Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
The January 2026 update has arrived.
A new GlassWorm malware attack through compromised OpenVSX extensions focuses on stealing passwords, crypto-wallet data, and developer credentials and configurations from macOS systems.