My second blog post in the series 'The Psychology of Bad Code' is now out, with videos and more about Building Systems That Support Secure Developer Behavior!
https://twp.ai/9PZOHJ
@shehackspurple.bsky.social
Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her https://shehackspurple.ca π»
My second blog post in the series 'The Psychology of Bad Code' is now out, with videos and more about Building Systems That Support Secure Developer Behavior!
https://twp.ai/9PZOHJ
SOC/DFIR Mentor here!
Feel free to reach out.
#CyberMentoringMonday
AppSec w/ experience in blue teaming (SOC) and software engineering. Feel free to reach out w/ any questions!
02.02.2026 14:15 β π 0 π 1 π¬ 0 π 0Itβs #CyberMentoringMonday!!!! Are you looking for a professional mentor or to learn more about InfoSec? Are you experienced and willing to βgive backβ? Use this thread and hashtag to connect!
02.02.2026 14:00 β π 3 π 0 π¬ 2 π 0I need to remember this and feel it. Thank you for this beautiful perspective.
02.02.2026 07:40 β π 1 π 0 π¬ 0 π 0Even if you are tough, independent, and strong. Sometimes we need help, and that is ok. As long as you show genuine gratitude (which I find very easy to do), it will all be ok.
Allow someone to be the hero of your story once in a while. It turns out that it's ok. β₯οΈ
For those of you who have trouble accepting or asking for help: I recently needed help, asked for it, and received. I literally had no idea the level of kindness and generosity that was available to me. I have been (recently) overwhelmed by the amazing kindness that other people are willing to give.
02.02.2026 03:33 β π 13 π 2 π¬ 1 π 0How To Get Your First Job In #Cybersecurity: a blog post of all the steps you need to transition into #InfoSec!
https://twp.ai/9PZTxa
FOLKS! The audiobook of Alice and Bob Learn Secure Coding is OUT on @audible now! If you buy it and like it, please rate it for me? I'm so pleased it's finally available.
https://twp.ai/9PZIi1
Yesssssss, do it!
31.01.2026 06:27 β π 0 π 0 π¬ 0 π 0I'm giving training in Denver on February at Wild West Hackin' Fest - Mile High! Check out my 2-day event, Secure Coding and API Hardening: Secure Design, Development, and Threat Modeling, here:
https://twp.ai/9PaUgw
Terminator themed conversation. Is JavaScript the best language for the backend? No.
OHHHHHHHHHH
30.01.2026 23:14 β π 10 π 0 π¬ 2 π 0I feel like there are so many invisible sacrifices in relationships... And when one partner stops bothering to notice the work from the other one, resentment can grow. β₯οΈ
30.01.2026 20:16 β π 1 π 0 π¬ 0 π 0Cyber blocks, random image from podcast page
I was on the Cyber Security Today podcast, hosted by Jim Love. Check it out!
https://twp.ai/9PaUVC
π
30.01.2026 05:25 β π 1 π 0 π¬ 1 π 0I spoke about 'Using Artificial Intelligence, Safely' at ExtremeJ, below video.
β
Risks when using AI in software development
β
How to prevent unsafe AI-driven decisions
β
Best practices for applying AI to security and development tasks
https://twp.ai/9Paarp
Canada is one step closer to mandatory secure coding in government software.
Petition e-7115 is live!
If you can sign, please do it today:
π https://twp.ai/9Paevn
This is how we make real change. π
Recent MCP Server Vulnerabilities and What To Do About Them:
https://twp.ai/9PaLPx
Signal boosting the heck out of this!
27.01.2026 22:11 β π 8 π 4 π¬ 0 π 0Every signature matters. Β π
2/2
Iβve been working toward this for years, and it finally happened.
Canada now has a parliamentary petition to require secure coding in federal software. If you care about cybersecurity, public safety, and better government tech, please sign:
π https://twp.ai/9Paevl
1/2
Thank you!
27.01.2026 22:00 β π 1 π 0 π¬ 0 π 0A3 and A2
27.01.2026 21:59 β π 1 π 0 π¬ 1 π 0My ask:
β
Download the doc
β
Start conversations with your dev & security teams about what to do, not just what to avoid. π
https://twp.ai/Imtgl2
5/5
BRAND NEW:
A10 Mishandling of Exceptional Conditions. Error handling MATTERS, and itβs time we talk about it, and how to do it correctly and safely.
4/5
In this edition:
β’ A01 Broken Access Control remains #1: the most serious risk weβre facing.
β’ A02 Security Misconfiguration moves up to #: configuration mistakes keep happening.
β’ A03 Software Supply Chain Failures is significantly expanded. It's more than dependencies!
3/5
Why does it matter? Because we've updated the items to match wasn't happening RIGHT NOW in industry. Breaches keep happening, and we need updated advice.
2/5
The new owasp top ten, the list of items
Big news in #AppSec: the #OWASP Top 10 2025 is now available! I'm part of the project team and ALL OF US want every dev, security engineer, and leader to read it (please).
https://twp.ai/E6ERYy
1/5
Join @shehackspurple.bsky.social for her precon training class, "Secure Coding and API Hardening," at Wild West Hackin' Fest @ Mile High 2026! Don't ya go missin' it, grab yer tickets to the con today! --> wildwesthackinfest.com/wild-west-ha...
26.01.2026 18:13 β π 4 π 1 π¬ 0 π 0π₯³
27.01.2026 04:09 β π 0 π 0 π¬ 0 π 0