Sam Stepanyan

5.4K posts

Sam Stepanyan banner
Sam Stepanyan

Sam Stepanyan

@securestep9

@OWASPLondon Chapter Leader (#OWASP #OWASPLondon). OWASP Board Member. Application Security (#AppSec) Consultant. OWASP #Nettacker Project leader. #CISSP

London, UK เข้าร่วม Eylül 2013
3.7K กำลังติดตาม7.3K ผู้ติดตาม
Miles Deutscher
Miles Deutscher@milesdeutscher·
underrated af new Claude features: • Interactive charts • Cowork scheduled tasks • Cowork plug-ins • Memory management (import/export) • Claude in Excel • Infinite chats • Push-to-talk in Claude Code These features alone make Claude the most powerful AI platform available.
English
76
24
303
21.7K
Sam Stepanyan
Sam Stepanyan@securestep9·
@ErezYalon ^My eyes 👀 hurt from seeing a SQL Injection and plain-text password storage - vulnerabilities so typical for AI-generated (vibe-coded) applications. When reviewing AI-Coded apps I also frequently come across AWS, Vercel and Supabase credentials exposed in client-side JavaScript
English
0
0
0
32
Erez
Erez@ErezYalon·
Code review challenge 👇 What security issue jumps out first?
Erez tweet media
English
2
0
1
98
Sam Stepanyan
Sam Stepanyan@securestep9·
#OpenClaw: Never thought I'd see a picture of #Nvidia CEO Jensen Huang with claws - but here it is on my computer screen this morning and Nvidia has now launched a 'secure and enterprise-ready' open-source plugin for OpenClaw called #NemoClaw: 👇 github.com/NVIDIA/NemoClaw
Sam Stepanyan tweet media
English
0
1
1
182
Sam Stepanyan
Sam Stepanyan@securestep9·
UK Government Companies House new website had a basic OWASP Top 10 authentication bypass #vulnerability for God knows how long until it was identified and reported. I wonder if this is a result of vibe-coding? 🤔 👇
Dan Neidle@DanNeidle

I see some weird things but this takes the biscuit. A vulnerability in the Companies House website, that let anyone view the private dashboard of any one of the five million registered companies, see directors' personal details. And modify them.

English
2
0
4
628
Sam Stepanyan
Sam Stepanyan@securestep9·
Looks like a cyber security incident at @LloydsBank & @HalifaxBank First thing this morning the customers reported seeing other people's transactions and bank statements, and now the system appears to have stopped logging people in: #Lloyds #LloydsBank #Halifax #IDOR 👇
myexploit2600@myexploit2600

Anyone know anyone who works at Halifax in cyber? They are not picking up the phone. And the AI bot they replaced humans with is saying everything is hunky dory.

English
2
1
3
930
Sam Stepanyan
Sam Stepanyan@securestep9·
#linux: Ubuntu, Fedora, Mint Linux are considering adding age verification to Linux due to the upcoming law mandating that OS providers and application developers implement age verification measures to protect minors online. This will have a huge impact: 9to5linux.com/ubuntu-fedora-…
English
1
1
2
202
Sam Stepanyan
Sam Stepanyan@securestep9·
I am speaking at NDC Security! Come catch my talk in Room 4.
Sam Stepanyan tweet media
English
0
1
4
171
Sam Stepanyan รีทวีตแล้ว
OWASP London
OWASP London@OWASPLondon·
Our February Meetup has started and right now we have Mriya Hristova (@mariya_e_h) on stage speaking about North Korean Spies trying to get a job in your organisation! Watch the live-stream 📺 here: 👇 youtube.com/live/VwSCOJWqa…
YouTube video
YouTube
OWASP London tweet media
English
0
6
5
393
Sam Stepanyan รีทวีตแล้ว
Lord Steak
Lord Steak@Adrian__T·
Lord Steak tweet media
ZXX
0
4
5
343
Sam Stepanyan รีทวีตแล้ว
Summer Yue
Summer Yue@summeryue0·
Nothing humbles you like telling your OpenClaw “confirm before acting” and watching it speedrun deleting your inbox. I couldn’t stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb.
Summer Yue tweet mediaSummer Yue tweet mediaSummer Yue tweet media
English
2.4K
1.7K
17.5K
10M