Tanya Janca | Shehackspurple

62K posts

Tanya Janca | Shehackspurple banner
Tanya Janca | Shehackspurple

Tanya Janca | Shehackspurple

@shehackspurple

Secure Coding Trainer, Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her 🌻

Canada - West Coast 🍁 Katılım Haziran 2017
2.4K Takip Edilen50.3K Takipçiler
sudox
sudox@kmcnam1·
sudox tweet media
ZXX
18
57
586
9.1K
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
I joined The Secure Disclosure to talk OWASP Top 10, vibe coding, broken access control, and why “we’ll fix security later” remains one of our industry’s most cursed little traditions. Spoiler: secure coding is not magic. It is a skill. We should probably teach it. 💜 Listen to the full episode with Vinit Patel now! YouTube: twp.ai/uH9DTY Spotify: twp.ai/paTyHU Apple Podcasts: twp.ai/gD9TtM
English
1
3
7
544
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
I joined The Secure Disclosure to talk OWASP Top 10, vibe coding, broken access control, and why “we’ll fix security later” remains one of our industry’s most cursed little traditions. Spoiler: secure coding is not magic. It is a skill. We should probably teach it. 💜 Listen to the full episode with Vinit Patel now! YouTube: twp.ai/uH9DTZ Spotify: twp.ai/ktoj5R Apple Podcasts: twp.ai/WpozVF
English
1
0
6
581
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
Yes. Your heart is telling you not to copy and paste from the AI into production. Seriously, listen to it.
Tanya Janca | Shehackspurple tweet media
English
2
3
12
691
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
I’m doing another live book stream 😊 June 3, 8:00 am PST, I’ll be diving into Chapter 3 of Alice and Bob Learn Secure Coding with Scott Helme. This chapter, “Improving”, is one of my favourites because it’s all the “okay but how do I actually do that?” stuff. twp.ai/gDAGLi We’ll talk about: • safer file uploads • protecting databases • avoiding overflows (yes, even in 2026…) • logging, monitoring, alerting • crypto practices that won’t hurt you later It’s casual, it’s interactive, and you can jump in with questions anytime. Would love to see you there 💜 RSVP here for calendar invites: twp.ai/gDAGLi Or just join us live: twp.ai/S9AWlW
Tanya Janca | Shehackspurple tweet media
English
0
0
4
299
Tanya Janca | Shehackspurple retweetledi
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
Developers do not need more shame about security. We need better systems. Software supply chain risk is something we can prevent with secure defaults. Watch the full podcast episode at the link below to learn how! twp.ai/IlpoLg
English
3
2
7
1.9K
Divine Kylian
Divine Kylian@TheCyberVine·
@shehackspurple Thank you ma 🔥🤍 Really appreciate you and your works so much I've sent the email through divinekylian360@gmail.com
English
1
0
1
4
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
I updated my training page and made a real brochure instead of “here’s a slide deck and blah” 😅 If you’re looking for secure-coding training that respects developers and actually sticks: 👉 twp.ai/SAHXhx Brochure: twp.ai/Imx3Jp
Tanya Janca | Shehackspurple tweet media
English
2
1
5
293
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
Yesssss, it’s happening! I’m joining Raghu Nandakumara from Illumio for a LinkedIn Live on a very spicy little topic: You’ve Built a Security Stack. Have You Built a False Sense of Security? Because buying more tools does not magically equal better security. Sometimes it just means you now have more dashboards to ignore. 😅 We’ll be talking about complexity, cyber resilience, and what it actually takes to improve security outcomes. 📅 Tuesday, May 19 ⏰ 9am PT / 12pm ET 📍 LinkedIn Live Come hang out with us! twp.ai/IlpPey
Tanya Janca | Shehackspurple tweet media
English
0
1
5
282
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
🚨 Emergency DevSec Station Drop There's an active npm supply chain attack happening right now. Compromised packages are stealing SSH keys, AWS credentials, GitHub tokens, browser passwords, and crypto wallets on install. Then using your publish token to infect every package you maintain. One command can protect you immediately: npm config set ignore-scripts true Do it today, please. Tell your team. Watch the full 60 seconds. Video link: twp.ai/IlpFux #AppSec #SupplyChainSecurity #DevSecOps #SecureCoding #npm
English
0
2
5
656
Divine Kylian
Divine Kylian@TheCyberVine·
@shehackspurple So we can get deep insights,advice and guidance on all our individual long term plan and future
English
1
0
1
8
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
I’m excited to announce that I’ll be teaching a two-day class at CppCon Sept 2026: Secure Engineering in Modern C++: Preventing Catastrophic Failures C++ powers infrastructure, robotics, finance, game engines, and safety-critical systems. But small engineering mistakes can turn into major security failures. In this hands-on class we’ll: • analyze insecure native code • learn best practices and common pitfalls • fix bugs together using modern C++ patterns • practice threat modeling and fuzz testing If you write or maintain C++ systems, this class will help you build software that stays secure under real-world pressure. 🎥 Short video below 🔗 Register here: twp.ai/Ilq47e
English
0
1
2
459
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
I had the absolute pleasure of joining Chris Hughes on the Resilient Cyber Show to talk about AI-generated code, “vibe coding,” the new AppSec reality, and why developers are now one of the most important attack surfaces we need to protect. We got into OWASP Top 10 2025, Mythos-class AI capabilities, secure coding with AI assistants, prompt-layer defenses, MCP servers, RAG pipelines, supply chain risks, and my new free prompt library: SecureMyVibe.ca. Basically: the robots are helping us write code now, which is great, except when the robots confidently hand us a security problem wearing a tiny little party hat. 🎉 If you build software, secure software, lead AppSec, or are currently side-eyeing your AI assistant, this episode is for you. Thank you, Chris, for such a thoughtful and fun conversation! Listen to the episode here: twp.ai/IlpFuq
English
0
0
2
338
Tanya Janca | Shehackspurple
Tanya Janca | Shehackspurple@shehackspurple·
I’m thrilled to share that I’ll be teaching at Black Hat USA this August! My training is Secure Coding for Embedded Systems in C and C++. If you write firmware or low-level code, we’ll dig into the security pitfalls that show up again and again in C and C++ and practice fixing them together. Lots of vulnerable code. Lots of practical fixes. Lots of ways to build safer software. 🎥 Watch the short video below 🔗 Save your seat: twp.ai/Ilq58r
English
0
5
12
1.2K