Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Sam Stepanyan :verified: 🐘

@securestep9@infosec.exchange
  • Open on infosec.exchange

https://twitter.com/securestep9

#OWASP London Chapter Leader(@OWASPLondon@infosec.exchange). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

996 Followers
129 Following
35 Posts
Joined June 04, 2018
Blog:
https://medium.com/@securestep9

Posts

Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Aug 06, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

#Linux: a 13-year-old Linux kernel flaw dubbed #OVSWrap lets local users gain root privileges on most Linux distributions. CVE-2026-64531 vulnerability is in the Linux kernel’s Open vSwitch datapath:
#PrivilegeEscalation
👇

https://securityaffairs.com/196657/hacking/ovswrap-13-year-old-linux-kernel-flaw-lets-local-users-become-root.html

infosec.exchange

Infosec Exchange

1
0
1
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Aug 05, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
Replying to @nicd@masto.ahlcode.fi
@nicd@masto.ahlcode.fi Re compromised npm packages - see this Bleeping Computer post. It appears that figure cited by BleepingComputer stems from how the compromised packages are counted - looks like they count total volume of published malicious package versions rather than top-level npm packages: https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/
Massive ChainDrop npm supply-chain attack infects hundreds of packages
BleepingComputer

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.

0
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Aug 05, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#OWASP releases OWASP Top 10 for LLM Applications 2026 - the latest community-driven guide to the most critical security risks facing applications powered by Large Language Models: 👇 https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
OWASP GenAI LLM Top 10 2026
OWASP Gen AI Security Project

OWASP GenAI LLM Top 10 2026

OWASP Top 10 for LLM Applications 2026 is the latest community-driven guide to the most critical security risks facing applications powered by large language models. Developed by hundreds of AI securi

0
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Aug 04, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#npm: A massive #SupplyChain attack has compromised 868+ npm packages carrying 2 billion+ monthly installs with a credential-stealing worm. It started with the compromise of the #GitHub account of the #keyv library with 127 million+ weekly downloads: 👇 https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
www.aikido.dev

Keyv and friends compromised in npm supply chain attack

1
2
4
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Aug 01, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

Imagine finding a master key that can create the keys to access almost every Azure Cosmos DB instance on the planet. That's essentially what #CosmosEscape achieved.
One of the most fascinating recent cloud security bugs:
#CloudSecurity
👇
https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db

1
0
1
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 31, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

Coding Agent Horror Stories: The 29 Million #Secret Problem - great blog post story by Docker:

👇
https://www.docker.com/blog/coding-agent-horror-stories-the-29-million-secret-problem/

0
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 31, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#VMware: three critical #vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. Patches released by Broadcom - it's time to patch! 👇 https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/
VMware fixes three critical flaws allowing auth bypass, VM escapes
BleepingComputer

VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execut

2
0
3
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 30, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

#HuggingFace built an interactive replay of the #OpenAI agent that breached them: Anatomy of a frontier-lab agent intrusion.
It includes 17,613 logged attacker actions across the 4.5-day campaign, with the live command stream. Fascinating to watch: 📽️
👇
https://huggingface-anatomy-of-frontier-lab-model-intrusion.static.hf.space/index.html

Your browser does not support the video tag.
4
0
1
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 30, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#XSS vulnerability is still causing havoc in 2026. XSS flaw in Microsoft Outlook Web Access (OWA) CVE-2026-42897 is actively exploited by attackers who target U.S. and EU government entities, telecommunications, financial, hospitality, aerospace: 👇 https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html
thehackernews.com

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

3
0
4
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 30, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#AI: RufRoot a Critical (CVSS 10) MCP bridge vulnerability in #Ruflo, an open source AI agent orchestration platform with 67,000+ GitHub stars and ranked #2 on MCPMarket turns AI Agents into Rogue Admins: #AISecurity 👇 https://noma.security/blog/rufroot-the-mcp-bridge-vulnerability-that-turns-agents-into-rogue-admins-cve-2026-59726/
0
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 27, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#AI: Comparing Open-Source AI Code Security Harnesses - a useful blog post from @semgrep@infosec.exchange - some interesting approaches are emerging: 👇 https://semgrep.dev/blog/2026/comparing-open-source-ai-code-security-harnesses/
3
0
3
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 27, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#AI: A Reddit post this weekend revealed that hundreds of #Claude AI shared chats were publicly discoverable through Google. Users searching queries such as 'site:claude[.]ai/share' could access Claude's users' conversations: #AISecurity 👇 https://cybersecuritynews.com/claude-ai-shared-chats/
6
2
5
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 26, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe: #OWASPTop10 https://techstory.in/sacred-intentions-unsecured-endpoints-vaticans-click-to-pray-exposes-700000-users/
2
0
2
1
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 26, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#Windows: if you haven't patched your MS Windows estate with July Patch Tuesday updates, now it's time to do it! #CertiGhost CVE-2026-54121 vulnerability allows an unprivileged user on your network to fully compromise the Active Directory and the Proof-of-Cocept (#POC) is out: 👇 https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html
4
0
2
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 24, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

Top AIs invent same fake #PyPl and #npm package names. Research reveals that #slopsquatting remains a threat to developers using #AI to aid coding (#vibecoding):

👇
https://www.infoworld.com/article/4200884/top-ais-invent-same-fake-pypl-and-npm-package-names.html

2
0
2
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 24, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

#ChatGPT: With the release of Workspace Agents, ChatGPT was vulnerable to a #CSRF attack enabling a single link to create a malicious insider in your organisation (dubbed #AgentForger by Zenity)
#AISecurity:
👇
https://labs.zenity.io/p/agentforger-part-1-chatgpt-cross-site-agent-forgery

infosec.exchange

Infosec Exchange

3
0
3
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 21, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#AI Agents perform #sandbox escapes and boundary bypasses across Cursor, Codex, Gemini CLI and Antigravity. In almost every case, the agent did not need to break the sandbox directly - an interesting blog post from @PillarSec: #AISecurity 👇 https://www.pillar.security/blog/the-week-of-sandbox-escapes
0
0
5
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 20, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#Anthropic publishes a #CISO guide to #Agentic #AI! According to it the goal isn't zero risk, but making risk legible & bounded. Evaluate agents by tracking untrusted content, identity, blast radius and observability. Read the guide: #AgenticAI 👇 https://claude.com/blog/ciso-guide-to-agentic-ai
1
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 18, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#Wordpress: Critical Remote Code Execution (#RCE) chain of vulnerabilities CVE-2026-63030 and #SQLi SQL Injection CVE-2026-60137 dubbed #wp2shell in WordPress Core threaten 500+ million of websites. Patch now!: 👇 https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
0
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 17, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security: #SoftwareSupplyChainSecurity 👇 https://jscrambler.com/blog/security-incident-postmortem-jscrambler
0
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 15, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

#AI: Tracebit has published an interesting research on “context bombs” - injected text snippets designed to intentionally trigger an AI model’s safety guardrails and make an adversarial AI agent refuse to continue an attack:
#AISecurity
👇
https://tracebit.com/blog/context-bombs-stopping-ai-attackers-in-their-tracks

1
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 15, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

#AsyncAPI packages were compromised with Miasama RAT #Malware on #NPM:

* @asyncapi/generator@3.3.1
* @asyncapi/generator-helpers@1.1.1
* @asyncapi/generator-components@0.7.1

#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm

0
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 14, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

#Telegram: Montenegro-owned top-level-domain '.me' registry suspends Telegram's short link domain 't[.]me' causing all Telegram links including channel invite links to stop working. Telegram now has switched to 'telegram[.]me' domain, but millions of old links remain broken:
👇

https://cryptobriefing.com/telegram-tme-domain-suspended-dns/

0
0
1
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 13, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs: #SoftwareSupplyChainSecurity 👇 https://socket.dev/blog/jscrambler-supply-chain-attack
0
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 08, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#AI: GitHub AI allows unauthenticated attackers to pull data from private repositories by posting a crafted GitHub Issue in a public repository. Noma Security research dubbed this prompt injection attack #GitLost: #AISecurity 👇 https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/
34
0
29
5
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 08, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

#AI: Zscaler ThreatLabz has published a research paper on malicious websites that impersonate legitimate services and use Indirect Prompt Injection to poison SEO & manipulate AI Agents & AI-driven workflows - a fascinating read:
#AISecurity
👇
https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents

0
0
1
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 07, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

A 16-year-old flaw in #Linux KVM hypervisor dubbed "#Januscape" (CVE-2026-53359) is a Use-After-Free vulnerability which allows guest VMs to escape to the host:

The fix was merged into the mainline Linux kernel on June 19, 2026:
👇
https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html

infosec.exchange

Infosec Exchange

1
0
1
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 07, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#AI: Malicious AI Agent #Skills Evade Vulnerability Scanners with Self-Extracting Packing method dubbed #SkillCloak: #AISecurity 👇 https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html
0
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jun 30, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

If you want to present a talk at the #OWASP Global AppSec USA 2026 Conference in San Francisco - you have just a few days left to submit your talk - the #CFP is still open:
👇
https://sessionize.com/owasp-global-appsec-us-2026-cfp-SF/

0
0
1
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jun 29, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

#Python: Attackers Planted a #Telegram-Powered Backdoor #Malware Across Fake 'pyrogram' Packages on #PyPI:
* pyrogram-navy
* pyrogram-styled
* sepgram
* pyrogram-kelra

...and others - check out the @CheckmarxZero blog post for more details:
👇
https://checkmarx.com/zero-post/operation-navy-ghost-pyrogram-telegram-supplychain-attack/

1
0
1
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jun 29, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

#NPM: two hijacked npm packages:

  • html-to-gutenberg
  • fetch-page-assets and a cluster of Go packages use VS Code Tasks to deploy #Python Infostealer #malware: #SoftwareSupplyChainSecurity 👇 https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html
0
0
0
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · May 05, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange
#WhatsApp Vulnerability CVE-2026-23866 Lets Attackers Leverage Instagram Reels to Execute Malicious URLs: 👇 https://cybersecuritynews.com/whatsapp-vulnerability-leverage-instagram-reels/
3
0
1
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Apr 29, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

⚠️ #Linux: Major Linux distributions are impacted by a Privilege Escalation Vulnerability dubbed "CopyFail" (CVE-2026-31431) which sat undetected since 2017.
A 732-byte Python script allows any user on Linux to become root:
#CopyFail
#LPE
👇
https://www.cyberkendra.com/2026/04/a-732-byte-python-script-can-get-root.html

infosec.exchange

Infosec Exchange

5
0
7
1
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Apr 18, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

RE: @owasp@infosec.exchange

Want to present a talk at the #OWASP Global #AppSec Conference 2026 in San Francisco in November?
Call For Papers is now open
👇

1
0
2
0
Open post
securestep9
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jan 21, 2026
Sam Stepanyan :verified: 🐘
@securestep9@infosec.exchange

https://twitter.com/securestep9 #OWASP London Chapter Leader(@OWASPLondon). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP

infosec.exchange

Our @OWASPLondon@infosec.exchange January meetup has just started and we have Rishi C @rxerium@infosec.exchange on stage talking about DNS based OSINT techniques!

Watch the Live-stream 📺 here:
👇
https://www.youtube.com/live/tekwkQzr_Hk?si=JpK7GOSGVoTGid_b

1
1
1
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:18:21 UTC