VS Code flaw exposes GitHub OAuth tokens via one-click attack on GitHub.dev, enabling private repo access and token theft.
Microsoft's June 2026 VS Code update turns on Autopilot by default and adds background sending for agent sessions.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results