> Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process
[DATE: 04/06/2026 13:37]
[LANGUAGE: EN]
The security researcher, Ammar Askar, released the new proof-of-concept exploit on his personal blog — alongside the public tracker for issues in VS Code — giving a GitHub security contact roughly one hour's notice beforehand.