SECURITYRECORDED FUTURE NEWS
Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process
Security researcher Ammar Askar published a GitHub token-stealing proof-of-concept exploit on his blog and a public tracker for VS Code issues, notifying GitHub's security contact about an hour before the release. He criticized Microsoft's disclosure process for contributing to the situation.
Mentioned
Related Signal
Adjacent reporting
- 'BlueHammer' Windows Zero-Day Exploit Signals Microsoft Bug Disclosure Issues
- Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures
- One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
- Security researchers flag ongoing Stake DAO exploit after attacker mints trillions of vsdCRV
- User just tricked Grok and Bankrbot to send tokens with Morse code
- Vercel Employee's AI Tool Access Led to Data Breach