SECURITYBLEEPING COMPUTER
VS Code zero-day lets hackers steal GitHub tokens in one click
A security researcher disclosed a Visual Studio Code zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a malicious link. The exploit code has been released.
Related Signal
Adjacent reporting
- Google spotted an AI-developed zero-day before attackers could use it
- New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges
- New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
- Critical cPanel and WHM bug exploited as a zero-day, PoC now available
- Hackers exploiting Acrobat Reader zero-day flaw since December
- A critical Palo Alto PAN-OS zero-day is being exploited in the wild