A published VS Code extension didn't hide the fact that it encrypts and exfiltrates data and also failed to remove obvious signs it was AI-generated.
This critical (CVSS 10.0) use-after-free (UAF) vulnerability in Lua scripting could allow authenticated attackers to execute ...
Microsoft's unified agent experience in VS Code consolidates Copilot, Codex, and custom agents, introducing Agent Sessions, a ...
A malicious extension was published on Microsoft’s official VS Code marketplace, and was able to remain there for some time ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results