Critical vulnerabilities in four widely used VS Code extensions could enable file theft and remote code execution across 125M installs.
Threat actors continue to probe Visual Studio Code's extension ecosystem, and a late November incident shows how quickly a trusted developer tool can be turned into a supply chain beachhead. In a ...