Peter Stöckli
ulldma@infosec.exchange
<p>Security Researcher and Software Engineer <span class="h-card" translate="no"><a href="https://infosec.exchange/@GitHubSecurityLab" class="u-url mention">@<span>GitHubSecurityLab</span></a></span></p>
Posts
-
Post #4136142
@G33KatWork@infosec.exchange new whale just dropped
-
Post #1299939
My colleague @jaras recently found that a an Android app with zero permissions could exfiltrate all decrypted Signal attachments (affecting the Android APKs downloaded directly from signal.org). Look at the attack scenario our GitHub Security Lab Taskflow Agent produced. This is what AI-assisted security research looks like: https://securitylab.github.com/advisories/GHSL-2026-102_Android_SignalApp/