
Kate Holterhoff sits down with Tanya Janca, Secure Coding and AI Trainer at SheHacksPurple, to talk about what AI is doing to application security. Tanya's take: we're driving a car at three times the speed limit after 25 beers. AI writes huge portions of production code, most developers were never taught to review code for security in the first place, and release velocity keeps climbing. The conversation gets into the difference between using AI to help you code and full-on vibe coding, why context collapse trips up LLMs on security decisions, and what's wrong with bolting AI onto legacy AppSec tools instead of building new ones. Tanya also weighs in on Anthropic's Mythos vulnerability-finding model, argues that the bug bounty economy is heading for collapse, discusses supply chain security and the future of the SDLC, and wraps by explaining Canada's Petition E-7115, which Janca helped draft to require secure coding standards across the Canadian federal government.
Show notes: https://redmonk.com/videos/tanya-janca/
Chapters
00:00 Introduction to AI and Security
02:58 The Current Security Landscape
05:49 Understanding Context Collapse in AI
09:51 The Role of Vibe Coding
13:50 Teaching Security in the Age of AI
16:45 The Need for New Security Tools
25:02 The Evolving Role of Bug Bounties
27:50 The Future of Pen Testing in an AI World
30:01 The Evolving Role of Application Security
31:46 Reimagining the Software Development Lifecycle
40:54 Rethinking Supply Chain Security
48:37 Advocating for Secure Coding Legislation
More episodes from "The MonkCast"



Don't miss an episode of “The MonkCast” and subscribe to it in the GetPodcast app.








