news.mlab.sh
Back to the feed
threat-intel

Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process

High
Summary

A security researcher, Ammar Askar, released a GitHub token-stealing exploit for Microsoft's VS Code, citing frustration with the company's vulnerability disclosure process. This follows a recent breach of GitHub repositories by TeamPCP and highlights a growing trend of researchers bypassing Microsoft's channels to publicly release exploits. The situation underscores concerns about the responsiveness and transparency of Microsoft's security response team.

The vulnerability, discovered and subsequently released by Ammar Askar, allows attackers to steal GitHub access tokens through a simple link click within VS Code. This exploit emerged amidst ongoing concerns about Microsoft's handling of vulnerability disclosures, particularly following a previous incident where Askar's report was silently fixed without attribution or acknowledgment. The release of this exploit, along with similar actions by other researchers like Nightmare Eclipse, reflects a broader dissatisfaction within the security community regarding Microsoft's processes. This has led to increased risk for developers and organizations who may be exposed before a fix is implemented.

Read the full article at The Record