@adamshostack@infosec.exchange
2026-09-09 22:52 UTC
Books and Games Received
• The C4 Model: Visualizing Software Architecture (https://www.amazon.com/gp/product/B0GC5YKYFD) by Simon Brown
• The Psychology of Software Teams (https://www.amazon.com/Psychology-Software-Teams-Cat-Hicks/dp/1032963387) by Cat Hicks
• Building Safer Technology: A Field Guide to Failing Well (https://www.amazon.com/Building-Safer-Technology-Field-Failing/dp/0135589320) by Yonatan Zunger, Lea Kissner, Neil Coles, Juan Hernandez, Harmony Mabrey, and Phillip Misner.
• Threat-Driven Software Development: Defending online services from modern threat actors (https://www.amazon.com/Threat-Driven-Software-Development-Defending-services/dp/0135567386) by Michael Howard, Lee Holmes, Sherrod DeGrippo, and Shawn Hernan. (Purchased as ebook).
• The vCISO Playbook: How Virtual CISOs Deliver Enterprise-Grade Cybersecurity to Small and Medium Businesses (SMBs) (https://www.amazon.com/vCISO-Playbook-Enterprise-Grade-Cybersecurity-Businesses/dp/1966415044) by Peter Green and Jan Ross.
• Cards Against Vulnerabilities (https://www.appsecvillage.com/events/dc-2026/cards-against-vulnerabilities-1276050) by Patrick Smyth of Chainguard.
• The second version of Bob Lord’s Secure by Design storycards.
(8/10)
Replies (1)
-
@Lee_Holmes@infosec.exchange 2026-09-11 13:29
@adamshostack@infosec.exchange Hope you like TDSD! One part I think you'll really dig is the concept of the Security Weakness Bug Bar to help target lines of questioning (and ranking of risks) during Threat Modeling.