
In this exclusive interaction with The Catalyst, Shuvo Bardhan, Scientist/Cybersecurity Expert, and Suman Chakraborty, Senior Security Researcher, ZERON who are also speakers at BlackHat MEA 2025 presenting their latest research paper on “Weaponizing Remote Dev Tunnels for Red Team Operations,” share their perspectives on the future of cybersecurity, the evolving responsibilities of platform vendors, and the cultural mindset needed to spark breakthrough innovation in the years ahead.
How can cybersecurity move beyond protection and become a direct enabler of digital trust, economic growth, and competitive advantage?
Shuvo Bardhan: Cybersecurity becomes an enabler when it’s seen as part of the product, not a blocker. When users trust a platform with their data and identity, they adopt faster — and that directly drives growth. Strong security also lets companies move quicker into cloud, AI, and new markets without fear of breaking something. And in a world where everyone offers similar features, trust becomes a real competitive edge. The companies that build security into their design, not as an afterthought, will always move faster and win more confidently.
What first prompted you to investigate Remote Tunnel abuse in Visual Studio Code, and when did you realize the attack surface was far bigger than assumed?
Shuvo Bardhan:
- Honestly, it started pretty simply. Cloud made it super easy to get powerful machines without owning them, so developers naturally moved to Remote Development. And the moment I saw how common remote tunnels were becoming, my attacker brain went, “This is interesting… this is basically remote access but with a developer label on it.”
- Then I came across reports from Palo Alto and a few other teams showing that some APT groups — especially Chinese ones — were already abusing VS Code tunnels in their own way. That was the moment I realised, “Okay, this isn’t just theory. People are actually doing this.”
- What pushed me into the research was my own red team instinct. I kept thinking: If attackers are already using this technique, why don’t red teamers have a proper tool or framework to simulate it? Everything I saw was very manual — lots of scripts, guesswork, and random exploration. Nothing streamlined.
- So, I basically decided to turn that manual attacker behaviour into something red teams can actually use in a clean, repeatable way. And that became VSXploit. It’s just me trying to bridge the gap between what APTs are already doing and what red teamers need to demonstrate the real risk.
Several APT groups, including Chinese threat actors, have exploited this technique manually. What gaps did you observe in existing exploitation workflows that led you to build VSXPloit?
Suman Chakraborty:
- When I looked at how APT groups were abusing remote tunnels, the main issue was that everything was extremely manual. Discovery was random, hijacking was inconsistent, there was no clear workflow after getting access, and there was zero tooling for red teams to replicate it properly.
- The one big gap I noticed was automation. Attackers had shown the technique works, but nobody had built a clean, repeatable way to do it especially using only Microsoft’s own ecosystem.
- That’s what pushed me to build VSXploit. By adding GitHub-based automation on top of what APTs were already doing, it became possible to run the entire attack chain — discovery, hijack, shell, and pivot — fully inside Microsoft infrastructure. Which makes it not just effective, but extremely stealthy.
As remote development becomes mainstream, what responsibilities do platform vendors like Microsoft have to secure developer-centric infrastructure?
Shuvo Bardhan: Now that remote development is becoming normal, platforms like Microsoft basically run the roads developers travel on. So they can’t think of these features as just “IDE conveniences” anymore; they’re real access pathways into company environments especially when VS-Code is being used as a base by multiple IDEs.
A few responsibilities are obvious:
- Secure defaults. Remote tunnels shouldn’t be wide open or overly permissive out of the box.
- Clear visibility. Security teams should actually be able to see when tunnels are created, reused, or accessed from new locations.
- Stronger identity checks. If a tunnel can reach sensitive systems, it needs proper authentication tied to the user, not just convenience tokens.
- Threat-modelling the abuse cases. Vendors have to treat these features the same way they treat VPNs and remote access tools — attackers will go after them.
Basically, if developer tools are becoming remote access infrastructure, then vendors need to secure them like remote access infrastructure. Developers get their convenience, and organisations don’t end up with hidden backdoors.
What new security disciplines or frameworks do you believe the world will require in the next five years to stay ahead of cyber adversaries?
Suman Chakraborty: In the next five years, one of the biggest things we’ll need is proper AI governance. And the funny part is — the standards already exist. ISO has published multiple frameworks for AI risk management, transparency, accountability, and safety (like ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 38507).
But the reality is that these standards are barely implemented, while AI itself is being adopted everywhere at full speed. That creates a huge gap: AI is moving fast, but AI security is not. And attackers always run toward the biggest gaps.
If we don’t fix this soon, we’ll end up with critical decisions, automation, and even identity workflows powered by AI systems that nobody is properly monitoring or verifying.
So the world will need:
- Strong AI governance actually applied in real organisations
- Clear processes for securing models, data, and AI-driven decisions
- Auditing and monitoring frameworks that work in practice, not just on paper
Because if we don’t close this gap quickly, AI will become the biggest ungoverned attack surface we’ve ever had.
How can we inspire young researchers to pursue breakthrough cybersecurity innovation instead of incremental improvement?
Shuvo Bardhan: I think the best way to inspire young researchers is to show them that breakthrough ideas usually start with simple curiosity, not huge budgets. Most big research happens because someone asked, “Why does this work like that?” and then didn’t drop the question.
We also need to expose them to real-world problems, not just textbook labs. When they see how attackers actually abuse cloud, AI, or developer tools, their minds automatically start exploring new angles.
Another big part is culture. We have to stop celebrating only CVE counts and start appreciating originality. If someone finds a weird edge-case in an AI model or a creative abuse in a dev tool, that should be recognised — even if it’s not a traditional “bug”.
And finally, mentorship matters. Sometimes young researchers just need someone to tell them, “Yes, chase that weird idea — that’s where innovation lives.”
Breakthroughs happen when curiosity meets encouragement. If we give them that space, they won’t settle for incremental work.
How do you see events like Black Hat shaping the global cybersecurity landscape, especially in terms of knowledge exchange, threat awareness, and driving innovation?
Suman Chakraborty: Events like Black Hat act like a global sync point for the entire security community. Researchers share new attack surfaces, defenders learn what’s coming next, and vendors see where their tools are falling behind. A lot of real collaboration happens there — not just on stage, but in hallways and private sessions. It raises threat awareness, accelerates innovation, and pushes the industry forward because everyone leaves with a clearer picture of how fast attackers are evolving and what we need to fix next.
The conversation highlights how cybersecurity is evolving from a defensive function into a strategic enabler of trust, growth, and innovation. By studying emerging attack surfaces, automating threat simulations, and embedding security into developer workflows and AI systems, organizations can stay ahead of adversaries while maintaining agility in cloud and digital environments. Equally important is fostering a culture that values curiosity, originality, and mentorship, inspiring the next generation of researchers to pursue breakthrough solutions. Events that promote collaboration and knowledge exchange further accelerate industry-wide innovation, ensuring that security becomes a foundational pillar for resilient, trustworthy, and forward-looking technology ecosystems.
All Content Rights Reserved by The Catalyst.








