SheHacksPurple: September 2026

#InfoSecGardening, International Adventures, and new AI Security Content

The SheHacksPurple Nerd-a-licious Newsletter

šŸ’œ Hit ā€˜reply’ to send me a message. Thank you for subscribing! šŸ’œ 

Hello!

As you can see, #InfoSecGardening is in full swing right now. That enormous pink flower is a Labyrinth Dahlia, and it’s one of my favourites. The two creamy-white ones behind it are called CafĆ© au Lait (or Cafe Ole, depending on who you ask), and I love those too! 🌸

I also just got back from a whirlwind trip through Paris, the UK, Norway, and Iceland, and it was amazing. I took a few actual vacation days in Paris and Iceland as a special treat for myself, which was absolutely wonderful. 🄰

I was supposed to be travelling again in November, this time to San Francisco for the OWASP Global AppSec conference, but I’ve decided to cancel that trip. I have multiple private (in person) training contracts in a row immediately afterward, my talk submissions weren’t accepted, and I have a rather large personal project underway that I’ll be able to tell you more about closer to Christmas. With all of that going on, crossing the border just for the conference no longer made sense.

If you registered for my training at OWASP, I’m really sorry. I’ll be sending you a little gift to make up for the change of plans. šŸ’œ

Speaking of travel, the growing tensions between Canada and the United States have made cross-border work feel very different this year. Even though I have a US work visa, I’ve found myself less and less comfortable crossing the border to visit my southern neighbours. I’ve also seen a dramatic drop in US companies reaching out to hire me.

So, for the foreseeable future, most of my in-person work will probably be here in Canada (with international adventures when they make sense). I really hope this is temporary. I have so many wonderful friends, colleagues, customers, and community members in the United States, and I miss seeing all of you. 🌻

My trip to Iceland. There was a lot of lava, rocks, and water. The food was delicious but very expensive, and I had to wear my touque (which is Canadian for ā€œwinter hatā€) the whole time, even though it was summer. I did a food tour, and for those of you ā€˜in the know’: No, I didn’t eat the fermented shark. I’m a wimp and backed out!

Your AI Copilot Just Snitched on Itself

Varonis Threat Labs didn't reverse engineer this AI flaw, they literally talked Microsoft Copilot into revealing it. A few reframed questions later, Copilot disclosed an undocumented parameter that let one clicked link auto run a hidden prompt and quietly pulled data from third-party apps and its own memory, all without tripping security alerts. CoSnitch is the third Copilot flaw Varonis Threat Labs has found this year and it’s one you’ll want to learn the details of.

New Content!

Events!

  • October 7th-9th, Wild West Hackin’ Fest - Virtual Appearance - I will talk about AI Security and how we can do better. :-D

  • November 3-6 OWASP Global AppSec in San Francisco - I have cancelled my 2-day secure coding training. My talks were not accepted, I have a lot of other travel happening this year for private training contracts, and a big personal project to work on. With all of this in mind, I made the hard decision to cancel the training as well as the entire trip to San Francisco.

I will not have any public appearances scheduled for the next while, so I can focus on the new product I am building. I will share more as I can!

I actually used my tractor for once! I only stalled it 6 times. Or 7. šŸ˜› Also, of course my tractor has googly eyes!

NEW SECTION: AI Coding and Security

We end with a meme.