Another researcher drops a zero-day without disclosure because they're tired of dealing with MSRC

https://blog.ammaraskar.com/github-token-stealing/

1-Click GitHub Token Stealing via a VSCode Bug

My blog, mostly about programming

Ammar's Blog
@campuscodi I'm so happy I gave up VS Code for Zed. There have been way too many vulnerabilities lately.
@campuscodi all security researchers should start doing this!
@campuscodi as convenient as it may be, github.dev has just been one big mistake after another. Bugs aside, it’s a pretty big DLP risk many organizations don’t even know they have.
@campuscodi no-algorithm timelines with serendipitous posts are the best
@campuscodi It's almost as if Microsoft has a problem...