Log inSign up
Michael Stepankin
293 posts
@artsploit

Michael Stepankin

@artsploit
Agent Security Engineer at @Google
Zurich, Switzerland
artsploit.blogspot.com
Joined July 2014
569
Following
6,961
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @artsploit
    Michael Stepankin
    @artsploit
    Aug 25, 2025
    Prompt injections are a serious concern for VS Code Copilot Agent. Discover how attackers can create GitHub issues with harmful instructions and find out how to protect the coding agent effectively.
    github.blog
    Safeguarding VS Code against prompt injections
    See how to reduce the risks of an indirect prompt injection, such as the exposure of confidential files or the execution of code without the user's consent.
    1
  • @artsploit
    Michael Stepankin
    @artsploit
    Jan 22, 2025
    Last year, I committed to uncovering critical vulnerabilities in Maven repositories. Now it’s time to share the findings: RCE in Sonatype Nexus, Cache Poisoning in JFrog Artifactory, and more! Read it all below 🧵
    Image
    7
  • @artsploit
    Michael Stepankin
    @artsploit
    Oct 3, 2024
    Hyped to speak at @ekoparty in November!
    @ekoparty
    Ekoparty | Hacking everything
    @ekoparty
    Oct 2, 2024
    Replying to @ekoparty
    Image
    1
  • @artsploit
    Michael Stepankin
    @artsploit
    Aug 21, 2024
    Just submitted a CFP to @ekoparty where I want to talk about breaking Maven repository managers. This is the one of the craziest and fruitful research projects I've done in my career.
    3
  • @artsploit
    Michael Stepankin
    @artsploit
    Jul 22, 2024
    Kafka UI can be a juicy target for bug hunters, here is why:
    Image
    3 ways to get Remote Code Execution in Kafka UI
    From github.blog
    1
Advertisement
Advertisement