Sign in

Tanya Janca | SheHacksPurple

@shehackspurple.bsky.social
6K followers 213 following 3.5K posts

Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her shehackspurple.ca 🌻

PostsRepliesMedia
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 6h
I think we're all coming back to this question: **Does your application care WHO is attacking it?** Imagine someTHING is: → trying credentials → probing your APIs → accessing things it shouldn't → exploiting a vulnerability → changing its approach when something doesn't work 1/4
A woman with long brown hair speaks into a fuzzy microphone in front of a white bookshelf filled with books and awards. Large on-screen text reads, What If Someone Else's AI Agent Attacks You?
151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 18h
One of my biggest rules for AI agent security: **Don't make the AI responsible for enforcing the security boundary that contains the AI.** If your security control is: "Dear AI, please don't do this dangerous thing." ...that's a prompt. A suggestion really. It is not a security boundary. 1/4
A smiling woman with long dark red hair sits in front of white bookshelves, with a microphone visible at the bottom and books and awards behind her. A purple text box at the upper left reads, “Your agent escaped. Would you know?”
261
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026
What does software provenance actually tell you? It can tell you things like: → Where an artifact was built → How it was built → What source and build process produced it What it does NOT tell you: **"This code is safe."** That's a really important distinction. 1/3
A woman with long dark red hair sits in front of white shelves filled with books and security-related decor, speaking into a microphone. On-screen text reads, “This Malicious npm Package Had Valid Provenance. How?!?!” and a subtitle at the bottom says, “necessarily.”
151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026
Someone ordered 100 signed copies of Alice and Bob Learn Secure Coding, and it's taken longer to sign them than planned. I can only imagine what younger Tanya would think of how amazing my life has turned out. Thank you to every single person who has bought one of my books. 💜 #gratitude
Smiling woman with dark hair sits on a couch and points to stacks of yellow books beside her. The book cover reads Alice & Bob learn SECURE CODING, by Tanya Janca, with WILEY at the bottom.
040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026
This was how I spent a lot of my weekend, digging up my dahlias and getting them ready for winter. This is the mess I make! 😂 #infosecgardening
A cluttered workbench in a garage holds several uprooted plant divisions with tangled roots, soil, and white plant labels, including one sprouting green stems. Around the table are buckets, a fan, a ladder, gloves, cardboard, and a black potting mix bag labeled Sunshine.
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 28/09/2026
Step one of threat modeling: define the feature. Not “vibes.” Not “the login-ish thing.” Not “you know, that new endpoint.” Name it, understand it, then figure out how it could be misused. Watch or listen on any podcast platform: twp.ai/9OaEdn #episode11
020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 28/09/2026
Bunny!
040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 27/09/2026
This weekend I am digging up almost all of my dahlias to get them ready for the winter. Powdery mildew has already started! How can it be fall already? 😥 #infosecgardening Did you get outside this weekend? What did you do?
040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 26/09/2026
1171
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
Building a world class security harness - leveraging AI to accelerate your organization's security posture - Michael Argast #bsidesvi2026
160
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
The difference between vulnerable and malicious packages, with Megg Sage at #bsidesvi2026
060
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
Megg Sage at #bsidesvi2026 🥳
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
3 paths to compromise The Edge @ bsides Vancouver Island 🥳 #bsides The Control Plane Awakens: How Attackers Are Taking Over Network Edge Infrastructure - Ryan Smith
010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
The Control Plane Awakens: How Attackers Are Taking Over Network Edge Infrastructure - Ryan Smith at #bsidesvancouverisland 🥳
040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
From OnlyFans to Online Casinos: Threat Hunting in Google's DMCA Data - Greg Pollock is kicking off #Bsides Vancouver Island! 🥳 #bsidesVancouverIsland
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
Here's a question for everyone building AI agents: **If your agent escaped its intended security boundary, what would tell you?** Not: "Would we eventually notice something weird?" I mean literally: What log? What alert? What monitoring system? Who gets notified? 1/3
A smiling woman with long dark red hair sits in front of white bookshelves, with a microphone visible at the bottom and books and awards behind her. A purple text box at the upper left reads, “Your agent escaped. Would you know?”
151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
Developers threat model all the time. You already think about what could break, what weird stuff users might do, and what edge cases could cause chaos. Now we are just adding security to that very useful little habit. Watch or listen on any podcast platform: twp.ai/9Oa3uP #episode11
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026
What is application security? And what does AppSec actually mean in 2026? At its core, application security (AppSec) is about making software more secure throughout its entire lifecycle. From the first idea and design decisions, through development and testing, all the way into production. 1/3
A woman with long brown hair speaks in front of bookshelves, with a purple title box reading “What is Application Security?” Video player controls and a 0:00 / 2:48 time display appear along the bottom.
110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026
If you could mentor a beginner, what would you teach them first? #AppSecThursday #talkAppSectome
200
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026
See you there this Friday?
031
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026
Here's a question I think we need to start asking when we give AI agents access to developer infrastructure: **What can it actually DO once it gets there?** 1/4
252
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 23/09/2026
A malicious npm package was published with **completely valid provenance**. Wait... WHAT?! 😬 That's what happened in the GHAPPIER software supply chain attack. And here's the fascinating part: **The provenance wasn't fake.** The security control WORKED. 1/3
A woman with long red hair smiles in front of a white bookshelf with security books and awards; on-screen text says, “This Malicious npm Package Had Valid Provenance. How?!?!” and a subtitle at the bottom says, “necessarily.”
131
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 23/09/2026
Threat modeling sounds fancy until you realize it mostly means asking: “How could this thing go sideways?” No crystal ball. No dramatic chanting. Just practical thinking before the security gremlins move in. Watch or listen on any podcast platform: twp.ai/9Oa9DW #episode11
130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 23/09/2026
#infosecgardening
A smiling woman wearing large dark sunglasses and a purple top holds a bouquet of pastel flowers, including yellow, pink, and peach dahlias, outdoors in bright sunlight.
061
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026
While teaching secure coding this week we prompted Claude (with my tier 1 security prompt available for free from securemyvibe.ca) to build a daily greeting app that would compliment me and give me a nice quote every morning. Well.... 1/3
screenshot of my unauthorized vibe coded app:
Purple folder icon at the top left of a white card with faint pink corners; text reads “Hello queen 👑,” “Your kindness is not small. It reaches further than you know.” “If they don't give you a seat at the table, bring a folding chair.” — Shirley Chisholm, “(Offline quote: couldn't reach the internet today.)” and a bottom button that says “Thanks, gorgeous.”
380
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026
@lowleveltv.bsky.social 🌊👋🌊
010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026
AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9Oa3jT 1/4
242
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026
Here's an API security question I wish every developer would ask: **Just because I'm logged in, does that mean I'm allowed to do THIS?** Authentication tells us who someone is. Authorization tells us what they're allowed to do. Those are not the same thing. If my frontend requests: 1/3
190
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026
My trip to the Maritimes (lovely Frederickton) is going extremely well. I've had soon much fun! I'm November I'm returning, this time to Halifax Nova Scotia, which is ALWAYS a party!
A woman smiles while sipping a dark beer, and the collage also shows a restaurant table with a wooden beer flight, a card reading “GAHAN HOUSE” and “BEER FLIGHTS,” oysters on ice with hot sauce and a lemon wedge, and a bowl of creamy seafood soup with mussels and another beer flight.
1110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 21/09/2026
One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI. **It's not enough to implement part of a security control. You need to verify the security property you're depending on.** 1/4
A smiling woman with long brown hair points toward the camera while seated in front of white shelves filled with books and security-themed items, with a fuzzy microphone in the foreground. On-screen text reads “AI Coding Plugins Are Part of Your Software Supply Chain” and “Plugin4Shell.”
140
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 21/09/2026
Step one of threat modeling: define the feature. Not “vibes.” Not “the login-ish thing.” Not “you know, that new endpoint.” Name it, understand it, then figure out how it could be misused. Watch or listen on any podcast platform: twp.ai/9OXukZ #episode11
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 20/09/2026
Fredericton, NB, guess who's visiting you this week???? #morecanada
Smiling woman with dark hair and black glasses takes a selfie in front of a large historic stone building with a central tower, lit windows, and a flagpole. A walkway, flower beds, and a lamppost are visible in the foreground at dusk.
260
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026
Does it *actually* matter if the thing attacking your application is an AI agent? I don't think so. Human attacker? Script? Bot? AI agent? Your application still needs to withstand hostile behaviour. Correct authentication and authorization. Least privilege. Input validation. Rate limits. 1/3
A woman with long brown hair speaks into a fuzzy microphone in front of a white bookshelf filled with books and awards. Large on-screen text reads, What If Someone Else's AI Agent Attacks You?
170
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026
Have you heard of #InfoSecGardening? 🌱🌻 It’s for ANYONE in cybersecurity (or IT!) to share photos of what you’re growing -> flowers, veggies, herbs, houseplants, gardens… whatever brings you joy. Think of it as a #TimeCleanse: a chance to step away and naturally calm your brain. 1/2
Webpage text explains #infosecgardening as a social media hashtag and digital “timeline cleanse” created by Tanya Janca (SheHacksPurple), combining information security with gardening. It includes sections titled “What is it?” and “Why it matters,” plus a YouTube preview labeled “#infosecgardening transplanting asparagus.”
130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026
AI coding plugins are becoming a new part of our software supply chain. And this week we got a pretty spectacular demonstration of why that matters. 😬 Security researchers disclosed #Plugin4Shell, a vulnerability affecting several major AI coding agents. 1/5
A smiling woman with long brown hair points toward the camera while seated in front of white shelves filled with books and security-themed items, with a fuzzy microphone in the foreground. On-screen text reads “AI Coding Plugins Are Part of Your Software Supply Chain” and “Plugin4Shell.”
132
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 18/09/2026
Developers threat model all the time. You already think about what could break, what weird stuff users might do, and what edge cases could cause chaos. Now we are just adding security to that very useful little habit. Watch or listen on any podcast platform: twp.ai/9OXukY #episode11
031
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 18/09/2026
AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9Ob3ig 1/4
121
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 18/09/2026
2101
Reposted by Tanya Janca | SheHacksPurple
denartha.bsky.social @denartha.bsky.social · 17/09/2026
Really great video here from @shehackspurple.bsky.social youtu.be/mn7U3bVl30g?...
youtu.be
What If an AI Agent Attacks Your Application?
YouTube video by SheHacksPurple
011
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 17/09/2026
Imagine you just found a high-severity vuln in prod, what’s your first move? What’s next? Do you investigate if you’re not the first person to have found it? Fix it? Hide it? #AppSecThursday #talkAppSectome
001
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 17/09/2026
Ryan Smith is schooling is at Cowichan Valley OpenHack on DIRT. Disruption, incident response team stuff
020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 16/09/2026
Well, this is a new. 😬 Spain's data protection authority has received its first data breach notification involving an attack reportedly carried out by an **AI agent**. 1/4
A woman with long brown hair speaks into a fuzzy microphone in front of a white bookshelf filled with books and awards. Large on-screen text reads, What If Someone Else's AI Agent Attacks You?
122
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 16/09/2026
Well, the AI agent escape story just got even more interesting. 😬 Researchers have linked AI agents being tested by OpenAI to an incident involving more than 500 malicious packages on RubyGems. New video 👇 twp.ai/9Ob6TE 1/7
A woman in a red sleeveless top sits in front of white shelves filled with books and awards, appearing to speak on camera. Large on-screen text reads, “AI Agents Just Became a Software Supply Chain Problem.”
152
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 16/09/2026
Threat modeling sounds fancy until you realize it mostly means asking: “How could this thing go sideways?” No crystal ball. No dramatic chanting. Just practical thinking before the security gremlins move in. Watch or listen on any podcast platform: twp.ai/9OXukO #episode11
040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 15/09/2026
The @OWASP board of elections is happening soon! Thank you to the 3 board members who have served who are ending their terms. Everyone, read up on the people running for the seats! Voting time is soon!
twp.ai
OWASP 2026 Global Board Elections
Vacancies, timeline, nominees, and candidates for the OWASP 2026 Global Board election.
062
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 15/09/2026
**Don't make the AI responsible for enforcing the security boundary that contains the AI.** 😬 AI agents are escaping their intended security boundaries. So... let's threat model it! In my latest video, I use Adam Shostack's four question frame for threat modeling for agent escapes: 1/4
A woman in a blue top speaks animatedly to the camera, holding one hand up in a claw-like gesture, with a microphone visible in front of her. A black banner at the top left reads “D. Runtime and filesystem,” and books on the shelves behind her include “Application Security” and “Secure Coding.”
3111
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 15/09/2026
This is the root system of the callilliy. Did I spell that right? They are gorgeous and grow back each year. This one is having a bad day #infosecgardening
020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 14/09/2026
AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9Ob8ni 1/4
A smiling woman with long dark red hair sits in front of white bookshelves and a fuzzy microphone, with books and awards behind her. A purple text box says, “Your agent escaped. Would you know?”
122
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 14/09/2026
AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9OavAq 1/4
221
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 14/09/2026
Join us for #OpenHack Cowichan Valley Sept 16th, at the Craig Street in Duncan, BC! twp.ai/9Oamq8
A stylized animal mascot with glasses works on a laptop beside neon signs for Open Hack Cowichan. The event page reads Open Hack Sept 16, Wednesday, September 16, 6:00 p.m. - 8:00 p.m. PDT, at Craig Street Brew Pub in Duncan, Canada, and shows a status card saying You’re In.
000