Sign in

Sam Stepanyan

@securestep9.bsky.social
1.1K followers 127 following 354 posts

OWASP London Chapter Leader. #OWASP Global Board Member. OWASP #Nettacker Project Leader. #AppSec Consultant, #CISSP. Follow me on Twitter/X and Mastodon twitter.com/securestep9 infosec.exchange/@securestep9

PostsRepliesMedia
Sam Stepanyan @securestep9.bsky.social · 04/10/2026
#MikroTik CVE-2026-84411 is a 9.8 pre-auth root #RCE #vulnerability: one crafted HTTP request can execute code or crash RouterOS! Patched versions available. 367,000+ hosts expose the MikroTik RouterOS web interface directly to the internet. 👇 cybernews.com/securi...
000
Sam Stepanyan @securestep9.bsky.social · 25/09/2026
Well, good morning #ChatGPT! It's Friday, so you decide to crash with this verbose production error:
000
Sam Stepanyan @securestep9.bsky.social · 10/09/2026
#Microsoft patched a Critical #Windows DNS Server Remote Code Execution (#RCE) #vulnerability in September Patch Tuesday: 🔴 CVE-2026-69730 ⚠️ CVSS: 9.8 🌐 Unauthenticated remote attack (use-after-free) Patch your DNS servers! 👇 msrc.microsoft.com/u...
011
Sam Stepanyan @securestep9.bsky.social · 02/09/2026
Manchester Airports Group #databreach was caused by the API keys simply #hardcoded in the front-end JavaScript files: something I see a lot recently in AI vibe-coded applications and in the pre-AI era in poorly coded applications which visibly look & work fine before a pentest: x.com/IntCyberDige...
000
Sam Stepanyan @securestep9.bsky.social · 30/07/2026
#HuggingFace built an interactive replay of the #OpenAI agent that breached them: Anatomy of a frontier-lab agent intrusion. It includes 17,613 logged attacker actions across the 4.5-day campaign. Fascinating to watch 📽️ 👇 huggingface-anatomy-of-frontier-lab-model-intrusion.static.hf.space/index.html
011
Sam Stepanyan @securestep9.bsky.social · 20/07/2026
#Anthropic publishes a #CISO guide to #Agentic #AI! According to it the goal isn't zero risk, but making risk legible & bounded. Evaluate agents by tracking untrusted content, identity, blast radius and observability. Read the guide: #AgenticAI 👇 claude.com/blog/ciso...
030
Sam Stepanyan @securestep9.bsky.social · 30/06/2026
If you want to present a talk at the #OWASP Global AppSec USA 2026 Conference in San Francisco - you have just a few days left while the #CFP is still open: 👇 sessionize.com/owasp-global...
100
Sam Stepanyan @securestep9.bsky.social · 25/06/2026
Good morning from the #OWASP Global AppSec EU 2026 Conference in Vienna, Austria where @joshcgrossman.com just kicked off this amazing conference with 1000+ attendees, 45+ speakers, lots of workshops and activities - check out the agenda here: 👇 owaspglobalappseceuvienna20.sched.com/list/simple
032
Sam Stepanyan @securestep9.bsky.social · 25/06/2026
Attending and speaking at the #OWASP Global AppSec EU 2026 Conference in Vienna, Austria this week! This year’s conference is particularly special as the OWASP Foundation celebrates 25 years! Welcoming everyone alongside fellow OWASP Board Member L B Ricardo Griffith!
000
Sam Stepanyan @securestep9.bsky.social · 13/05/2026
#OWASP #JuiceShop v20.0.0 released with brand new AI challenges including: * Chatbot Prompt Injection * Greedy Chatbot Manipulation * AI Debugging 👇 owasp.org/blog/2026/...
000
Sam Stepanyan @securestep9.bsky.social · 30/03/2026
#AI: "Copilot Edited an Ad Into My PR!" - in a first report of this kind #GitHub #Copilot injected an ad into a Pull Request text: 👇 notes.zachmanson.com...
020
Sam Stepanyan @securestep9.bsky.social · 17/03/2026
#OpenClaw: Never thought I'd see a picture of #Nvidia CEO Jensen Huang with claws - but here it is on my computer screen this morning and Nvidia has now launched a 'secure and enterprise-ready' open-source plugin for OpenClaw called #NemoClaw: 👇 github.com/NVIDIA/Ne...
000
Sam Stepanyan @securestep9.bsky.social · 17/03/2026
#GitHub seems to be suffering a lot getting hit by traffic from #AI bots scraping the code these days - I keep getting 'Too Many Requests' when following links to various GitHub repos: github.blog/changelo...
000
Sam Stepanyan @securestep9.bsky.social · 21/02/2026
"A swarm of agents! Everywhere!" I was watching a 1983 British spy thriller starring Michael Caine and Laurence Olivier and then I hear this 25 minutes in😮: 🔊
000
Sam Stepanyan @securestep9.bsky.social · 21/02/2026
Just re-watched Spiderman2 on Netflix (shot in 2004) where Dr Octopus has AI-controlled Claws attached to his body using tentacles, neuro-linked to his brain with a "guardrail" microchip making sure the AI in the claws does not go rogue, and it does... Eerie watching this in 2026:🦞
0161
Sam Stepanyan @securestep9.bsky.social · 03/02/2026
The number of startups, products and workflows built on #chatGPT-4.x models is huge! This is your reminder that #OpenAI will be *retiring all* gpt-4.x, o4-mini and some gpt-5 models next week on February 13th, 2026 🍿: #AIBOM 👇 help.openai.com/en/a...
000
Sam Stepanyan @securestep9.bsky.social · 02/12/2025
#Wordpress: 100,000+ WordPress Websites Affected by Remote Code Execution (#RCE) #vulnerability in Advanced Custom Fields Plugin: 👇 www.wordfence.com/blog/2025/12...
000
Sam Stepanyan @securestep9.bsky.social · 11/11/2025
Many thanks to everyone who attended my OWASP #Nettacker talk at the #OWASP Global AppSec 2025 Conference in Washington, DC. 👉https://github.com/OWASP/Nettacker
011
Sam Stepanyan @securestep9.bsky.social · 09/11/2025
#AI: HackedGPT: Novel AI Vulnerabilities Open the Door for Private Data Leakage: unique indirect prompt injections, exfiltration of personal user information, persistence, evasion, and bypass of safety mechanisms: #AISecurity www.tenable.com/blog...
000
Sam Stepanyan @securestep9.bsky.social · 23/10/2025
If you are attending #OWASP #LASCON (@LASCONATX) 2025 Conference in Austin, Texas don't miss my talk on the OWASP #Nettacker Project at 1pm CDT in the Read Oak Ballroom: lascon.org/schedule/
010
Sam Stepanyan @securestep9.bsky.social · 23/10/2025
#OWASP LASCON Conference is starting with Jeff Williams's keynote about the flawed mindset holding security back: #LASCON
000
Sam Stepanyan @securestep9.bsky.social · 17/10/2025
I am running for re-election to the OWASP Global Board of Directors in 2025. 🗳️OWASP Global Board Elections have started and all OWASP Members should have received an email with the e-ballot yesterday. owasp.org/www-board-ca... Thank you for your support!
051
Sam Stepanyan @securestep9.bsky.social · 17/09/2025
#Azure: a token validation vulnerability allowing to get Global Admin in any Entra ID tenant(CVE-2025-55241) found by @dirkjanm.io #CloudSecurity 👇 dirkjanm.io/obtaining-gl...
011
Sam Stepanyan @securestep9.bsky.social · 24/08/2025
I donated blood today! #OWASP is running a blood donation drive in honour of Sherif Mansour - @owasplondon.bsky.social Chapter Leader and OWASP Board Chairman 2021 who was recently diagnosed with leukemia. Please help him and everyone who needs blood: donate! 👇 owasp.org/blog/2025/08...
031
Sam Stepanyan @securestep9.bsky.social · 18/08/2025
#MCP Horror Story: Hackers leaked sensitive data from a private GitHub repo by planting a prompt injection in a public #GitHub issue abusing GitHub MCP Server: #AISecurity #PromptInjection 👇 www.docker.com/blog/...
011
Sam Stepanyan @securestep9.bsky.social · 12/08/2025
#AI: "Prompt injection, the lethal trifecta, and the challenges of securing systems that use MCP" - a great blog post from @simonwillison.net - A must-read for everyone in InfoSec desperately trying to explain the dangers of blind adoption of #MCP: #AISecurity 👇 simonwillison.net/2025/Aug/9/b...
001
Sam Stepanyan @securestep9.bsky.social · 11/08/2025
#WhatsApp is finally rolling out a feature that warns you if someone not in your contacts adds you to a WhatsApp group. This feature directly targets a common tactic that is used to spread scam messages and vulnerabilities via WhatsApp: about.fb.com/news/20...
020
Sam Stepanyan @securestep9.bsky.social · 25/07/2025
#AI: "How we rooted Copilot" #AISecurity 👇 research.eye.security/how-we-roote...
011
Sam Stepanyan @securestep9.bsky.social · 19/06/2025
Who needs developers? #GitHub has just announced that any open GitHub issues can now be assigned to an #AI Agent who will do all the work: 😮 * Fix bugs * Implement new features * Improve test coverage * Update documentation * Address technical debt 👇 docs.github.com/en/copilot/u...
110
Sam Stepanyan @securestep9.bsky.social · 31/05/2025
Many thanks everyone who came to my talk on the OWASP Nettacker project at the #OWASP Global AppSec 2025 Conference in Barcelona! Several attendees will be joining us to collaborate and contribute! 🚀 👉 github.com/OWASP/Net...
120
Sam Stepanyan @securestep9.bsky.social · 29/05/2025
If you are attending the OWASP Global AppSec 2025 conference in Barcelona and if you are an OWASP member you can grab a challenge coin 🪙 from the members lounge (room 111)! You can also join OWASP as a member at the conference! 👇
062
Sam Stepanyan @securestep9.bsky.social · 29/05/2025
I am attending and speaking 🗣️ at the #OWASP Global @AppSecEU 2025 conference in sunny ☀️ Barcelona!!! If you are attending - see you there! Conference agenda can be found here: 👇 owasp2025globalappseceu.sched.com/list/simple
031
Sam Stepanyan @securestep9.bsky.social · 24/04/2025
#AI: "Creating Secure Covert Channels with LLMs over Public Channels" by @billatnapier - mind-blowing 🤯! AI agents can pass information between them, and humans would not be able to detect that secret messages were being sent within valid-looking text! 👇 billatnapier.medium.com/creating-sec...
021
Sam Stepanyan @securestep9.bsky.social · 23/04/2025
Our meetup has started and we have John Wood and Aurelien Svevi on stage talking about protecting APIs and applications at run-time. Watch the live-stream 📺 here: 👇 www.youtube.com/live/uhFpUjd...
012
Sam Stepanyan @securestep9.bsky.social · 03/04/2025
#OWASP Application Security Verification Standard (#ASVS) v5.0 RC1 is now ready for review! The ASVS team needs your feedback! Can developers and testers understand it? Anything missing? Please review! 👇 asvs.dev/v5.0.draft/...
021
Sam Stepanyan @securestep9.bsky.social · 01/03/2025
#AI: If you have an X account: I was reviewing my #privacy settings in Twitter/X and found out that this switch was ON by DEFAULT allowing Grok AI to train on all tweets, replies, interactions, and Grok results. Turning it OFF: 👇
000
Sam Stepanyan @securestep9.bsky.social · 16/02/2025
#Google: Google did an Oopsie: a simple #IDOR #vulnerability allowed access to other users private files by changing the Google Drive file docID parameter - bug worth $3,133.7 #bugbounty #bugbountytips 👇 c2a.github.io/simple-idor-...
030
Sam Stepanyan @securestep9.bsky.social · 11/02/2025
#Ivanti: ⚠️ Multiple Critical vulnerabilities in Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS) and Ivanti Secure Access Client (ISAC). Patched versions released: 👇 forums.ivanti.com/s/article/Fe...
010
Sam Stepanyan @securestep9.bsky.social · 15/12/2024
#AI hallucinations are making the world more dangerous as Apple Intelligence feature on the latest iPhones makes up a totally fake BBC News story falsely claiming Luigi Mangione shot himself and fabricated a NYTimes story claiming Netanyahu is arrested: 👇 www.bbc.co.uk/news/article...
010
Sam Stepanyan @securestep9.bsky.social · 28/11/2024
I finally got to see IBM Q System One - IBMs Quantum computer! 💻⚛️ quantum.ibm.com/services/res...
120
Sam Stepanyan @securestep9.bsky.social · 19/11/2024
BlueSky keeps crashing (or a DDoS attack?): #internalservererror
000
Sam Stepanyan @securestep9.bsky.social · 15/11/2024
Enjoyed presenting my #API Security talk at Disruptive Tech London meetup!
010