securestep9 Profile Banner
Sam Stepanyan Profile
Sam Stepanyan

@securestep9

Followers
7K
Following
11K
Statuses
5K

@OWASPLondon Chapter Leader (#OWASP #OWASPLondon). OWASP Board Member. Application Security (#AppSec) Consultant. OWASP Nettacker Project co-leader. #CISSP

London, UK
Joined September 2013
Don't wanna be here? Send us removal request.
@securestep9
Sam Stepanyan
6 hours
#iPhone: if you own one it's time to do a Software Update again as Apple issues an emergency iOS version 18.3.1 to patch a #zeroday vulnerability CVE-2025-24200 which can be exploited to bypass the USB restriction mode and pull the data from the device:
0
0
0
@securestep9
Sam Stepanyan
3 days
#Kubernetes Policy Enforcement at Risk: OPA Gatekeeper Bypass Exposes #Security Flaws. AquaSec researchers have demonstrated ways to bypass its security controls due to common misconfigurations and policy weaknesses:
0
1
1
@securestep9
Sam Stepanyan
5 days
#Cisco Patches Critical Identity Services Engine (ISE) #Vulnerabilities with CVSS 9.1 & 9.1 Enabling Root Remote Code Execution (#RCE) and Privilege Escalation (CVE-2025-20124,CVE-2025-20125). Both CVEs are API flaws (Deserialization & Auth bypass):
0
0
0
@securestep9
Sam Stepanyan
5 days
#Microsoft fixes CVSS 9.9 vulnerability in Azure #AI Face service potentially leading to elevation of privileges over a network:
0
1
3
@securestep9
Sam Stepanyan
5 days
I was interviewed by the Cybersecurity Sessions podcast a few of weeks ago - you can catch the episode on Spotify here🎤:
0
0
2
@securestep9
Sam Stepanyan
6 days
@UK_Daniel_Card Check out some UK companies with 1337 in the LTD name 😎
0
0
1
@securestep9
Sam Stepanyan
6 days
#SecureByDesign: "Google's Blueprint for a High-Assurance Web Framework" blog post discusses how Google addresses the challenge of preventing vulnerabilities from occurring in the first place through careful design, rigorous testing & a commitment to ongoing security: #AppSec
@royalhansen
Royal Hansen
6 days
"This blog post aims to provide a detailed blueprint for how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities."
0
1
5
@securestep9
Sam Stepanyan
9 days
#WhatsApp Meta Confirms Zero-Click WhatsApp #Spyware affected at least 90 Journalists. A specially-crafted PDF file was sent to individuals who were added to group chats on WhatsApp. Once the file was received the WhatsApp account was compromised:
0
1
2
@securestep9
Sam Stepanyan
13 days
Broadcom Warns of High-Severity unauthenticated SQL Injection #Vulnerability (CVE-2025-22217) in #VMware Avi Load Balancer/WAF:
0
0
0
@securestep9
Sam Stepanyan
13 days
#Facebook's internal policy makers decided that #Linux is "malware" and labeled posts and groups associated with Linux as being 'cybersecurity threats' blocking them citing Community Standards:
0
0
0
@securestep9
Sam Stepanyan
13 days
#Wacom informs customers of a #databreach impacting credit card data 💳:
@troyhunt
Troy Hunt
13 days
Very light on detail, but,apparently *something* happened at @wacom that exposed credit cards:
Tweet media one
0
1
3
@securestep9
Sam Stepanyan
13 days
RT @iAnonymous3000: Facebook’s Anti-Linux Fiasco @facebook has done some ridiculous things, but flagging Linux—an open source backbone of…
0
6
0
@securestep9
Sam Stepanyan
14 days
#Apple: If you own an Apple device like an iPhone , iPad, Mac, Apple TV, Apple Watch, Apple Vision Pro headset - today is the day to update it as Apple patches a zero-day privilege escalation vulnerability CVE-2025-24085 and 5 Airplay vulnerabilities:
0
0
4
@securestep9
Sam Stepanyan
16 days
CVE-2024-50050: Critical Vulnerability in meta-llama/#llama-stack by Meta - a popular #GenAI framework. The deserialization flaw allows remote attackers to execute arbitrary code, posing severe risks to AI model hosting, data integrity & system security:
1
16
38
@securestep9
Sam Stepanyan
16 days
@starrdlux @kingthorin_rm @zbraiterman @thejonmccoy @InfoSecMap Let's add @adamshostack and @izar_t to the discussion as I feel they are more qualified to answer this question (or to coin a new threat modeling industry term)😎
1
0
4
@securestep9
Sam Stepanyan
20 days
RT @OWASPLondon: Many thanks to @InsiderPhD for presenting her talk "Go Hack Yourself: API Hacking for Beginners" at the #OWASP London Chap…
0
1
0
@securestep9
Sam Stepanyan
20 days
RT @OWASPLondon: Many thanks to Tanya Janca (@shehackspurple) for presenting her talk "Maturing Your Application Security Program" at the #…
0
2
0
@securestep9
Sam Stepanyan
24 days
#jobs for Interns - #cybersecurity researcher at Microsoft Ireland (Dublin) or UK (Cheltenham): 🔁
@reprise_99
Matt Zorich
25 days
We are looking for some interns to join our team here at Microsoft. If you are currently studying cyber security, computer science, mathematics or anything similar and based in Ireland or Cheltenham then we would love to hear from you -
0
1
4
@securestep9
Sam Stepanyan
25 days
The EU Digital Operational Resilience Act (#DORA) officially applies as of today: January 17, 2025. This regulation aims to enhance the operational resilience of financial services organisations against cyber threats and disruptions:
1
0
1
@securestep9
Sam Stepanyan
26 days
#Ivanti: Researcher Uncovers Critical Vulnerabilities in Multiple Versions of Ivanti Endpoint Manager (#EPM) and Ivanti Avalanche Application Control Engine. CVE-2024-10811, CVE-2024-13161, CVE-2024-13160, CVE-2024-13159 have been patched - update! 👇
0
0
0