Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 2hOne of the last flowers of the season. #infosecgardening 040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 5hThey also named it Tanner with me today, because apparently this little guy visits them all the time too. 3/3 020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 5hThat's why it seems so docile, and comfortable with humans. They said not to feed it, because there's way too many of them and they keep eating all of the farmers Fields. So there's no responsibility here for me to find its owner. 2/3 130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 5hFor those of you who have been following #bunnygate it turns out that this bunny is not someone's pet. Apparently, someone let a lot of bunnies go in my little neighborhood 3 or 4 years ago and they've been making little baby bunnies for years now. 1/3 191
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 8hRestrictions need to be enforced somewhere the agent cannot simply bypass them. I introduce this concept in my latest video about the reported AI-agent activity targeting Library and Archives Canada. 🎥 twp.ai/9OblJl 4/4twp.aiyoutu.beWhat Happens When an AI Agent Doesn't Take No for an Answer? 050
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 8h**A harness is not automatically a security boundary.** If your harness blocks the production deployment tool, but the agent still has unrestricted terminal access AND production credentials... Well, congratulations. You now have a very fancy control with a giant hole in it. 😂 3/4 250
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 8hTurns out, an agent harness is generally software that surrounds the AI model and manages how it operates. It can coordinate tool access, execution, credentials, approvals, and other capabilities. But here's the important security distinction: 2/4 130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 8hI recently heard someone at a conference say that putting a "harness" around an AI agent could prevent it from doing things we didn't want it to do. And I thought: Okay. But what the heck is this harness made out of?! Is it code? Another AI? A collection of very sternly worded prompts? 😂 1/4 170
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 9hQuestion for you: What's one security control you've added (or changed) specifically because your team started using AI coding tools? I'd love to hear what people are actually doing right now. #AppSec #AISecurity #SecureSoftwareDevelopment 5/5 010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 9hLimiting blast radius. We don't need AI to be perfectly predictable. We need systems that can safely survive a 'surprise'. 🎧 Season 2, Episode 1: Your AI Worked 59 Times. What About the 60th? twp.ai/9Obuha 4/5twp.ai- YouTubeEnjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube. 120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 9hIf an AI assistant has access to sensitive files, credentials, tools, or deployment capabilities, we need independent controls that don't rely on the AI consistently making good decisions. Least privilege. Independent security checks. HUMAN approvals for consequential actions. 3/5 100
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 9hIn the latest episode of DevSec Station, I share a real classroom experience where one AI-generated result behaved very differently from the other 59. It reminded me of something important: A prompt is NOT a security boundary. 2/5 100
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 9hQuestion for everyone using AI coding assistants or agents: **Are you designing your security controls around what you've ASKED your AI to do, or what it's actually CAPABLE of doing?** Because those are two very different things. 1/5 241
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 04/10/2026The Bunny is now a regular at my place. 😂 What should I name him? 😂 I suspect he's someone's pet, but I don't know how to 'return' him or find his owner if there are no signs... Is it safe to grab him? And if I do, what do I feed him until I find his owners? I've never had a bunny. 110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026I'm curious what other AppSec and AI practitioners think (that's you). What security controls do you see as essential for AI agents? And what are we still not sure about? What are your 'may haves'? Article: twp.ai/9Obx3f #AppSec #AISecurity #SecureCoding #AIAgents 6/6twp.aiwww.theguardian.comOpenAI says its review into hacks, including on Australian government sites, is costing $500,000 a day 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026🔥 AI agents are no exception. 🔥 If we're building AI to improve efficiency and reduce costs, we also need to consider the potential costs of NOT designing for security, containment, least privilege, and observability from the start. Otherwise, all those savings can disappear. 😥 5/6 110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026But I DO think there's an important lesson here for the rest of us. 👂 We've spent over a decade talking about shifting security left (or at least I have). Building security requirements into software from the beginning, rather than trying to bolt them on after something goes wrong. 4/6 110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026I don't want to criticize OpenAI in this post. They're at the forefront of an emerging technology, and we don't know what security controls they originally implemented, what worked, what didn't, or what unexpected challenges they encountered. They are literally inventing this as they go along. 3/6 100
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026According to recent reporting, OpenAI is reviewing approximately 50 PETABYTES of data to reconstruct what its agents did, using around 7,000 GPUs at a reported cost of over $500,000 USD per DAY. 😱 That's an extraordinary amount of incident response work. Talk about #hugops! 2/6 110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026AI is supposed to help us save time and money. But what happens when we don't build security in from the beginning? 1/6 110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026Who should be responsible when an autonomous agent goes rogue? 🎥 Watch here: twp.ai/9Obi3l #AISecurity #AppSec #AIAgents #SecureCoding 5/5twp.aiyoutu.beWhen Your AI Agent Breaks the Law, Who Is Responsible? 021
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026In my new video, I dig into accountability, containment, least privilege, logging, and why telling an AI agent to behave itself is NOT a security control. We need to stop vibe coding agents and letting them loose without proper security requirements. What do you think? 4/5 130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026When your AI agent accesses someone else's systems without authorization, who's responsible? The developer? The company deploying it? The model provider? What if nobody explicitly instructed the agent to do anything wrong? 3/5 120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026California's Attorney General has now issued an investigative subpoena to OpenAI concerning cybersecurity incidents and risks involving its AI models. This isn't a criminal charge or a finding of wrongdoing, but it raises VERY interesting questions. 2/5 120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026Yesterday, someone commented on my LinkedIn asking when the law was going to get involved with AI agents accessing systems they aren't authorized to access. I said I thought it was only a matter of time. Apparently, that time was about 24 hours. 😳 1/5 232
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026Picture it: the feature ships, everyone's thrilled, and then someone says "is the password being logged?" OH NO. Nobody's the villain here! That's the frustrating part. The rule was never written, so nobody broke it. Watch or listen on any podcast platform: twp.ai/9OXtHu #Episode12 010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026If you had to use emojis to summarize Application security as an industry, which ones would you use? #AppSecThursday #talkAppSectome 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026It doesn't get to decide what it's allowed to do.** 🎥 twp.ai/9OblIy 4/4twp.aiyoutu.beWhat Happens When an AI Agent Doesn't Take No for an Answer? 020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026But what actually STOPS them from doing something we didn't intend? In my new video, I talk about this incident, introduce the concept of an AI agent harness, and explain the security controls we need to put around autonomous agents. Because: **The agent can decide what it wants to do. 3/4 351
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026Good news: there's no indication that government systems were compromised. But this raises a REALLY interesting question: **What happens when an AI agent encounters a security boundary and decides to 'be creative'?** We give agents goals. We give them tools. We give them access to systems. 2/4 250
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026Apparently, AI agents have been trying to hack the Canadian government. Oh, good. That's new. 😬 Researchers at Transluce reported suspicious AI-agent activity targeting Library and Archives Canada, including requests containing attack payloads and SQL injection attempts. 1/4 2107
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026In this video, I explain what application security means, what AppSec teams do, and how AI is changing both. twp.ai/9OaNCU 3/3twp.aiyoutu.beWhat is Application Security? 010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026It is everything you to do ensure it is safe, rugged, and secure. But AppSec is changing. Developers are using AI coding assistants. Actually, EVERYONE is using AI assistants. We're going faster than ever before. And sometimes it feels like no one is wearing a seat belt. 2/3 120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026What is application security? And what does AppSec actually mean in 2026? At its core, application security (AppSec) is about making software more secure throughout its entire lifecycle. From the first idea and design decisions, through development and testing, all the way into production. 1/3 130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026Nobody gets excited about "requirements." Yet here I am, all fired up, because the ones nobody writes down are the reason things blow up later. Sorry, I don't make the rules. But that's the point. Somebody has to. Watch or listen on any podcast platform: twp.ai/9OXtHf #Episode12 030
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026I made a short video about this after Spain's data protection authority received its first breach notification involving an attack reportedly carried out by an AI agent: 🎥 twp.ai/9Oa8cK 4/4twp.aiyoutu.beWhat If an AI Agent Attacks Your Application? 021
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026Rate limits. Logging. Monitoring. Alerting. FastER detection and response. AI agents may make attackers faster and more adaptable. But they don't make good application security obsolete. **They make it more important than ever before.** 3/4 120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026Does it matter whether there's a person sitting behind a keyboard? A script? A bot? An AI agent? From the application's perspective, hostile behaviour is hostile behaviour. And that makes the answer surprisingly boring: Authentication. Authorization. Least privilege. Input validation. 2/4 110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026I think we're all coming back to this question: **Does your application care WHO is attacking it?** Imagine someTHING is: → trying credentials → probing your APIs → accessing things it shouldn't → exploiting a vulnerability → changing its approach when something doesn't work 1/4 161
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026I talk more about agent escapes and the controls we can put around them here: twp.ai/9Oa8e0 4/4twp.aiyoutu.beYour AI Agent Escaped. Would You Know? 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026If an action is especially dangerous, require approval outside the agent. Prompts can help guide behaviour. **Security controls should limit what happens when the behaviour isn't what we expected.** That's how we make an AI agent doing something weird a lot less exciting. :-) 3/4 100
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026If the agent should not be able to access something, restrict its permissions. If it should not be able to communicate somewhere, restrict its network access. If it should not be able to call a particular tool, don't give it that tool. 2/4 210
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026One of my biggest rules for AI agent security: **Don't make the AI responsible for enforcing the security boundary that contains the AI.** If your security control is: "Dear AI, please don't do this dangerous thing." ...that's a prompt. A suggestion really. It is not a security boundary. 1/4 261
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026It built and published the attacker's code. Provenance is GOOD. We should use it! We just need other security layers too. 🎥 I explain what happened here: twp.ai/9OaPzH 3/3twp.aiyoutu.beThis Malicious npm Package Had Valid Provenance. How?!!?!?! 000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026In the recent GHAPPIER software supply chain attack, a malicious npm package had valid provenance. The provenance wasn't broken. The attackers had compromised the source repository. So the legitimate build and publishing infrastructure did exactly what it was supposed to do. 2/3 210
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026What does software provenance actually tell you? It can tell you things like: → Where an artifact was built → How it was built → What source and build process produced it What it does NOT tell you: **"This code is safe."** That's a really important distinction. 1/3 151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026Someone ordered 100 signed copies of Alice and Bob Learn Secure Coding, and it's taken longer to sign them than planned. I can only imagine what younger Tanya would think of how amazing my life has turned out. Thank you to every single person who has bought one of my books. 💜 #gratitude 040