Sam Stepanyan
@securestep9.bsky.social
980 followers
120 following
160 posts
OWASP London Chapter Leader. #OWASP Global Board Member. OWASP Nettacker Project Leader. #AppSec Consultant, #CISSP. Follow me on Twitter/X and Mastodon https://twitter.com/securestep9 https://infosec.exchange/@securestep9
Posts
Media
Videos
Starter Packs
Sam Stepanyan
@securestep9.bsky.social
· Sep 18
Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions
Google releases critical Chrome update patching zero-day CVE-2025-10585, discovered Sept 16, to block active V8 JavaScript engine exploits worldwide.
thehackernews.com
Sam Stepanyan
@securestep9.bsky.social
· Sep 16
ctrl/tinycolor and 40+ NPM Packages Compromised - StepSecurity
The popular @ctrl/tinycolor package with over 2 million weekly downloads has been compromised alongside 40+ other NPM packages in a sophisticated supply chain attack. The malware self-propagates across maintainer packages, harvests AWS/GCP/Azure credentials using TruffleHog, and establishes persistence through GitHub Actions backdoors - representing a major escalation in NPM ecosystem threats.
www.stepsecurity.io
Sam Stepanyan
@securestep9.bsky.social
· Aug 28
Nx build platform compromised by supply chain attack – How attackers collude with AI code assistants | Blog | Endor Labs
Nx supply chain attack: malicious npm versions of Nx exfiltrated SSH keys and tokens to GitHub—abusing AI code assistants. Learn how to detect and fix.
www.endorlabs.com
Sam Stepanyan
@securestep9.bsky.social
· Aug 26
Citrix fixes critical NetScaler RCE flaw exploited in zero-day attacks
Citrix fixed three NetScaler ADC and NetScaler Gateway flaws today, including a critical remote code execution flaw tracked as CVE-2025-7775 that was actively exploited in attacks as a zero-day vulnerability.
www.bleepingcomputer.com