Skip to content
The Nexus
SECURITYJun 4 · 13:37 UTCRECORDED FUTURE NEWS

Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process

Security researcher Ammar Askar published a GitHub token-stealing proof-of-concept exploit on his blog and a public tracker for VS Code issues, notifying GitHub's security contact about an hour before the release. He criticized Microsoft's disclosure process for contributing to the situation.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting