securestep9 Profile Banner
Sam Stepanyan Profile
Sam Stepanyan

@securestep9

Followers
7K
Following
11K
Media
1K
Statuses
5K

@OWASPLondon Chapter Leader (#OWASP #OWASPLondon). OWASP Board Member. Application Security (#AppSec) Consultant. OWASP Nettacker Project co-leader. #CISSP

London, UK
Joined September 2013
Don't wanna be here? Send us removal request.
@securestep9
Sam Stepanyan
6 days
#ScatteredSpider: 3 teenagers aged 17-19 and a 20-year-old woman arrested in the UK this morning in connection with cyber attacks on Marks & Spencer (M&S) and Co-op retail chains in April-May this year (luxury store Harrods was also affected):.๐Ÿ‘‡.
@BBCBreaking
BBC Breaking News
6 days
Four people arrested in UK over cyber-attacks that caused havoc at M&S and the Co-op
0
2
5
@securestep9
Sam Stepanyan
6 days
RT @Hesamation: some guy at Mastercard prompt injected a job posting and just days later it tricked somebodyโ€™s ai ๐Ÿ˜‚
Tweet media one
0
1K
0
@securestep9
Sam Stepanyan
6 days
#McDonald's #AI hiring bot exposed 64 million job applicants' personal data in McHire platform through #IDOR security vulnerability and weak password "123456.":.๐Ÿ‘‡.
0
1
5
@securestep9
Sam Stepanyan
8 days
#WhatsApp: Google Gemini can now read your WhatsApp chats without you knowing (and how to disable it):.
0
0
0
@securestep9
Sam Stepanyan
11 days
#Azure: Security researchers have identified a combination of over-privileged built-in roles and API implementation flaws in Microsoft Azure that create dangerous attack vectors:.#CloudSecurity.๐Ÿ‘‡.
0
1
3
@securestep9
Sam Stepanyan
12 days
#Linux: #DjVuLibre vulnerability CVE-2025-53367 could be exploited to gain code execution on a Linux Desktop system when the user tries to open a crafted PDF document. The POC works on a fully up-to-date Ubuntu 25.04 (x86_64):.๐Ÿ‘‡.
0
1
2
@securestep9
Sam Stepanyan
12 days
RT @OWASPLondon: The next OWASP London Chapter in-person Meetup will take place on Thursday 17th July 2025 kindly hosted by Civo Tech Junctโ€ฆ.
0
4
0
@securestep9
Sam Stepanyan
13 days
#Cisco: Unified Communications Manager systems could allow remote attackers to gain root-level access The vulnerability CVE-2025-20309 with a maximum CVSS 10.0, stems from hardcoded SSH root credentials that cannot be modified or removed .๐Ÿ‘‡.
0
1
4
@securestep9
Sam Stepanyan
16 days
Goodbye @contrastsec Community Edition! Very sad to see yet another #AppSec vendorโ€™s promise to support their community version โ€œforeverโ€ abruptly end with the users having the rug pulled out from under them. ๐Ÿ˜ข.Hoping other vendors will continue to invest in the community!
Tweet media one
0
0
7
@securestep9
Sam Stepanyan
19 days
#CISCO: Critical severity CVSS 10 CVE-2025-20281 and CVE-2025-20282 vulnerabilities allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root! Updates released - patched now:.๐Ÿ‘‡.
0
0
0
@securestep9
Sam Stepanyan
19 days
Actively exploited vulnerability in CVE-2024-54085 in AMI MegaRAC gives attackers extraordinary control over server fleets by allowing a remote attacker to create an admin account without any authentication:.๐Ÿ‘‡.
0
0
3
@securestep9
Sam Stepanyan
20 days
RT @OWASPLondon: Our meetup has started! We have @anantshri on stage right now speaking about: "You secured your code dependencies, is thaโ€ฆ.
0
4
0
@securestep9
Sam Stepanyan
23 days
#Citrix Critical Netscaler #vulnerability CVE-2025-5777 patch released!.Like CtirixBleed this vulnerability allows attackers to grab valid session tokens from the memory of internet-facing #Netscaler devices by sending malformed request:.
0
1
9
@securestep9
Sam Stepanyan
27 days
Who needs developers? #GitHub has just announced that any open GitHub issues can now be assigned to an #AI Agent who will do all the work: ๐Ÿ˜ฎ. * Fix bugs.* Implement new features.* Improve test coverage.* Update documentation.* Address technical debt.๐Ÿ‘‡.
Tweet media one
1
0
2
@securestep9
Sam Stepanyan
28 days
#JWT: 'Attacking JWT using X509 Certificates': how an attacker could sign the JWT token with their own private key and modify the header value to specify their public key for signature verification:.#AppSec.#APIsecurity.
Tweet media one
0
1
7
@securestep9
Sam Stepanyan
1 month
RT @OWASPLondon: The next OWASP London Chapter in-person Meetup will take place on Thursday 26th June 2025 kindly hosted by @thoughtmachineโ€ฆ.
0
2
0
@securestep9
Sam Stepanyan
1 month
#Nettacker: very pleased to see @helpnetsecurity publishing an article about our #OWASP Nettacker project!.๐Ÿ‘‡.
0
0
3
@securestep9
Sam Stepanyan
1 month
RT @helpnetsecurity: OWASP Nettacker: Open-source scanner for recon and vulnerability assessment - - @owasp #OpenSoโ€ฆ.
0
2
0
@securestep9
Sam Stepanyan
1 month
#NPM: New Supply Chain #Malware Hits NPM and #PyPI Package Ecosystems. #ReactNative-Aria & #GlueStack packages with cumulative 1mln+ weekly downloads backdoored overnight - check your dependencies!.#SoftwareSupplyChainSecurity.๐Ÿ‘‡.
1
5
10
@securestep9
Sam Stepanyan
1 month
RT @NahamSec: In case you missed it, we released all of the talks from this yearโ€™s #NahamCon on our website for free! Link down below ๐Ÿ‘‡๐Ÿฝ htโ€ฆ.
0
11
0