Sam Stepanyan
@securestep9
@OWASPLondon Chapter Leader (#OWASP #OWASPLondon). OWASP Board Member. Application Security (#AppSec) Consultant. OWASP #Nettacker Project co-leader. #CISSP
내가 좋아할 만한 콘텐츠
Many thanks to Dr Katie Paxton-Fear (@InsiderPhD) for presenting her talk "AI Agents gone Rogue" at the #OWASP London Chapter meetup last week! The video recording of the talk is now available to watch on the #OWASPLondon YouTube channel 📺: 👇 youtube.com/watch?v=f3N2Rn…
youtube.com
YouTube
AI Agents Gone Rogue? Hackbots, AI Agents and TheFuture of the AI...
#OpenAI API Data Breach: OpenAI has disclosed a #databreach affecting some API customers due to a hack at third-party vendor #Mixpanel. What was exposed: Names & Emails, Approximate Location, UserID/Org IDs 👇 bleepingcomputer.com/news/security/…
#Maven: hundreds of packages just got caught running Shai-Hulud v2 - the same malware that hijacked npm two days ago. It spread through automated rebuilds, infecting devs who never used npm stealing & leaking secrets across thousands of GitHub repos: 👇 thehackernews.com/2025/11/shai-h…
Over 80,000 files with #passwords and keys from governments, banks, and tech firms were found online pasted into public code tools like #JSONFormatter and #CodeBeautify. Cybercriminals are already scraping and using the data. And yes - it’s still live! 👇 thehackernews.com/2025/11/years-…
#NPM: Second Shai-Hulud Infection Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft: #SoftwareSupplyChainSecurity 👇 thehackernews.com/2025/11/second…
#AWS launched Agentic AI Security Scoping Matrix – a framework designed to help organizations securely deploy autonomous AI systems: #AISecurity 👇 aws.amazon.com/blogs/security…
The NPM module `glob` (230M downloads per week) packages a command-line tool that includes a command injection flaw. This high-severity vulnerability (CVE-2025-64756 CVSSv3=7.5) allows malicious file names to serve as injection vectors for code exection.. Vulnerability affects…
#WhatsApp: Largest data leak in history - the entire directory of 3.5bln of WhatsApp was available online unprotected for retrieval. Austrian researchers were able to download all phone numbers, profile pictures & data including public keys: 👇 heise.de/en/news/3-5-Bi…
#Cloudflare: A Cloudflare outage is taking down big parts of the internet: #CloudflareDown 👇 techradar.com/pro/live/a-clo…
#GitHub: Downdetector and social media platforms are currently filled with reports about a GitHub outage, and the official GitHub Status portal has confirmed the problem: #GitHubDown 👇 howtogeek.com/github-is-down…
#Cloudflare: Cloudflare apologises for outage which took down most of the Internet today, including X and ChatGPT: #CloudflareDown bbc.co.uk/news/articles/…
#Fortinet: Critical vulnerability in Fortinet FortiWeb (CVE-2025-64446), is under active exploitation - CISA adds it to KEV catalog: cybersecuritydive.com/news/critical-…
#NPM: Over 67,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack Exposing Major Security Gaps: 👇 thehackernews.com/2025/11/over-4…
#Linux: Rust-based sudo-rs Affected By Multiple Security Vulnerabilities - Impacting #Ubuntu 25.10 including partial password exposure (CVE-2025-64170) and incorrect User ID in timestamps. Patches for both issues have been released: 👇 phoronix.com/news/sudo-rs-s…
#NPM: Malicious NPM Package @acitons/artifact With 206K+ Downloads Stole GitHub Tokens: #SoftwareSupplyChainSecirity 👇 hackread.com/fake-npm-packa…
Many thanks to everyone who came to my OWASP #Nettacker talk at the #OWASP Global AppSec 2025 Conference in Washington, DC. 👉github.com/OWASP/Nettacker
#SAP: Patches 3 Critical Vulnerabilities (CVSS 10.0) Including RCE / Code Injection and Hardcoded Credentials affecting SQL Anywhere Monitor (Non-GUI), SAP NetWeaver AS Java, and SAP Solution Manager:(CVE-2025-42890, CVE-2025-42944, CVE-2025-42887): 👇 securityonline.info/sap-november-2…
#AI: HackedGPT: Novel AI Vulnerabilities Open the Door for Private Data Leakage: unique indirect prompt injections, exfiltration of personal user information, persistence, evasion, and bypass of safety mechanisms: #AISecurity tenable.com/blog/hackedgpt…
United States 트렌드
- 1. Michigan 139K posts
- 2. Ohio State 60.7K posts
- 3. Mateer 1,958 posts
- 4. Ryan Day 8,888 posts
- 5. Underwood 9,563 posts
- 6. #GoBucks 12.6K posts
- 7. Stoops 6,113 posts
- 8. Sherrone Moore 3,473 posts
- 9. Julian Sayin 6,360 posts
- 10. Clemson 8,896 posts
- 11. Arbuckle N/A
- 12. Louisville 10.3K posts
- 13. Venezuela 435K posts
- 14. Demond N/A
- 15. Fortnite 229K posts
- 16. Tim Banks N/A
- 17. Brutus 18.6K posts
- 18. #TheGame 4,635 posts
- 19. Beamer 2,091 posts
- 20. #GoBlue 9,707 posts
내가 좋아할 만한 콘텐츠
-
mohammed eldeeb
@malcolmx0x -
André Baptista
@0xacb -
ProjectDiscovery
@pdiscoveryio -
Nicolas Grégoire
@Agarri_FR -
YoKo Kho
@YoKoAcc -
BSides London
@BSidesLondon -
Jeff Foley
@jeff_foley -
spaceraccoon | Eugene Lim
@spaceraccoonsec -
Th3g3nt3lman
@Th3G3nt3lman -
Zoe Braiterman
@zbraiterman -
Vandana Verma
@InfosecVandana -
Inti De Ceukelaire
@securinti -
OWASP London
@OWASPLondon -
nikhil(niks)
@niksthehacker -
Rahul Maini
@iamnoooob
Something went wrong.
Something went wrong.