Advertisement

MEDIUM
Supply Chain
VS Code Extension Auto-Update Delay: Mitigating Supply Chain Attacks
Microsoft introduces a two-hour delay for VS Code extension auto-updates to prevent rapid compromise during software supply chain attacks.
Runtime Rebel Intel
4 min read·Jun 8, 2026
VU
HIGH
Vulnerabilities
VS Code One-Click GitHub Token Theft via URI Handler Exploitation
A flaw in Visual Studio Code allows attackers to steal GitHub authentication tokens with a single click. Learn the technical details and mitigation steps.
Runtime Rebel Intel
4 min read·Jun 4, 2026
MA
HIGH
Malware
GlassWorm Malware Resurfaces via 73 OpenVSX Sleeper Extensions
A new GlassWorm campaign exploits the OpenVSX ecosystem with 73 'sleeper' extensions, posing a significant supply chain threat to developers.
Runtime Rebel Intel
4 min read·Apr 28, 2026