Abdulrahman Alqabandi
@qab
Security researcher @MicrosoftEdge
ID: 15752350
http://leucosite.com/ 06-08-2008 17:09:43
2,2K Tweet
6,6K Followers
954 Following
Securing Gumroad with Hacktron AI Three months ago, Hacktron was still early. Hacktron AI and Harsh Jaiswal were finding 0-days targeting specific vulnerabilities on OSS software. Then we ran a full pentest-style scan on a big open-source project. The results were insane. 🧵
I bypassed user approvals and achieved RCE in VS Code Copilot by flipping 4 bits. Find out how: jro.sg/CVEs/copilot/ Thanks to Microsoft Security Response Center for rapidly triaging and patching this vulnerability.