SECURITYTHE REGISTER
Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures
Ammar Askar, a bug hunter, leaked a vulnerability in Microsoft's Visual Studio Code after becoming disillusioned with the company's handling of security reports. The exploit allows attackers to steal OAuth tokens via malicious extensions, compromising GitHub repos, and was disclosed publicly due to past negative experiences with Microsoft Security Response Center (MSRC).
Mentioned
Related Signal
Adjacent reporting
- Mystery Microsoft bug leaker keeps the zero-days coming
- Bug hunter tracks down three massive MCP flaws and one vendor won't fix theirs
- 'BlueHammer' Windows Zero-Day Exploit Signals Microsoft Bug Disclosure Issues
- CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
- NGINX Rift attackers waste no time targeting exposed servers
- Recent DeFi Exploits Highlight Ongoing Security Risks (~$800M Reported)