The January 2026 update has arrived.
Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
Eclipse Foundation to require pre-publish security checks for Open VSX extensions to reduce VS Code supply-chain risk.
This week’s cybersecurity recap highlights key attacks, zero-days, and patches to keep you informed and secure.
A compromised Open VSX publisher account was used to distribute malicious extensions in a new GlassWorm supply chain attack.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results