Prompt injections are a serious concern for VS Code Copilot Agent.
Discover how attackers can create GitHub issues with harmful instructions and find out how to protect the coding agent effectively.
Last year, I committed to uncovering critical vulnerabilities in Maven repositories. Now it’s time to share the findings: RCE in Sonatype Nexus, Cache Poisoning in JFrog Artifactory, and more! Read it all below 🧵
Just submitted a CFP to @ekoparty where I want to talk about breaking Maven repository managers. This is the one of the craziest and fruitful research projects I've done in my career.