Sam Stepanyan

5.4K posts

Sam Stepanyan banner
Sam Stepanyan

Sam Stepanyan

@securestep9

@OWASPLondon Chapter Leader (#OWASP #OWASPLondon). OWASP Board Member. Application Security (#AppSec) Consultant. OWASP #Nettacker Project leader. #CISSP

London, UK 가입일 Eylül 2013
3.7K 팔로잉7.3K 팔로워
TESS
TESS@ArmanSameer95·
@AnthropicAI Your recent update just killed Claude capabilities to do any security research.
English
10
8
77
9.5K
Miles Deutscher
Miles Deutscher@milesdeutscher·
underrated af new Claude features: • Interactive charts • Cowork scheduled tasks • Cowork plug-ins • Memory management (import/export) • Claude in Excel • Infinite chats • Push-to-talk in Claude Code These features alone make Claude the most powerful AI platform available.
English
76
24
302
21.7K
Sam Stepanyan
Sam Stepanyan@securestep9·
@ErezYalon ^My eyes 👀 hurt from seeing a SQL Injection and plain-text password storage - vulnerabilities so typical for AI-generated (vibe-coded) applications. When reviewing AI-Coded apps I also frequently come across AWS, Vercel and Supabase credentials exposed in client-side JavaScript
English
0
0
0
32
Erez
Erez@ErezYalon·
Code review challenge 👇 What security issue jumps out first?
Erez tweet media
English
2
0
1
98
Sam Stepanyan
Sam Stepanyan@securestep9·
UK Government Companies House new website had a basic OWASP Top 10 authentication bypass #vulnerability for God knows how long until it was identified and reported. I wonder if this is a result of vibe-coding? 🤔 👇
Dan Neidle@DanNeidle

I see some weird things but this takes the biscuit. A vulnerability in the Companies House website, that let anyone view the private dashboard of any one of the five million registered companies, see directors' personal details. And modify them.

English
2
0
4
628
Sam Stepanyan
Sam Stepanyan@securestep9·
Looks like a cyber security incident at @LloydsBank & @HalifaxBank First thing this morning the customers reported seeing other people's transactions and bank statements, and now the system appears to have stopped logging people in: #Lloyds #LloydsBank #Halifax #IDOR 👇
myexploit2600@myexploit2600

Anyone know anyone who works at Halifax in cyber? They are not picking up the phone. And the AI bot they replaced humans with is saying everything is hunky dory.

English
2
1
3
930
Sam Stepanyan
Sam Stepanyan@securestep9·
#linux: Ubuntu, Fedora, Mint Linux are considering adding age verification to Linux due to the upcoming law mandating that OS providers and application developers implement age verification measures to protect minors online. This will have a huge impact: 9to5linux.com/ubuntu-fedora-…
English
1
1
2
204
Sam Stepanyan
Sam Stepanyan@securestep9·
I am speaking at NDC Security! Come catch my talk in Room 4.
Sam Stepanyan tweet media
English
0
1
4
171