- SheHacksPurple Newsletter
- Posts
- SheHacksPurple: August 2026
SheHacksPurple: August 2026
New formats and European Adventures

The SheHacksPurple Nerd-a-licious Newsletter
💜 Hit ‘reply’ to send me a message. Thank you for subscribing! 💜
Hello everyone! Welcome to the August newsletter!
If you're heading to Black Hat or DEF CON in Las Vegas next week, I'd love to see you IRL! I'll be teaching my “Supply Chain Security Isn't Just Dependencies Anymore” workshop at AppSec Village, signing free copies of my books in the Black Hat expo hall, and hosting a few coffee meetups. (Details are in the Events section below.) And if you happen to wander into Hacker Karaoke... there's a non-zero chance you'll find me there. 😉
Speaking of travel, after Vegas I'm off to Europe for a few training engagements and Security Festival in Lillehammer, Norway. Thanks to a fortunate, last-minute travel schedule change, I was able to add in a few days in Paris to my trip. 😍 Yes, I know, I am very lucky! I'm looking forward to practicing my French, eating entirely too much cheese, drinking some wine, and wandering around one of my favourite cities before it's time to get to work.

Flowers from my garden
/Back at home, things are growing! Literally and figuratively. My flower garden has absolutely exploded this month, and it makes me ridiculously happy. 🌸 #InfoSecGardening photos below and on my socials with that hashtag.
I've also been making a few changes to my content (we can call that ‘growing’ right?). After some experimentation and data analysis (because I am a nerd, after all), I've decided to replace my 2-hour live book streams with shorter video lessons. The data made it very clear that people enjoy learning that way more (20X more, actually!), and honestly, it's less work for me to create fun lessons than to convince everyone to show up at the same time every month.
A casualty of this change is my August 15 stream with the brilliant Katie Paxton-Fear. Between the new format and my travel schedule, we've decided to postpone it. Don't worry, we're still going do something together, just later.
Thank you for reading, sharing my work, and always cheering me on. 🌻
Now, on to this month's newsletter content! Let’s gooooooo!
Tanya


Security Awareness Month
Starts with Developers
Are you looking for a Security Awareness Month speaker? What a coincidence… I happen to know one. 😄
I give practical, engaging talks on secure coding, AI-assisted ("vibe") coding, application security, threat modeling, supply chain security, and more. My goal is simple: make developers laugh, learn something useful, and leave excited to build more secure software. Whether you need a keynote for everyone or a deep engineering talk for just one room, I'd love to help your team make security easier.
New Content!
Alice and Bob Learn Secure Coding: Chapter 4 with Gavin Klondike!
DevSec Station Episode 6: Vibe Coding, Copilots, and Security Drift, watch on YouTube or listen on any podcast platform. Please subscribe!
DevSec Station Episode 7: Why Current Security Tools Fail Developers, watch on YouTube or listen on any podcast platform.
DevSec Station Episode 8: Secure Defaults Beat Secure Training, watch on YouTube or listen on any podcast platform.
A live recording of my talk: Threat Modeling Developer Behaviour: The Psychology of Bad Code, from Toronto, NDC
A rundown of how OWASP Global AppSec EU in Vienna, 2026 went for me

Events!
August 5: Coffee Meetup #1, 12:30 - 2:30 PM, in person, Mandalay Bay, Las Vegas, at the Starbucks just outside the entrance to Black Hat - I will be hanging around and drinking mochas, come hang out! (no pass required)
August 5, 3:00-4:00 pm, Booth #4917: Book signings with ESET in the Black Hat Expo hall, free books! (expo pass required) Las Vegas, NV
August 6: Coffee Meetup #2, 11:30 - 1:30 PM, in person, Mandalay Bay, at the Starbucks just outside the entrance to Black Hat (no pass required) Las Vegas
August 6, 2:00-3:00 pm, Booth #4917: Book signings with ESET in the Black Hat Expo hall, free books! (expo pass required) Las Vegas, NV
August 8, 1:15 - 4:00 pm - Def Con - AppSec Village - “Supply Chain Security Isn't Just Dependencies Anymore” . Las Vegas, NV You need to register in advance, and have a Def Con pass.
August 15, 11:00 am PT: Join Katie Paxton-Fear and I for chapter 5 of Alice and Bob Learn Secure Coding! Register here, or just join us live on YouTube, LinkedIn or Twitch. Virtual
August, 24-26, 2026 Keynote for Sikkerhetsfestivalen (Security Festival) in Lillehammer, Norway! In person
September 12-18, Aurora, CO, CPPcon - Cancelled (I cancelled my appearance, the event is still on). The conference is amazing though, you should still go.
November 3-6 OWASP Global AppSec in San Francisco - My 2-day secure coding training was just accepted, and hopefully one of my talks will be accepted too. This will probably be my last public event for some time.
Deep Thoughts
One of my clients just told me they had two agent escapes this month. I wonder how many others aren’t telling me?
The internet is alight with discussion about the agent escapes from Anthropic and OpenAI, but if they can lose an agent, imagine how many ‘normal’ companies are doing it on the regular but keeping it a secret? And how many others are being attacked and have no idea it’s a rogue agent, rather than a human threat actor?
If we don’t talk about it, we can’t fix it. Hiding things we are embarrassed about will just result in more of us falling prey to this new risk.
Hats off to Anthropic, OpenAI, and HuggingFace for talking about mistakes, regrets, and new threats.
We end with a meme.

PS THANK YOU FOR THE
5,000 Downloads of DevSec Station!



A friend made this for me when she heard my travel schedule. I LOVE IT. Dates aren’t quite right, but that’s okay!