A compromised Open VSX publisher account was used to distribute malicious extensions in a new GlassWorm supply chain attack.
A JavaScript sandbox bug rated CVSS 9.9 enables attackers to bypass AST‑based protections, while a Python execution bypass ...