Sam Stepanyan

@securestep9.bsky.social

OWASP London Chapter Leader. #OWASP Global Board Member. OWASP #Nettacker Project Leader. #AppSec Consultant, #CISSP. Follow me on Twitter/X and Mastodon https://twitter.com/securestep9 https://infosec.exchange/@securestep9

#npm: A massive #SupplyChain attack has compromised 868+ npm packages carrying 2 billion+ monthly installs with a credential-stealing worm. It started with the compromise of the #GitHub account of the #keyv library with 127 million+ weekly downloads: 👇 www.aikido.dev/blog/keyv-an...

Keyv and friends compromised in npm supply chain attack

Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account

aikido.dev

Imagine finding a master key that can create the keys to access almost every Azure Cosmos DB instance on the planet. That's essentially what #CosmosEscape achieved. One of the most fascinating recent cloud security bugs: #CloudSecurity 👇 www.wiz.io/blog/cosmose...

CosmosEscape: Taking Over Every Azure Cosmos DB | Wiz Blog

Wiz Research details CosmosEscape, a critical vulnerability in Azure Cosmos DB that granted full read/write access to every database. Now fully remediated.

wiz.io

#XSS vulnerability is still causing havoc in 2026. XSS flaw in Microsoft Outlook Web Access (OWA) CVE-2026-42897 is actively exploited by attackers who target U.S. and EU government entities, telecommunications, financial, hospitality, aerospace: 👇 thehackernews.com/2026/07/russ...

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Russian hackers exploit CVE-2026-42897 in OWA to deploy OWAReaper, a browser implant that persists through credential rotation and device re-imaging.

thehackernews.com

#AI: A Reddit post this weekend revealed that hundreds of #Claude AI shared chats were publicly discoverable through Google. Users searching queries such as 'site:claude[.]ai/share' could access Claude's users' conversations: #AISecurity 👇

Claude AI Shared Chats Reportedly Exposed in Google Search Results

Anthropic’s Claude share links appeared in public search results, raising fresh privacy concerns for users who shared sensitive conversations.

cybersecuritynews.com

#Windows: if you haven't patched your MS Windows estate with July Patch Tuesday updates, now it's time to do it! #CertiGhost CVE-2026-54121 vulnerability allows an unprivileged user on your network to fully compromise the Active Directory - the public #POC is out: 👇 thehackernews.com/2026/07/cert...

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Certighost exploit lets a domain user obtain a Domain Controller certificate and reach DCSync through a vulnerable AD CS chase.

thehackernews.com

#Telegram: Montenegro-owned top-level-domain '.me' registry suspends Telegram's short link domain 't[.]me' causing all Telegram links including channel invite links to stop working. Telegram has now switched to 'telegram[.]me' domain: 👇 cryptobriefing.com/telegram-tme...

Telegram's t.me domain goes offline after registry suspension

Telegram's t.me domain has been suspended by the .me registry and removed from DNS, breaking all shared links and raising questions for crypto communities.

cryptobriefing.com

#NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs: #SoftwareSupplyChainSecurity 👇

jscrambler npm Package Compromised in Supply Chain Attack - ...

A compromised jscrambler npm release added a malicious preinstall hook that runs hidden native binaries on Linux, macOS, and Windows.

socket.dev

#AI: Zscaler ThreatLabz has published a research paper on malicious websites that impersonate legitimate services and use Indirect Prompt Injection to poison SEO & manipulate AI Agents & AI-driven workflows - a fascinating read: #AISecurity 👇 www.zscaler.com/blogs/securi...

Indirect Prompt Injection Targets AI Agents | ThreatLabz

ThreatLabz details indirect prompt injection hidden in malicious webpages meant to mislead AI agents performing tasks.

zscaler.com

A 16-year-old flaw in #Linux KVM hypervisor dubbed "#Januscape" (CVE-2026-53359) is a Use-After-Free vulnerability which allows guest VMs to escape to the host: The fix was merged into the mainline Linux kernel on June 19, 2026: 👇

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

Januscape abuses KVM shadow MMU page reuse to panic x86 hosts, with Kim reporting a controlled full escape exploit behind the unreleased path.

thehackernews.com