Sign in

Shostack + Associates

@shostackassociates.bsky.social
21 followers 7 following 42 posts

Shostack + Associates helps customers deliver better products, faster and with less churn or internal conflict. Our approach focuses on threat modeling as a way to “measure twice, cut once.”

PostsRepliesMedia
Shostack + Associates @shostackassociates.bsky.social · 22/09/2026
If, by "partying", you mean obsessing over EU compliance bureaucracy and talking threat modeling, then we're ready to party! Check our conference plans. Also, want to level up your skills? We have training spots left for Threat Modeling Intensive Using AI (Nov 2-4). shostack.org/blog/our-pla...
shostack.org
Heading to San Francisco and ready to party for OWASP's 25th
If by party, you mean obsess over European bureaucracy, train people in the ways of the Force.. umm, threat modeling, and talk about the book until our voices give out.
000
Shostack + Associates @shostackassociates.bsky.social · 15/09/2026
Our engineer just finished assisting at their 3rd Threat Modeling Intensive, this time the new AI-integrated 4-day format at Black Hat. Takeaway: everyone's a little confused about LLMs, so you should take a threat modeling course that integrates AI. Full post: shostack.org/blog/threat-...
shostack.org
Threat Modeling Intensive with Complete AI: From a Developer's POV
Reflections from a Developer
010
Shostack + Associates @shostackassociates.bsky.social · 10/09/2026
On the blog today, Adam tackles concrete ways to improve diagram readability and style, overcoming the tendency of threat modeling diagrams to be hard to read, cluttered, or confusing. All fall, Adam will share insights from the new book on Threat Model Thursdays. shostack.org/blog/diagram...
shostack.org
Diagram Style (Threat Model Thursday)
What makes a diagram good or useful?
000
Shostack + Associates @shostackassociates.bsky.social · 03/09/2026
This fall, Threat Model Thursday is back on the Shostack + Friends Blog featuring key topics in the updated version of Threat Modeling. Today brings a look at diagrams. Get a sneak peek on the blog and then pre-order your copy of the book! shostack.org/blog/clarity...
shostack.org
Diagrams and Clarity (Threat Model Thursday)
Diagrams serve needs, and surprisingly, form follows function
000
Shostack + Associates @shostackassociates.bsky.social · 25/08/2026
AI deployment speed v. system safety: friction or the greatest friction in tech right now? Threat modeling meets this challenge. New post about why and what PHANTOM-B adds is on the blog. Plus the second edition of Threat Modeling is available to pre-order. shostack.org/blog/threat-...
shostack.org
Why threat modeling is the technique that survives AI disruption
AI is disrupting software security, but traditional threat modeling remains the ultimate survival skill.
020
Shostack + Associates @shostackassociates.bsky.social · 21/08/2026
Adam has announced the second edition of his threat modeling classic! Half of the book is completely new or heavily rewritten to handle a decade of shifts in tech and security. If you want to build safer systems, pre-order today! Adam's written about it on the blog: shostack.org/blog/threat-...
022
Shostack + Associates @shostackassociates.bsky.social · 07/08/2026
Kymberlee Price summarizes Adam Shostack's talk at Black Hat on the Shostack + Friends blog today. If you missed it, Adam will reprise the talk tomorrow at 12:30pm on the AppSec Village™ main stage at DEF CON. shostack.org/blog/phantom...
shostack.org
Threat Modeling LLMs: Adam’s talk at Black Hat USA
PHANTOM-B is a practical tool built for threat modeling AI systems
000
Shostack + Associates @shostackassociates.bsky.social · 04/08/2026
Grab the slide deck for @adamshostack.bsky.social's Black Hat USA talk introducing the PHANTOM-B model, now available on the Shostack + Friends blog. The talk starts at Wednesday at 11:05am in Oceanside C, Level 2. shostack.org/blog/phantom...
shostack.org
Threat Modeling LLMs: Adam’s talk at Black Hat USA
PHANTOM-B is a practical tool built for threat modeling AI systems
055
Shostack + Associates @shostackassociates.bsky.social · 27/07/2026
Three lessons from the OpenAI/HuggingFace incident: volume overwhelms judgment, anthropomorphization distorts analysis, and stealing benchmark answers is Goodhart's Law made literal. Adam's new post, with pointers to other useful takes on the incident:
shostack.org
Lessons from the OpenAI/HuggingFace AI Security Incident
The big takeaways from the OpenAI incident are over-reliance on benchmarks, anthropomorphization and volume.
020
Shostack + Associates @shostackassociates.bsky.social · 23/07/2026
Kymberlee's Black Hat 2026 must-see list is up: adversarial scarves, agentic trust boundaries, developer compromise blast radius, risks of security scanners in the supply chain, and a community conversation on threat modeling AI systems.
shostack.org
Black Hat Talks I'm Excited to Attend This Year (Kymberlee's version)
Kymberlee's list of must-see talks at Black Hat this year
000
Shostack + Associates @shostackassociates.bsky.social · 22/07/2026
Threat modeling LLMs & AI pipelines is hard, and no single org has all the answers. Come trade notes, failures, and open questions at our Black Hat community meetup Thu, Aug 6 @ 12 PM | The Convergence (Business Hall) | Any hall pass gets you in! Read more:
shostack.org
Come think out loud with us: Threat Modeling AI Systems
Kymberlee on the Threat Modeling AI Systems community meetup at Black Hat
000
Shostack + Associates @shostackassociates.bsky.social · 16/07/2026
Seats are filling up for our Threat Modeling Intensive w/ Complete AI at Black Hat! Learn the fundamentals + when/how to use LLMs in threat modeling Apply it live in a hackathon-style exercise with personalized feedback from Adam + team. Regular pricing ends Friday. blackhat.com/us-26/traini...
000
Shostack + Associates @shostackassociates.bsky.social · 16/07/2026
PHANTOM-B whitepaper is out today. A STRIDE analog for LLMs built for teams shipping under real constraints, not writing PhD theses. Read it, then catch Adam at Black Hat. Click through for the whitepaper+talk+our training, all must-sees for folks building AI systems. shostack.org/blog/why-pha...
000
Shostack + Associates @shostackassociates.bsky.social · 14/07/2026
AI is changing threat modeling, but fundamentals still matter most. Join @adamshostack.bsky.social's 4-day Threat Modeling Intensive with Complete AI at Black Hat USA 2026 (Aug 1-4, Las Vegas). Regular pricing ends July 17. 🔗 shorturl.at/CmBtW Read more: shorturl.at/aPqVP #ThreatModeling
shorturl.at
Black Hat USA 2026
Black Hat USA 2026
000
Shostack + Associates @shostackassociates.bsky.social · 13/07/2026
👻 Adam Shostack's PHANTOM-B white paper drops this week. Unlike OWASP's LLM Top 10, PHANTOM-B is a threat elicitation tool, built to answer "what can go wrong in this system," not just list known failures. He's also speaking on it at Black Hat. Catch both 😉 #LLMSecurity #ThreatModeling
010
Shostack + Associates @shostackassociates.bsky.social · 09/07/2026
The S+A team had a blast in Vienna at OWASP Global AppSec EU 2026! From leading our Threat Modeling Intensive to meeting fellow AppSec folks, thanks to everyone who showed up, dove deep, and learned by doing. Reflections on the training here: shostack.org/blog/owasp-t...
shostack.org
OWASP Global AppSec EU 2026 Recap (Next up, BlackHat!)
Reflecting on the S+A team's adventures in Vienna and excitement for BlackHat 2026
101
Shostack + Associates @shostackassociates.bsky.social · 26/06/2026
Tomorrow at ThreatModCon EU: five Threat Modeling Manifesto working group members challenge their own work in public. Does it still hold in the age of AI? 9am CEST, Vienna. Adam's on the panel before his talk later in the day. We’ve also got a booth, so drop by!
shostack.org
The Unkeynote: challenging the Threat Modeling Manifesto in Vienna
It's a trap. (The trap being: can five Threat Modeling Manifesto working group members sit on the ThreatModCon EU Unkeynote stage together and agree on how AI requires them to amend their own work?)
000
Shostack + Associates @shostackassociates.bsky.social · 24/06/2026
Security is a decision-making discipline. Michael Novack of Cranium is back on the Shostack + Friends blog to explain why interactive learning builds better instincts than passive training and what that looks like in practice.
shostack.org
Michael at OWASP: Why interactive learning sticks in cybersecurity
Why are we big fans of using games as a learning tool? Michael makes the case for experience-driven learning.
000
Shostack + Associates @shostackassociates.bsky.social · 18/06/2026
Michael Novack of Cranium AI is putting the friend in the Shostack + Friends blog with a post on why "the AI explained it" isn't good enough and what a real explainability standard looks like. It's a great read ahead of his OWASP Vienna talk on June 25.
shostack.org
Shostack + Friends Blog > Why “The AI Explained It” Isn't Good Enough: Introducing the SCORE Framework
Exploring what it means for an AI to explain itself, and why “it gave a reason” is not the same as accountability.
021
Reposted by Shostack + Associates
Adam Shostack @adamshostack.bsky.social · 28/05/2026
"Focus on high priority threats" sounds obvious. I'm not sure it is. New post on why unstructured prioritization is its own kind of risk, and what to do about it. shostack.org/blog/focus-o...
shostack.org
Shostack + Friends Blog > Focus on high priority threats(?)
It’s easy to think prioritization is an easy problem, but it’s one deserving careful consideration.
002
Shostack + Associates @shostackassociates.bsky.social · 26/05/2026
Anthropic dropped a lot of Glasswing numbers. Adam made a Sankey diagram and it raised some questions. The interesting part isn't the find rate. It's the 1,006 unpatched vulns, the gap between finding and fixing, and the impact on humans.
shostack.org
Shostack + Friends Blog > Vulnerability Finding: Two Inflection Points
Understanding the numbers from Anthropic and the system that surrounds Glasswing gives us new possibilities for effective defense.
064
Shostack + Associates @shostackassociates.bsky.social · 21/05/2026
Excited to announce that Adam is presenting Threat Modeling LLMs: The PHANTOM-B Model at Black Hat, a practical threat modeling tool for real deployment timelines. Also, early bird pricing for our Black Hat training course ends tomorrow. Details:
shostack.org
Shostack + Friends Blog > PHANTOM-B goes to Black Hat
A busy Black Hat: A new talk, a new practical tool, and a deadline you should know about
000
Reposted by Shostack + Associates
Adam Shostack @adamshostack.bsky.social · 19/05/2026
There are changes coming to HIPAA security rules and I have some thoughts on what that will mean for organizations. shostack.org/blog/hipaa-n...
shostack.org
Shostack + Friends Blog > HIPAA Updates and Threat Models
HIPAA reform seems to lead to published threat models, and that’s going to be a hard change.
001
Reposted by Shostack + Associates
Adam Shostack @adamshostack.bsky.social · 14/05/2026
Some thoughts about evaluating chatbot-driven threat modeling. shostack.org/blog/claude-...
shostack.org
Shostack + Friends Blog > Claude Opus 4.7 and Threat Modeling
LLMs are great at providing credible answers to questions. And those answers are worth looking at closely.
021
Shostack + Associates @shostackassociates.bsky.social · 12/05/2026
New on the blog: a reminder about Threat Modeling Intensive with Complete AI, our four-day course at Black Hat, and the end of early bird pricing next Friday. Adam walks through the course in a video on the post.
shostack.org
Shostack + Friends Blog > Black Hat training earlybird pricing ends soon
All about the upcoming Threat Modeling Intensive with Complete AI at Black Hat and why you should be the early bird
011
Shostack + Associates @shostackassociates.bsky.social · 08/05/2026
It's Friday, a good day to check "register for that course" off your list before the weekend and we have some exciting options! The new Threat Modeling AI Systems in DC starts May 19. Early pricing for our Intensive with Complete AI at BlackHat ends May 22. Links to courses at shostack.org/training
shostack.org
Training from Shostack + Associates
Structured, systematic and comprehensive security comes when your team has trained in a standard approach for threat modeling.
000
Shostack + Associates @shostackassociates.bsky.social · 07/05/2026
April Appsec roundup: slow time, AI agents, Claude bypassing its own rules, and faster-but-not-better patch cycles. Plus, Adam is presenting "Threat Modeling in the Age of AI" at VanSecSIG tomorrow and links to upcoming training.
shostack.org
Shostack + Friends Blog > Appsec roundup - April 2026
The importance of slow time in work is a theme for April, along with how Claude optimized away its own security rules. Also fun games collected at RSA!
000
Shostack + Associates @shostackassociates.bsky.social · 04/05/2026
Not a model to follow is Darth Maul's training. Different is ours. Our code maythe4th you must use for one-fourth off self-paced courses. shostack.org/blog/may-the...
shostack.org
Shostack + Friends Blog > May the Fourth Be With You!
Celebrating Star Wars Day with a look at what Darth Maul’s training can teach you.
021
Shostack + Associates @shostackassociates.bsky.social · 29/04/2026
Adam is excited to join the Vancouver Security Special Interest Group (VanSecSig)/ ISC2 Vancouver Chapter on May 8th 2pm to 4pm PT for a talk: “Threat Modeling in the Age of AI". Registration is available through VanSecSig. us06web.zoom.us/meeting/regi...
021
Shostack + Associates @shostackassociates.bsky.social · 24/04/2026
This week, we’ve got a new blog post about how we use AI in our work and what we’ve learned in our AI-focused courses. We’ve also got two courses coming up: Threat Modeling AI Systems in DC next month, and a Complete AI edition at Black Hat.
shostack.org
Shostack + Friends Blog > Lessons from Threat Modeling Intensive With AI
Actionable lessons from delivering Threat Modeling with AI, and using AI more generally.
021
Shostack + Associates @shostackassociates.bsky.social · 17/04/2026
Kymberlee Price uses her experience with secure design engineering practices to suggest ways to measure the ROI of threat modeling that track impact, not just activity, in our latest blog post . shostack.org/blog/roi-of-...
shostack.org
Shostack + Friends Blog > Measuring the ROI of threat modeling: moving from activity to impact
Shostack + Associates COO Kymberlee Price shares her experience measuring the impact of secure design engineering practices on security outcomes
021
Shostack + Associates @shostackassociates.bsky.social · 16/04/2026
Early bird price extended on our exciting new course, Threat Modeling AI Systems, delivered by Shoshana Cox and Michael Novack on May 19 + 20 in Washington, D.C. The price is active until the end of the day today, April 16, anywhere on Earth. Claim your spot: courses.shostack.org/courses/Thre...
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
000
Shostack + Associates @shostackassociates.bsky.social · 15/04/2026
Adam went to San Francisco for BSides SF and RSAC and immediately jumped into some projects after getting back (did you know we have upcoming open courses?). He's finally had the chance to post his reflections on the conferences. shostack.org/blog/adam-re...
shostack.org
Shostack + Friends Blog > Adam reflects on BSides SF and RSAC
Adam finally caught his breath and sat down to reflect on BSides SF and RSAC 2026.
021
Shostack + Associates @shostackassociates.bsky.social · 08/04/2026
There's one week left to take advantage of early bird pricing for our newest course, Threat Modeling AI Systems, taking place in-person on May 19-20 in Washington DC. Register by April 15 at courses.shostack.org/courses/Thre...
courses.shostack.org
011
Shostack + Associates @shostackassociates.bsky.social · 03/04/2026
First Contact Day falls on a Sunday this year. We did not plan that but we did plan the second post in our Star Trek series. Come meet the crew with us. Picard. Worf. Troi. Data. It turns out the Enterprise senior staff has a lot to teach security engineers. Check back Sunday at shostack.org/blog!
shostack.org
Shostack + Friends Blog
Security, privacy, economics & unrelated topics, since 2005.
011
Shostack + Associates @shostackassociates.bsky.social · 01/04/2026
See what Star Trek can teach security engineers. Kymberlee Price sets a course in today's Shostack + Friends blog post. Live long and threat model.
shostack.org
Shostack + Friends Blog > DevSecOps: What Every Security Engineer Should Learn from Star Trek
Security engineers in a DevSecOps world can learn a few things from Star Trek.
131
Shostack + Associates @shostackassociates.bsky.social · 01/04/2026
We're very excited to transport into our new branding today. Let us know what you think of our new look! shostack.org
shostack.org
Shostack + Associates > Home
010
Shostack + Associates @shostackassociates.bsky.social · 30/03/2026
Shields up. Something's coming to the Shostack + Associates website on Wednesday and we're not sure the internet is ready. Make it so.
011
Shostack + Associates @shostackassociates.bsky.social · 23/03/2026
Adrian Sanabria of The Defenders Initiative and Adam Shostack take the stage this morning at 9:40 to discuss the case for breach transparency. Find the slides on the Shostack + Friends blog. shostack.org/blog/wasting...
shostack.org
Shostack + Friends Blog > Wasting Failures at RSAC™ 2026 Conference
Cybersecurity should learn lessons from industries that are transparent about failure.
011
Shostack + Associates @shostackassociates.bsky.social · 17/03/2026
Our newest course is now available and there’s an open session this May in Washington DC. We’re thrilled to have Shoshana and Michael join us to deliver this timely but durable course. More details and early bird registration at
courses.shostack.org
Threat Modeling AI Systems Training: 2‑Day Intensive Course
Learn to identify, evaluate, and mitigate AI‑specific threats in this 2‑day, in‑person intensive training. Build skills in threat modeling for ML, generative AI, RAG systems, and AI agents using a…
031
Shostack + Associates @shostackassociates.bsky.social · 13/03/2026
Are you subscribed to our course announcements? We have a new Threat Modeling AI Systems course debuting next week, so sign up to find out all the details as soon as they’re public. Visit our Contact page and sign up under Stay Informed.
shostack.org
Contact Shostack + Associates
Contact information for Shostack + Associates
001
Shostack + Associates @shostackassociates.bsky.social · 05/03/2026
Aviation and medicine improve by studying failures openly. Cybersecurity practitioners’ tendency to hide these failures opens the field up to preventable breaches. Adam and Adrian Sanabria sat down with Dark Reading ahead of their talk at RSAC 2026.
darkreading.com
The Case for Why Better Breach Transparency Matters
It's become a standard practice for organizations to disclose the bare minimum about a data breach, or worse — not disclose the incident at all.
000
Shostack + Associates @shostackassociates.bsky.social · 27/02/2026
A small defensive toolbox limits the choices defenders make, so what models can expand those choices? That’s the subject of Adam’s talk at BSides Seattle, starting now.
000
Shostack + Associates @shostackassociates.bsky.social · 27/02/2026
Hello world! Shostack + Associates will be at BSides Seattle this weekend. Adam’s Track 4 talk, Layering Defenses: A New Hope, starts at 3pm today.
040