⤷ Title: Critical Flaw in Cursor Puts Nearly a Million Developers at Risk
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 07:13:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #Code Editor #Cursor #cybersecurity #developer tools #software vulnerability #supply chain attack #Visual Studio Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 07:13:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #Code Editor #Cursor #cybersecurity #developer tools #software vulnerability #supply chain attack #Visual Studio Code
Penetration Testing Tools
Critical Flaw in Cursor Puts Nearly a Million Developers at Risk
A critical vulnerability in the Cursor code editor can allow attackers to execute malicious code automatically. Learn how this flaw works and how to protect yourself.
⤷ Title: Microsoft Launches MCP Server for AI to Access Official Documentation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Sep 2025 08:00:10 +0000
════════════════════════
⌗ Tags: #Technology #AI Development #API #Developers #documentation #MCP server #Microsoft Learn #visual studio
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Sep 2025 08:00:10 +0000
════════════════════════
⌗ Tags: #Technology #AI Development #API #Developers #documentation #MCP server #Microsoft Learn #visual studio
Daily CyberSecurity
Microsoft Launches MCP Server for AI to Access Official Documentation
Microsoft's new MCP Server allows AI models to directly access official, real-time documentation from Microsoft Learn for enhanced accuracy and efficiency.
⤷ Title: Security Flaws in VS Extensions Expose Developers to Threats
════════════════════════
𐀪 Author: Valentin Podkamennyi
════════════════════════
ⴵ Time: Sat, 18 Oct 2025 23:05:02 GMT
════════════════════════
⌗ Tags: #visual_studio_code #supply_chain_attack #software_security #developer_security #cybersecurity
════════════════════════
𐀪 Author: Valentin Podkamennyi
════════════════════════
ⴵ Time: Sat, 18 Oct 2025 23:05:02 GMT
════════════════════════
⌗ Tags: #visual_studio_code #supply_chain_attack #software_security #developer_security #cybersecurity
Medium
Security Flaws in VS Extensions Expose Developers to Threats
Developers publishing Visual Studio extensions to open marketplaces have inadvertently exposed sensitive access tokens.
⤷ Title: GlassWorm Malware Targets Developers Through OpenVSX Marketplace
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 10:22:48 +0000
════════════════════════
⌗ Tags: #Malware #Security #Blockchain #Cybersecurity #GlassWorm #Marketplace #OpenVSX #Solana #Visual Studio
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 10:22:48 +0000
════════════════════════
⌗ Tags: #Malware #Security #Blockchain #Cybersecurity #GlassWorm #Marketplace #OpenVSX #Solana #Visual Studio
Hackread
GlassWorm Malware Targets Developers Through OpenVSX Marketplace
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Token Leak: Eclipse Revokes Exposed Keys to Halt Open VSX Supply Chain Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:02:19 +0000
════════════════════════
⌗ Tags: #Malware #Eclipse Foundation #MSRC #Open VSX #security incident #Supply Chain #Token Security #Visual Studio Code #Wiz
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:02:19 +0000
════════════════════════
⌗ Tags: #Malware #Eclipse Foundation #MSRC #Open VSX #security incident #Supply Chain #Token Security #Visual Studio Code #Wiz
Penetration Testing Tools
Token Leak: Eclipse Revokes Exposed Keys to Halt Open VSX Supply Chain Attacks
Eclipse revoked compromised Open VSX tokens found in repositories. New "ovsxp_" prefix and shorter validity periods will strengthen supply chain security.
⤷ Title: SleepyDuck: The Ethereum-Powered Malware That Redefines Command and Control
════════════════════════
𐀪 Author: C. Oscar Lawshea
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 19:10:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #visual_studio #blockchain #malware #smart_contracts
════════════════════════
𐀪 Author: C. Oscar Lawshea
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 19:10:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #visual_studio #blockchain #malware #smart_contracts
Medium
SleepyDuck: The Ethereum-Powered Malware That Redefines Command and Control
Introduction
⤷ Title: Google Launches Official Colab Extension for VS Code: Seamless ML Workflow!
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 09:36:36 +0000
════════════════════════
⌗ Tags: #Google #Technology #AI #Cloud Computing #developer tools #Google Colab #GPU #Jupyter Notebooks #machine learning #ML #Visual Studio Code #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 09:36:36 +0000
════════════════════════
⌗ Tags: #Google #Technology #AI #Cloud Computing #developer tools #Google Colab #GPU #Jupyter Notebooks #machine learning #ML #Visual Studio Code #VS Code
Penetration Testing Tools
Google Launches Official Colab Extension for VS Code: Seamless ML Workflow!
Google's official Colab extension for VS Code brings Colab's cloud resources (GPUs/TPUs) directly into the popular editor for a seamless ML development experience.
⤷ Title: Glassworm Strikes Again: Third Wave of Malicious VS Code Extensions Bypasses Moderation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 08:11:54 +0000
════════════════════════
⌗ Tags: #Malware #GlassWorm #Infostealer #malware #OpenVSX #supply chain attack #Unicode Obfuscation #Visual Studio Marketplace #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 08:11:54 +0000
════════════════════════
⌗ Tags: #Malware #GlassWorm #Infostealer #malware #OpenVSX #supply chain attack #Unicode Obfuscation #Visual Studio Marketplace #VS Code
Penetration Testing Tools
Glassworm Strikes Again: Third Wave of Malicious VS Code Extensions Bypasses Moderation
The Glassworm campaign targeting popular Visual Studio Code extensions has entered yet another phase — researchers are now
⤷ Title: Malicious Visual Studio Code Extensions Hide Trojan in Fake PNG Files
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 17:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Security #Cyber Attack #Cybersecurity #Developers #ReversingLabs #TROJAN #Visual Studio #VS Code
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 17:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Security #Cyber Attack #Cybersecurity #Developers #ReversingLabs #TROJAN #Visual Studio #VS Code
Hackread
Malicious Visual Studio Code Extensions Hide Trojan in Fake PNG Files
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: The Dev Environment Trap: 128 Million Users at Risk as Top VS Code Extensions Unmask Critical Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:35:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Runner #CVE_2025_65715 #CVE_2025_65717 #data exfiltration #Live Server #Markdown Preview Enhanced #OX Security #rce #Remote Code Execution #Tech News 2026 #Visual Studio Code security #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:35:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Runner #CVE_2025_65715 #CVE_2025_65717 #data exfiltration #Live Server #Markdown Preview Enhanced #OX Security #rce #Remote Code Execution #Tech News 2026 #Visual Studio Code security #VS Code
Daily CyberSecurity
The Dev Environment Trap: 128 Million Users at Risk as Top VS Code Extensions Unmask Critical Flaws
Critical flaws in Live Server, Code Runner, and more expose 128M+ developers to file theft and remote code execution. Is your VS Code workspace secure?
⤷ Title: The Long Game: How North Korea’s UNC4736 Spent Six Months Infiltrating Drift for a $285M Payday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 10:15:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AppleJeus #Blockchain Security #Crypto Hack 2026 #Drift Protocol #Golden Chollima #North Korea #Social Engineering #Solana #TestFlight Malware #UNC4736 #Visual Studio Code Exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 10:15:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AppleJeus #Blockchain Security #Crypto Hack 2026 #Drift Protocol #Golden Chollima #North Korea #Social Engineering #Solana #TestFlight Malware #UNC4736 #Visual Studio Code Exploit
Penetration Testing Tools
The Long Game: How North Korea’s UNC4736 Spent Six Months Infiltrating Drift for a $285M Payday
The recent incursion into the cryptocurrency sanctuary Drift, which culminated in the exfiltration of $285 million, has been
⤷ Title: The Trojan Update: How “GlassWorm” Developers are Using Sleeper Extensions to Hijack Workspaces
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:32:31 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #Developer Security #extension security #GlassWorm #malware #OpenVSX #Socket #supply chain attack #Trojan Update #Visual Studio Code #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:32:31 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #Developer Security #extension security #GlassWorm #malware #OpenVSX #Socket #supply chain attack #Trojan Update #Visual Studio Code #VS Code
Penetration Testing Tools
The Trojan Update: How "GlassWorm" Developers are Using Sleeper Extensions to Hijack Workspaces
The GlassWorm campaign has resurfaced within the developer community, though the adversaries have adopted a more surreptitious operational
⤷ Title: Shai-Hulud Malware Hits @antv Ecosystem, Poisoning Hundreds of npm Packages
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 08:04:06 +0000
════════════════════════
⌗ Tags: #Malware #@antv Malicious Packages #atool Maintainer Account #CI/CD Secret Stealer #Claude Code Backdoor #OIDC Token Hijacking #Session P2P Network #Shai_Hulud npm Attack #Sigstore Provenance Forgery #Software Supply Chain Worm #Visual Studio Code Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 08:04:06 +0000
════════════════════════
⌗ Tags: #Malware #@antv Malicious Packages #atool Maintainer Account #CI/CD Secret Stealer #Claude Code Backdoor #OIDC Token Hijacking #Session P2P Network #Shai_Hulud npm Attack #Sigstore Provenance Forgery #Software Supply Chain Worm #Visual Studio Code Malware
Penetration Testing Tools
Shai-Hulud Malware Hits @antv Ecosystem, Poisoning Hundreds of npm Packages
The npm ecosystem has been subjected to a massive, highly coordinated supply-chain assault. Within a compressed one-hour envelope,
⤷ Title: Developer Alert: Poisoned Nx Console VS Code Extension Steals AWS, npm, and GitHub Tokens
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:37:38 +0000
════════════════════════
⌗ Tags: #Malware #Bun JavaScript Runtime #Dangling Orphan Commit #DNS Tunneling Exfiltration #GitHub Token Theft #Multi_Stage Credential Harvester #Nx Console Extension Compromise #rwl.angular_console #Sigstore Supply Chain Poisoning #StepSecurity Forensic Audit #Visual Studio Code Marketplace
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:37:38 +0000
════════════════════════
⌗ Tags: #Malware #Bun JavaScript Runtime #Dangling Orphan Commit #DNS Tunneling Exfiltration #GitHub Token Theft #Multi_Stage Credential Harvester #Nx Console Extension Compromise #rwl.angular_console #Sigstore Supply Chain Poisoning #StepSecurity Forensic Audit #Visual Studio Code Marketplace
Penetration Testing Tools
Developer Alert: Poisoned Nx Console VS Code Extension Steals AWS, npm, and GitHub Tokens
The highly popular Nx Console extension for Visual Studio Code has been compromised via a weaponized supply-chain injection.
⤷ Title: Siggen Backdoor Hits Windows Developers Via Infected Visual Studio Projects
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 11:08:18 +0000
════════════════════════
⌗ Tags: #Security #Malware #backdoor #Cryptocurrency #Cybersecurity #Scam #Siggen #Steam #Supply Chain #TROJAN #Visual Studio
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 11:08:18 +0000
════════════════════════
⌗ Tags: #Security #Malware #backdoor #Cryptocurrency #Cybersecurity #Scam #Siggen #Steam #Supply Chain #TROJAN #Visual Studio
Hackread
Siggen Backdoor Hits Windows Developers Via Infected Visual Studio Projects
Dr.Web details Siggen Windows backdoor that uses Steam for C2, steals credentials and crypto data and infects Visual Studio projects to spread among developers.