Damus
Adam Shostack :donor: :rebelverified: profile picture
Adam Shostack :donor: :rebelverified:
@Adam Shostack :donor: :rebelverified:

Author, game designer, technologist, teacher.

Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board.

Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security.

Following back if you have content.

Relays (1)
  • wss://relay.ditto.pub – read & write

Recent Notes

Adam Shostack :donor: :rebelverified: profile picture
Really, really impressed with MSRC:

Hello Adam,

My name is Nic Fillingham and I work for the Microsoft Security Response Center (MSRC) based in Redmond, WA. I help manage Coordinated Vulnerability Disclosure (also known as Responsible Disclosure) for vulnerabilities discovered in Microsoft products, services, and technologies.

Congratulations on having your talk “Threat Modeling LLMs: The PHANTOM-B model” selected for presentation at Black Hat USA 2026.

I’m reaching out to Black Hat USA 2026 presenters to ask whether their talk will disclose or discuss any MSRC cases or submissions.

Could you please reply and let me know if your talk will include any MSRC cases or submissions? If so, can you please provide the MSRC submission VULN-ID(s), case number(s) or CVEs numbers you plan to disclose or discuss.

Please let me know if you have any questions.

Thank you,

Nic

Given the volume of talks, I’m utilizing automation to send these emails. My apologies if you receive this email in error or more than once.
2
kravietz 🦇 · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq074dk2mqqxl7kgukea6th3xaa9fdgx7vty2x8zger32uydyf6e3qg70rz0 Thank God they didn’t ask you to pay a “moderate fee” for processing your responses! Copilot tokens ain’t cheap these days…
Marcus Hutchins :verified: · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq074dk2mqqxl7kgukea6th3xaa9fdgx7vty2x8zger32uydyf6e3qg70rz0 Someone needs to check the office water coolers at Redmond. I think it might have gotten filled with lead
Tarah Wheeler · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq074dk2mqqxl7kgukea6th3xaa9fdgx7vty2x8zger32uydyf6e3qg70rz0 nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqz96sewfq3gryu873wyhf86rmeeucfzkvankf8kxtlcqm2ru4pyrs7rjfkc for this passage to involve time travel we’d have to summon the lich o...
Seth of the Fediverse ⁂ · 4w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq074dk2mqqxl7kgukea6th3xaa9fdgx7vty2x8zger32uydyf6e3qg70rz0 That's a lot of words to digest!
Adam Shostack :donor: :rebelverified: profile picture
A few thoughts remembering Peter Neumann:

Peter shaped my professional career since the start.

Peter epitomized and modeled the idea that a computer scientist should not “stay in a lane,” but rather be engaged with the impacts of our work, and he did so so effortlessly that to this day I’m surprised when I hear someone say dismiss impacts of their work by saying “that’s not a computer science problem.”

While I was at Zero-Knowledge Systems, Peter was on our advisory board and I have fond memories of many dinners, and less fond memories of him critiquing our system design. Those memories are unhappy not because he was wrong, but because once he made his points, they were so obviously right that it was embarrassing to have missed them.

(and more in the post)

https://shostack.org/blog/remembering-peter-neumann/