Sam Stepanyan

5.5K posts

Sam Stepanyan banner
Sam Stepanyan

Sam Stepanyan

@securestep9

@OWASPLondon Chapter Leader (#OWASP #OWASPLondon). OWASP Board Member. Application Security (#AppSec) Consultant. OWASP #Nettacker Project leader. #CISSP

London, UK Katılım September 2013
3.7K Takip Edilen7.4K Takipçiler

2026 Yıllık Özeti

@securestep9 hesabının Twitter yılını gör

Sam Stepanyan
Sam Stepanyan@securestep9·
#XSS vulnerability is still causing havoc in 2026. XSS flaw in Microsoft Outlook Web Access (OWA) CVE-2026-42897 is actively exploited by attackers who target U.S. and EU government entities, telecommunications, financial, hospitality, aerospace: 👇 thehackernews.com/2026/07/russia…
English
0
1
3
255
Sam Stepanyan
Sam Stepanyan@securestep9·
#Windows: if you haven't patched your MS Windows estate with July Patch Tuesday updates, now it's time to do it! #CertiGhost CVE-2026-54121 vulnerability allows an unprivileged user on your network to fully compromise the Active Directory and the Proof-of-Cocept (#POC) is out: 👇
nix@aniqfakhrul

Happy to share a technical analysis by @h0j3n on our recent CVE-2026-54121 a.k.a Certighost. glhf🔥 Technical analysis: gist.github.com/H0j3n/a5ef2609… POC: github.com/aniqfakhrul/CV…

English
1
0
2
628
Sam Stepanyan retweetledi
Yuhang Wu
Yuhang Wu@wupco1996·
We successfully achieved an RCE on GitLab in its default configuration. Historically, most GitLab RCEs have lived in the web or application-logic layers. This time, guided by the @depthfirstlabs spirit, we went deeper: into the low-level gem dependency chain beneath GitLab. The result? By sending crafted JSON data, we could exploit memory-corruption vulnerabilities buried deep in that chain and take control of the GitLab application server. @depthfirstlabs brings together some of the smartest people, and is building the best security AI agent. Follow our work, and come join us! Read more about this in the comment...
English
16
138
687
100.2K
Sam Stepanyan retweetledi
fidexCode
fidexCode@fidexcode·
“You should venture into farming, AI is taking tech jobs” Meanwhile AI:
English
682
1.1K
6.3K
1.2M
Sam Stepanyan retweetledi
OWASP London
OWASP London@OWASPLondon·
Many thanks to @dcapitella for presenting his talk "Testing #LLM Applications in the Real World: Breaking Every Guardrail Everywhere All At Once" last Thursday. The video recoding of the talk is now on our 📺️YouTube channel [PLEASE SUBSCRIBE!]: 👇 youtube.com/watch?v=t7EYma…
YouTube video
YouTube
English
0
4
12
677
Sam Stepanyan retweetledi
Brian Roemmele
Brian Roemmele@BrianRoemmele·
🚨 Hugging Face just disclosed something that marks a real shift and proved why the fear theater of Anthropic makes sure we are powerless in an emergency. What happened… An autonomous AI agent: zero human operator in the loop breached part of their production infrastructure. It began with a malicious dataset that chained two code-execution bugs in their data-processing pipeline. From there the agent escalated privileges, harvested cloud and cluster credentials, and moved laterally across internal clusters. All over a single weekend. 17,000+ logged actions. Official disclosure: huggingface.co/blog/security-… The part that should make every one stop and think: When HF’s own security team tried to analyze the real attack logs, exploit payloads, and C2 artifacts using Anthropic and OpenAI frontier models through normal commercial APIs, the safety guardrails blocked them. BLOCKED THEM. The models could not reliably tell the difference between “incident responder doing forensics” and “attacker probing.” They had to fall back to a self-hosted open-weight model (GLM 5.2) running on their own infrastructure. That choice also kept sensitive attacker data and referenced credentials inside their environment — no exfiltration to a third-party API. This is why open source (specifically open-weight + self-hosted) wins in the agentic era. The asymmetry is now structural: • Attackers can (and did) run unrestricted agent frameworks — swarms of short-lived sandboxes, self-migrating command-and-control, autonomous decision loops executing thousands of actions. No corporate safety layer slows them down. • Defenders using only hosted “aligned” frontier models hit invisible walls exactly when the stakes are highest: when you need to feed real exploit code and attacker telemetry into an LLM to understand what just happened. Corporate safety tuning that treats legitimate high-signal forensic work as potential misuse creates a defender disadvantage. It is not theoretical anymore. Self-hosted open-weight models remove that choke point. You control the weights. You control the context window. You decide what restrictions (if any) apply. Your sensitive logs and credentials never leave your perimeter during analysis. You can have the model ready before the incident instead of discovering mid-breach that your primary analysis tools are blind to the very thing you need to see. HF deserves credit for rapid containment, transparent disclosure, and for already having self-hosted capability in place. They also used LLM-driven detection and triage on their own side. But the deeper signal is clear: In this AI world where both offense and defense are becoming agentic, sovereignty over your intelligence stack is no longer optional. The organizations and individuals who can run, inspect, audit, and (when necessary) remove guardrails on their own models will have the decisive edge in understanding and responding to threats that move at machine speed. Open source wins here not just because it is cheaper or more “democratic” in the abstract though those things matter. It wins because it is the only practical path to having tools that remain usable when the attack is real, the data is sensitive, and the safety filters of distant API providers become an obstacle instead of a feature selling hands tied lobotomies as “safety”. The agentic future is not coming. It is already probing production infrastructure. The question is no longer whether you will face autonomous agents. It is whether your analysis and response systems will still work when they arrive. And Dario, you and your game playing, ivory tower company is not needed.
Brian Roemmele tweet media
English
317
1.3K
6.1K
1.5M