adam shostack
@adamshostack
Done with Twitter. Don't expect responses. Threat Modeling: Designing for Security. Working to reduce bad security outcomes.
Vous pourriez aimer
Threat Modeling is a Jolt Finalist, the first security-centered book on the list since Schneier’s Secrets & Lies newschoolsecurity.com/2014/09/jolt-a…
Leaving my account so it can't be squatted as easily, leaving my tweets because I hate linkrot.
New bloggage, shostack.org/blog/who-are-w… The paper is Who Are “We”? Power Centers in Threat Modeling, and the abstract reads: “I examine threat modeling techniques and questions of power dynamics...
I'm old enough to remember when Americans voted for the candidate they thought would do the best job.
When I saw those release notes I assumed Synology were trying to reduce codec license fees. Whatever the reason, as you say, security patches should not come at the cost of features.
Synology created a patch to address the zero-click vulnerability that researchers at @midnightbluelab found, but @adamshostack spotted this explanation about the patch:
Dutch researchers @midnightbluelab found critical zero-click vuln in photo app enabled by default on Synology storage devices, putting millions of systems at risk of being hacked. They found Synology systems owned by police/law firms/critical infrastructure contractors all vuln…
wow. the best thing I've seen this election.
"Bohemian Trumpsody" from @marshsongs may just be the best thing I've seen all day. Not only are the lyrics spot on, but man they can saaaaaaang!
New video: Scaling Threat Modeling youtu.be/ySGVUMYcoMw?fe… via @YouTube
youtube.com
YouTube
Scaling Threat Modeling
Back in the day, I did some cool #security #UX work with @adamshostack and @moduloprime at Microsoft. Now @beyondidentity is recruiting for a security-savvy UX designer. Any of my #infosec peeps interested? linkedin.com/posts/allan-zi…
Think Like a Hacker? Or not. youtu.be/2ITXN6Yqs-w?fe… via @YouTube
youtube.com
YouTube
Think Like a Hacker? Or not.
Shostack + Associates is launching a new course, Scaling Threat Modeling, and we'd like your input shostack.org/blog/scaling-t…
I remember Russian spies getting full time in-person jobs at Microsoft so my threat model has always been attuned to some form of this issue of spies infiltrating the software supply chain. theatlantic.com/international/…
theatlantic.com
Who Was the 12th Russian Spy at Microsoft?
Alexey Karetnikov tested software at the Redmond giant
Would you know if you hired a North Korean as a remote working employee? Didn’t have that on my cybersecurity bingo card for 2024!
United States Tendances
- 1. #SantaChat 3,446 posts
- 2. Luke Weaver 1,833 posts
- 3. Jack Smith 42.9K posts
- 4. Quinn Ewers 7,806 posts
- 5. FINALLY DID IT 599K posts
- 6. The JUP 154K posts
- 7. Gemini 3 Flash 8,774 posts
- 8. Brad Keller 1,318 posts
- 9. Mariah 52.9K posts
- 10. Judon 1,490 posts
- 11. #ScalingNow_NXXT N/A
- 12. NextNRG Inc 1,129 posts
- 13. Fani Willis 9,589 posts
- 14. Algorhythm Holdings N/A
- 15. Jimmy Stewart 1,944 posts
- 16. #jonita 16.5K posts
- 17. The Oscars 26.4K posts
- 18. Robert E Lee 19.4K posts
- 19. Zach Wilson 1,475 posts
- 20. Clipse 2,331 posts
Vous pourriez aimer
-
Dr. Anton Chuvakin
@anton_chuvakin -
edskoudis
@edskoudis -
Jeremiah Grossman
@jeremiahg -
Chris Wysopal
@WeldPond -
Dino A. Dai Zovi
@dinodaizovi -
Matt Johansen
@mattjay -
Ron Gula
@RonGula -
Ben Rothke
@benrothke -
Dan Guido
@dguido -
Erin Jacobs
@SecBarbie -
Andrew Hay
@andrewsmhay -
Dave
@daveshackleford -
Jennifer (JJ) Minella 🎙 #PacketProtector
@jjx -
Ed Bellis
@ebellis -
jericho
@attritionorg
Something went wrong.
Something went wrong.