MaccariTA (@ari_maccarita) 's Twitter Profile
MaccariTA

@ari_maccarita

Security Researcher | ex-Content Creator @ youtube.com/maccarita

ID: 716274190714855426

linkhttps://www.maccarita.com/ calendar_today02-04-2016 14:40:49

29 Tweet

661 Followers

17 Following

MaccariTA (@ari_maccarita) 's Twitter Profile Photo

It's been a pleasure working with @MoonsworthLLC on the Lunar Network. I'd like to thank my guys @macguymc Jordan Matt Griffin I started content creation few months back (youtube.com/MaccariTA) and it's time to move forward. <3

MaccariTA (@ari_maccarita) 's Twitter Profile Photo

I found 22 CVEs (and counting...) in AI IDEs this year. As part of this research, I discovered a new vulnerability class in AI IDEs. It's an ๐—œ๐——๐—˜๐˜€๐—ฎ๐˜€๐˜๐—ฒ๐—ฟ. ๐ŸŽค Come listen to my talk at - Bsides Warsaw (Nov 28th) - BSidesPorto (Nov 29th) - BSides Dresden (Dec 6th)

I found 22 CVEs (and counting...) in AI IDEs this year. As part of this research, I discovered a new vulnerability class in AI IDEs. It's an ๐—œ๐——๐—˜๐˜€๐—ฎ๐˜€๐˜๐—ฒ๐—ฟ.
 
๐ŸŽค Come listen to my talk at
- <a href="/BSidesWarsaw/">Bsides Warsaw</a> (Nov 28th)
- <a href="/bsidesporto/">BSidesPorto</a>  (Nov 29th)
- <a href="/BSidesDresden/">BSides Dresden</a>  (Dec 6th)
MaccariTA (@ari_maccarita) 's Twitter Profile Photo

I bypassed CVE-2025-53773. The ๐—ฅ๐—–๐—˜ previously reported in GitHub's ๐—–๐—ผ๐—ฝ๐—ถ๐—น๐—ผ๐˜. Microsoft released the fix recently (CVE-2025-64660) - update! Less than 10 days for IDEsaster. Are you ready? Follow so you don't miss it. #aisecurity #idesaster

I bypassed CVE-2025-53773. The ๐—ฅ๐—–๐—˜ previously reported in GitHub's ๐—–๐—ผ๐—ฝ๐—ถ๐—น๐—ผ๐˜.
Microsoft released the fix recently (CVE-2025-64660) - update!
 
Less than 10 days for IDEsaster. Are you ready?
Follow so you don't miss it.

#aisecurity #idesaster
The Hacker News (@thehackersnews) 's Twitter Profile Photo

๐Ÿ›‘ Over 30 security flaws found in AI-powered coding tools like Copilot, Cursor, and Zed โ€” letting hackers steal data or run malicious code without you doing a thing. Researchers are calling it โ€œIDEsaster.โ€ ๐Ÿ”— Details here โ†’ thehackernews.com/2025/12/researโ€ฆ

Lord Steak (@adrian__t) 's Twitter Profile Photo

This yearโ€™s BSides Dresden was an incredible experience, and Iโ€™m genuinely grateful we had the chance to be part of it in more ways than one. FORTBRIDGE was honored to sponsor and contribute to the event, and itโ€™s been inspiring to support a conference that brings so much

This yearโ€™s <a href="/BSidesDresden/">BSides Dresden</a> was an incredible experience, and Iโ€™m genuinely grateful we had the chance to be part of it in more ways than one. 

<a href="/FORTBRIDGE/">FORTBRIDGE</a> was honored to sponsor and contribute to the event, and itโ€™s been inspiring to support a conference that brings so much
AISecHub (@aisechub) 's Twitter Profile Photo

Top AI Security Monthly Insights โ€“ December 2025 1๏ธโƒฃ Microsoft Copilot Studio Security Risk: How Simple Prompt Injection Leaked Credit Cards and Booked a $0 Trip - tenable.com/blog/microsoftโ€ฆ - Guy Zetland and Keren Katz at Tenable 2๏ธโƒฃ 186 Jailbreaks: Applying MLOps to AI

Top AI Security Monthly Insights โ€“ December 2025

1๏ธโƒฃ Microsoft Copilot Studio Security Risk: How Simple Prompt Injection Leaked Credit Cards and Booked a $0 Trip - tenable.com/blog/microsoftโ€ฆ - Guy Zetland and Keren Katz at <a href="/TenableSecurity/">Tenable</a>

2๏ธโƒฃ 186 Jailbreaks: Applying MLOps to AI
MaccariTA (@ari_maccarita) 's Twitter Profile Photo

Are you actually doing the work in AI security? Share it with us! I'm excited to take part in the CFP board for [un]prompted,ย a community conference for AI security practitioners (Salesforce Tower in San Francisco, March 3-4). More information --> unpromptedcon.org

Are you actually doing the work in AI security? Share it with us!

I'm excited to take part in the CFP board for [un]prompted,ย a community conference for AI security practitioners (Salesforce Tower in San Francisco, March 3-4).

More information --&gt; unpromptedcon.org
MaccariTA (@ari_maccarita) 's Twitter Profile Photo

We received an EXTREME amount of submissions for [un]prompted. It took a while but the agenda is out. See you in San Francisco! Thanks Gadi Evron for the initiative. The entire CFP team and my employer Microsoft for the opportunity to be there ๐Ÿ™

We received an EXTREME amount of submissions for [un]prompted. It took a while but the agenda is out. See you in San Francisco!

Thanks <a href="/gadievron/">Gadi Evron</a> for the initiative. The entire CFP team and my employer <a href="/Microsoft/">Microsoft</a> for the opportunity to be there ๐Ÿ™
Confidence Staveley (@sisinerdtweets) 's Twitter Profile Photo

This dude tested all the major AI coding tools. Guess what? He found vulnerabilities in every single one! In todayโ€™s podcast, I sat with him (MaccariTA) to discuss how he found 30+ vulnerabilities across GitHub Copilot, Cursor, Claude Code and more. This chat exposes how

Confidence Staveley (@sisinerdtweets) 's Twitter Profile Photo

"Every single IDE feature might be your next vulnerability." ๐Ÿ‘€ In the last episode of AI Cyber Podcast, Ari Marzuk (MaccariTA) explained that IDEs were built before AI agents existed and features that seemed harmless are now potential vulnerabilities waiting to be

Black Hat (@blackhatevents) 's Twitter Profile Photo

Black Hat Asia Speaker Spotlight Series ๐ŸŽฌ Meet Ari (MaccariTA) Marzouk MaccariTA, Senior Security Researcher, Microsoft Red Team, as he answers three key questions in our latest Speaker Spotlight: ๐Ÿ‘‰ What are you most excited about Black Hat Asia? ๐Ÿ‘‰ What will your session