Shostack + Associates

@shostackassociates.bsky.social

Shostack + Associates helps customers deliver better products, faster and with less churn or internal conflict. Our approach focuses on threat modeling as a way to “measure twice, cut once.”

Tomorrow at ThreatModCon EU: five Threat Modeling Manifesto working group members challenge their own work in public. Does it still hold in the age of AI? 9am CEST, Vienna. Adam's on the panel before his talk later in the day. We’ve also got a booth, so drop by!

The Unkeynote: challenging the Threat Modeling Manifesto in Vienna

It's a trap. (The trap being: can five Threat Modeling Manifesto working group members sit on the ThreatModCon EU Unkeynote stage together and agree on how AI requires them to amend their own work?)

shostack.org

Michael Novack of Cranium AI is putting the friend in the Shostack + Friends blog with a post on why "the AI explained it" isn't good enough and what a real explainability standard looks like. It's a great read ahead of his OWASP Vienna talk on June 25.

Shostack + Friends Blog > Why “The AI Explained It” Isn't Good Enough: Introducing the SCORE Framework

Exploring what it means for an AI to explain itself, and why “it gave a reason” is not the same as accountability.

shostack.org

Anthropic dropped a lot of Glasswing numbers. Adam made a Sankey diagram and it raised some questions. The interesting part isn't the find rate. It's the 1,006 unpatched vulns, the gap between finding and fixing, and the impact on humans.

Shostack + Friends Blog > Vulnerability Finding: Two Inflection Points

Understanding the numbers from Anthropic and the system that surrounds Glasswing gives us new possibilities for effective defense.

shostack.org

It's Friday, a good day to check "register for that course" off your list before the weekend and we have some exciting options! The new Threat Modeling AI Systems in DC starts May 19. Early pricing for our Intensive with Complete AI at BlackHat ends May 22. Links to courses at shostack.org/training

Training from Shostack + Associates

Structured, systematic and comprehensive security comes when your team has trained in a standard approach for threat modeling.

shostack.org

April Appsec roundup: slow time, AI agents, Claude bypassing its own rules, and faster-but-not-better patch cycles. Plus, Adam is presenting "Threat Modeling in the Age of AI" at VanSecSIG tomorrow and links to upcoming training.

Shostack + Friends Blog > Appsec roundup - April 2026

The importance of slow time in work is a theme for April, along with how Claude optimized away its own security rules. Also fun games collected at RSA!

shostack.org