Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 6hI think we're all coming back to this question: **Does your application care WHO is attacking it?** Imagine someTHING is: → trying credentials → probing your APIs → accessing things it shouldn't → exploiting a vulnerability → changing its approach when something doesn't work 1/4 151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 18hOne of my biggest rules for AI agent security: **Don't make the AI responsible for enforcing the security boundary that contains the AI.** If your security control is: "Dear AI, please don't do this dangerous thing." ...that's a prompt. A suggestion really. It is not a security boundary. 1/4 261
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026What does software provenance actually tell you? It can tell you things like: → Where an artifact was built → How it was built → What source and build process produced it What it does NOT tell you: **"This code is safe."** That's a really important distinction. 1/3 151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026Someone ordered 100 signed copies of Alice and Bob Learn Secure Coding, and it's taken longer to sign them than planned. I can only imagine what younger Tanya would think of how amazing my life has turned out. Thank you to every single person who has bought one of my books. 💜 #gratitude 040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026This was how I spent a lot of my weekend, digging up my dahlias and getting them ready for winter. This is the mess I make! 😂 #infosecgardening 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 28/09/2026Step one of threat modeling: define the feature. Not “vibes.” Not “the login-ish thing.” Not “you know, that new endpoint.” Name it, understand it, then figure out how it could be misused. Watch or listen on any podcast platform: twp.ai/9OaEdn #episode11 020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 27/09/2026This weekend I am digging up almost all of my dahlias to get them ready for the winter. Powdery mildew has already started! How can it be fall already? 😥 #infosecgardening Did you get outside this weekend? What did you do? 040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026Building a world class security harness - leveraging AI to accelerate your organization's security posture - Michael Argast #bsidesvi2026 160
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026The difference between vulnerable and malicious packages, with Megg Sage at #bsidesvi2026 060
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026Megg Sage at #bsidesvi2026 🥳 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/20263 paths to compromise The Edge @ bsides Vancouver Island 🥳 #bsides The Control Plane Awakens: How Attackers Are Taking Over Network Edge Infrastructure - Ryan Smith 010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026The Control Plane Awakens: How Attackers Are Taking Over Network Edge Infrastructure - Ryan Smith at #bsidesvancouverisland 🥳 040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026From OnlyFans to Online Casinos: Threat Hunting in Google's DMCA Data - Greg Pollock is kicking off #Bsides Vancouver Island! 🥳 #bsidesVancouverIsland 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026Here's a question for everyone building AI agents: **If your agent escaped its intended security boundary, what would tell you?** Not: "Would we eventually notice something weird?" I mean literally: What log? What alert? What monitoring system? Who gets notified? 1/3 151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026Developers threat model all the time. You already think about what could break, what weird stuff users might do, and what edge cases could cause chaos. Now we are just adding security to that very useful little habit. Watch or listen on any podcast platform: twp.ai/9Oa3uP #episode11 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026What is application security? And what does AppSec actually mean in 2026? At its core, application security (AppSec) is about making software more secure throughout its entire lifecycle. From the first idea and design decisions, through development and testing, all the way into production. 1/3 110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026If you could mentor a beginner, what would you teach them first? #AppSecThursday #talkAppSectome 200
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026Here's a question I think we need to start asking when we give AI agents access to developer infrastructure: **What can it actually DO once it gets there?** 1/4 252
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 23/09/2026A malicious npm package was published with **completely valid provenance**. Wait... WHAT?! 😬 That's what happened in the GHAPPIER software supply chain attack. And here's the fascinating part: **The provenance wasn't fake.** The security control WORKED. 1/3 131
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 23/09/2026Threat modeling sounds fancy until you realize it mostly means asking: “How could this thing go sideways?” No crystal ball. No dramatic chanting. Just practical thinking before the security gremlins move in. Watch or listen on any podcast platform: twp.ai/9Oa9DW #episode11 130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026While teaching secure coding this week we prompted Claude (with my tier 1 security prompt available for free from securemyvibe.ca) to build a daily greeting app that would compliment me and give me a nice quote every morning. Well.... 1/3 380
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9Oa3jT 1/4 242
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026Here's an API security question I wish every developer would ask: **Just because I'm logged in, does that mean I'm allowed to do THIS?** Authentication tells us who someone is. Authorization tells us what they're allowed to do. Those are not the same thing. If my frontend requests: 1/3 190
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026My trip to the Maritimes (lovely Frederickton) is going extremely well. I've had soon much fun! I'm November I'm returning, this time to Halifax Nova Scotia, which is ALWAYS a party! 1110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 21/09/2026One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI. **It's not enough to implement part of a security control. You need to verify the security property you're depending on.** 1/4 140
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 21/09/2026Step one of threat modeling: define the feature. Not “vibes.” Not “the login-ish thing.” Not “you know, that new endpoint.” Name it, understand it, then figure out how it could be misused. Watch or listen on any podcast platform: twp.ai/9OXukZ #episode11 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 20/09/2026Fredericton, NB, guess who's visiting you this week???? #morecanada 260
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026Does it *actually* matter if the thing attacking your application is an AI agent? I don't think so. Human attacker? Script? Bot? AI agent? Your application still needs to withstand hostile behaviour. Correct authentication and authorization. Least privilege. Input validation. Rate limits. 1/3 170
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026Have you heard of #InfoSecGardening? 🌱🌻 It’s for ANYONE in cybersecurity (or IT!) to share photos of what you’re growing -> flowers, veggies, herbs, houseplants, gardens… whatever brings you joy. Think of it as a #TimeCleanse: a chance to step away and naturally calm your brain. 1/2 130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026AI coding plugins are becoming a new part of our software supply chain. And this week we got a pretty spectacular demonstration of why that matters. 😬 Security researchers disclosed #Plugin4Shell, a vulnerability affecting several major AI coding agents. 1/5 132
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 18/09/2026Developers threat model all the time. You already think about what could break, what weird stuff users might do, and what edge cases could cause chaos. Now we are just adding security to that very useful little habit. Watch or listen on any podcast platform: twp.ai/9OXukY #episode11 031
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 18/09/2026AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9Ob3ig 1/4 121
Reposted by Tanya Janca | SheHacksPurpledenartha.bsky.social @denartha.bsky.social · 17/09/2026Really great video here from @shehackspurple.bsky.social youtu.be/mn7U3bVl30g?...youtu.beWhat If an AI Agent Attacks Your Application?YouTube video by SheHacksPurple 011
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 17/09/2026Imagine you just found a high-severity vuln in prod, what’s your first move? What’s next? Do you investigate if you’re not the first person to have found it? Fix it? Hide it? #AppSecThursday #talkAppSectome 001
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 17/09/2026Ryan Smith is schooling is at Cowichan Valley OpenHack on DIRT. Disruption, incident response team stuff 020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 16/09/2026Well, this is a new. 😬 Spain's data protection authority has received its first data breach notification involving an attack reportedly carried out by an **AI agent**. 1/4 122
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 16/09/2026Well, the AI agent escape story just got even more interesting. 😬 Researchers have linked AI agents being tested by OpenAI to an incident involving more than 500 malicious packages on RubyGems. New video 👇 twp.ai/9Ob6TE 1/7 152
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 16/09/2026Threat modeling sounds fancy until you realize it mostly means asking: “How could this thing go sideways?” No crystal ball. No dramatic chanting. Just practical thinking before the security gremlins move in. Watch or listen on any podcast platform: twp.ai/9OXukO #episode11 040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 15/09/2026The @OWASP board of elections is happening soon! Thank you to the 3 board members who have served who are ending their terms. Everyone, read up on the people running for the seats! Voting time is soon!twp.aiOWASP 2026 Global Board ElectionsVacancies, timeline, nominees, and candidates for the OWASP 2026 Global Board election. 062
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 15/09/2026**Don't make the AI responsible for enforcing the security boundary that contains the AI.** 😬 AI agents are escaping their intended security boundaries. So... let's threat model it! In my latest video, I use Adam Shostack's four question frame for threat modeling for agent escapes: 1/4 3111
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 15/09/2026This is the root system of the callilliy. Did I spell that right? They are gorgeous and grow back each year. This one is having a bad day #infosecgardening 020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 14/09/2026AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9Ob8ni 1/4 122
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 14/09/2026AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9OavAq 1/4 221
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 14/09/2026Join us for #OpenHack Cowichan Valley Sept 16th, at the Craig Street in Duncan, BC! twp.ai/9Oamq8 000