Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > VSCode
#VSCode

1-Click GitHub Token Theft: VSCode Webview Flaw Exposes OAuth Tokens for All Private Repositories

3 June 2026  |  dark6  |  Vulnerability

A critical VSCode webview vulnerability lets attackers steal GitHub OAuth tokens with a single click, granting full access to all private repositories. Researcher Ammar Askar published a complete...

>> read more

A Silent Killer Sneaking into Your Code: New Campaign Targets VS Code Developers

11 December 2025  |  dark6  |  Phishing

From seemingly innocuous extensions to stealthy trojans, the threat landscape for developers is evolving. While the world continues to grapple with the ever-shifting tide of cybersecurity threats, a...

>> read more

VSCode: A New Wave of Malware Exploits the Heart of Creative Workflows

9 December 2025  |  dark6  |  Malware

The lines between personal work and corporate security are increasingly blurring, especially for developers. With tools like Visual Studio Code (VS Code) becoming integral to both individual projects...

>> read more

Malicious VSCode extensions: a growing threat to developers

7 April 2025  |  securebulletin.com  |  Malware

The Visual Studio Code (VSCode) Marketplace has recently become a target for sophisticated cyberattacks, with malicious extensions infiltrating development environments to deploy cryptominers. These attacks highlight vulnerabilities in...

>> read more