Security Researcher and Software Engineer @GitHubSecurityLab
Security Researcher and Software Engineer @GitHubSecurityLab@infosec.exchange
Posts
Security Researcher and Software Engineer @GitHubSecurityLab
Security Researcher and Software Engineer @GitHubSecurityLab
Security Researcher and Software Engineer @GitHubSecurityLab
Security Researcher and Software Engineer @GitHubSecurityLab
Security Researcher and Software Engineer @GitHubSecurityLab
Security Researcher and Software Engineer @GitHubSecurityLab
My colleague @jaras@infosec.exchange recently found that a an Android app with zero permissions could exfiltrate all decrypted Signal attachments (affecting the Android APKs downloaded directly from signal.org). Look at the attack scenario our GitHub Security Lab Taskflow Agent produced. This is what AI-assisted security research looks like:
https://securitylab.github.com/advisories/GHSL-2026-102_Android_SignalApp/
Security Researcher and Software Engineer @GitHubSecurityLab