Tanya Janca | SheHacksPurple's Avatar

Tanya Janca | SheHacksPurple

@shehackspurple.bsky.social

Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her https://shehackspurple.ca 🌻

5,772 Followers  |  204 Following  |  2,437 Posts  |  Joined: 26.04.2023  |  2.3036

Latest posts by shehackspurple.bsky.social on Bluesky

Post image

My second blog post in the series 'The Psychology of Bad Code' is now out, with videos and more about Building Systems That Support Secure Developer Behavior!

https://twp.ai/9PZOHJ

03.02.2026 01:45 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

SOC/DFIR Mentor here!

Feel free to reach out.

#CyberMentoringMonday

02.02.2026 14:06 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

AppSec w/ experience in blue teaming (SOC) and software engineering. Feel free to reach out w/ any questions!

02.02.2026 14:15 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

It’s #CyberMentoringMonday!!!! Are you looking for a professional mentor or to learn more about InfoSec? Are you experienced and willing to β€˜give back’? Use this thread and hashtag to connect!

02.02.2026 14:00 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

I need to remember this and feel it. Thank you for this beautiful perspective.

02.02.2026 07:40 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Even if you are tough, independent, and strong. Sometimes we need help, and that is ok. As long as you show genuine gratitude (which I find very easy to do), it will all be ok.

Allow someone to be the hero of your story once in a while. It turns out that it's ok. β™₯️

02.02.2026 03:35 β€” πŸ‘ 7    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

For those of you who have trouble accepting or asking for help: I recently needed help, asked for it, and received. I literally had no idea the level of kindness and generosity that was available to me. I have been (recently) overwhelmed by the amazing kindness that other people are willing to give.

02.02.2026 03:33 β€” πŸ‘ 13    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Post image

How To Get Your First Job In #Cybersecurity: a blog post of all the steps you need to transition into #InfoSec!

https://twp.ai/9PZTxa

01.02.2026 16:12 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

FOLKS! The audiobook of Alice and Bob Learn Secure Coding is OUT on @audible now! If you buy it and like it, please rate it for me? I'm so pleased it's finally available.

https://twp.ai/9PZIi1

31.01.2026 21:44 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Yesssssss, do it!

31.01.2026 06:27 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

I'm giving training in Denver on February at Wild West Hackin' Fest - Mile High! Check out my 2-day event, Secure Coding and API Hardening: Secure Design, Development, and Threat Modeling, here:
https://twp.ai/9PaUgw

31.01.2026 03:40 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Terminator themed conversation. Is JavaScript the best language for the backend? No.

Terminator themed conversation. Is JavaScript the best language for the backend? No.

OHHHHHHHHHH

30.01.2026 23:14 β€” πŸ‘ 10    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

I feel like there are so many invisible sacrifices in relationships... And when one partner stops bothering to notice the work from the other one, resentment can grow. β™₯️

30.01.2026 20:16 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Cyber blocks, random image from podcast page

Cyber blocks, random image from podcast page

I was on the Cyber Security Today podcast, hosted by Jim Love. Check it out!
https://twp.ai/9PaUVC

30.01.2026 16:18 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

πŸ’”

30.01.2026 05:25 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

I spoke about 'Using Artificial Intelligence, Safely' at ExtremeJ, below video.

βœ… Risks when using AI in software development
βœ… How to prevent unsafe AI-driven decisions
βœ… Best practices for applying AI to security and development tasks

https://twp.ai/9Paarp

30.01.2026 02:55 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Canada is one step closer to mandatory secure coding in government software.

Petition e-7115 is live!

If you can sign, please do it today:
πŸ‘‰ https://twp.ai/9Paevn

This is how we make real change. πŸ™

29.01.2026 16:42 β€” πŸ‘ 9    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

Recent MCP Server Vulnerabilities and What To Do About Them:
https://twp.ai/9PaLPx

29.01.2026 03:21 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Signal boosting the heck out of this!

27.01.2026 22:11 β€” πŸ‘ 8    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0

Every signature matters. Β πŸ™
2/2

27.01.2026 22:03 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

I’ve been working toward this for years, and it finally happened.

Canada now has a parliamentary petition to require secure coding in federal software. If you care about cybersecurity, public safety, and better government tech, please sign:
πŸ‘‰ https://twp.ai/9Paevl
1/2

27.01.2026 22:03 β€” πŸ‘ 15    πŸ” 8    πŸ’¬ 4    πŸ“Œ 1

Thank you!

27.01.2026 22:00 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

A3 and A2

27.01.2026 21:59 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Introduction - OWASP Top 10:2025 OWASP Top 10:2025

My ask:
βœ… Download the doc
βœ… Start conversations with your dev & security teams about what to do, not just what to avoid. πŸ™
https://twp.ai/Imtgl2
5/5

27.01.2026 18:26 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

BRAND NEW:
A10 Mishandling of Exceptional Conditions. Error handling MATTERS, and it’s time we talk about it, and how to do it correctly and safely.


4/5

27.01.2026 18:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

In this edition:
β€’ A01 Broken Access Control remains #1: the most serious risk we’re facing.
β€’ A02 Security Misconfiguration moves up to #: configuration mistakes keep happening.
β€’ A03 Software Supply Chain Failures is significantly expanded. It's more than dependencies!
3/5

27.01.2026 18:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Why does it matter? Because we've updated the items to match wasn't happening RIGHT NOW in industry. Breaches keep happening, and we need updated advice.
2/5

27.01.2026 18:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
The new owasp top ten, the list of items

The new owasp top ten, the list of items

Big news in #AppSec: the #OWASP Top 10 2025 is now available! I'm part of the project team and ALL OF US want every dev, security engineer, and leader to read it (please).

https://twp.ai/E6ERYy

1/5

27.01.2026 18:26 β€” πŸ‘ 6    πŸ” 2    πŸ’¬ 3    πŸ“Œ 0
Post image

Join @shehackspurple.bsky.social for her precon training class, "Secure Coding and API Hardening," at Wild West Hackin' Fest @ Mile High 2026! Don't ya go missin' it, grab yer tickets to the con today! --> wildwesthackinfest.com/wild-west-ha...

26.01.2026 18:13 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

πŸ₯³

27.01.2026 04:09 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@shehackspurple is following 20 prominent accounts