The Copilot Studio extension for Visual Studio Code is now generally available, allowing agents to be developed and managed directly from the editor. The extension enables software-style workflows for ...
Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
In a a robust Hacker News thread sparked by Jamf Threat Labs research, a VS Code team member defended the editor's Workspace ...
A compromised Open VSX publisher account was used to distribute malicious extensions in a new GlassWorm supply chain attack.
Two VSCode extensions exfiltrated sensitive user data to Chinese servers ChatGPT – 中文版 and ChatMoss had over 1.5 million installs combined Extensions used hidden iframes, commands, and SDKs to steal ...
First malicious Outlook add-in abused an abandoned domain to host a fake Microsoft login page, stealing 4,000+ credentials in ...
Malware targets macOS developers via compromised VS Code extensions, stealing credentials and crypto data via blockchain-based C2..
Visual Studio Code 1.109 introduces enhancements for providing agents with more skills and context and managing multiple ...
The Conductor extension now can generate post-implementation code quality and compliance reports based on developer specifications.
The January 2026 update has arrived.
This week’s cybersecurity recap highlights key attacks, zero-days, and patches to keep you informed and secure.
Two malicious VS Code extensions have exfiltrated code snippets, API keys, and proprietary algorithms from 1.5 million ...