Adam Shostack :donor: :rebelverified:
adamshostack.infosec.exchange.ap.brid.gy
Adam Shostack :donor: :rebelverified:
@adamshostack.infosec.exchange.ap.brid.gy
Author, game designer, technologist, teacher.

Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board.

Books […]

[bridged from https://infosec.exchange/@adamshostack on the fediverse by https://fed.brid.gy/ ]
Reposted by Adam Shostack :donor: :rebelverified:
Get that flu shot, folks—it looks like the 2025–26 flu season is going to be a humdinger.
The US may be headed for a rough flu season, with a virus that causes more severe symptoms than the one last year and seems to be spreading more rapidly and earlier than usual.

www.nytimes.com/2025/11/19/h...
Early Signs Point to a Harsh Flu Season in the U.S.
www.nytimes.com
November 20, 2025 at 2:34 AM
Just discovered that in app web browsing gets its own #location service on #iphone! Hugely shocking #privacy fail
November 19, 2025 at 4:19 PM
Reposted by Adam Shostack :donor: :rebelverified:
Scoop: CISA plans to embark on a hiring spree and change some workforce policies in an effort to rebuild its depleted ranks ahead of a possible conflict with China, according to a memo from its acting director that I obtained.

www.cybersecuritydive.com/news/cisa-hi...
CISA, eyeing China, plans hiring spree to rebuild its depleted ranks
The agency will also change some of its workforce policies to avoid driving away talented staff.
www.cybersecuritydive.com
November 17, 2025 at 9:30 PM
I’m not sure if this says more about the ansi standard or the kindle conversion
November 16, 2025 at 11:28 PM
Maybe it’s my imagination but scams seem to be way up since Facebook leaked that as long as they’re only 95% certain it’s a scam, they’ll run it. https://bsky.app/profile/k8em0.bsky.social/post/3m5pukt35s22l https://bsky.app/profile/victoriastrauss.com/post/3m5rdbv424k26
November 16, 2025 at 8:16 PM
Going after the drug mules has worked well, I’m glad to see we’re replicating the strategy. It’ll thought leadership a newly disruptive influencer model https://infosec.exchange/@BleepingComputer/115549872630802616
BleepingComputer (@BleepingComputer@infosec.exchange)
The U.S. Department of Justice announced that five individuals pleaded guilty to aiding North Korea's illicit revenue generation schemes, including remote IT worker fraud and cryptocurrency theft. https://www.bleepingcomputer.com/news/security/five-plead-guilty-to-helping-north-koreans-infiltrate-us-firms/
infosec.exchange
November 15, 2025 at 2:06 AM
I think when companies start spamming me by creating new email lists and signing me up, I'm going to linkedin stalk their staff and email them about my business.
November 14, 2025 at 9:39 PM
Reposted by Adam Shostack :donor: :rebelverified:
Best quote I've seen all day so far, from an Ars piece by @dangoodin on skepticism around OpenAI's breathless claim that a Chinese hacking group used Claude code to automate 90 percent of their attack:

“I continue to refuse to believe that attackers are somehow able to get these models to jump […]
Original post on infosec.exchange
infosec.exchange
November 14, 2025 at 1:59 PM
We have always been at war with Venezuela.
November 13, 2025 at 2:34 AM
New blog Secure By Design roundup - October 2025

Phil Venables, CSO for Goldman Sachs and then Google cloud has kicked off a series, Security Leadership Master Class. Even if you’re not a CISO, understanding the leadership principles he lays out is helpful to you.

(1/5)
November 12, 2025 at 3:21 PM
RE: https://hachyderm.io/@skinnylatte/115524200484374556

While this is fun, the temperature engineering subcommittee of the HOA has asked me to explain that a huuuuge amount of heat energy is visibly just bouncing off and people should not be trusted with a 3300 degree heat source.
November 10, 2025 at 5:36 PM
In these trying times, I'm glad to see this notebook still works for both men and women!

https://www.amazon.com/Journal-Hardcover-Notebook-Journals-Notebooks/dp/B0FDKZVFM8/
Amazon.com
www.amazon.com
November 10, 2025 at 4:22 PM
Doctor conferences get different door junk!
November 8, 2025 at 11:27 PM
RE: https://infosec.exchange/@SheHacksPurple/115516213748812207

I'm really glad this is no longer a conversation between me and Tanya!
infosec.exchange
November 8, 2025 at 10:57 PM
Publish your threat models? It's sparking debate. Join our discussion with OSTIF to talk about the benefits, dangers, and "why" of publication.

🗓️ Nov 12, 2pm CST 🔗 https://luma.com/zwsqlhs2
Threat Modeling w/ Adam Shostack · Zoom · Luma
Description Publish your threat models! This talk will cover the idea of publishing threat models, the dangers associated with the idea, and why open source…
luma.com
November 7, 2025 at 6:31 PM
@mattblaze if you haven't seen, some interesting numbers from a local paper

https://www.thestranger.com/news/2025/11/06/80313522/your-ballot-might-not-have-counted
Your Ballot Might Not Have Counted
As of blog time, King County Elections has challenged 4,119 ballots countywide because of signature-related issues including not signing the ballot at all or the signature not matching the one King County Elections has on file. In Seattle, 1,794 ballots aren’t being counted yet for similar issues. That’s only a little more than half a percent of the total ballots received—small, maybe, yet enough to make a difference in a tight race. by Nathalie Graham Last year, I was minding my own business, smug and confident because I’d bucked demographic trends and voted weeks before the election. Then, I got a text. King County Elections. An issue? With my ballot? It hadn’t been counted. I’d forgotten to sign the outside of my ballot. Fuck! The good news is I wasn’t the first illiterate dumbass to bypass simple instructions. And I am far from the last. This happens all the time (and have you _seen_ those reading scores?), including this cycle. As of blog time, King County Elections has challenged 4,119 ballots countywide because of signature-related issues including not signing the ballot at all or the signature not matching the one King County Elections has on file. In Seattle, 1,794 ballots aren’t being counted yet for similar issues. That’s only a little more than half a percent of the total ballots received—small, maybe, yet enough to make a difference in a tight race. Voters across all demographics are fucking up their signatures, but particularly the young people. Voters under the age of 35 account for 42 percent of the current challenged ballots. Surprisingly, the 25 to 34-year-olds are fucking this up more than the 18 to 24-year-olds with 428 challenged ballots. Though, not by much. The youths have 330 challenged ballots. Don’t get all high and mighty, elder millennials, the 34 to 44-year-olds also have 341 challenged ballots. You’re not “adulting.” You’re a mess. Just look at the state of you SCREENSHOT FROM KING COUNTY ELECTIONS All of your votes matter, of course, but they may really end up mattering in the race for Seattle mayor depending on how things shape up with ballot drops on today and tomorrow. Thankfully, this is an easy fix. First, figure out if your ballot was counted. If you wrote your phone number or email on the front of your ballot, King County Elections will drop you a line to let you know if there’s a ballot problem. You’ll also be notified of any problems if you signed up for ballot tracking. Fun fact: King County voters who tracked their ballots had a 63 percent voter turnout compared to 45 percent of county turnout in this election! But, if you haven’t signed up to track your ballot—which you can still do even after voting— _and_ you didn’t put any contact information on your ballot, King County Elections will mail you a notice letting you know there’s an issue. You can also check to make sure your ballot is counted by peeping at your voter portal. King County Elections will send a link to cure your ballot online. For me, that looked like signing my signature multiple times on an online form. If you do it by mail, you’ll do the same thing on a paper form and send it back to King County Elections to review. “We do see more voters use that online option,” Halei Watkins, communications director at King County Elections says. “It's very quick and easy. You get it done in like two minutes, and then you know it's taken care of, rather than filling out your form, waiting for us to receive it, and all of that.” Whatever method you choose to fix your ballot, you have until 4:30 p.m. on Nov. 24 to do so. And, for snail mail, that means your ballot-curing forms must be at King County Elections by then, not postmarked by then. According to Watkins, around 50 to 60 percent of challenged ballot voters respond and rectify their issues and their vote counts. The rest remain lonely, uncounted. Sad! Don’t be one of the uncounted few. Fix your shit.
www.thestranger.com
November 7, 2025 at 12:56 PM
twenty twenty twenty four hours to go....stop managing risk!

https://shostack.org/blog/stop-trying-to-manage-risk/
November 6, 2025 at 1:05 PM
Stop Trying To Manage Risk! That’s the title of my keynote for OWASP Global Appsec in Washington DC on Friday. And if you’re saying “WTF,” well, good. That’s the goal: to make you stop and think.

People hope risk management will solve all their cyber […]

[Original post on infosec.exchange]
November 6, 2025 at 2:58 AM
Reposted by Adam Shostack :donor: :rebelverified:
If you've been following the Castlevax mucosal #COVID #COVID19 vaccine development, you know that it has been looking like they lost US NextGen funding for their phase 2 trial in (one of the) the Trump cuts to biomedical research.

But today Castlevax announced that they are going ahead with a […]
Original post on infosec.exchange
infosec.exchange
November 5, 2025 at 2:12 AM
I have been reliably informed that as many in one in fifty or so of the ASPH attendees are masking. I regret the error https://infosec.exchange/@adamshostack/115483591518057581
Adam Shostack :donor: :rebelverified: (@adamshostack@infosec.exchange)
The other conference at this hotel is .. checks notes.. the American Society of Public Health.. and I’m the only one in a mask.
infosec.exchange
November 4, 2025 at 12:56 AM
The other conference at this hotel is .. checks notes.. the American Society of Public Health.. and I’m the only one in a mask.
November 3, 2025 at 3:16 AM
Reposted by Adam Shostack :donor: :rebelverified:
And it here is! Thanks to a South Korean website, the worst kept secret can finally be seen.

The #lego Star Trek Enterprise NCC-1701-D, set 10356.

The model is 60cm long and consists of around 3600 bricks. If you buy it on release or a few days after, the […]

[Original post on mastodon.me.uk]
November 2, 2025 at 10:37 PM
Risk isn’t a hammer—and most problems aren’t nails.

I show why quantifying risk won’t fix cyber’s hardest decisions at USENIX '25.

🔨 https://tinyurl.com/4dj5mj3w
USENIX Security '25 (Enigma Track) - Risk Is Not a Hammer, and Most Hazards Aren't Nails
Risk Is Not a Hammer, and Most Hazards Aren't NailsAdam Shostack, Shostack + Associates"Risk management" has been given a privileged position in security, th...
www.youtube.com
October 31, 2025 at 5:04 PM
I don't know who needs to hear this, but if you do, "6/7" means "you're trying to hard."
October 31, 2025 at 12:44 AM