Tanya Janca | SheHacksPurple
@shehackspurple.bsky.social
Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her https://shehackspurple.ca 🌻
Will you be at Hacker Summer Camp? Come drink coffee with me. ☕️ I'm having informal meetups, in person, Mandalay Bay, Las Vegas, at the Starbucks just outside the entrance to Black Hat 🥳 August 5: 12:30 - 2:30 PM August 6: 11:30 - 1:30 PM Yes the image is AI and yes it's kinda creepy!
I will be signing and giving away of my book Alice and Bob Learn Secure Coding at the ESET booth #4917 in the Black Hat Expo hall August 5, 3:00-4:00 pm and August 6, 2:00-3:00 pm! Come hang out with me and the ESET team! PLUS Cybersecurity Trivia Showdown and The Great Escape: Cyber Challenge
When everything is an emergency, nothing is an emergency. When every scan result looks like a fire drill, developers eventually stop running toward the smoke. We need help prioritizing, not false alarms. Watch here or listen on any podcast platform: https://twp.ai/9OXwdK #Episode7
Do you live in the Cowichan Valley or on Vancouver Island? Want to join us for #OpenHack?!?!?! Of course you do! Sign up for the meetup here: July 22: https://twp.ai/IlspJ2 August 12: https://twp.ai/9OYKuu (I will be at this one)
Will you be at Hacker Summer Camp? Come drink coffee with me. ☕️ I'm having informal meetups, in person, Mandalay Bay, Las Vegas, at the Starbucks just outside the entrance to Black Hat 🥳 August 5: 12:30 - 2:30 PM August 6: 11:30 - 1:30 PM Yes the image is AI and yes it's kinda creepy!
I will be signing and giving away of my book Alice and Bob Learn Secure Coding at the ESET booth #4917 in the Black Hat Expo hall August 5, 3:00-4:00 pm and August 6, 2:00-3:00 pm! Come hang out with me and the ESET team! PLUS Cybersecurity Trivia Showdown and The Great Escape: Cyber Challenge
False positives are not just annoying. They break trust. Every useless finding teaches developers that the tool might be wasting their time, and once trust is gone, the real issues get ignored too. Watch here or listen on any podcast platform: https://twp.ai/9OXwd7 #Episode7
Will you be at Hacker Summer Camp? Come drink coffee with me. ☕️ I'm having informal meetups, in person, Mandalay Bay, Las Vegas, at the Starbucks just outside the entrance to Black Hat 🥳 August 5: 12:30 - 2:30 PM August 6: 11:30 - 1:30 PM Yes the image is AI and yes it's kinda creepy!
One of my clients just told me they had two agent escapes this month. I wonder how many others are silent? The internet is alight discussion about the agent escapes from Anthropic and OpenAI, but if they can lose an agent, imagine how many others have, but have kept it a secret? 1/3
I was on Run As Radio podcast! How can sysadmins help software developers work securely and make more secure applications?We talked about the evolving security concerns around developers; black hats have targeted their privileged accounts and secrets! https://twp.ai/4htDV8
If you were starting in AppSec today, what is one topic, goal or task you would prioritize? And why? #AppSecThursday #talkAppSectome
October (Security Awareness Month) will be here before we know it, and my calendar is officially open for bookings! If you're looking for engaging security content that software developers will actually enjoy, I'd love to help. tanya AT shehackspurple DOT ca 1/4
After being away from home for a bit, I returned to my flowers looking amazing! These are for a friend. I love giving women flowers. The reaction is always wonderful. ☺️ #infosecgardening Do you like receiving flowers? Open question.
I was on the VIA Knowledge Hub podcast: The One Thing Devs Can't Outsource to AI! Watch: https://twp.ai/E5Cxqs Listen: https://twp.ai/4hsTSk
I will be signing and giving away of my book Alice and Bob Learn Secure Coding at the ESET booth #4917 in the Black Hat Expo hall August 5, 3:00-4:00 pm and August 6, 2:00-3:00 pm! Come hang out with me and the ESET team! PLUS Cybersecurity Trivia Showdown and The Great Escape: Cyber Challenge
I will be giving a 2-day training at #OWASPglobalAppSec in San Francisco Nov 3-4, 2026, "Secure Coding That Sticks: From Bad Code to Secure Design". Want to understand the code the AI spits out? Let's over-analyze together! https://twp.ai/9OYKiS
I have decided to give myself a gift; I have added a couple days in Paris and an evening in Oslo to a series of European contracts I have. Extra days of fun, in-between all the work. Do I know anyone in those cities? Does anyone want to meet up for a coffee or something? Message me.
Do you live in the Cowichan Valley or on Vancouver Island? Want to join us for #OpenHack?!?!?! Of course you do! Sign up for the meetup here: July 22: https://twp.ai/NSXjzB August 12: https://twp.ai/9OY0Oz (I will be at this one)
Adjust threat models not just for being the victim but also the attacker. New paper by many authors gives a detailed set of recommendations, supporting my initial assertions last week that orgs need to assume their own agents could attack others & factor that into agentic AI risk
Releasing: Post mortem analysis of the Hugging Face incident was written over the weekend by hundreds of CISOs (and reviewed by Hugging Face). Link: cloudsecurityalliance.org/artifacts/hu... (+free download) From CSA, SANSInstitute, Knostic, [un]prompted, RSAC, FIRST
I have another AI definition for you: Houseplant app: An app that is created only for you and/or your team. It's something that helps you do your job better, but has no other business value. It generally does not touch sensitive data, or connect to any outside systems.
Today I learned what coil whine is. When you push your brand new MacBook pro so hard the GPU literally whines due to micro-vibrations in the coils and capacitos. I'm hard at work! 💪