Sign in

Michael Stepankin

@artsploit.com
211 followers 49 following 1 posts

Security Researcher at GitHub Security Lab, ex Portswigger. artsploit.blogspot.com

PostsRepliesMedia
Reposted by Michael Stepankin
GitHub Security Lab @securitylab.github.com · 25/08/2025
What if attackers could hijack your coding agent through a simple GitHub issue? Prompt injections are a real and growing threat for VS Code Copilot Agent. Learn how these attacks work and how you can defend your environment. Read the full research: github.blog/security/vul...
github.blog
Safeguarding VS Code against prompt injections
See how to reduce the risks of an indirect prompt injection, such as the exposure of confidential files or the execution of code without the user's consent.
052
Michael Stepankin @artsploit.com · 22/01/2025
Last year, I committed to uncovering critical vulnerabilities in Maven repositories. Now it’s time to share the findings: RCE in Sonatype Nexus, Cache Poisoning in JFrog Artifactory, and more! github.blog/security/vul...
12916
Reposted by Michael Stepankin
ϻг_ϻε @steven.srcincite.io · 26/11/2024
I just wrote a new blog post! This is how I (ab)used a jailed file write bug in Tomcat/Spring. Enjoy! Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...
srcincite.io
Remote Code Execution with Spring Properties
Recently a past student came to me with a very interesting unauthenticated vulnerability in a Spring application that they were having a hard time exploiting...
17636
Reposted by Michael Stepankin
James Kettle @jameskettle.com · 15/11/2024
How's your day going?
2252