Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, repositories, and extensions on GitHub, npm, and VSCode/OpenVSX extensions. Evidence ...
GitHub confirmed on May 20 that a poisoned VS Code extension installed on an employee’s device gave attackers access to roughly 3,800 internal repositories at the Microsoft-owned code storage and ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Threat actors continue to probe Visual Studio Code's extension ecosystem, and a late November incident shows how quickly a trusted developer tool can be turned into a supply chain beachhead. In a ...
Opinion
Tech Times on MSNOpinion
Cursor patched a silent repo-poisoning zero-day with no advisory and no CVE
Cursor IDE zero-day vulnerability: AI security firm Mindgard spent seven months trying to report a Windows code-execution flaw that let a cloned repository run attacker code automatically. Cursor ...
A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results