Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 21hIf your AI agent did something it wasn't supposed to do tomorrow, would you even know? And if someone asked you to explain what happened three months later, could you? What systems did it access? What credentials did it use? What information did it retrieve? 1/4 131
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 05/10/2026One of the last flowers of the season. I need to celebrate all the gardening while I still can. #infosecgardening 191
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 05/10/2026Vague requirements produce vague security. Compare "the app should be secure" with "every endpoint requires authentication and authorization." Only one of those tells a developer what to actually build. Watch here or listen on any podcast platform: twp.ai/9OXtHr #Episode12 120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 05/10/2026One of the last flowers of the season. #infosecgardening 060
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 05/10/2026For those of you who have been following #bunnygate it turns out that this bunny is not someone's pet. Apparently, someone let a lot of bunnies go in my little neighborhood 3 or 4 years ago and they've been making little baby bunnies for years now. 1/3 1101
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 04/10/2026I recently heard someone at a conference say that putting a "harness" around an AI agent could prevent it from doing things we didn't want it to do. And I thought: Okay. But what the heck is this harness made out of?! Is it code? Another AI? A collection of very sternly worded prompts? 😂 1/4 1100
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 04/10/2026The Bunny is now a regular at my place. 😂 What should I name him? 😂 I suspect he's someone's pet, but I don't know how to 'return' him or find his owner if there are no signs... Is it safe to grab him? And if I do, what do I feed him until I find his owners? I've never had a bunny. 110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026Yesterday, someone commented on my LinkedIn asking when the law was going to get involved with AI agents accessing systems they aren't authorized to access. I said I thought it was only a matter of time. Apparently, that time was about 24 hours. 😳 1/5 232
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026Picture it: the feature ships, everyone's thrilled, and then someone says "is the password being logged?" OH NO. Nobody's the villain here! That's the frustrating part. The rule was never written, so nobody broke it. Watch or listen on any podcast platform: twp.ai/9OXtHu #Episode12 010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026If you had to use emojis to summarize Application security as an industry, which ones would you use? #AppSecThursday #talkAppSectome 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026Apparently, AI agents have been trying to hack the Canadian government. Oh, good. That's new. 😬 Researchers at Transluce reported suspicious AI-agent activity targeting Library and Archives Canada, including requests containing attack payloads and SQL injection attempts. 1/4 2107
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026What is application security? And what does AppSec actually mean in 2026? At its core, application security (AppSec) is about making software more secure throughout its entire lifecycle. From the first idea and design decisions, through development and testing, all the way into production. 1/3 130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026Nobody gets excited about "requirements." Yet here I am, all fired up, because the ones nobody writes down are the reason things blow up later. Sorry, I don't make the rules. But that's the point. Somebody has to. Watch or listen on any podcast platform: twp.ai/9OXtHf #Episode12 030
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026I think we're all coming back to this question: **Does your application care WHO is attacking it?** Imagine someTHING is: → trying credentials → probing your APIs → accessing things it shouldn't → exploiting a vulnerability → changing its approach when something doesn't work 1/4 161
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026One of my biggest rules for AI agent security: **Don't make the AI responsible for enforcing the security boundary that contains the AI.** If your security control is: "Dear AI, please don't do this dangerous thing." ...that's a prompt. A suggestion really. It is not a security boundary. 1/4 261
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026What does software provenance actually tell you? It can tell you things like: → Where an artifact was built → How it was built → What source and build process produced it What it does NOT tell you: **"This code is safe."** That's a really important distinction. 1/3 151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026Someone ordered 100 signed copies of Alice and Bob Learn Secure Coding, and it's taken longer to sign them than planned. I can only imagine what younger Tanya would think of how amazing my life has turned out. Thank you to every single person who has bought one of my books. 💜 #gratitude 040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026This was how I spent a lot of my weekend, digging up my dahlias and getting them ready for winter. This is the mess I make! 😂 #infosecgardening 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 28/09/2026Step one of threat modeling: define the feature. Not “vibes.” Not “the login-ish thing.” Not “you know, that new endpoint.” Name it, understand it, then figure out how it could be misused. Watch or listen on any podcast platform: twp.ai/9OaEdn #episode11 020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 27/09/2026This weekend I am digging up almost all of my dahlias to get them ready for the winter. Powdery mildew has already started! How can it be fall already? 😥 #infosecgardening Did you get outside this weekend? What did you do? 040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026Building a world class security harness - leveraging AI to accelerate your organization's security posture - Michael Argast #bsidesvi2026 160
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026The difference between vulnerable and malicious packages, with Megg Sage at #bsidesvi2026 060
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026Megg Sage at #bsidesvi2026 🥳 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/20263 paths to compromise The Edge @ bsides Vancouver Island 🥳 #bsides The Control Plane Awakens: How Attackers Are Taking Over Network Edge Infrastructure - Ryan Smith 010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026The Control Plane Awakens: How Attackers Are Taking Over Network Edge Infrastructure - Ryan Smith at #bsidesvancouverisland 🥳 040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026From OnlyFans to Online Casinos: Threat Hunting in Google's DMCA Data - Greg Pollock is kicking off #Bsides Vancouver Island! 🥳 #bsidesVancouverIsland 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026Here's a question for everyone building AI agents: **If your agent escaped its intended security boundary, what would tell you?** Not: "Would we eventually notice something weird?" I mean literally: What log? What alert? What monitoring system? Who gets notified? 1/3 151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026Developers threat model all the time. You already think about what could break, what weird stuff users might do, and what edge cases could cause chaos. Now we are just adding security to that very useful little habit. Watch or listen on any podcast platform: twp.ai/9Oa3uP #episode11 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026What is application security? And what does AppSec actually mean in 2026? At its core, application security (AppSec) is about making software more secure throughout its entire lifecycle. From the first idea and design decisions, through development and testing, all the way into production. 1/3 110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026If you could mentor a beginner, what would you teach them first? #AppSecThursday #talkAppSectome 200
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026Here's a question I think we need to start asking when we give AI agents access to developer infrastructure: **What can it actually DO once it gets there?** 1/4 252
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 23/09/2026A malicious npm package was published with **completely valid provenance**. Wait... WHAT?! 😬 That's what happened in the GHAPPIER software supply chain attack. And here's the fascinating part: **The provenance wasn't fake.** The security control WORKED. 1/3 131
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 23/09/2026Threat modeling sounds fancy until you realize it mostly means asking: “How could this thing go sideways?” No crystal ball. No dramatic chanting. Just practical thinking before the security gremlins move in. Watch or listen on any podcast platform: twp.ai/9Oa9DW #episode11 130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026While teaching secure coding this week we prompted Claude (with my tier 1 security prompt available for free from securemyvibe.ca) to build a daily greeting app that would compliment me and give me a nice quote every morning. Well.... 1/3 380
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9Oa3jT 1/4 242
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026Here's an API security question I wish every developer would ask: **Just because I'm logged in, does that mean I'm allowed to do THIS?** Authentication tells us who someone is. Authorization tells us what they're allowed to do. Those are not the same thing. If my frontend requests: 1/3 190
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026My trip to the Maritimes (lovely Frederickton) is going extremely well. I've had soon much fun! I'm November I'm returning, this time to Halifax Nova Scotia, which is ALWAYS a party! 1110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 21/09/2026One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI. **It's not enough to implement part of a security control. You need to verify the security property you're depending on.** 1/4 140
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 21/09/2026Step one of threat modeling: define the feature. Not “vibes.” Not “the login-ish thing.” Not “you know, that new endpoint.” Name it, understand it, then figure out how it could be misused. Watch or listen on any podcast platform: twp.ai/9OXukZ #episode11 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 20/09/2026Fredericton, NB, guess who's visiting you this week???? #morecanada 260
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026Does it *actually* matter if the thing attacking your application is an AI agent? I don't think so. Human attacker? Script? Bot? AI agent? Your application still needs to withstand hostile behaviour. Correct authentication and authorization. Least privilege. Input validation. Rate limits. 1/3 170
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026Have you heard of #InfoSecGardening? 🌱🌻 It’s for ANYONE in cybersecurity (or IT!) to share photos of what you’re growing -> flowers, veggies, herbs, houseplants, gardens… whatever brings you joy. Think of it as a #TimeCleanse: a chance to step away and naturally calm your brain. 1/2 130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026AI coding plugins are becoming a new part of our software supply chain. And this week we got a pretty spectacular demonstration of why that matters. 😬 Security researchers disclosed #Plugin4Shell, a vulnerability affecting several major AI coding agents. 1/5 132
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 18/09/2026Developers threat model all the time. You already think about what could break, what weird stuff users might do, and what edge cases could cause chaos. Now we are just adding security to that very useful little habit. Watch or listen on any podcast platform: twp.ai/9OXukY #episode11 031
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 18/09/2026AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9Ob3ig 1/4 121