A security researcher has publicly disclosed a new Visual Studio Code zero-day vulnerability that can reportedly let ...
VS Code flaw exposes GitHub OAuth tokens via one-click attack on GitHub.dev, enabling private repo access and token theft.
A researcher has disclosed details of a severe VS Code vulnerability that can be exploited to steal GitHub tokens and access ...
GitHub confirmed attackers stole 3,800 internal repositories via a poisoned VS Code extension. The same threat group, TeamPCP, simultaneously compromised Microsoft's durabletask Python ...
A VS Code vulnerability in GitHub.dev lets attackers steal full GitHub OAuth tokens via a single malicious link, exposing all private repositories.
GitHub says hackers stole about 3,800 internal repos after a poisoned VS Code extension hit an employee device ...
Microsoft has had a VS Code extension for a long time, and it finally came back to bite them.
GitHub confirmed a breach affecting about 3,800 internal repositories after an employee installed a malicious VS Code ...
Developers who rely on GitHub Copilot inside Visual Studio Code now have a new option built entirely by Microsoft. The ...
Microsoft's May 2026 VS Code update makes BYOK usable in restricted environments while adding agent, browser and issue-reporting updates.