securestep9's profile picture. @OWASPLondon Chapter Leader (#OWASP #OWASPLondon). OWASP Board Member. Application Security (#AppSec) Consultant. OWASP #Nettacker Project co-leader. #CISSP

Sam Stepanyan

@securestep9

@OWASPLondon Chapter Leader (#OWASP #OWASPLondon). OWASP Board Member. Application Security (#AppSec) Consultant. OWASP #Nettacker Project co-leader. #CISSP

Sam Stepanyan 님이 재게시함

Many thanks to Dr Katie Paxton-Fear (@InsiderPhD) for presenting her talk "AI Agents gone Rogue" at the #OWASP London Chapter meetup last week! The video recording of the talk is now available to watch on the #OWASPLondon YouTube channel 📺: 👇 youtube.com/watch?v=f3N2Rn…

OWASPLondon's tweet card. AI Agents Gone Rogue? Hackbots, AI Agents and TheFuture of the AI...

youtube.com

YouTube

AI Agents Gone Rogue? Hackbots, AI Agents and TheFuture of the AI...


#OpenAI API Data Breach: OpenAI has disclosed a #databreach affecting some API customers due to a hack at third-party vendor #Mixpanel. What was exposed: Names & Emails, Approximate Location, UserID/Org IDs 👇 bleepingcomputer.com/news/security/…


#Maven: hundreds of packages just got caught running Shai-Hulud v2 - the same malware that hijacked npm two days ago. It spread through automated rebuilds, infecting devs who never used npm stealing & leaking secrets across thousands of GitHub repos: 👇 thehackernews.com/2025/11/shai-h…


Over 80,000 files with #passwords and keys from governments, banks, and tech firms were found online pasted into public code tools like #JSONFormatter and #CodeBeautify. Cybercriminals are already scraping and using the data. And yes - it’s still live! 👇 thehackernews.com/2025/11/years-…


#AWS launched Agentic AI Security Scoping Matrix – a framework designed to help organizations securely deploy autonomous AI systems: #AISecurity 👇 aws.amazon.com/blogs/security…


Sam Stepanyan 님이 재게시함

The NPM module `glob` (230M downloads per week) packages a command-line tool that includes a command injection flaw. This high-severity vulnerability (CVE-2025-64756 CVSSv3=7.5) allows malicious file names to serve as injection vectors for code exection.. Vulnerability affects…

CheckmarxZero's tweet image. The NPM module `glob` (230M downloads per week) packages a command-line tool that includes a command injection flaw. This high-severity vulnerability (CVE-2025-64756 CVSSv3=7.5) allows malicious file names to serve as injection vectors for code exection.. 

Vulnerability affects…

#WhatsApp: Largest data leak in history - the entire directory of 3.5bln of WhatsApp was available online unprotected for retrieval. Austrian researchers were able to download all phone numbers, profile pictures & data including public keys: 👇 heise.de/en/news/3-5-Bi…


#GitHub: Downdetector and social media platforms are currently filled with reports about a GitHub outage, and the official GitHub Status portal has confirmed the problem: #GitHubDown 👇 howtogeek.com/github-is-down…


#Cloudflare: Cloudflare apologises for outage which took down most of the Internet today, including X and ChatGPT: #CloudflareDown bbc.co.uk/news/articles/…


#Fortinet: Critical vulnerability in Fortinet FortiWeb (CVE-2025-64446), is under active exploitation - CISA adds it to KEV catalog: cybersecuritydive.com/news/critical-…


#NPM: Over 67,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack Exposing Major Security Gaps: 👇 thehackernews.com/2025/11/over-4…


#Linux: Rust-based sudo-rs Affected By Multiple Security Vulnerabilities - Impacting #Ubuntu 25.10 including partial password exposure (CVE-2025-64170) and incorrect User ID in timestamps. Patches for both issues have been released: 👇 phoronix.com/news/sudo-rs-s…


Many thanks to everyone who came to my OWASP #Nettacker talk at the #OWASP Global AppSec 2025 Conference in Washington, DC. 👉github.com/OWASP/Nettacker

securestep9's tweet image. Many thanks to everyone who came to my OWASP #Nettacker talk at the #OWASP Global AppSec 2025 Conference in Washington, DC.
👉github.com/OWASP/Nettacker

#SAP: Patches 3 Critical Vulnerabilities (CVSS 10.0) Including RCE / Code Injection and Hardcoded Credentials affecting SQL Anywhere Monitor (Non-GUI), SAP NetWeaver AS Java, and SAP Solution Manager:(CVE-2025-42890, CVE-2025-42944, CVE-2025-42887): 👇 securityonline.info/sap-november-2…


#AI: HackedGPT: Novel AI Vulnerabilities Open the Door for Private Data Leakage: unique indirect prompt injections, exfiltration of personal user information, persistence, evasion, and bypass of safety mechanisms: #AISecurity tenable.com/blog/hackedgpt…

securestep9's tweet image. #AI: HackedGPT: Novel AI Vulnerabilities Open the Door for Private Data Leakage:  unique indirect prompt injections, exfiltration of personal user information, persistence, evasion, and bypass of safety mechanisms:
#AISecurity

tenable.com/blog/hackedgpt…

Loading...

Something went wrong.


Something went wrong.