Skip to content
The Nexus
DossierENTITY

Ammar Askar

Coverage of Ammar Askar in the Nexus archive.

Earliest in view: Jun 3 · 12:58 UTCMost recent: Jun 4 · 13:37 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJun 4 · 13:37 UTCRECORDED FUTURE NEWS
    Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process

    Security researcher Ammar Askar published a GitHub token-stealing proof-of-concept exploit on his blog and a public tracker for VS Code issues, notifying GitHub's security contact about an hour before the release. He criticized Microsoft's disclosure process for contributing to the situation.

  • SECURITYJun 3 · 14:30 UTCTHE REGISTER
    Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures

    Ammar Askar, a bug hunter, leaked a vulnerability in Microsoft's Visual Studio Code after becoming disillusioned with the company's handling of security reports. The exploit allows attackers to steal OAuth tokens via malicious extensions, compromising GitHub repos, and was disclosed publicly due to past negative experiences with Microsoft Security Response Center (MSRC).

  • SECURITYJun 3 · 12:58 UTCTHE HACKER NEWS
    One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens

    Cybersecurity researchers disclosed a one-click attack via Microsoft Visual Studio Code that can steal GitHub OAuth tokens, allowing attackers to read and write to user repositories, including private ones. The attack exploits GitHub's GitHub.dev feature, enabling token theft through a malicious link click.

Ammar Askar · Dossier · The Nexus