
Recent accessibility improvements for the Shostack + Associates website
Accessibility is an ongoing process. Learn about some recent updates to the Shostack + Associates website that increase accessibility and usability.

Accessibility is an ongoing process. Learn about some recent updates to the Shostack + Associates website that increase accessibility and usability.

Get in, we’re rebooting the OWASP Threat Modeling project!

Two new versions of our “Publish your threat model” work are now available.

Phil Venables is releasing a masterclass; new guidance from SAFECode, a new paper from JPMorganChase on their tools, how Facebook uses “waves”, a new AI shared responsibility model and more!

Risk doesn’t do what we hope. We need to talk.

Read up on Adam's New Thing from October

Go see The Moonwalkers

Please vote for the OWASP 2025 board

Watch a masterclass in effective security processes


LLM Insurance is, and will remain, a great source of insurer profits.

The secret service, the CSRB, the CMMC, Sept was pretty busy in government. Plus Apple's Memory Integrity and a nice short paper on prompt-based attacks.

Learn from the past and advance your threat modeling skills!

What can the moon buggy teach us about modeling?

What can a signed Apollo 15 print teach us about modern threat modeling and risk management?