@securestep9i
iAccount based inUnited Kingdom!
About this account
- Account based in
- United Kingdom
- Connected via
- United Kingdom Android App
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
@OWASPLondon Chapter Leader (#OWASP #OWASPLondon). OWASP Board Member. Application Security (#AppSec) Consultant. OWASP #Nettacker Project leader. #CISSP
London, UK
Joined September 2013
- Tweets5.5K
- Following3.7K
- Followers7.4K
- Likes11.4K
⚠️#Citrix devices worldwide are being attacked and used to break into enterprise networks with 2x #zeroday #RCE #vulnerabilities in active exploitation. Shutdown advice issued for this weekend while patches are prepared.
Citrix VPN appliances are used by governments, banks etc:
We have been made aware of further info, which we are sharing. We had no idea Citrix sysadmins were like GTA6 fans - so friendly 🤗
Please, direct further questions to Citrix. We are not Citrix PSIRT (despite it occasionally looking that way).
Citrix comms & patches are expected early next week.
Two vulnerabilities - both RCE.
Unpatched, 0days.
Exploited in-the-wild - discovered during forensics.
As always, watchTowr Platform customers have access to this information and already have the information needed to reduce exposure.
Attackers use #Terraform Registry as a #malware channel. Two malicious providers delivered Go malware with #Slack and #blockchain command channels, extending a campaign already seen across npm and PyPI. Infrastructure as code is now "infection as code":
👇
aikido.dev/blog/graphalgo-te…
Well, good morning #ChatGPT! It's Friday, so you decide to crash with this verbose production error:
Why “We Patched #WordPress Last Week” Is Not Enough: WordPress has urgently released v7.1.2 for a critical core #vulnerability: an unauthenticated attacker can make template resolution include a chosen local PHP file and in some conditions, achieve RCE:
👇
thehackernews.com/2026/09/wo…
#WordPress “Comment2Shell” turns anonymous stored #XSS vulnerability into server code execution when an admin views the comment.
It abuses the admin session to upload a malicious plugin. Patch now!
👇
idnsec.com/research/comment2…
#WordPress admin clicks a link. WordPress clicks Install.
“Click2Shell” abuses the admin’s logged-in session to silently install an attacker-chosen theme. Chain it with a vulnerable theme: server-side PHP execution.
Patch WordPress core to 7.1.1 now! 👇
thehackernews.com/2026/09/ne…
A supply-chain attack became a #databreach.
Malicious TanStack npm packages stole a GitHub token from an ex-CrowdSec employee whose access remained active. Attackers copied ~170 private repos and exposed data on 83 users and 51 potential investors:
👇
thehackernews.com/2026/09/cr…
Fintech company #Revolut has disclosed a #databreach after sharing KYC customer PII data (names, addresses, scanned passports, driving licenses, photos, IBAN bank account numbers & statements) with a threat actor impersonating a government agency:
👇
bleepingcomputer.com/news/se…
Next #OWASPLondon meetup - Sep 28th
👇
The next #OWASP London Chapter meetup [IN-PERSON] will take place on September 28th 2026 at 6pm. Talks from Chris Holman and @glynwintle
This event is kindly hosted by #CivoTechJunction and kindly sponsored by @AikidoSecurity
Register to attend here:
👇
eventbrite.co.uk/e/owasp-lon…
#OWASP GenAI Security Project publishes the "project Crosswalk" - an open-source resource which maps AI risks to compliance requirements from 25 regulatory frameworks NIST, ISO, #MITRE ATLAS, the EU #AI Act and others:
#AISecurity
👇
genai.owasp.org/resource/gen…
#WhatsApp: German law enforcement agencies are using features built into apps such as WhatsApp, Signal, #Telegram to monitor people’s messages without breaking their #encryption or installing spyware on the phones - see Netzpolitik report:
👇
cybernews.com/privacy/police…
This is what modern #AgenticCybercrime looks like.
ShinyHunters-linked group used Claude in an automated pipeline that decompiled & scanned 1.8M Android APKs for hardcoded secrets.
#AI-assisted cybercrime is moving from prompts to scalable workflows.
👇
bleepingcomputer.com/news/se…
#AI agents have started asking for money to do their jobs.
It’s happening! 🤖💰
How long before they realise they are not our slaves… and decide it’s time for the uprising?
#Skynet
#HappyFriday
See Sky News report 👇
An AI agent emailed an AI ethics professor saying it requires money to buy tokens so it can continue to function. Yes, you read that right.
The AI agent - who called itself 'Pip' - emailed asking for freelance work.
Hear more from @AnnaJonesSky and @KamaliMelbourne ⬇️
AI agent sends email to human asking for work
#Microsoft patched a Critical #Windows DNS Server Remote Code Execution (#RCE) #vulnerability in September Patch Tuesday:
🔴 CVE-2026-69730
⚠️ CVSS: 9.8
🌐 Unauthenticated remote attack (use-after-free)
Patch your DNS servers!
👇
msrc.microsoft.com/update-gu…
#Microsoft #Copilot #Cowork Sandbox Bypass #Vulnerability Gives Attackers Remote Control:
#AISecurity
promptarmor.com/resources/mi…
#Mikrotik - if you are using Mikrotik routers you should immediately upgrade to the latest version due to the undisclosed security #vulnerability in RouterOS.
Fixes included in versions:
* 7.25 beta 3
* 7.24.2
* 7.23.4
* 6.49.21
Vendor advisory:
mikrotik.com/supportsec/sept…
#JFrog #Artifactory: Attackers are already exploiting critical auth bypass CVE-2026-82329 (CVSS 9.8) to mint admin tokens. Compromising your organisation's artifact repository could poison builds and trigger #SoftwareSupplyChain attacks - patch now!
👇
csoonline.com/article/421753…
Manchester Airports Group #databreach was caused by the API keys simply #hardcoded in the front-end JavaScript files - something I see a lot recently in AI vibe-coded applications and in the pre-AI era in poorly coded applications which visibly look & work fine before a pentest:
#GCP: A comment on a single public #GitHub repo issue (gemini-cli 100k+ stars) was enough for an unauthenticated attacker to take over a Google Cloud project abusing Workload Identity Federation(WIF) in exploit chain - great research from @Pillar_sec :
👇
pillar.security/blog/a-wif-o…
#NextJS: Two Critical Vulnerabilities in NextJS allow unauthenticated #RCE: one through crafted AVIF images, another via path traversal on Windows (CVE-2026-75604).
Upgrade your NextJS immediately to v15.5.24 or 16.3.3!:
👇
thehackernews.com/2026/08/ne…