Heya, I'm Dimitar
Recent posts
all posts →- ANSI Escape Code Injection in OpenAI's Codex CLI Leading to RCE
How a simple unsanitized model parameter in Codex CLI leads from terminal spoofing to remote code execution
- Bypassing VSCode Copilot's Premium Requests
Bypassing VSCode Copilot's premium requests using an infinite loop
- Reverse Engineering: "Tzar The Burden of the Crown" - Part 1 (WDT Files)
Reverse Engineering: "Tzar The Burden of the Crown"
- Implementing custom autocomplete in VSCode
Implementing custom autocomplete in VSCode
- Bulgarian OSINT Guide
Guide to OSINT techniques for Bulgarian investigations.
- Tracking Down the Bulgarian Marketplace Scams
Investigation into Bulgarian marketplace scams.
CTF writeups
all writeups →Talks
all talks →- Hacking AI Agents: From Prompt Injection to Malicious MCP Servers
SoftUni — A deep dive into the attack surface of AI agents, covering prompt injection, jailbreaks, malicious MCP servers, weaponized skills, and agent-to-agent attacks.
- Converting Third-Party Threat Intelligence into VMware Carbon Black Cloud
VMware Explore 2022, San Francisco — A session on importing third-party threat intelligence data into VMware Carbon Black Cloud using a custom-built conversion tool.