News

Hacktron AI
hacktron. ai > blog > rce-in-vscode-copilot

RCE in VSCode Copilot Chat

5+ day, 15+ hour ago  (508+ words) Hacktron reviews your code and finds real vulnerabilities before they ship to production. Copilot agent mode is vulnerable to a prompt injection attack. If a repository maintainer clicks "code with agent mode" on an issue, it will open a new…...

Hacktron AI
hacktron. ai > blog

Blog

1+ year, 1+ week ago  (634+ words) We are opening up Hacktron Review for Open Source, giving qualifying maintainers free PR security reviews with inline findings, auto-resolution, and project-specific learning. Working with Vercel Team to Keep the Internet Secure from React2 Shell Hacktron Review is an AI security…...

Symbols: render,not-so,nasdaq:bzfd
Hacktron AI
hacktron. ai > blog > react2shell-vercel-waf-bypass

$170k in Bypasses: The Vercel React2 Shell Challenge

1+ week, 6+ day ago  (1334+ words) Hacktron reviews your code and finds real vulnerabilities before they ship to production. We won't be diving into the full internals of the bug here. If you want a solid technical breakdown of how React2 Shell works, I recommend the deep…...

Symbols: index.js
Hacktron AI
hacktron. ai > blog > i-let-claude-opus-to-write-me-a-chrome-exploit

I Let Claude Opus Write a Chrome Exploit: The Next Model (Mythos?) Won't Need My Help?

1+ mon, 2+ day ago  (1801+ words) Hacktron reviews your code and finds real vulnerabilities before they ship to production. TLDR: I pointed Claude Opus at Discord's bundled Chrome (version 138, nine major versions behind upstream) and asked it to build a full V8 exploit chain. The V8 OOB we…...

Symbols: queryts,sse:when