RVAsec Deep Dive - September
by RVAsec Security Community
About
**You must be registered to attend this event.** As we head into fall, [Nick Copi](https://nickcopi.com/) is back for his second RVAsec Deep Dive. Nick ran our very first Deep Dive, a hands on lab, and he’s returning with another one: [Hacking IDE Extensions - VSCode Workshop](https://gist.github.com/nickcopi/daf5b24b262c802830ab6c1ef9d5d49d), a hands on session built around the IDE extension bug bounty work he’s done professionally, work that also landed him a speaking slot at this year’s DEF CON Bug Bounty Village. He spent four years as a Cyber Security Engineer at CarMax working application security and containerization, and now hunts bugs full time. IDE extensions run with privileged access to your filesystem, shell, and credentials, and increasingly ship AI features that read untrusted workspace files and act on what they find. Nick will walk through a generalized exploitation killchain, then turn everyone loose on Nopilot, a deliberately vulnerable mock AI assistant extension built for this workshop. Attendees will debug it, find real primitives, and chain them into full pretrust code execution. Bring a laptop with VS Code (or Cursor/VSCodium), Node 20+, and some familiarity with JavaScript. No prior extension dev experience needed. Location: • ECPI (11104 W Broad Street) Agenda: • 6:00 PM – Doors open, socializing & refreshments • 6:30 PM – Threat model crash course and killchain walkthrough • 6:45 PM – Tooling primer and live debugging demo • 7:00 PM – Hands-on: pick a primitive, build your own exploit chain • 8:00 PM – Walkthrough of the full pretrust code execution chain • 8:30 PM – Wrap up and open conversation Capacity: We expect roughly 40 seats. If you sign up, please show up; if something comes up, no problem, but cancel or update ASAP so someone else can take the spot.