
The Sessions I'm Genuinely Excited About at Black Hat 2026 (Adam's version)
The things I'm looking forward to at Black Hat this year.

The things I'm looking forward to at Black Hat this year.

Learn what goes into our Threat Modeling Intensive with Complete AI

Reflecting on the S+A team's adventures in Vienna and excitement for BlackHat 2026

It's a trap. (The trap being: can five Threat Modeling Manifesto working group members sit on the ThreatModCon EU Unkeynote stage together and agree on how AI requires them to amend their own work?)

A look at what's happening in the Threat Modeling Intensive session this week in Vienna

Exploring what it means for an AI to explain itself, and why “it gave a reason” is not the same as accountability.

A roundup of where you'll find us over the next couple of months

A busy Black Hat: A new talk, a new practical tool, and a deadline you should know about

Adam finally caught his breath and sat down to reflect on BSides SF and RSAC 2026.

Some of the best parts of BSidesSF and RSAC 2026 don't make it into session recordings...

Cybersecurity should learn lessons from industries that are transparent about failure.

BlackHat invites human factors work

How do we use models to help us answer what are we going to do?

Adam’s plans for summer camp

BlackHat invites human factors work

Output encoding is a tool, not a hammer. Or maybe it's a hammer.

Slides from Adam's talk at the Symposium

BlackHat invites human factors work

Why it’s ok to use the Defcon wifi

Adam's AppSecPNW 2023 keynote
AppSec Pacific Northwest Conference is a free application security conference that will be held Saturday, June 19th. It is a virtual, online event sponsored by the OWASP chapters of Portland, Vancouver, and Victoria.

Rupin Gupta runs Digital Guru books. He's one of the nicest people you'll ever meet, a real joy to work with, and he works hard to put books on shelves so that you can discover them. With the conference business changing, Digital Guru needs some help.

I'll be speaking at the MDIC's Annual Public Forum today, discussing how threat modeling helps bring maturity to the medtech sector.
A few tips on getting the most out of attending a virtual security conference.

As a member of the BlackHat Review Board, I would love to see more work on Human Factors presented there.

Earlier this year, I helped to organize a workshop at Schloss Dagstuhl on Empirical Evaluation of Secure Development Processes. I think the workshop was a tremendous success.

How to get back into the workflow after time away at conferences.
Reminders about some conference best practices.
Some tips on how to regoup and catch up after being away for conferences.
Where and when to find Adam Shostack at RSA 2019
Check out my talk from Blackhat 2018

[no description provided]
The slides from my Blackhat talk are now available.

[no description provided]
Help me help you.

[no description provided]
[no description provided]
[no description provided]
[no description provided]