Secure Coding Trainer, Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her 🌻

Canada - West Coast 🍁
📢 Announcing DevSec Station, my new podcast! 💜 If you write code, this is for you. Short, practical #AppSec lessons. No scare tactics. Very little homework. 😉 twp.ai/kuwhZt twp.ai/gEHSNp
1
4
24
5,716
This weekend I am digging up almost all of my dahlias to get them ready for the winter. Powdery mildew has already started! How can it be fall already? 😥 #infosecgardening Did you get outside this weekend? What did you do?
2
399
From OnlyFans to Online Casinos: Threat Hunting in Google's DMCA Data - Greg Pollock is kicking off #Bsides Vancouver Island! 🥳 #bsidesVancouverIsland
1
9
1,420
The Control Plane Awakens: How Attackers Are Taking Over Network Edge Infrastructure - Ryan Smith at #bsidesvancouverisland 🥳
1
2
1,014
3 paths to compromise The Edge @ bsides Vancouver Island 🥳 #bsides The Control Plane Awakens: How Attackers Are Taking Over Network Edge Infrastructure - Ryan Smith
2
1
4
902
Building a world class security harness - leveraging AI to accelerate your organization's security posture - Michael Argast #bsidesvi2026
1
3
1,206
The difference between vulnerable and malicious packages, with Megg Sage at #bsidesvi2026
2
1
13
1,623
Here's a question for everyone building AI agents: **If your agent escaped its intended security boundary, what would tell you?** Not: "Would we eventually notice something weird?" I mean literally: What log? What alert? What monitoring system? Who gets notified? Because preventing an AI agent from doing something unexpected is only part of the job. We also need to be able to **detect when our containment has failed.** If your answer is: "Ummm... I think we'd probably notice?" That's something worth fixing. 😬 I talk about preventing, containing, detecting, and responding to AI agent escapes here: twp.ai/E5FNs0
3
4
16
1,301
Tanya Janca | Shehackspurple retweeted
Developers threat model all the time. You already think about what could break, what weird stuff users might do, and what edge cases could cause chaos. Now we are just adding security to that very useful little habit. Watch or listen on any podcast platform: twp.ai/E5D9wc #episode11
3
9
1,466
What is application security? And what does AppSec actually mean in 2026? At its core, application security (AppSec) is about making software more secure throughout its entire lifecycle. From the first idea and design decisions, through development and testing, all the way into production. It is everything you to do ensure it is safe, rugged, and secure. But AppSec is changing. Developers are using AI coding assistants. Actually, EVERYONE is using AI assistants. We're going faster than ever before. And sometimes it feels like no one is wearing a seat belt. In this video, I explain what application security means, what AppSec teams do, and how AI is changing both. twp.ai/E5G9lJ
1
4
916
Tanya Janca | Shehackspurple retweeted
Always love the work that @shehackspurple produces ! Worth a watch! :D
A malicious npm package was published with **completely valid provenance**. Wait... WHAT?! 😬 That's what happened in the GHAPPIER software supply chain attack. And here's the fascinating part: **The provenance wasn't fake.** The security control WORKED. The attackers had gained legitimate access to the source repository and changed the code and publishing workflow. So the totally legitimate CI/CD system built the malicious code. The 100% legitimate publishing process published it. And the provenance very legitimately told us when, where and how that artifact was built. Because provenance does NOT mean: "This code is safe." I made a very short video explaining what happened AND, of course, what developers can do to protect themselves: 🎥 twp.ai/E5FfB0
1
1
3
4,015
If you could mentor a beginner, what would you teach them first? #AppSecThursday #talkAppSectome
1
663
Tanya Janca | Shehackspurple retweeted
🎟️ Have your ticket yet? Time is running out for BSides Vancouver Island! Join the island's cybersecurity community for a day packed with insightful talks, great networking, hands-on learning, and an incredible lineup of security professionals. #BSidesVI2026 #CyberSecurity
1
1
2
256