Ammar Askar
Coverage of Ammar Askar in the Nexus archive.
- Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process
Security researcher Ammar Askar published a GitHub token-stealing proof-of-concept exploit on his blog and a public tracker for VS Code issues, notifying GitHub's security contact about an hour before the release. He criticized Microsoft's disclosure process for contributing to the situation.
- Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures
Ammar Askar, a bug hunter, leaked a vulnerability in Microsoft's Visual Studio Code after becoming disillusioned with the company's handling of security reports. The exploit allows attackers to steal OAuth tokens via malicious extensions, compromising GitHub repos, and was disclosed publicly due to past negative experiences with Microsoft Security Response Center (MSRC).
- One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
Cybersecurity researchers disclosed a one-click attack via Microsoft Visual Studio Code that can steal GitHub OAuth tokens, allowing attackers to read and write to user repositories, including private ones. The attack exploits GitHub's GitHub.dev feature, enabling token theft through a malicious link click.