Sam Stepanyan
@securestep9
OWASP London Chapter Leader. #OWASP Global Board Member. OWASP #Nettacker Project Leader. #AppSec Consultant, #CISSP. Follow me on Twitter/X and Mastodon
Good morning from the #OWASP Global AppSec EU 2026 Conference in Vienna, Austria where @joshcgrossman.com just kicked off this amazing conference with 1000+ attendees, 45+ speakers, lots of workshops and activities - check out the agenda here: 👇 owaspglobalappseceuvienna20.sched.com/list/simple
Attending and speaking at the #OWASP Global AppSec EU 2026 Conference in Vienna, Austria this week! This year’s conference is particularly special as the OWASP Foundation celebrates 25 years! Welcoming everyone alongside fellow OWASP Board Member L B Ricardo Griffith!
#OWASP #JuiceShop v20.0.0 released with brand new AI challenges including: * Chatbot Prompt Injection * Greedy Chatbot Manipulation * AI Debugging 👇 owasp.org/blog/2026/...
"A swarm of agents! Everywhere!" I was watching a 1983 British spy thriller starring Michael Caine and Laurence Olivier and then I hear this 25 minutes in😮: 🔊
Just re-watched Spiderman2 on Netflix (shot in 2004) where Dr Octopus has AI-controlled Claws attached to his body using tentacles, neuro-linked to his brain with a "guardrail" microchip making sure the AI in the claws does not go rogue, and it does... Eerie watching this in 2026:🦞
#Wordpress: 100,000+ WordPress Websites Affected by Remote Code Execution (#RCE) #vulnerability in Advanced Custom Fields Plugin: 👇 www.wordfence.com/blog/2025/12...
Many thanks to everyone who attended my OWASP #Nettacker talk at the #OWASP Global AppSec 2025 Conference in Washington, DC. 👉https://github.com/OWASP/Nettacker
#AI: HackedGPT: Novel AI Vulnerabilities Open the Door for Private Data Leakage: unique indirect prompt injections, exfiltration of personal user information, persistence, evasion, and bypass of safety mechanisms: #AISecurity www.tenable.com/blog...
If you are attending #OWASP #LASCON (@LASCONATX) 2025 Conference in Austin, Texas don't miss my talk on the OWASP #Nettacker Project at 1pm CDT in the Read Oak Ballroom: lascon.org/schedule/
I am running for re-election to the OWASP Global Board of Directors in 2025. 🗳️OWASP Global Board Elections have started and all OWASP Members should have received an email with the e-ballot yesterday. owasp.org/www-board-ca... Thank you for your support!
#Azure: a token validation vulnerability allowing to get Global Admin in any Entra ID tenant(CVE-2025-55241) found by @dirkjanm.io #CloudSecurity 👇 dirkjanm.io/obtaining-gl...
I donated blood today! #OWASP is running a blood donation drive in honour of Sherif Mansour - @owasplondon.bsky.social Chapter Leader and OWASP Board Chairman 2021 who was recently diagnosed with leukemia. Please help him and everyone who needs blood: donate! 👇 owasp.org/blog/2025/08...
#MCP Horror Story: Hackers leaked sensitive data from a private GitHub repo by planting a prompt injection in a public #GitHub issue abusing GitHub MCP Server: #AISecurity #PromptInjection 👇 www.docker.com/blog/...
#AI: "Prompt injection, the lethal trifecta, and the challenges of securing systems that use MCP" - a great blog post from @simonwillison.net - A must-read for everyone in InfoSec desperately trying to explain the dangers of blind adoption of #MCP: #AISecurity 👇 simonwillison.net/2025/Aug/9/b...
#WhatsApp is finally rolling out a feature that warns you if someone not in your contacts adds you to a WhatsApp group. This feature directly targets a common tactic that is used to spread scam messages and vulnerabilities via WhatsApp: about.fb.com/news/20...
#AI: "How we rooted Copilot" #AISecurity 👇 research.eye.security/how-we-roote...
Many thanks everyone who came to my talk on the OWASP Nettacker project at the #OWASP Global AppSec 2025 Conference in Barcelona! Several attendees will be joining us to collaborate and contribute! 🚀 👉 github.com/OWASP/Net...
If you are attending the OWASP Global AppSec 2025 conference in Barcelona and if you are an OWASP member you can grab a challenge coin 🪙 from the members lounge (room 111)! You can also join OWASP as a member at the conference! 👇
#AI: "Creating Secure Covert Channels with LLMs over Public Channels" by @billatnapier - mind-blowing 🤯! AI agents can pass information between them, and humans would not be able to detect that secret messages were being sent within valid-looking text! 👇 billatnapier.medium.com/creating-sec...
Our meetup has started and we have John Wood and Aurelien Svevi on stage talking about protecting APIs and applications at run-time. Watch the live-stream 📺 here: 👇 www.youtube.com/live/uhFpUjd...