Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
A compromised Open VSX publisher account was used to distribute malicious extensions in a new GlassWorm supply chain attack.
Security researchers found two AI-branded VS Code extensions with 1.5M installs that covertly send source code and files to ...