Press

I am very pleased when people notice my work and talk about it. Part of my life as a pundit is to help cut through security baloney and explain things as clearly as possible to normal people in every day language.

Over the years, my work has been extensively covered in the popular press. I am most proud of two stories. The Wall Street Journal covered my work in a long interview published Monday July 18, 2005. And more recently in February 2007, the University of Virginia College of Arts & Science magazine did a piece on my work.

Wall Street Journal UVA Arts and Sciences Magazine Yin Yang hat logo

Here is a sample of some other recent stories:

11/30/11Software [In]security: Third-Party Software and Security, InformIT.
11/27/11In 2012, a mobile security minefield, CSO Online.
10/31/11Software [In]security: Software Security Training , InformIT.
10/26/11Web application risks exacerbated by social media ties, says ISACA, SearchSecurity.com.
10/07/11Security Upgrades Needed With Growing Cyberwar Threats, PCWorld.
10/04/11Developing IT risk management decision-making criteria an ongoing challenge, SearchSecurity.com.
09/30/11SAFECode and the BSIMM: Two Paths to a Common Goal, SAFECode blog.
09/30/11BSIMM3 Continues To Add Real-World Data to Security Maturity Model , Application Development Trends.
09/29/11New BSIMM3 Guide Provides New Data On Secure Software Development, OnlySoftwareBlog.
09/29/11New BSIMM3 Guide Provides New Data On Secure Software Development, DarkReading.
09/28/11Multi-year study of real-world software security initiatives, Help Net Security.
09/28/11Podcast Gary McGraw on the BSIMM3 Data Release, Threatpost.
09/27/11BSIMM3 launches today, CSO Online.
09/27/11BSIMM3 Released: "An Excellent Tool for Devising a Software Security Strategy" , CyBlog.
09/27/11Software [In]security: BSIMM3, InformIT.
09/27/11BSIMM3 Release Doubles Software Security Measurement Data and Includes Measurements Over Time, Global Security Mag.
09/27/11A Secure Software Development Lifecycle Model Matures, DeviceLine Blog.
09/27/11A Secure Software Model Matures, Forbes.com.
09/27/11Cigital BSIMM 3 study provides software security metrics data, SearchSecurity.com.
09/14/11NKU to host top information security experts in pair of public talks Saturday and Monday , The Lane Report.
09/13/11The Past, Present and Future of Software Security, Threatpost.
09/13/11The Rise of Software Security, Slashdot.
08/03/11New Microsoft BlueHat Prize offers $250,000 for security innovation, SearchSecurity.com.
08/02/11Report on ‘Operation Shady RAT’ identifies widespread cyber-spying, Washington Post.
07/21/11Software [In]security: Software Security Zombies, InformIT.
07/07/11Simple Isn't Simple, Darkreading.com.
06/10/11Secure coding news flash: BSIMM3 coming in August, CSO Online.
06/08/11Banks replace SecurID tokens, FierceCIO.
06/07/11Cigital acquires Consciere, brings in security vets, SearchSecurity.com.
06/07/11RSA Faces Angry Users After Breach, New York Times.
06/02/11While U.S. Plots Cyber Strategy, Experts See Obstacles Ahead, Threatpost.
05/30/11Software [In]security: Computer Security and International Norms, InformIT.
04/21/11Register for May 17 IEEE Computer Society Software Experts Summit, Digital Journal.
04/12/11Software [In]security: vBSIMM (BSIMM for Vendors), InformIT .
04/01/11Marcus Ranum and Gary McGraw talk about software security issues, Security.
03/31/11Microsoft Cites Progress in SDL Report, Advocates More Adoption of ASLR, DEP, Threatpost.
03/30/11Most Windows Applications Use Microsoft's DEP, DarkReading.
03/30/11Microsoft cites software security progress despite sluggish ASLR support, SearchSecurity.com.
03/22/11Software [In]security: Modern Malware, InformIT.
03/15/11How to Mine Customer Data the Right Way, PCWorld.
03/14/11BSIMM's European Tour, Application Development Trends.
03/14/11Industry groups, businesses attempt security awareness training plan, SearchSecurity.com.
03/09/11Keynote Speakers Announced for May 17 Software Experts Summit in Silicon Valley, Digital Journal.
02/16/11Podcast IEEE Security & Privacy Cyberwar Panel at RSA Conference 2011, Computing Now.
02/09/11Hotel Technology Event to Feature Top Speakers and Issues, Hospitality.net - Industry News.
02/08/11New Funding, New Website, New Research, Dasient Blog.
02/08/11Podcast Advanced Persistent Threat: Industrial Strength Hacking, Expert Voices Speaker Series.
02/04/11Real Cyber Warfare: Carr’s Top Five Picks, Forbes.com.
01/25/11Social Networking: Keeping It Clean, The Journal.
01/09/11Security Awareness and Embedded Software, Making Life Easier - Ronald Landheer-Cieslak Blog.
01/01/11Old information security challenges persist, SearchSecurity.com.
12/15/10Security expert suggests demilitarizing cybersecurity, ZDNet.
12/14/10Cracks in cyber security reveal gaping holes in our digital defenses, TechJournal South .
12/02/10Talk of Cyber War: What is It Good for? Absolutely Nothing, Experts Say, The New New Internet (TNNI).
12/02/10Wikileaks: Uncle Sam Was Warned, Threatpost.
12/01/10Demilitarizing cybersecurity (Q&A), CNET.
12/01/10McGraw and Arce on Cyberwar, 1 Raindrop.
11/30/10Podcast Gary McGraw on Cyber War, Cyber FUD and Rhetoric, Threatpost.
11/30/10Expert: BSIMM Can Help Enterprises Build Secure App Development Processes, DarkReading.
11/26/10Sky News, Stuxnet and the End of the World, ComputerWeekly.com.
10/12/10PCI Compliance Means Getting Your App Security Together , DarkReading.
10/05/10Stuxnet: Fact vs. theory, CNET.
10/01/10Defending Against Stuxnet Type Threats, Invincea.
09/28/10All About Stuxnet, Six Lines blog.
09/28/10Podcast How to Develop More Secure Software - Practices from Thirty Organizations, CERT podcast.
09/27/10Stuxnet: An important change in the national security landscape, CTOvision.com.
09/23/10Stuxnet Heralds New Generation of Targeted Attacks , DarkReading.
09/22/10Most Third-Party Software Fails Security Tests, DarkReading.
09/10/10What Adobe could learn from The Flying Wallendas, The Register.
09/01/10It’s time to change... but how?, SDTimes.
09/01/10Hack-Proof Dream?, ABA Journal.
08/23/10Bejtlich on Silver Bullet Podcast, TaoSecurity.
08/18/10HP’s Fortify Buyout Numbers Tell Lucrative Story For Software Security, Forbes.
08/17/10HP's Fortify Acquisition: More Validation of Security in the App Dev Lifecycle, Application Development Trends.
08/17/10Secure software Experts say it’s no longer a pipe, gagsandgiggles.com blog.
08/06/10Real-World Software Security, Dr. Dobb's.
07/07/10With about 12m paying customers, World of Warcraft Gold Blog.
06/20/10Cyber War: Hype or Consequences?, UGN InfoManager.
06/09/10McGraw's Advice to Programmers, Dr. InfoSec™ Blog.
06/07/10Open-Source Could Mean an Open Door for Hackers, Technology by MIT Review.
05/20/10Staff prefer Facebook to pay rises, says report, ComputerWorld UK.
05/17/10Podcast Gary McGraw on software security research, SearchSecurity.com - Security Wire Weekly.
05/13/10Cigital expands software security model, includes data from 30 major firms, SearchSecurity.com.
05/13/10Real-world data on software security initiatives, Help Net Security.
05/13/10Cigital expands software security model, includes data from 30 major firms, Hacking Expose.
05/12/10Podcast Secure coders, take note: BSIMM2 released, CSO Online.
05/12/10Leading Software Security Maturity Model Triples to Include More Real-World Data on Real Software Security Initiatives , EarthTimes.
05/12/10Building Security In Maturity Model gets an Update, ComputerWeekly.com.
05/12/10Podcast Gary McGraw on BSIMM2, Software Security and Cargo Cult Science, Threatpost.
05/12/10Justice League - BSIMM2, My Security Planet Blog.
05/12/10Does your secure software development measure up? See BSIMM, the Sequel, Security and Risk in the Real World - Neil Roiter Blog.
05/12/10Evolving Rapidly, BSIMM2 Offers Key Elements of Successful Software Security Initiatives Shared by 30 Major Corporations, CyBlog: Security, Privacy and Mobility in the Information Age.
05/12/10Gary McGraw on Developing Secure Software (Q&A), CNET.
05/12/10Product Watch: 'Measuring Stick' For Software Security Gets An Update , DarkReading.
05/12/10SAFECode and BSIMM: A Powerful Combination in the Work to Improve Software Security, SAFECode blog.
05/12/10Measuring Software Security: BSIMM2 and Beyond, eSecurity Planet.
05/12/10BSIMM2: Look Left, Look Right, GEEKONOMICS.
05/12/10[WEB SECURITY] BSIMM2, Web Application Security Consortium .
05/12/10Leading Software Security Maturity Model Triples to Include More Real-World Data on Real Software Security Initiatives, FOX Business.
05/12/10New BSIMM report released..., MSDN blog.
05/12/10BSIMM2, Justice League Blog.
05/05/10How Bad Assumptions Are Making Software Less Secure, Forbes.
05/01/10The Debate Over Social Media at the Office, Entrepreneur Magazine.
04/22/10Hackers and Social Networking: A Love Story, TechNewsWorld.
04/09/10Securing the smart grid, cnet.
04/01/10Game developers battle cheaters in a virtual world, Orlando Sentinel.
04/01/10OWASP Top 10 vulnerabilities list adds risk to equation, Information Security Magazine.
03/31/10Survey Says: More Than Half of Software Companies Deploying Secure Coding Methods, DarkReading.
03/27/10Pokerstars RNG Certified, RecentPoker.com.
03/24/10Promoting the CS at trade shows, Inside the Computer Society (IEEE Computer Society).
03/18/10Warren Axelrod on Banking Information Security Exclusive Interview on Trends, Threats and Priorities, BankInfoSecurity.
03/07/10Exploiting Online Games: Cheating Massively Distributed Systems, Blizz Hackers blog.
03/04/10How a process model can help bring security into software development, Government Computer News.
03/02/10RSA 2010: Lifestyle Hacking -- Notes on "Social Networks & Gen Y Meet Security & Privacy", CyBlog.
03/02/10Hot topic at RSA: The pitfalls and promise of social networking, Infosecurity.
02/23/10Sprechen Sie SSL?, News from the Lab.
02/19/10Proposal Would Hold Software Developers Accountable For Security Bugs, InformationWeek.
02/18/10New York State holds software developers accountable, Infosecurity.
02/18/10Infrastructure vs. Application Security Spending, Jeremiah Grossman.
02/18/10Legal Liability For Faulty Code, Mark Hess' Behind The Lines.
02/17/10Morning Security Brief: Cyberdisaster Exercise, Software Security, Pandemic Tools, and More, Security Management.
02/16/10Group Proposes Suits Over Faulty Code, Gov Info Security.
02/16/10SANS Institute, MITRE release new top 25 dangerous coding errors list, SearchSecurity.com.
02/16/10Top 25 Programming Errors: Should Software Developers be Liable?, Bank Info Security.
02/16/10Hold vendors liable for buggy software, group says, Computer World.
02/16/1025 ways to better secure software from cyber attacks, Scientific American Observations.
02/16/10Security agencies release Top 25 programming errors, Washington Technology.
02/16/10Proposal Would Hold Software Developers Accountable For Security Bugs, Dark Reading.
02/16/10Hold Vendors Liable for Buggy Software, Group Says, CIO.
02/12/10Improving software with the Building Security in Maturity Model (BSIMM), SearchSecurity.com.
02/09/10Microsoft, Google split over browser bug bounty, Insecurity Complex (cnet news).
02/08/10Trailer: The New Face of Cybercrime, Internet SecuritT Group.
02/03/10DHS Takes Steps In The Right Direction, Gartner Blog Network.
02/01/10In their words: Experts weigh in on Mac vs. PC security, Insecurity Complex (cnet news).
01/28/10BSIMM: A Descriptive Model of Software Security, good code.
01/27/10David Rice on Silver Bullet Security Podcast with Gary McGraw, Geekonomics.
01/26/10Books you need to buy 3, Rock'n'Roll Programming.
01/21/10Podcast Special Webcast: The Impact of BSI-MM in Software Development Programs, GEEKONOMICS.
01/20/10Podcast The Building Security In Maturity Model, CERIAS Security Seminar Podcast.
01/18/10SANS Application Security Summit 2010, GEEKONOMICS.
01/04/10Podcast Software Security – An interview with Dr. Gary McGraw, Imperva Security Podcasts.
12/31/09Building Security In Maturity Model, RiskPundit.
12/30/09The All-Decade Interview Team, threatpost.
12/30/09Fun Reading on Security and Compliance #22, Anton Chuvakin Blog - "Security Warrior".
12/28/09Web Application Security Podcasts, Secweb.nerd.it blog.
12/23/09Exploiting Online Games: Cheating Massively Distributed Systems, Security Reading Room Blog.
12/15/09SANS Institute to Host First Annual Application Security Focused Event and Summit, JAVA Developer's Journal.
12/13/09Coding gems 11-20, Confessions of a Chief Home Officer.
12/05/09Lifestyle Hacking, WSVG Tech Blog.
12/01/09Silver Bullet Talks with Fred Schneider, IEEE SECURITY & PRIVACY.
11/23/09looking out for lifestyle hackers in the workplace, terminal 23.
11/18/09Bring Your Computer to Work Day?, 1 Raindrop.
11/13/09Best practices in information security, Continuity Central.
11/13/09Interested in application (code) security?, Bloor.
11/12/09Fortify Software: New Study Provides Real-World Data on Leading Software Security Initiatives in Europe, TradingMarkets.com.
11/12/09Differences between EU and US attitudes to application security detailed in new report, SC Magazine.
11/12/09Cigital, Fortify tailor security model for Europe, SD Times.
11/12/09New Study Provides Real-World Data on Leading Software Security Initiatives in Europe; First-ever European Maturity Model Details Success of SWIFT, Nokia and others, TMCnet.com.
11/11/09Real-world data on software security initiatives, Help Net Security.
11/11/09BSIMM Europe, Minded Security Blog.
11/11/09BSIMM Europe, Off by On.
11/10/09Hot-or-Not sessie over software security, Beveiliging Nieuws.
11/10/09From Biometrics to BSIMM , & "50 Hurricanes Hitting At Once!" -- A Report on the Sixth Annual Partners Conference, CyBlog: Security, Privacy and Mobility in the Information Age.
11/06/09Podcast Gary McGraw on Software Security, the BSIMM Model and Critical Thinking, Digital Underground podcast.
11/06/09Gary McGraw on Software Security, the BSIMM Model and Critical Thinking, Gary McGraw on Software Security, the BSIMM Model and Critical Thinking.
11/05/09Journal: Out of Touch with Reality I, Public Intelligence Blog.
11/04/09Lifestyle Hackers: o desafio da Net Generation, Miguel Almeida.
11/03/09Lifestyle Hackers, Hack in the Box.
11/03/09The new insider threat - lifestyle hackers, RiskPundit.
11/03/09Lifestyle Hackers, Hayes on Security.
11/02/09Hacking Is A Way Of Life, Dark Reading.
11/02/09Lifestyle Hackers, LinuxSecurity.com.
11/09Fortify: New Study Provides Real-World Data on Leading Software Security Initiatives in Europe, Global Security Mag.
10/27/09Leer denken als een hacker en programmeren als een security expert, engineersonline.nl.
10/24/09Hoff on Silver Bullet Podcast, SecuObs.com.
10/24/09Hoff on Silver Bullet Podcast, 1 Raindrop.
10/24/09Cigital’s Gary McGraw talks cloud security with Chris Hoff, IT Knowledge Exchange.
10/22/09Web application firewall use goes beyond compliance, company finds, SearchSecurity.com.
10/22/09Sicurezza Open, Il sole 24 ore.
10/20/09New Lecture Series Centers on Security Issues, UA News.
10/12/09Exploiting Online Games, TEEYAI's Blog.
10/09/09Reality Check, 1 Raindrop.
10/08/09Cigital, SANS Institute Roll Out Software Security Self-Measurement With BSIMM, DarkReading.
09/25/09Benchmarking Security – Are We Safe Yet?, John Pescatore (Gartner Blog Network).
09/17/09Is SQL Password Vulnerability A Real Threat?, Redmond Developer News.
09/16/09Silver Bullet Security Podcast: Fred Schneider, Computing Now (IEEE Computer Society Newsletter).
09/15/09Information Security Summit 2009 - Overview, Gartner.
08/18/09SQL Injection continues to trouble firms, lead to breaches, SearchSecurity.com.
07/27/09Book Review: Exploiting Online Games, 404 Tech Support.
07/21/09Silver Bullet Podcast Interviews Bob Blakley, Burton Group Blogs: Security and Privacy.
07/08/09Suspicion Centers on N. Korea in DoS Blitz but No Smoking Gun, TechNewsWorld.
07/01/09Gov't official: We're serious about cybersecurity this time, ITworld.
06/25/09The Value of Static Analysis Tools, Building Real Software.
06/22/09From computer determinism to real world indeterminism, Thinking Inside a Bigger Box.
06/20/09Q&A: Twitter And Clouds, Dr. Dobb's.
06/19/09Developing Secure Applications, Data Manager Online.
06/10/09How Microsoft Influenced Adobe Security In a Good Way, ComputerWorld.
06/05/09Summer Reading for Security Pros: Schneier or Sagan?, CSO Online.
06/03/09PayPal Software Security Podcast, cgisecurity.com.
06/02/09Xbox: Integrating Social Networks, ESET Threat Blog.
05/10/09CyLab Business Risks Forum: Gary McGraw on Online Games, Electronic Voting and Software Security, CyBlog.
04/27/09Gary McGraw Interviews Virgil Gligor on Software Security and Other Vital Issues, CyLab news.
04/24/09Hacking in online games a widespread problem, FierceCIO TechWatch (also: cnet).
04/23/09Top Cybersecurity Official Spurs White House to Take Lead, TechNewsWorld.
04/23/09Hacking online games a widespread problem, cnet news.
04/22/09RSA: The fundamental challenge of security versus privacy, SC Magazine.
04/22/09Denim Group Mention in InformIT Article on Software Security Industry Trends, Denim Group.
04/22/09Experts call for better measurement of security, threatpost: digital underground.
04/20/09Secure software? Experts say it's no longer a pipedream, cnet security news.
04/19/09Podcast Brian Chess and Gary McGraw AND-401: Building Security In Maturity Model (BSIMM), RSA Conference 365.
04/17/09Podcast Gary McGraw FEA-105: Surveillance: Security, Privacy and Risk and HT2-303: Exploiting Online Games, RSA Conference 365.
04/16/09RSA 2009, SecurityCurve.
04/14/09RSA panel to discuss surveillance, privacy concerns, SearchSecurity.com.
04/08/09Building Security In Maturity Model (BSIMM), (ISC)2 Blog.
04/07/09Software [In]security: Nine Things Everybody Does: Software Security Activities from the BSIMM, threatpost Punditry.
04/07/09IEEE Security & Privacy Magazine Sponsors Surveillance Panel at RSA, PR Newswire (press release).
04/06/09Building Security In, Maturely, Emergent Chaos.
04/03/09Brad’s Reality Check Interview, ASSET (Adobe blog).
04/01/09Een maturiteitsmodel voor software security, IT Professional.
03/31/09Conficker Fears Create Fertile Ground for Other Scammers, TechNewsWorld.
03/31/09Podcast An Experience-Based Maturity Model for Software Security, CERT Podcast.
03/27/09BSIMM lays out security blueprint, SDTimes.
03/27/09The He Got Game Rule, 1 Raindrop.
03/25/09It B-SIMM-ply Marvelous!, Enterprise Security Blog.
03/23/09SDWest, SDBestPractices, SDArch&Design: RIP, 1975 - 2009, The Blog Ride.
03/17/09First Data-Based Security Maturity Model Released, Visual Studio Magazine (also: Redmondmag.com).
03/17/09Podcast How to Write Apps Without the Security Sinkholes, CSO Online's Security Insights (podcast).
03/17/09First Data-Based Security Maturity Model Released, Application Development Trends.
03/13/09Microsoft on ‘Building Security In Maturity Model’, Ruminations on Architecture and Security.
03/13/09Fortify & Cigital Release BSIMM -- Integrating Best Practices from Nine Software Security Initiatives, CyBlog.
03/12/09Software Security Model – BSI-MM released, Mike Andrews.
03/12/09Building Security In Maturity Model, The Security Development Lifecycle (MSDN).
03/12/09New report offers low-down on secure develoment, Network World.
03/11/09New report offers low-down on secure develoment, Techworld.com.
03/11/09Application Security is Journey, Not a Destination, Security Incite.
03/10/09Obama's New Tech Czar, BusinessWeek.
03/10/09Maturity model offers software security yardstick, Computer Business Review (also: Computer World UK).
03/10/09Modelo de Maturidade para Segurança de Software (translate), marcelosouza.com.
03/10/09A New Hope for Software Security?, Network World (also: CSO Online).
03/09/09Political Turf Wars Drive Out US Cybersecurity Chief, TechNewsWorld.
03/09/09Building Security In Maturity Model Partly Applies to Detection and Response, TaoSecurity.
03/06/09BSI-MM est arrivé!, 1Raindrop.
03/06/09CAG, BSIMM and field-assessed security, Security Balance.
03/06/09Fortify, Cigital Release Software Security Program Benchmarks, Dark Reading.
03/06/09Risks Digest 25.60, RISKS.
03/05/09Benchmarks for developing and growing an enterprise-wide software security program, Help Net Security.
03/05/09Build Security In Maturity Model Released, Web Security Testing Cookbook blog.
03/05/09Building Security In Maturity Model, Sylvan von Stuppe.
03/05/09BSIMM: Maturing the process of Building Security In., SilverStr's Blog.
03/05/09BSIMM lives, SC-L.
03/04/09The Building Security In Maturity Model (BSIMM), Dr. InfoSec.
03/04/09New Effort Hopes to Improve Software Security, The Wall Street Journal Blog: Digits.
02/16/09锁好数据防盗门 走出安全误区, (translate) cnet China.
02/16/09Podcast Why top lists don’t work, SearchSecurity.com podcast.
02/11/09Enterprise Architecture: What is a worst practice in your organization?, Enterprise Architecture: From Incite comes Insight....
02/09/09SQL injection attacks targeting Flash, JavaScript errors, SearchSecurity.com.
02/03/09Silver Bullet Security Podcast, 1 Raindrop.
02/03/09Book Review: Exploiting Software - How to Break Code, 404 Tech Support.
01/20/09Source Code Analysis Tools: How to Choose and Use Them, CSO Online (also: ComputerWorld).
01/20/09Spécial sécurité : politique et malware, mélange sulfureux, LeMagIT (English translation).
01/19/09Fuzzing Is Still Widely Unknown, ITworld.
01/19/09Podcast Are vulnerability lists helpful?, SearchSecurity.com Security Squad podcast.
01/15/09Gary McGraw's Reality Check Security Podcast, The Security Development Lifecycle.
01/15/09Should states lead the charge for secure application development?, SearchSecurity.com.
01/15/09Podcast OWASP Podcast Series #5.
01/12/09Reality Check, Off by On.
01/12/09Protection Poker, Emergent Chaos.
01/08/09Gary McGraw and Steve Lipner, Emergent Chaos.
01/07/09Fuzzing Is A Surprise To Some, But Not To Us - Right?, Fuzzing.
11/28/08TOP PC, Internet, Information Security & Identity Management Blogs!, CEOWORLD Magazine.
11/21/08Cheating, security, & theft in virtual worlds and online games, GranneBlog.
11/18/08The Economics of Finding and Fixing Vulnerabilities in Distributed Systems, 1 Raindrop.
11/13/08Book meme, Bleadof's world of tinkering.
11/04/08Lecture 07 , UCB CS 294-22 Web Security.
10/20/08Browsers getting harder and harder to secure, SearchSecurity.
10/17/08The Untapped Open Source Online Gaming Opportunity, TechNewsWorld.
10/16/08What Videogames Teach Us About Security, Forbes.com (also: CBC News, Gamefan blog, Game Hype, cgisecurity.com, Rupeesmatter.com, Sify)
10/15/08Browser security a concern for website development, SearchSoftwareQuality.com.
09/22/08New “Likes and Dislikes”- Based RavenWhite Password Protection Technique Helps Consumers and Businesses Thwart Email Hackers, Business Wire.
09/18/08Top 10 Tricks to exploit SQL Server Systems, ultimate windows and pc tips tricks tweaks and hacks.
09/16/08The Chosen, System Advancements at the Monastery.
09/16/08Twenty cans of worms on the wall … (The Greek Hackers vs CERN Saga), Cyberpunk as a commodity.
09/05/08Don't ignore internal security (and don’t write passwords on Post-it's), CIO Symmetry.
09/05/08Think like a hacker (and other World of Warcraft-inspired musings), TotalCIO.
09/03/08Multiplayer online games pose threat, FierceCIO.
09/08New Exploits at Black Hat (sidebar: "Microsoft Lays out Security MAPP"), Redmond Developer News.
08/29/08Cybercrime Gets Its Game On, Forbes.
08/25/08Software Security Market, 1 Raindrop.
08/20/08Podcast Gary McGraw and Julia Allen: How to Start a Secure Software Development Program, CERT Podcast Series.
08/19/08Security outbreaks an insight 2008, Ammasajan's Weblog.
08/18/08IT School to Watch: Indiana University, ComputerWorld.
08/12/08Software security is all grown up (or at least walking on its own), Security Bytes.
08/12/08Space Race, The Secure Software Zone.
08/12/08Best of the Web (August 2008), Dark Reading.
08/11/08Denim Group Mention from Gary McGraw, Denim Group blog.
08/08/08Daniel Suarez - Daemon: Bot-Mediated Reality, The Long Now Foundation.
08/02/08锁好数据防盗门 走出安全误区 (translation), IT168.com.
08/01/08Zero tolerance for bugs, SD Times.
07/31/08Podcast The state of software security, SearchSecurity.com.
07/25/08Getting Started - put Security into your SDLC, ePrivacyAwareness.
07/16/08Forrester Research Security Forum 2008, September 4-5, 2008 in Boston (press release), TradingMarkets.com.
07/07/08Microsoft Talks Up SDL, Application Development Trends.
07/08In Plain Text: Exploiting Online Games, Security Management.
06/30/08Exploting Online Games, Rev Dan Catt (reader review).
06/27/08Review: Exploiting Online Games Computing Reviews (subscription required).
06/24/08Yikes! Vista Security to be Obliterated!, David LeBlanc's Web Log.
06/17/08Podcast Rise of managed security services, Security Squad podcast (13 min. in).
06/11/08Financial Services Lead Spend in $650m Software Security Industry, A-TeamGroup.
06/10/08Podcast Network Security Podcast, Episode 107.
06/06/08Gary McGraw on secure software development, SearchSecurity.com.
06/06/08Gary McGraw on secure software development, SearchSecurity.com.
06/04/08Protecting the Critical Infrastructure: Beware of Crimeware, BlogInfoSec.com.
05/29/08Cigital's Gary McGraw's Monthly Security Column Moves To InformIT, redOrbit.
05/07/08Newspapers - Yesterday's News for Yesterday's People, 1 Raindrop.
05/08In Search of Trust, Redmond Developer News.
04/29/08What tech book are you reading right now?, Blogus Maximus.
04/24/08Payment Card Industry standard under attack?, SD Times.
04/07/08Addison-Wesley Professional Showcases The New School of Information Security at RSA 2008, press release.
03/18/08The oldest debate: Cheating, Level 1 Wizard.
03/17/08Seven categories of software security flaws, ComputerWeekly.com.
03/17/08Making software secure from first principles, ComputerWeekly.com.
03/12/08Criminals step into virtual world, The Gazette (Canada).
02/19/08HiR Reading Room: Hakin9 Magazine, HiR Information Report.
02/18/08Top 10 Podcast Episodes, Eon Security Blog.
02/11/0815th Annual Network and Distributed System Security Symposium, Supported by the Internet Society, Brings Together Internet Security Experts From Around the Globe, Centre Daily Times.
02/07/08Exploiting Online Games, HiR Information Report.
02/06/08Haxx0ring 4tw, The Joshua Tree.
02/08Improving Software Quality, Software Quality Assurance Engineering.
01/31/08The Daily Incite - January 31, 2008, Security Incite.
01/28/08Do you see seven misunderstanding Zhendong network security (translated), CSDN.
01/20/08Online Game Security, UW Computer Security Course Blog.
01/18/08Information security makes the silver screen, Security Bites.
01/16/08 The State of Security in MMORPGs, Slashdot.
01/16/08MMORPG Security, WarCry Network.
01/15/08The Daily Incite, Security Incite.
01/12/08Top 10 Tricks to exploit SQL Server Systems, Hacking Truths.
01/10/08Hacking & the Academy Awards, DarkReading.
01/10/08Software Security News, System Advancements at the Monastery.
01/09/08Film highlights impact of cybercrime, Engineer Live.
01/08/08Freedom to Tinker's 2008 Predictions, Securology blog.
01/07/08The Daily Incite, Security Incite.
01/07/08Trailer: The New Face of Cybercrime
01/02/08Top IT Conversations Shows for December 2007, Phil Windley's Technometria.
01/01/08Security researchers warn of dangers in online games, Massively.
01/08Best Practices to Secure Your Code, Microsoft Certified Professional Magazine (also: Redmond Developer News).

I welcome press contact and continue to interact with the press on a regular basis.