Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Microsoft's fifth July update expands agent monitoring, adds offline speech transcription and changes Python environment management.
BSides Las Vegas 2026 spent three days making the case that AI coding tools are supply chain attack targets. ChainDrop, a ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
In the new release, developers can experimentally dictate in VS Code without a speech extension and gain deeper insights into ...
Microsoft's latest weekly VS Code release advances shared agent sessions, multi-file change review, chat visibility and terminal navigation ...
A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository.
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...
Moonshot AI released Kimi K3, a 2.8 trillion-parameter open-source AI model from China that rivals OpenAI, Anthropic and other top U.S. systems in frontier AI benchmarks.
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
VS Code update brings info on running subagents into the Agents window and previews built-in dictation and a Markdown editor ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results