at": "2022-12-09T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d2d347cb", "title": "The Threats book is complete", "url": "https://shostack.org/blog/threats-announce/", "published_at": "2022-12-08T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d1e6b8df", "title": "Application Security Roundup - October and Nov", "url": "https://shostack.org/blog/appsec-roundup-oct/", "published_at": "2022-11-30T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d2a1de0d", "title": "Cybersecurity Magazine: Podcast Episode with Han Christian Rudolph", "url": "https://shostack.org/blog/csm-podcast/", "published_at": "2022-11-30T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d18f7a94", "title": "Trainings and discounts", "url": "https://shostack.org/blog/trainings-and-discounts/", "published_at": "2022-11-11T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d171106d", "title": "Miro Threat Modeling Template for EoP", "url": "https://shostack.org/blog/eop-miro/", "published_at": "2022-11-10T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d1420a6c", "title": "Medical Device Threat Modeling Boot Camp", "url": "https://shostack.org/blog/bootcamp/", "published_at": "2022-11-01T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373d04fee1c", "title": "Worthwhile Books Q3 2022", "url": "https://shostack.org/blog/worthwhile-books-q3-2022/", "published_at": "2022-10-23T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373cf5c9d6b", "title": "Bic Transit Gloria Mundi", "url": "https://shostack.org/blog/pens/", "published_at": "2022-10-15T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373ce8d6b8c", "title": "Application Security Roundup - September", "url": "https://shostack.org/blog/appsec-roundup-sept/", "published_at": "2022-09-30T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373ce714915", "title": "Oregon Forestry", "url": "https://shostack.org/blog/oregon/", "published_at": "2022-09-16T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373cd8370b5", "title": "Threat Modeling for Security Champs", "url": "https://shostack.org/blog/oct-champs-course/", "published_at": "2022-09-14T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373cd12bb74", "title": "Doing an AMA", "url": "https://shostack.org/blog/reddit-privacy-ama/", "published_at": "2022-09-09T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373ccf3385d", "title": "Threat Modeling Training Announcements Fall, 2022", "url": "https://shostack.org/blog/course-announcement-fall/", "published_at": "2022-09-06T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373cc5b5db1", "title": "Threats — The Cover", "url": "https://shostack.org/blog/threats-cover/", "published_at": "2022-08-19T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373cbc552a4", "title": "Podcast: A Fully Trained Jedi", "url": "https://shostack.org/blog/ITSP-jedi/", "published_at": "2022-08-02T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373cb28d896", "title": "Application Security Roundup - July", "url": "https://shostack.org/blog/appsec-roundup-july/", "published_at": "2022-07-30T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373ca3e0b74", "title": "The Buffet Overflow cafe", "url": "https://shostack.org/blog/buffet-overflow/", "published_at": "2022-07-22T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c973c168", "title": "Major Cyber Incidents Investigations", "url": "https://shostack.org/blog/mciib/", "published_at": "2022-07-19T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c8afa8e2", "title": "Webb Telescope comparitor", "url": "https://shostack.org/blog/webb-comparator/", "published_at": "2022-07-18T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c7e8c166", "title": "Congratulations to the CSRB!", "url": "https://shostack.org/blog/csrb-report/", "published_at": "2022-07-14T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c76dd90a", "title": "Application Security Roundup - June", "url": "https://shostack.org/blog/appsec-roundup-june/", "published_at": "2022-06-28T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c768b58f", "title": "Authentic Thoughts About What Can Go Wrong", "url": "https://shostack.org/blog/what-can-go-wrong-authentic-thoughts/", "published_at": "2022-06-09T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c6f9df84", "title": "A Science of Cybersecurity Public Health", "url": "https://shostack.org/blog/cybergreen/", "published_at": "2022-06-02T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c65a9b14", "title": "OWASP podcast with Matt Tesauro", "url": "https://shostack.org/blog/owasp-podcast/", "published_at": "2022-05-31T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c576de2b", "title": "Plants grow in lunar soil", "url": "https://shostack.org/blog/moon-dirt/", "published_at": "2022-05-13T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c47c97ca", "title": "Application Security Roundup - May", "url": "https://shostack.org/blog/appsec-roundup-may/", "published_at": "2022-05-12T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c3850fd9", "title": "on the security of Star Wars", "url": "https://shostack.org/blog/on-security-of-star-wars/", "published_at": "2022-05-09T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c2f94a35", "title": "Happy Star Wars Day: A Big Announcement & Small Gift", "url": "https://shostack.org/blog/star-wars-day-2022/", "published_at": "2022-05-04T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c28e0866", "title": "Worthwhile Books May 2022", "url": "https://shostack.org/blog/worthwhile-books-q2-2022/", "published_at": "2022-05-02T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c27aa295", "title": "CyberPeace", "url": "https://shostack.org/blog/cyberpeace/", "published_at": "2022-04-25T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c18d7ae8", "title": "Future of Appsec podcast", "url": "https://shostack.org/blog/future-of-appsec/", "published_at": "2022-04-21T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c0f37b5a", "title": "FDA Draft Premarket Guidance", "url": "https://shostack.org/blog/fda-premarket-draft/", "published_at": "2022-04-08T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c074a88d", "title": "The Grimes Model of Scams", "url": "https://shostack.org/blog/grimes-model-of-scams/", "published_at": "2022-03-31T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c0457827", "title": "Short reads, March 2022", "url": "https://shostack.org/blog/shortreads-march/", "published_at": "2022-03-28T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373c007dc0d", "title": "The Evergreen Running Aground Problem", "url": "https://shostack.org/blog/ever-forward/", "published_at": "2022-03-23T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373bfd70c6c", "title": "How Executives Can Use Threat Modeling", "url": "https://shostack.org/blog/how-executives-can-use-threat-modeling/", "published_at": "2022-03-18T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373bfa1ab52", "title": "Elevation of Defenses", "url": "https://shostack.org/blog/elevation-of-defenses/", "published_at": "2022-03-15T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373bf229f7a", "title": "I need an extension!", "url": "https://shostack.org/blog/i-need-an-extension/", "published_at": "2022-02-23T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373be3336ff", "title": "How To Choose a Threat Modeling Training", "url": "https://shostack.org/blog/how-to-choose-threat-modeling-training/", "published_at": "2022-02-18T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373be0a97e4", "title": "Ten Questions we hope the CSRB answers", "url": "https://shostack.org/blog/ten-questions-for-the-csrb/", "published_at": "2022-02-09T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373bd3a2545", "title": "Worthwhile Books Q1 2022", "url": "https://shostack.org/blog/worthwhile-books-q1-2022/", "published_at": "2022-01-28T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373bc7e4ef5", "title": "Wearing Many Hats", "url": "https://shostack.org/blog/wearing-many-hats/", "published_at": "2022-01-24T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373bbecd7ac", "title": "#WeHackPurple: Podcast Episode with Tanya Janca", "url": "https://shostack.org/blog/we-hack-purple/", "published_at": "2022-01-22T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373bb400104", "title": "Elevation of Privilege: New Cards for 2022", "url": "https://shostack.org/blog/elevation-of-privilege-2022/", "published_at": "2022-01-20T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373bae26ada", "title": "Threat Modeling Open Training: First Quarter, 2022", "url": "https://shostack.org/blog/threat-modeling-open-training/", "published_at": "2022-01-13T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373baccdeea", "title": "Letterlocking", "url": "https://shostack.org/blog/letterlocking/", "published_at": "2022-01-12T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373bac8a3dc", "title": "25 Years in AppSec: Looking Back, Looking Forward", "url": "https://shostack.org/blog/25-years-appsec-keynote/", "published_at": "2022-01-10T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373ba316658", "title": "The Allegory of Rocks and Sand", "url": "https://shostack.org/blog/allegory-rocks-sand/", "published_at": "2021-12-29T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b9da05b0", "title": "Missed it by that much!", "url": "https://shostack.org/blog/missed-it-by-that-much/", "published_at": "2021-12-16T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b90018f4", "title": "Fast, Cheap + Good Whitepaper", "url": "https://shostack.org/blog/fast-cheap-good/", "published_at": "2021-12-15T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b8ff1427", "title": "Gävle Goat, 2021 edition", "url": "https://shostack.org/blog/gavle-goat-2021/", "published_at": "2021-12-11T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b80fdda8", "title": "FDA Threat Modeling Playbook Now Available", "url": "https://shostack.org/blog/fda-threat-modeling-playbook-available/", "published_at": "2021-11-30T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b7cdd150", "title": "Medical Device Threat Modeling Webinar", "url": "https://shostack.org/blog/medical-device-threat-modeling-webinar/", "published_at": "2021-11-21T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b740be68", "title": "Learning Lessons from Aviation", "url": "https://shostack.org/blog/cyber-lessons-learned/", "published_at": "2021-11-15T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b69e2ff1", "title": "25 Years of Appsec - Appsec Global", "url": "https://shostack.org/blog/25-years-of-appsec-owasp/", "published_at": "2021-11-11T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b5b2a65f", "title": "Breaking into threat modeling", "url": "https://shostack.org/blog/breaking-into-threat-modeling/", "published_at": "2021-11-01T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b514d88b", "title": "Trainings at Global Appsec 2021", "url": "https://shostack.org/blog/trainings-global-appsec-2021/", "published_at": "2021-10-20T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b4998453", "title": "What are we going to do: CO2 edition", "url": "https://shostack.org/blog/what-are-we-going-to-do-co2-edition/", "published_at": "2021-10-05T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b3bb4496", "title": "Lessons Learned: Playing Elevation of Privilege", "url": "https://shostack.org/blog/lessons-learned-elevation-of-privilege/", "published_at": "2021-09-28T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b35b8768", "title": "NIST Brings Threat Modeling into the Spotlight", "url": "https://shostack.org/blog/nist-brings-threat-modeling-into-the-spotlight/", "published_at": "2021-09-23T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b2bd2ae5", "title": "A Vulnerable System", "url": "https://shostack.org/blog/a-vulnerable-system/", "published_at": "2021-09-13T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b23d29a5", "title": "What can go wrong?", "url": "https://shostack.org/blog/what-can-go-wrong/", "published_at": "2021-09-10T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b1606539", "title": "Training discounts!", "url": "https://shostack.org/blog/training-discount/", "published_at": "2021-09-02T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b0bad333", "title": "This is the blog you're looking for", "url": "https://shostack.org/blog/this-is-the-blog-youre-looking-for/", "published_at": "2021-08-24T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373b02bf4ed", "title": "Threat Modeling Through the JoHari Window", "url": "https://shostack.org/blog/threat-modeling-through-the-johari-window/", "published_at": "2021-08-20T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373afe39d28", "title": "Training - October", "url": "https://shostack.org/blog/training-october/", "published_at": "2021-08-16T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373af9285e6", "title": "25 Years in AppSec: Looking Back", "url": "https://shostack.org/blog/25-years-in-appsec-looking-back/", "published_at": "2021-08-09T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373af776147", "title": "The COVID testbed and AI", "url": "https://shostack.org/blog/ai-and-covid/", "published_at": "2021-08-04T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373aeb594b8", "title": "Zen and the art of not quantifying risk", "url": "https://shostack.org/blog/zen-and-the-art-of-not-quantifying-risk/", "published_at": "2021-07-27T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373ae0432f8", "title": "Threat Model Thursday: NIST’s Code Verification Standard", "url": "https://shostack.org/blog/tmt-NIST-code-verification-standard/", "published_at": "2021-07-15T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373adb5a68f", "title": "Collaboration in Threat Modeling", "url": "https://shostack.org/blog/collaboration-video/", "published_at": "2021-07-13T00:00:00+00:00" }, { "id": "01a087e0-3155-7094-a0ec-0373ad75b881", "title": "Sketching to Answer 'What are we working on?'", "url": "https://shostack.org/blog/sketching-video/", "published_at": "2021-07-07T00:00:00+00:00" }, { "id": "01a087e0-3154-710d-8a76-d3ba4b4321fe", "title": "Threat Model Thursday: 5G Infrastructure", "url": "https://shostack.org/blog/tmt-5g-infra/", "published_at": "2021-07-01T00:00:00+00:00" }, { "id": "01a087e0-3154-710d-8a76-d3ba4b02edcb", "title": "Applied Threat Modeling at BlackHat 2021", "url": "https://shostack.org/blog/applied-tm-at-blackhat21/", "published_at": "2021-06-28T00:00:00+00:00" }, { "id": "01a087e0-3154-710d-8a76-d3ba4a667d17", "title": "Why Threat Model?", "url": "https://shostack.org/blog/why-threat-model/", "published_at": "2021-06-23T00:00:00+00:00" }, { "id": "01a087e0-3154-710d-8a76-d3ba4a59bde7", "title": "Juneteenth: A New Federal Holiday", "url": "https://shostack.org/blog/juneteenth/", "published_at": "2021-06-19T00:00:00+00:00" }, { "id": "01a087e0-3154-710d-8a76-d3ba49d03ee1", "title": "Fast threat modeling videos", "url": "https://shostack.org/blog/fast-threat-modeling-videos/", "published_at": "2021-06-17T00:00:00+00:00" }, { "id": "01a087e0-3154-710d-8a76-d3ba49a50c86", "title": "'Not in my threat model'?", "url": "https://shostack.org/blog/not-in-my-tm/", "published_at": "2021-06-15T00:00:00+00:00" }, { "id": "01a087e0-3154-710d-8a76-d3ba49598a55", "title": "Ransomware is Not the Problem", "url": "https://shostack.org/blog/ransomware-is-not-the-problem/", "published_at": "2021-06-09T00:00:00+00:00" } ] posts Claim your blog
Back to shostack.org
Blog · corpus.blog/blogs/shostack.org/posts

shostack.org

shostack.org

2023

2022

2021