![Sam Stepanyan Profile](https://pbs.twimg.com/profile_images/1114515035865399296/V6nLLbjK_x96.jpg)
Sam Stepanyan
@securestep9
Followers
7K
Following
11K
Statuses
5K
@OWASPLondon Chapter Leader (#OWASP #OWASPLondon). OWASP Board Member. Application Security (#AppSec) Consultant. OWASP Nettacker Project co-leader. #CISSP
London, UK
Joined September 2013
#Kubernetes Policy Enforcement at Risk: OPA Gatekeeper Bypass Exposes #Security Flaws. AquaSec researchers have demonstrated ways to bypass its security controls due to common misconfigurations and policy weaknesses:
0
1
1
#Cisco Patches Critical Identity Services Engine (ISE) #Vulnerabilities with CVSS 9.1 & 9.1 Enabling Root Remote Code Execution (#RCE) and Privilege Escalation (CVE-2025-20124,CVE-2025-20125). Both CVEs are API flaws (Deserialization & Auth bypass):
0
0
0
#Microsoft fixes CVSS 9.9 vulnerability in Azure #AI Face service potentially leading to elevation of privileges over a network:
0
1
3
#SecureByDesign: "Google's Blueprint for a High-Assurance Web Framework" blog post discusses how Google addresses the challenge of preventing vulnerabilities from occurring in the first place through careful design, rigorous testing & a commitment to ongoing security: #AppSec
"This blog post aims to provide a detailed blueprint for how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities."
0
1
5
Broadcom Warns of High-Severity unauthenticated SQL Injection #Vulnerability (CVE-2025-22217) in #VMware Avi Load Balancer/WAF:
0
0
0
#Wacom informs customers of a #databreach impacting credit card data 💳:
0
1
3
RT @iAnonymous3000: Facebook’s Anti-Linux Fiasco @facebook has done some ridiculous things, but flagging Linux—an open source backbone of…
0
6
0
#Apple: If you own an Apple device like an iPhone , iPad, Mac, Apple TV, Apple Watch, Apple Vision Pro headset - today is the day to update it as Apple patches a zero-day privilege escalation vulnerability CVE-2025-24085 and 5 Airplay vulnerabilities:
0
0
4
@starrdlux @kingthorin_rm @zbraiterman @thejonmccoy @InfoSecMap Let's add @adamshostack and @izar_t to the discussion as I feel they are more qualified to answer this question (or to coin a new threat modeling industry term)😎
1
0
4
RT @OWASPLondon: Many thanks to @InsiderPhD for presenting her talk "Go Hack Yourself: API Hacking for Beginners" at the #OWASP London Chap…
0
1
0
RT @OWASPLondon: Many thanks to Tanya Janca (@shehackspurple) for presenting her talk "Maturing Your Application Security Program" at the #…
0
2
0
#jobs for Interns - #cybersecurity researcher at Microsoft Ireland (Dublin) or UK (Cheltenham): 🔁
We are looking for some interns to join our team here at Microsoft. If you are currently studying cyber security, computer science, mathematics or anything similar and based in Ireland or Cheltenham then we would love to hear from you -
0
1
4
The EU Digital Operational Resilience Act (#DORA) officially applies as of today: January 17, 2025. This regulation aims to enhance the operational resilience of financial services organisations against cyber threats and disruptions:
1
0
1