News
RCE in VSCode Copilot Chat
5+ day, 15+ hour ago (508+ words) Hacktron reviews your code and finds real vulnerabilities before they ship to production. Copilot agent mode is vulnerable to a prompt injection attack. If a repository maintainer clicks "code with agent mode" on an issue, it will open a new…...
Blog
1+ year, 1+ week ago (634+ words) We are opening up Hacktron Review for Open Source, giving qualifying maintainers free PR security reviews with inline findings, auto-resolution, and project-specific learning. Working with Vercel Team to Keep the Internet Secure from React2 Shell Hacktron Review is an AI security…...
$170k in Bypasses: The Vercel React2 Shell Challenge
1+ week, 6+ day ago (1334+ words) Hacktron reviews your code and finds real vulnerabilities before they ship to production. We won't be diving into the full internals of the bug here. If you want a solid technical breakdown of how React2 Shell works, I recommend the deep…...
I Let Claude Opus Write a Chrome Exploit: The Next Model (Mythos?) Won't Need My Help?
1+ mon, 2+ day ago (1801+ words) Hacktron reviews your code and finds real vulnerabilities before they ship to production. TLDR: I pointed Claude Opus at Discord's bundled Chrome (version 138, nine major versions behind upstream) and asked it to build a full V8 exploit chain. The V8 OOB we…...