Advertisement ยท 728 ร— 90

Posts by Cas van Cooten

Post image

Not thinking about infosec for a while ๐Ÿฅฐ

11 months ago 27 0 6 0
Post image

BTW - I don't see this as a vulnerability. It is (clearly) by design, just something to be cautious with for all the vibe coders out there :)

The @vscode.dev is doing an excellent job here - they even disable Copilot entirely in untrusted (restricted) workspaces.

1 year ago 1 0 0 0
Video

quack.py needs work still

1 year ago 1 0 0 0
Post image

10/10 no notes, excellent blending in

1 year ago 2 1 2 0
Post image

Pretty fun proof of concept - VS Code's `copilot-instructions.md` allows for blatant backdooring of agents if any AI agents or edits are run from an untrusted repository. It can seemingly fulfil the user's request, but actually implement (and hide) some nefarious side activities ๐Ÿ˜‚

1 year ago 6 0 1 0

Very glad I'm not going - at least for this year. We'll see if (or when?) this situation crystallizes out ๐Ÿ˜…

1 year ago 1 0 1 0

This is actually so good ๐Ÿ‘Œ

1 year ago 0 0 0 0

Yes! Already made plans to link up ๐Ÿ™Œ

1 year ago 0 0 1 0
Advertisement
Post image

Touched down in Singapore! Looking forward to Black Hat Asia. Hope to see many of you around!

1 year ago 4 0 1 0
A diagram describing the negotiate protocol, only saying 'negotiate protocol' twice between client and server

A diagram describing the negotiate protocol, only saying 'negotiate protocol' twice between client and server

This must be the most informative graphic contained in the Microsoft docs
learn.microsoft.com/en-us/opensp...

1 year ago 6 1 1 0

Doing it out of spite. Love it! ๐Ÿ˜‚

1 year ago 1 0 1 0

Yeah on sunny days I sometimes get 15-20kWh from my panels of which almost everything is returned to grid ๐Ÿ˜…. I guess it's not really about that number though, but more the question "does 2.7kWh last you until the next sunrays" maybe. And the 800W extra is nice to cover peak usage that exceeds solar

1 year ago 1 0 1 0

Good stuff! Definitely subscribing to your opinions on it in the future ๐Ÿ˜‚. 2.7kWh ain't much but it's enough to bridge the night on solar I guess!

1 year ago 1 0 1 0

I've been keeping an eye on these! What is your experience so far? Seems like a great solution in between nothing and a ridiculously expensive all-out battery setup. Too much uncertainty regarding saldering for me to buy anything yet tho ๐Ÿ˜‚

1 year ago 0 0 1 0

Truly mask off at this point.. it's saddening

1 year ago 1 0 0 0
Advertisement
Post image

I was invited to present Nimplant at Black Hat Asia 2025 in Singapore this April! If you're around, please do reach out to talk offensive development, modern programming languages, or how to use (or detect) Nimplant in your ops. Looking forward to it!

www.blackhat.com/asia-25/arse...

1 year ago 0 0 0 0

That's very cool! I briefly looked into adding plugins the "classical" way as well but backdooring an existing one seems much cleaner. Nice post!

1 year ago 0 0 0 0
Preview
Abusing VS Code's Bootstrapping Functionality To Quietly Load Malicious Extensions Wow, been a while since my last blog ๐Ÿ˜…. During some research I came across a technique variation which I felt was interesting enough to share in a brief blog post. It relates to how the bootstrapping ...

Recently came across a pretty neat technique to silently load (malicious) VS Code extensions using its bootstrapping and portability features. Thought it was interesting enough to warrant my first blog post in 4 years ๐Ÿ™ƒ

Check it out ๐Ÿ‘‡
casvancooten.com/posts/2025/0...

1 year ago 7 3 0 0

Leuk Johannes, dank!

1 year ago 0 0 0 0

Haha yeah this sounds familiar ๐Ÿ˜…. The smaller the feature the more bugs will pop up ๐Ÿ˜‚

1 year ago 1 0 0 0

Great updates! Thanks for sticking with the maintenance, still very useful in work automations! ๐Ÿ”ฅ

1 year ago 2 0 1 0

First day back after leave, man does my brain feel the same trying to remember what all I did before ๐Ÿ˜‚๐Ÿ˜‚

1 year ago 0 0 0 0

Thumb 11/10, will definitely watch first thing after holiday ๐Ÿ˜‚

1 year ago 3 0 0 0
Preview
a puppet master poster shows a hand holding a puppet on strings ALT: a puppet master poster shows a hand holding a puppet on strings
1 year ago 2 0 0 0
Advertisement
Post image

Lol 75% thought leader, must be because I interact with @xpnsec.com too much ๐Ÿ˜‚
blueskyroast.com/roast/casvan...

1 year ago 6 0 1 0
Preview
a group of people are screaming and laughing in a crowd ALT: a group of people are screaming and laughing in a crowd

let's goooo

1 year ago 0 0 0 0

Agreed, they're so much fun as a collectible.. maybe we should start re-using badges, new badge for first-time con visitors, firmware update for existing badge holders? ๐Ÿ˜‚

1 year ago 2 0 1 0

I think it's the latter for most? Less frustrations with the platform maybe, and/or not willing to juggle multiple platforms (temporarily) potentially

1 year ago 1 0 0 0

Unfortunately there are still too many capable and informative folks on there :(. At least to the degree I'm not comfortable burning my account with fire just yet. @xpnsec.com is doing a great job with influencing everyone to move over here, though!

1 year ago 1 0 2 0

My ears were ringing when this was presented at RedTreat. Time for round two with this blog and tool release ๐Ÿ˜… ๐Ÿ”ฅ

1 year ago 1 0 1 0