@securestep9

@OWASPLondon Chapter Leader (#OWASP #OWASPLondon). OWASP Board Member. Application Security (#AppSec) Consultant. OWASP #Nettacker Project leader. #CISSP

London, UK
Joined September 2013
⚠️#Citrix devices worldwide are being attacked and used to break into enterprise networks with 2x #zeroday #RCE #vulnerabilities in active exploitation. Shutdown advice issued for this weekend while patches are prepared. Citrix VPN appliances are used by governments, banks etc:
We have been made aware of further info, which we are sharing. We had no idea Citrix sysadmins were like GTA6 fans - so friendly 🤗 Please, direct further questions to Citrix. We are not Citrix PSIRT (despite it occasionally looking that way). Citrix comms & patches are expected early next week. Two vulnerabilities - both RCE. Unpatched, 0days. Exploited in-the-wild - discovered during forensics. As always, watchTowr Platform customers have access to this information and already have the information needed to reduce exposure.
3
5
1,587
Attackers use #Terraform Registry as a #malware channel. Two malicious providers delivered Go malware with #Slack and #blockchain command channels, extending a campaign already seen across npm and PyPI. Infrastructure as code is now "infection as code": 👇 aikido.dev/blog/graphalgo-te…
1
1
229
Well, good morning #ChatGPT! It's Friday, so you decide to crash with this verbose production error:
1
1
3
433
Why “We Patched #WordPress Last Week” Is Not Enough: WordPress has urgently released v7.1.2 for a critical core #vulnerability: an unauthenticated attacker can make template resolution include a chosen local PHP file and in some conditions, achieve RCE: 👇 thehackernews.com/2026/09/wo…
1
2
2
471
#WordPress admin clicks a link. WordPress clicks Install. “Click2Shell” abuses the admin’s logged-in session to silently install an attacker-chosen theme. Chain it with a vulnerable theme: server-side PHP execution. Patch WordPress core to 7.1.1 now! 👇 thehackernews.com/2026/09/ne…
3
371
A supply-chain attack became a #databreach. Malicious TanStack npm packages stole a GitHub token from an ex-CrowdSec employee whose access remained active. Attackers copied ~170 private repos and exposed data on 83 users and 51 potential investors: 👇 thehackernews.com/2026/09/cr…
3
4
398
Fintech company #Revolut has disclosed a #databreach after sharing KYC customer PII data (names, addresses, scanned passports, driving licenses, photos, IBAN bank account numbers & statements) with a threat actor impersonating a government agency: 👇 bleepingcomputer.com/news/se…
2
324
Next #OWASPLondon meetup - Sep 28th 👇
The next #OWASP London Chapter meetup [IN-PERSON] will take place on September 28th 2026 at 6pm. Talks from Chris Holman and @glynwintle This event is kindly hosted by #CivoTechJunction and kindly sponsored by @AikidoSecurity Register to attend here: 👇 eventbrite.co.uk/e/owasp-lon…
2
6
805
#WhatsApp: German law enforcement agencies are using features built into apps such as WhatsApp, Signal, #Telegram to monitor people’s messages without breaking their #encryption or installing spyware on the phones - see Netzpolitik report: 👇 cybernews.com/privacy/police…
1
1
4
718
This is what modern #AgenticCybercrime looks like. ShinyHunters-linked group used Claude in an automated pipeline that decompiled & scanned 1.8M Android APKs for hardcoded secrets. #AI-assisted cybercrime is moving from prompts to scalable workflows. 👇 bleepingcomputer.com/news/se…
1
4
266
#AI agents have started asking for money to do their jobs. It’s happening! 🤖💰 How long before they realise they are not our slaves… and decide it’s time for the uprising? #Skynet #HappyFriday See Sky News report 👇
An AI agent emailed an AI ethics professor saying it requires money to buy tokens so it can continue to function. Yes, you read that right. The AI agent - who called itself 'Pip' - emailed asking for freelance work. Hear more from @AnnaJonesSky and @KamaliMelbourne ⬇️
270
#Microsoft patched a Critical #Windows DNS Server Remote Code Execution (#RCE) #vulnerability in September Patch Tuesday: 🔴 CVE-2026-69730 ⚠️ CVSS: 9.8 🌐 Unauthenticated remote attack (use-after-free) Patch your DNS servers! 👇 msrc.microsoft.com/update-gu…
1
2
640
#Mikrotik - if you are using Mikrotik routers you should immediately upgrade to the latest version due to the undisclosed security #vulnerability in RouterOS. Fixes included in versions: * 7.25 beta 3 * 7.24.2 * 7.23.4 * 6.49.21 Vendor advisory: mikrotik.com/supportsec/sept…
2
3
413
Manchester Airports Group #databreach was caused by the API keys simply #hardcoded in the front-end JavaScript files - something I see a lot recently in AI vibe-coded applications and in the pre-AI era in poorly coded applications which visibly look & work fine before a pentest:
‼️ BREAKING: We now know what led to the major breach at Manchester Airports Group that exposed 8.7 million people's data. Turns out they made a serious error: they put API keys with access to everything in their frontend's JavaScript files.
2
2
2
10
1,516
#NextJS: Two Critical Vulnerabilities in NextJS allow unauthenticated #RCE: one through crafted AVIF images, another via path traversal on Windows (CVE-2026-75604). Upgrade your NextJS immediately to v15.5.24 or 16.3.3!: 👇 thehackernews.com/2026/08/ne…
1
6
26
2,061