Start your day with intelligence. Get The OODA Daily Pulse.
Researcher exposes VS Code flaw enabling GitHub token theft.
Ammar Askar publicly disclosed a VS Code vulnerability that lets attackers steal a user’s GitHub token through a malicious Jupyter notebook opened on github.dev. Hidden code can simulate keystrokes to install a rogue extension that sends the victim’s token to the attacker, granting full access to all repositories. Microsoft patched the web version on June 3, though the desktop version remains harder to exploit and still unpatched. The disclosure follows other recent zero‑days released without vendor notification, prompting tense exchanges between researchers and Microsoft.
Read more:
https://www.securityweek.com/vs-code-vulnerability-allows-one-click-github-token-theft/