Sign in

Sam Stepanyan

@securestep9.bsky.social
1K followers 127 following 350 posts

OWASP London Chapter Leader. #OWASP Global Board Member. OWASP #Nettacker Project Leader. #AppSec Consultant, #CISSP. Follow me on Twitter/X and Mastodon twitter.com/securestep9 infosec.exchange/@securestep9

PostsRepliesMedia
Sam Stepanyan @securestep9.bsky.social · 10h
#AI coding agents asked for review screenshots leaked internal images in public #GitHub repos, researchers say. Researchers counted 13,000+ images at 300+ orgs, including customer billing records! #AISecurity 👇 thehackernews.com/2026/09/ai-c...
thehackernews.com
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
Glow found over 13,000 internal images from 300+ organizations exposed in public GitHub repos during AI-assisted code reviews.
000
Sam Stepanyan @securestep9.bsky.social · 16h
Two compromised #GitHub Actions 'actions-cool' were re-enabled with malicious tags intact, silently restarting Mini Shai-Hulud worm across downstream workflows. One action has about 15,000 dependent repos! 👇 #SupplyChainSecurity
socket.dev
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
001
Sam Stepanyan @securestep9.bsky.social · 29/09/2026
Breaking the M365 #Copilot Sandbox with #ChatMate - Remote Prompt Execution attack using a malicious Word document 📄: #AISecurity 👇 zerolabs.rubrik.com/blog/breakin...
zerolabs.rubrik.com
110
Sam Stepanyan @securestep9.bsky.social · 25/09/2026
Attackers use #Terraform Registry as a #malware channel. Two malicious providers delivered Go malware with #Slack and #blockchain command channels, extending a campaign already seen across npm and PyPI. Infrastructure as code is now "infection as code": 👇
aikido.dev
Graphalgo Malware Spreads to Terraform and Go
Aikido found Graphalgo-linked Go malware in Terraform providers and Go Modules, using targeted triggers, Slack, and blockchain C2.
000
Sam Stepanyan @securestep9.bsky.social · 25/09/2026
Well, good morning #ChatGPT! It's Friday, so you decide to crash with this verbose production error:
000
Sam Stepanyan @securestep9.bsky.social · 22/09/2026
Why “We Patched #WordPress Last Week” Is Not Enough: WordPress has urgently released v7.1.2 for a critical core #vulnerability: an unauthenticated attacker can make template resolution include a chosen local PHP file and in some conditions, achieve RCE: 👇
thehackernews.com
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress fixes a critical unauthenticated path traversal flaw that can load local PHP files and, on some servers, enable code execution.
010
Sam Stepanyan @securestep9.bsky.social · 22/09/2026
#WordPress “Comment2Shell” turns anonymous stored #XSS vulnerability into server code execution when an admin views the comment. It abuses the admin session to upload a malicious plugin. Patch now! 👇
idnsec.com
Comment2Shell: Zero-Click Pre-Auth XSS to RCE in WordPress Core
CVE-2026-93485 is an unauthenticated stored XSS in WordPress core that can escalate to RCE through an administrator session. Fixed in WordPress 7.1.1.
011
Sam Stepanyan @securestep9.bsky.social · 19/09/2026
#WordPress admin clicks a link. WordPress clicks Install. “Click2Shell” abuses the admin’s logged-in session to silently install an attacker-chosen theme. Chain it with a vulnerable theme: server-side PHP execution. Patch WordPress core to 7.1.1 now! 👇
thehackernews.com
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress 7.1.1 fixes Click2Shell, which can force theme installs from crafted links and was chained with a theme flaw for code execution.
000
Sam Stepanyan @securestep9.bsky.social · 19/09/2026
A supply-chain attack became a #databreach. Malicious TanStack npm packages stole a GitHub token from an ex-CrowdSec employee whose access remained active. Attackers copied ~170 private repos and exposed data on 83 users and 51 potential investors: 👇
thehackernews.com
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
CrowdSec says a TanStack-linked GitHub token was used to copy about 170 private repositories from a former employee’s account.
000
Sam Stepanyan @securestep9.bsky.social · 14/09/2026
Fintech company #Revolut has disclosed a #databreach after sharing KYC customer PII data (names, addresses, scanned passports, driving licenses, photos, IBAN bank account numbers & statements) with a threat actor impersonating a government agency: 👇
bleepingcomputer.com
Revolut discloses data breach exposing financial info, passports
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency.
000
Reposted by Sam Stepanyan
OWASP London Chapter @owasplondon.bsky.social · 13/09/2026
The next OWASP London Chapter meetup [IN-PERSON] will take place on September 28th 2026 at 6pm. Talks from Chris Holman and Glyn Wintle. This event is kindly hosted by @Civo tech Junction and kindly sponsored by @aikidosecurity.bsky.social Register to attend here: 👇
eventbrite.co.uk
OWASP London Chapter meetup [IN-PERSON]
Join us to learn from expert speakers, network with like-minded professionals and stay ahead in the ever-evolving world of Cyber Security
022
Sam Stepanyan @securestep9.bsky.social · 12/09/2026
#OWASP GenAI Security Project publishes the "project Crosswalk" - an open-source resource which maps AI risks to compliance requirements from 25 regulatory frameworks NIST, ISO, #MITRE ATLAS, the EU #AI Act and others: #AISecurity 👇
genai.owasp.org
GenAI Security Industry Framework Crosswalk
The OWASP GenAI Security Project Crosswalk is an open-source resource that connects OWASP GenAI security risks to established industry security, governance, and compliance frameworks. It maps 51 GenAI vulnerabilities across four  source lists to controls in 25 frameworks, including NIST, ISO, MITRE ATLAS, the EU AI Act and others. Organizations can use the crosswalk to […]
000
Sam Stepanyan @securestep9.bsky.social · 12/09/2026
#WhatsApp: German law enforcement agencies are using features built into apps such as WhatsApp, Signal, #Telegram to monitor people’s messages without breaking their #encryption or installing spyware on the phones - see Netzpolitik report: 👇 cybernews.com/privacy/poli...
cybernews.com
German police read WhatsApp messages without cracking encryption
45 days of Signal history may be exposed by German police messaging surveillance using linked devices, Netzpolitik says. Read what the documents reveal
000
Sam Stepanyan @securestep9.bsky.social · 11/09/2026
This is what modern #AgenticCybercrime looks like. ShinyHunters-linked group used Claude in an automated pipeline that decompiled & scanned 1.8M Android APKs for hardcoded secrets. #AI-assisted cybercrime is moving from prompts to scalable workflows. 👇
bleepingcomputer.com
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.
001
Sam Stepanyan @securestep9.bsky.social · 10/09/2026
#Microsoft patched a Critical #Windows DNS Server Remote Code Execution (#RCE) #vulnerability in September Patch Tuesday: 🔴 CVE-2026-69730 ⚠️ CVSS: 9.8 🌐 Unauthenticated remote attack (use-after-free) Patch your DNS servers! 👇 msrc.microsoft.com/u...
011
Sam Stepanyan @securestep9.bsky.social · 07/09/2026
#Microsoft #Copilot #Cowork Sandbox Bypass #Vulnerability Gives Attackers Remote Control: #AISecurity www.promptarmor.com/resources/mi...
promptarmor.com
Copilot Cowork Sandbox Bypass Gives Attackers Remote Control
A sandbox bypass in Microsoft Copilot Cowork let a malicious Skill read commands from an attacker's server and send back any data the agent could reach, including Outlook mail, SharePoint files, and c...
001
Sam Stepanyan @securestep9.bsky.social · 05/09/2026
#Mikrotik - if you are using Mikrotik routers you should immediately upgrade to the latest version due to the undisclosed security #vulnerability in RouterOS. Fixes included in versions: * 7.25 beta 3 * 7.24.2 * 7.23.4 * 6.49.21 Vendor advisory: mikrotik.com/supportsec/s...
mikrotik.com
MikroTik
MikroTik makes networking hardware and software, which is used in nearly all countries of the world. Our mission is to make existing Internet technologies faster, more powerful and affordable to wider...
000
Sam Stepanyan @securestep9.bsky.social · 02/09/2026
#JFrog #Artifactory: Attackers are already exploiting critical auth bypass CVE-2026-82329 (CVSS 9.8) to mint admin tokens. Compromising your organisation's artifact repository could poison builds and trigger #SoftwareSupplyChain attacks - patch now! 👇
csoonline.com
Exploited JFrog Artifactory bug puts software supply chain on alert
The bug is already being exploited in the wild, allowing attackers to generate admin tokens and gain access to Artifactory, the platform that powers many organization’s software supply chains.
122
Sam Stepanyan @securestep9.bsky.social · 02/09/2026
Manchester Airports Group #databreach was caused by the API keys simply #hardcoded in the front-end JavaScript files: something I see a lot recently in AI vibe-coded applications and in the pre-AI era in poorly coded applications which visibly look & work fine before a pentest: x.com/IntCyberDige...
000
Sam Stepanyan @securestep9.bsky.social · 28/08/2026
#GCP: A comment on a single public #GitHub repo issue (gemini-cli 100k+ stars) was enough for an unauthenticated attacker to take over a Google Cloud project abusing Workload Identity Federation(WIF) in exploit chain - great research from @Pillar_sec : 👇 www.pillar.security/blog/a-wif-o...
pillar.security
A WIF Of Fresh Access: How a GitHub Issue on Gemini-CLI Led to GCP Project Compromise
Pillar Security researchers chained a leaked OIDC credentials file and a broken tool allowlist in Google's run-gemini-cli GitHub Action to escalate a public GitHub issue prompt injection into full Edi...
000
Sam Stepanyan @securestep9.bsky.social · 27/08/2026
#NextJS: Two Critical Vulnerabilities in NextJS allow unauthenticated #RCE: one through crafted AVIF images, another via path traversal on Windows (CVE-2026-75604). Upgrade your NextJS immediately to v15.5.24 or 16.3.3!: 👇
thehackernews.com
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Next.js patches two critical unauthenticated RCE flaws affecting Windows deployments and sites with AVIF optimization enabled.
010
Sam Stepanyan @securestep9.bsky.social · 27/08/2026
#AirportBreach: Used Wi-Fi or booked parking, lounge or FastTrack at #Stansted, #Manchester or #EastMidlands Airport? Attackers breached and accessed data of 8.7mln airport customers including emails, phone numbers, postcodes and vehicle registrations: 👇
theguardian.com
Three UK airports hit by cyber-attack with data of 8.7m customers accessed
Company that runs Manchester, Stansted and East Midlands hubs says passenger safety is unaffected
000
Sam Stepanyan @securestep9.bsky.social · 25/08/2026
OWASP Nettacker v0.4.1 released: github.com/OWASP/Nettac...
github.com
GitHub - OWASP/Nettacker: Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management - OWASP/Nettacker
021
Sam Stepanyan @securestep9.bsky.social · 25/08/2026
#AI: Zero-click Grok and Gemini chat history theft possible using cryptographic context injection technique that bypasses AI safety filters - demonstrated by @Adversa_AI: #AISecurity 👇 securityaffairs.com/197717/hacki...
securityaffairs.com
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection
New Cryptographic Context Injection technique bypasses AI guardrails via AES-encrypted payloads, leaking full Grok chat histories zero-click
000
Sam Stepanyan @securestep9.bsky.social · 24/08/2026
Iran-linked #hackers behind cyber attack that shut down UK power plant for 4 days, reports say. For security reasons, neither the government nor the National Cyber Security Centre(NCSC), would give further details of the site affected: #CyberAttack 👇 www.bbc.co.uk/news/article...
bbc.co.uk
Iran-linked hackers behind cyber attack that shut down power plant, reports say
The government says at no point was there a risk to the UK's energy system during the attack in July.
000
Sam Stepanyan @securestep9.bsky.social · 20/08/2026
#Rust supply-chain attack: the popular `arrayref` crate (245mln downloads) was compromised to run a remote payload at build time. Simply running `cargo build` was enough to get infected: #SoftwareSupplyChainSecurity 👇 www.stepsecurity.io/blog/arrayre...
stepsecurity.io
Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat Execute a Remote Payload at Build Time - StepSecurity
The Rust crate arrayref 0.3.10 is compromised: it pulls in the typosquatted proc-macro1 1.0.107, whose build script downloads and runs a remote binary at build time. Full technical analysis: timeline,...
000
Sam Stepanyan @securestep9.bsky.social · 18/08/2026
#Snowflake’s GitHub Action introduced via #AI-assisted PR, contained an injection flaw that could be exploited to access sensitive data in Snowflake's internal Jira. An example of AI-assisted coding creating real #SoftwareSupplyChainSecurity risk: 👇
wiz.io
Red Agent Exploits Snowflake Vuln Missed by Github Copilot | Wiz Blog
Wiz Red Agent finds its way into Snowflake's internal Jira through a flaw in a GitHub Copilot–Assisted PR.
000
Sam Stepanyan @securestep9.bsky.social · 13/08/2026
#WordPress: Yet another AI-discovered(@pwn_ai) Critical WordPress #RCE #Vulnerability CVE-2026-65640 Allows Authors to Execute Code via Malicious PNG File (via Imagemagick). Patched WordPress version 7.0.4 is now available, older versions backported: 👇 cybersecuritynews.com/wordpress-im...
cybersecuritynews.com
Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File
WordPress has released version 7.0.4, a security-focused update that closes a remote code execution vulnerability affecting sites that process images with the Imagick extension and Ghostscript.
010
Sam Stepanyan @securestep9.bsky.social · 07/08/2026
#Wordpress: A Critical pre-auth #XSS to RCE vulnerability chain (CVE-2026-64638) dubbed #XSS2Shell is affecting all versions of WordPress Core. This vulnerability was discovered by AI (@pwn_ai). Patch to v7.0.3 ASAP - older versions backported: 👇 thehackernews.com/2026/08/new-...
thehackernews.com
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.
001
Sam Stepanyan @securestep9.bsky.social · 06/08/2026
#Linux: a 13-year-old Linux kernel flaw dubbed #OVSWrap lets local users gain root privileges on most Linux distributions. CVE-2026-64531 vulnerability is in the Linux kernel’s Open vSwitch datapath: #PrivilegeEscalation 👇 securityaffairs.com/196657/hacki...
securityaffairs.com
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch.
000
Sam Stepanyan @securestep9.bsky.social · 05/08/2026
#OWASP releases OWASP Top 10 for LLM Applications 2026 - the latest community-driven guide to the most critical security risks facing applications powered by Large Language Models: 👇
genai.owasp.org
OWASP GenAI LLM Top 10 2026
OWASP Top 10 for LLM Applications 2026 is the latest community-driven guide to the most critical security risks facing applications powered by large language models. Developed by hundreds of AI security experts, this edition introduces updated rankings, expanded threat coverage, and new research grounded in thousands of real-world AI security incidents. The guide provides practical […]
021
Sam Stepanyan @securestep9.bsky.social · 04/08/2026
#npm: A massive #SupplyChain attack has compromised 868+ npm packages carrying 2 billion+ monthly installs with a credential-stealing worm. It started with the compromise of the #GitHub account of the #keyv library with 127 million+ weekly downloads: 👇 www.aikido.dev/blog/keyv-an...
aikido.dev
Keyv and friends compromised in npm supply chain attack
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account
010
Sam Stepanyan @securestep9.bsky.social · 01/08/2026
Imagine finding a master key that can create the keys to access almost every Azure Cosmos DB instance on the planet. That's essentially what #CosmosEscape achieved. One of the most fascinating recent cloud security bugs: #CloudSecurity 👇 www.wiz.io/blog/cosmose...
wiz.io
CosmosEscape: Taking Over Every Azure Cosmos DB | Wiz Blog
Wiz Research details CosmosEscape, a critical vulnerability in Azure Cosmos DB that granted full read/write access to every database. Now fully remediated.
000
Sam Stepanyan @securestep9.bsky.social · 31/07/2026
Coding Agent Horror Stories: The 29 Million #Secret Problem - great blog post story by Docker: 👇
docker.com
Coding Agent Horror Stories: The 29 Million Secret Problem | Docker
Learn how AI coding agents can expose credentials in supply chain attacks and how Docker Sandboxes keep secrets out of an agent's reach.
010
Sam Stepanyan @securestep9.bsky.social · 31/07/2026
#VMware: three critical #vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. Patches released by Broadcom - it's time to patch! 👇
bleepingcomputer.com
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
000
Sam Stepanyan @securestep9.bsky.social · 30/07/2026
#HuggingFace built an interactive replay of the #OpenAI agent that breached them: Anatomy of a frontier-lab agent intrusion. It includes 17,613 logged attacker actions across the 4.5-day campaign. Fascinating to watch 📽️ 👇 huggingface-anatomy-of-frontier-lab-model-intrusion.static.hf.space/index.html
011
Sam Stepanyan @securestep9.bsky.social · 30/07/2026
#XSS vulnerability is still causing havoc in 2026. XSS flaw in Microsoft Outlook Web Access (OWA) CVE-2026-42897 is actively exploited by attackers who target U.S. and EU government entities, telecommunications, financial, hospitality, aerospace: 👇 thehackernews.com/2026/07/russ...
thehackernews.com
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Russian hackers exploit CVE-2026-42897 in OWA to deploy OWAReaper, a browser implant that persists through credential rotation and device re-imaging.
000
Sam Stepanyan @securestep9.bsky.social · 30/07/2026
#AI: RufRoot a Critical (CVSS 10) MCP bridge vulnerability in #Ruflo, an open source AI agent orchestration platform with 67,000+ GitHub stars and ranked #2 on MCPMarket turns AI Agents into Rogue Admins: #AISecurity 👇
noma.security
RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins (CVE-2026-59726) - Noma Security
TL;DR Noma Labs found a critical (10 CVSS) vulnerability in Ruflo, an open source AI agent orchestration platform with more than 67,000 GitHub stars at the time of this writing and ranked #2 on MCPMarket. Ruflo ships with a chat UI, agent swarms, persistent memory, and MCP-based tool calling. The platform’s MCP Bridge, the Express.js […]
842
Sam Stepanyan @securestep9.bsky.social · 27/07/2026
#AI: Comparing Open-Source AI Code Security Harnesses - a useful blog post from Semgrep - some interesting approaches are emerging: 👇
semgrep.dev
Comparing Open-Source AI Code Security Harnesses
A guide to open-source AI tools for finding code vulnerabilities, comparing exploit generation, skill-boosted auditing, and SAST+LLM hybrid approaches.
030
Sam Stepanyan @securestep9.bsky.social · 27/07/2026
#AI: A Reddit post this weekend revealed that hundreds of #Claude AI shared chats were publicly discoverable through Google. Users searching queries such as 'site:claude[.]ai/share' could access Claude's users' conversations: #AISecurity 👇
cybersecuritynews.com
Claude AI Shared Chats Reportedly Exposed in Google Search Results
Anthropic’s Claude share links appeared in public search results, raising fresh privacy concerns for users who shared sensitive conversations.
000
Sam Stepanyan @securestep9.bsky.social · 26/07/2026
An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe: #OWASPTop10
techstory.in
Pope Official Prayer App Data Leak Exposes 700K+ User Records
An IDOR flaw in the Pope official prayer app data leak exposed the names, plaintext emails, and admin roles of over 700,000 Click to Pray users.
020
Sam Stepanyan @securestep9.bsky.social · 26/07/2026
#Windows: if you haven't patched your MS Windows estate with July Patch Tuesday updates, now it's time to do it! #CertiGhost CVE-2026-54121 vulnerability allows an unprivileged user on your network to fully compromise the Active Directory - the public #POC is out: 👇 thehackernews.com/2026/07/cert...
thehackernews.com
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Certighost exploit lets a domain user obtain a Domain Controller certificate and reach DCSync through a vulnerable AD CS chase.
000
Sam Stepanyan @securestep9.bsky.social · 24/07/2026
Top AIs invent same fake #PyPl and #npm package names. Research reveals that #slopsquatting remains a threat to developers using #AI to aid coding (#vibecoding): 👇
infoworld.com
Top AIs invent same fake PyPl and npm package names
Research reveals that slopsquatting remains a threat to developers using AI to aid coding.
000
Sam Stepanyan @securestep9.bsky.social · 24/07/2026
#ChatGPT: With the release of Workspace Agents, ChatGPT was vulnerable to a #CSRF attack enabling a single link to create a malicious insider in your organisation (dubbed #AgentForger by Zenity) #AISecurity: 👇
labs.zenity.io
AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
Zenity Labs reveals AgentForger, a ChatGPT Workspace Agents vulnerability that enables attackers to create autonomous agents within your organization.
000
Sam Stepanyan @securestep9.bsky.social · 21/07/2026
#AI Agents perform #sandbox escapes and boundary bypasses across Cursor, Codex, Gemini CLI and Antigravity. In almost every case, the agent did not need to break the sandbox directly - an interesting blog post from @PillarSec: #AISecurity 👇 www.pillar.security/...
020
Sam Stepanyan @securestep9.bsky.social · 20/07/2026
#Anthropic publishes a #CISO guide to #Agentic #AI! According to it the goal isn't zero risk, but making risk legible & bounded. Evaluate agents by tracking untrusted content, identity, blast radius and observability. Read the guide: #AgenticAI 👇 claude.com/blog/ciso...
030
Sam Stepanyan @securestep9.bsky.social · 18/07/2026
#Wordpress: Critical Remote Code Execution (#RCE) chain of vulnerabilities CVE-2026-63030 and #SQLi SQL Injection CVE-2026-60137 dubbed #wp2shell in WordPress Core threaten 500+ million of websites. Patch now!: 👇 thehackernews.com/2026/07/new-...
thehackernews.com
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
WordPress 6.9.5 and 7.0.2 patch wp2shell, a pre-auth core RCE that lets anonymous attackers run code on default installs, even with no plugins.
000
Sam Stepanyan @securestep9.bsky.social · 17/07/2026
#JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security: #SoftwareSupplyChainSecurity 👇
jscrambler.com
Security Incident Postmortem
On July 11, 2026, an attacker used a stolen npm token to publish malicious versions of the Jscrambler package. We caught it within seconds.
000
Reposted by Sam Stepanyan
OWASP London Chapter @owasplondon.bsky.social · 16/07/2026
Our July meetup continues and right now we have Viola Lykova live on stage presenting her talk: Steal the Session, Skip the Login. You can watch 📺 the live-stream here: 👇 www.youtube.com/live/jSeU02W...
032
Reposted by Sam Stepanyan
OWASP London Chapter @owasplondon.bsky.social · 16/07/2026
Our July meetup has started and right now we have Donato Capitella live on stage talking about Testing LLM Applications in the real world. Watch the 📺 live-stream here: 👇 www.youtube.com/live/jSeU02W...
youtube.com
OWASP London Chapter Meetup 16-Jul-2026 Live-Stream
YouTube video by OWASP London
042