⤷ Title: MirrorFace: Unmasking the Chinese Cyber Espionage Group Targeting Japan
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 09 Jan 2025 01:51:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #Array Networks Array AG #Citrix ADC #CVE_2023_27997 #CVE_2023_28461 #CVE_2023_3519 #Earth Kasha #Fortinet FortiOS #FortiProxy #MirrorFace #visual studio code #Windows Sandbox
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 09 Jan 2025 01:51:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #Array Networks Array AG #Citrix ADC #CVE_2023_27997 #CVE_2023_28461 #CVE_2023_3519 #Earth Kasha #Fortinet FortiOS #FortiProxy #MirrorFace #visual studio code #Windows Sandbox
Cybersecurity News
MirrorFace: Unmasking the Chinese Cyber Espionage Group Targeting Japan
Discover the cyberattacks attributed to the MirrorFace group in Japan. Learn about their campaigns, targets, and the vulnerabilities they exploit.
⤷ Title: ShibaCoin Ransom: Microsoft Disables Infected VS Code Extensions
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 25 Mar 2025 03:53:16 +0000
════════════════════════
⌗ Tags: #Malware #ShibaCoin Ransom #visual studio code
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 25 Mar 2025 03:53:16 +0000
════════════════════════
⌗ Tags: #Malware #ShibaCoin Ransom #visual studio code
Cybersecurity News
ShibaCoin Ransom: Microsoft Disables Infected VS Code Extensions
Discover how ShibaCoin Ransom works and the risks posed by ransomware integrated into Visual Studio Code extensions.
⤷ Title: The Easiest Way to Comment Code in VS Code
════════════════════════
𐀪 Author: Tanu N Prabhu
════════════════════════
ⴵ Time: Sun, 30 Mar 2025 23:52:53 GMT
════════════════════════
⌗ Tags: #visual_studio_code #hacking #tips_and_tricks #tips #programming
════════════════════════
𐀪 Author: Tanu N Prabhu
════════════════════════
ⴵ Time: Sun, 30 Mar 2025 23:52:53 GMT
════════════════════════
⌗ Tags: #visual_studio_code #hacking #tips_and_tricks #tips #programming
Medium
The Easiest Way to Comment Code in VS Code
One shortcut to save time in any programming language
⤷ Title: Electron Flaws: ASAR Bypass & Buffer Overflow Threaten Desktop Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 09:29:48 +0000
════════════════════════
⌗ Tags: #Vulnerability #ASAR Archive #cybersecurity #Desktop Applications #Electron #Heap Buffer Overflow #Integrity Bypass #rce #Remote Code Execution #visual studio code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 09:29:48 +0000
════════════════════════
⌗ Tags: #Vulnerability #ASAR Archive #cybersecurity #Desktop Applications #Electron #Heap Buffer Overflow #Integrity Bypass #rce #Remote Code Execution #visual studio code
Daily CyberSecurity
Electron Flaws: ASAR Bypass & Buffer Overflow Threaten Desktop Apps
Electron has critical flaws: CVE-2024-46993 allows RCE via image buffer overflow, and CVE-2024-46992 is an ASAR integrity bypass on Windows.
⤷ Title: VS Code ETHcode Extension Hacked: Just 2 Lines of Code Led to Supply Chain Compromise Via GitHub PR
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:46:20 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #ETHcode #Ethereum #Extension #github #malware #Pull Request #ReversingLabs #supply chain attack #Typosquatting #visual studio code #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:46:20 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #ETHcode #Ethereum #Extension #github #malware #Pull Request #ReversingLabs #supply chain attack #Typosquatting #visual studio code #VS Code
Daily CyberSecurity
VS Code ETHcode Extension Hacked: Just 2 Lines of Code Led to Supply Chain Compromise Via GitHub PR
ReversingLabs exposes a supply chain compromise of the VS Code ETHcode extension via two lines of malicious code in a GitHub PR, leading to malware deployment.
⤷ Title: Cursor AI IDE Hacked: Fraudulent Extension Steals $500K in Crypto from Russian Developer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:13:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #cryptocurrency #Cursor AI #Extension #Infostealer #kaspersky #malware #Open VSX #PureLogs #ScreenConnect #Solidity #supply chain attack #visual studio code #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 02:13:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #cryptocurrency #Cursor AI #Extension #Infostealer #kaspersky #malware #Open VSX #PureLogs #ScreenConnect #Solidity #supply chain attack #visual studio code #VS Code
Daily CyberSecurity
Cursor AI IDE Hacked: Fraudulent Extension Steals $500K in Crypto from Russian Developer
A Russian crypto developer lost $500K after installing a fraudulent "Solidity Language" extension for Cursor AI IDE from Open VSX, which deployed malware for remote access and data theft.
⤷ Title: Crypto Dev Loses $500K to Fake Cursor AI Extension: A New Supply Chain Threat
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 16 Jul 2025 03:06:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cryptocurrency #Cursor AI #Info_stealer #malware #Open VSX #PureLogs #Quasar RAT #supply chain attack #Visual Studio Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 16 Jul 2025 03:06:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cryptocurrency #Cursor AI #Info_stealer #malware #Open VSX #PureLogs #Quasar RAT #supply chain attack #Visual Studio Code
Penetration Testing Tools
Crypto Dev Loses $500K to Fake Cursor AI Extension: A New Supply Chain Threat
A Russian crypto developer lost $500K due to a malicious "Solidity Language" extension on Open VSX for Cursor AI, highlighting new supply chain risks.
⤷ Title: Amazon Q Pulled After Malicious Pull Request Instructs AI to Delete User Files and AWS Resources
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 26 Jul 2025 00:49:09 +0000
════════════════════════
⌗ Tags: #Malware #AI Assistant #Amazon Q #AWS #code injection #cybersecurity #File Deletion #Pull Request #supply chain attack #Visual Studio Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 26 Jul 2025 00:49:09 +0000
════════════════════════
⌗ Tags: #Malware #AI Assistant #Amazon Q #AWS #code injection #cybersecurity #File Deletion #Pull Request #supply chain attack #Visual Studio Code
Penetration Testing Tools
Amazon Q Pulled After Malicious Pull Request Instructs AI to Delete User Files and AWS Resources
Amazon was forced to withdraw a compromised version of its AI assistant, Q, after a malicious pull request instructed it to delete local files and AWS resources.
⤷ Title: ByteDance’s Trae IDE Under Fire: AI Coding Tool Caught Telemetry Spying Even After Opt-Out
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 08:48:09 +0000
════════════════════════
⌗ Tags: #Data Leak #AI #ByteDance #cybersecurity #Data Collection #IDE #privacy #Programming Tool #Telemetry #Trae IDE #visual studio code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 08:48:09 +0000
════════════════════════
⌗ Tags: #Data Leak #AI #ByteDance #cybersecurity #Data Collection #IDE #privacy #Programming Tool #Telemetry #Trae IDE #visual studio code
Daily CyberSecurity
ByteDance's Trae IDE Under Fire: AI Coding Tool Caught Telemetry Spying Even After Opt-Out
⤷ Title: Coding with GPT-5: Microsoft Integrates New AI Powerhouse into Visual Studio Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 07:23:25 +0000
════════════════════════
⌗ Tags: #Technology #AI #developer #GitHub Copilot #GPT_5 #Microsoft #Programming #visual studio code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 07:23:25 +0000
════════════════════════
⌗ Tags: #Technology #AI #developer #GitHub Copilot #GPT_5 #Microsoft #Programming #visual studio code
Daily CyberSecurity
Coding with GPT-5: Microsoft Integrates New AI Powerhouse into Visual Studio Code
Microsoft is rolling out GPT-5 support for Visual Studio Code via GitHub Copilot. The new model promises smarter and faster coding for paid subscribers.
⤷ Title: A New Era for AI Coding: OpenAI’s Codex Gets a Major Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Sep 2025 02:02:19 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding #ChatGPT #Codex #Developers #github #OpenAI #Productivity #software update #visual studio code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Sep 2025 02:02:19 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding #ChatGPT #Codex #Developers #github #OpenAI #Productivity #software update #visual studio code
Daily CyberSecurity
A New Era for AI Coding: OpenAI’s Codex Gets a Major Update
OpenAI's Codex gets a major update with a new VS Code extension and local-to-cloud handoff. The update allows for seamless, synced coding tasks from anywhere.
⤷ Title: Critical Flaw in Cursor Puts Nearly a Million Developers at Risk
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 07:13:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #Code Editor #Cursor #cybersecurity #developer tools #software vulnerability #supply chain attack #Visual Studio Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 07:13:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #Code Editor #Cursor #cybersecurity #developer tools #software vulnerability #supply chain attack #Visual Studio Code
Penetration Testing Tools
Critical Flaw in Cursor Puts Nearly a Million Developers at Risk
A critical vulnerability in the Cursor code editor can allow attackers to execute malicious code automatically. Learn how this flaw works and how to protect yourself.
⤷ Title: Security Flaws in VS Extensions Expose Developers to Threats
════════════════════════
𐀪 Author: Valentin Podkamennyi
════════════════════════
ⴵ Time: Sat, 18 Oct 2025 23:05:02 GMT
════════════════════════
⌗ Tags: #visual_studio_code #supply_chain_attack #software_security #developer_security #cybersecurity
════════════════════════
𐀪 Author: Valentin Podkamennyi
════════════════════════
ⴵ Time: Sat, 18 Oct 2025 23:05:02 GMT
════════════════════════
⌗ Tags: #visual_studio_code #supply_chain_attack #software_security #developer_security #cybersecurity
Medium
Security Flaws in VS Extensions Expose Developers to Threats
Developers publishing Visual Studio extensions to open marketplaces have inadvertently exposed sensitive access tokens.
⤷ Title: Token Leak: Eclipse Revokes Exposed Keys to Halt Open VSX Supply Chain Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:02:19 +0000
════════════════════════
⌗ Tags: #Malware #Eclipse Foundation #MSRC #Open VSX #security incident #Supply Chain #Token Security #Visual Studio Code #Wiz
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:02:19 +0000
════════════════════════
⌗ Tags: #Malware #Eclipse Foundation #MSRC #Open VSX #security incident #Supply Chain #Token Security #Visual Studio Code #Wiz
Penetration Testing Tools
Token Leak: Eclipse Revokes Exposed Keys to Halt Open VSX Supply Chain Attacks
Eclipse revoked compromised Open VSX tokens found in repositories. New "ovsxp_" prefix and shorter validity periods will strengthen supply chain security.
⤷ Title: Google Launches Official Colab Extension for VS Code: Seamless ML Workflow!
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 09:36:36 +0000
════════════════════════
⌗ Tags: #Google #Technology #AI #Cloud Computing #developer tools #Google Colab #GPU #Jupyter Notebooks #machine learning #ML #Visual Studio Code #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 09:36:36 +0000
════════════════════════
⌗ Tags: #Google #Technology #AI #Cloud Computing #developer tools #Google Colab #GPU #Jupyter Notebooks #machine learning #ML #Visual Studio Code #VS Code
Penetration Testing Tools
Google Launches Official Colab Extension for VS Code: Seamless ML Workflow!
Google's official Colab extension for VS Code brings Colab's cloud resources (GPUs/TPUs) directly into the popular editor for a seamless ML development experience.
⤷ Title: The Dev Environment Trap: 128 Million Users at Risk as Top VS Code Extensions Unmask Critical Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:35:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Runner #CVE_2025_65715 #CVE_2025_65717 #data exfiltration #Live Server #Markdown Preview Enhanced #OX Security #rce #Remote Code Execution #Tech News 2026 #Visual Studio Code security #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:35:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Runner #CVE_2025_65715 #CVE_2025_65717 #data exfiltration #Live Server #Markdown Preview Enhanced #OX Security #rce #Remote Code Execution #Tech News 2026 #Visual Studio Code security #VS Code
Daily CyberSecurity
The Dev Environment Trap: 128 Million Users at Risk as Top VS Code Extensions Unmask Critical Flaws
Critical flaws in Live Server, Code Runner, and more expose 128M+ developers to file theft and remote code execution. Is your VS Code workspace secure?
⤷ Title: The Long Game: How North Korea’s UNC4736 Spent Six Months Infiltrating Drift for a $285M Payday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 10:15:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AppleJeus #Blockchain Security #Crypto Hack 2026 #Drift Protocol #Golden Chollima #North Korea #Social Engineering #Solana #TestFlight Malware #UNC4736 #Visual Studio Code Exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 10:15:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AppleJeus #Blockchain Security #Crypto Hack 2026 #Drift Protocol #Golden Chollima #North Korea #Social Engineering #Solana #TestFlight Malware #UNC4736 #Visual Studio Code Exploit
Penetration Testing Tools
The Long Game: How North Korea’s UNC4736 Spent Six Months Infiltrating Drift for a $285M Payday
The recent incursion into the cryptocurrency sanctuary Drift, which culminated in the exfiltration of $285 million, has been
⤷ Title: The Trojan Update: How “GlassWorm” Developers are Using Sleeper Extensions to Hijack Workspaces
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:32:31 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #Developer Security #extension security #GlassWorm #malware #OpenVSX #Socket #supply chain attack #Trojan Update #Visual Studio Code #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:32:31 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #Developer Security #extension security #GlassWorm #malware #OpenVSX #Socket #supply chain attack #Trojan Update #Visual Studio Code #VS Code
Penetration Testing Tools
The Trojan Update: How "GlassWorm" Developers are Using Sleeper Extensions to Hijack Workspaces
The GlassWorm campaign has resurfaced within the developer community, though the adversaries have adopted a more surreptitious operational
⤷ Title: Shai-Hulud Malware Hits @antv Ecosystem, Poisoning Hundreds of npm Packages
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 08:04:06 +0000
════════════════════════
⌗ Tags: #Malware #@antv Malicious Packages #atool Maintainer Account #CI/CD Secret Stealer #Claude Code Backdoor #OIDC Token Hijacking #Session P2P Network #Shai_Hulud npm Attack #Sigstore Provenance Forgery #Software Supply Chain Worm #Visual Studio Code Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 08:04:06 +0000
════════════════════════
⌗ Tags: #Malware #@antv Malicious Packages #atool Maintainer Account #CI/CD Secret Stealer #Claude Code Backdoor #OIDC Token Hijacking #Session P2P Network #Shai_Hulud npm Attack #Sigstore Provenance Forgery #Software Supply Chain Worm #Visual Studio Code Malware
Penetration Testing Tools
Shai-Hulud Malware Hits @antv Ecosystem, Poisoning Hundreds of npm Packages
The npm ecosystem has been subjected to a massive, highly coordinated supply-chain assault. Within a compressed one-hour envelope,
⤷ Title: Developer Alert: Poisoned Nx Console VS Code Extension Steals AWS, npm, and GitHub Tokens
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:37:38 +0000
════════════════════════
⌗ Tags: #Malware #Bun JavaScript Runtime #Dangling Orphan Commit #DNS Tunneling Exfiltration #GitHub Token Theft #Multi_Stage Credential Harvester #Nx Console Extension Compromise #rwl.angular_console #Sigstore Supply Chain Poisoning #StepSecurity Forensic Audit #Visual Studio Code Marketplace
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:37:38 +0000
════════════════════════
⌗ Tags: #Malware #Bun JavaScript Runtime #Dangling Orphan Commit #DNS Tunneling Exfiltration #GitHub Token Theft #Multi_Stage Credential Harvester #Nx Console Extension Compromise #rwl.angular_console #Sigstore Supply Chain Poisoning #StepSecurity Forensic Audit #Visual Studio Code Marketplace
Penetration Testing Tools
Developer Alert: Poisoned Nx Console VS Code Extension Steals AWS, npm, and GitHub Tokens
The highly popular Nx Console extension for Visual Studio Code has been compromised via a weaponized supply-chain injection.