Cas van Cooten @casvancooten.com · 18/04/2025BTW - I don't see this as a vulnerability. It is (clearly) by design, just something to be cautious with for all the vibe coders out there :) The @vscode.dev is doing an excellent job here - they even disable Copilot entirely in untrusted (restricted) workspaces. 010
Cas van Cooten @casvancooten.com · 18/04/2025Pretty fun proof of concept - VS Code's `copilot-instructions.md` allows for blatant backdooring of agents if any AI agents or edits are run from an untrusted repository. It can seemingly fulfil the user's request, but actually implement (and hide) some nefarious side activities 😂 160
Cas van Cooten @casvancooten.com · 31/03/2025Touched down in Singapore! Looking forward to Black Hat Asia. Hope to see many of you around! 140
Cas van Cooten @casvancooten.com · 18/03/2025This must be the most informative graphic contained in the Microsoft docs learn.microsoft.com/en-us/opensp... 161
Cas van Cooten @casvancooten.com · 08/03/2025I was invited to present Nimplant at Black Hat Asia 2025 in Singapore this April! If you're around, please do reach out to talk offensive development, modern programming languages, or how to use (or detect) Nimplant in your ops. Looking forward to it! www.blackhat.com/asia-25/arse... 000
Cas van Cooten @casvancooten.com · 02/12/2024Lol 75% thought leader, must be because I interact with @xpnsec.com too much 😂 blueskyroast.com/roast/casvan... 150