Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code ExtensionThe Hacker News·Jul 10, 10:33 UTC · Jul 10, 2025Malware142
Week in review: Accenture data breach, great open-source cybersecurity toolsHelp Net Security·Jul 12, 00:00 UTC · Jul 12, 2026Data breach in the wildCVE-2026-48282CVE-2026-55255CVE-2026-50656160
Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572)Help Net Security·Oct 8, 00:00 UTC · Oct 8, 2024Exploit / PoC in the wildCVE-2024-43573CVE-2024-43572CVE-2024-38112+3 CVEs60
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEsThe Hacker News·Apr 10, 13:23 UTC · Apr 10, 2026Threat actor145
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain RisksThe Hacker News·Oct 31, 07:59 UTC · Oct 31, 2025Ransomware60
Bridgecrew announces automated cloud security in VS CodeHelp Net Security·Mar 3, 00:00 UTC · Mar 3, 2021Tools30
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential StealerThe Hacker News·May 25, 09:00 UTC · May 25, 2026Malware142
Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 MalwareThe Hacker News·Apr 28, 04:06 UTC · Apr 28, 2026Malware42
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs60
⚡ Weekly Recap: Lazarus Hits Web3, Intel/AMD TEEs Cracked, Dark Web Leak Tool & MoreThe Hacker News·Nov 3, 17:59 UTC · Nov 3, 2025Threat actorCVE-2025-61932CVE-2025-55315CVE-2025-10680+18 CVEs160
Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious RepositoriesThe Hacker News·Sep 12, 04:49 UTC · Sep 12, 2025VulnerabilityCVE-2025-52882CVE-2025-48757247
Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX ExtensionsThe Hacker News·Feb 4, 06:26 UTC · Feb 4, 2026Malware42
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and CredentialsThe Hacker News·Aug 10, 10:57 UTC · Aug 10, 2026Malware130
Self-Spreading 'GlassWorm' Infects VS Code Extensions in Widespread Supply Chain AttackThe Hacker News·Oct 24, 07:00 UTC · Oct 24, 2025Malware42
⚡ Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & MoreThe Hacker News·Jan 26, 16:53 UTC · Jan 26, 2026MalwareCVE-2025-59718CVE-2025-59719CVE-2026-2406160
Critical Flaws Found in Four VS Code Extensions with Over 125 Million InstallsThe Hacker News·Feb 18, 13:16 UTC · Feb 18, 2026VulnerabilityCVE-2025-65717CVE-2025-65716CVE-2025-65715160
Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer DataThe Hacker News·Jan 20, 10:47 UTC · Jan 20, 2026Malware130
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain AttacksThe Hacker News·Jun 8, 17:09 UTC · Jun 8, 2026Malware42
VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSXThe Hacker News·Jan 6, 14:17 UTC · Jan 6, 2026Threat actor57
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60
Malicious Commands in GitHub Codespaces Enable RCEInfosecurity Magazine·Feb 5, 14:30 UTC · Feb 5, 2026Vulnerability142
Russian Hackers Exploit Microsoft OAuth to Target Ukraine Allies via Signal and WhatsAppThe Hacker News·Apr 30, 09:51 UTC · Apr 30, 2025Threat actor145
Data-stealing VS Code extensions removed from official MarketplaceHelp Net Security·May 21, 00:00 UTC · May 21, 2025Vulnerability42
Mimecast confirms SolarWinds attackers breached security certificate, 'potentially exfiltrated' credentialsCyberScoop·Jan 26, 20:15 UTC · Jan 26, 2021Data breach in the wild60
SAP-Related npm Packages Compromised in CredentialThe Hacker News·Apr 30, 16:39 UTC · Apr 30, 2026Data breach60
Default Cursor setting can be exploited to run malicious code on developers' machinesHelp Net Security·Sep 11, 00:00 UTC · Sep 11, 2025Exploit / PoC145
Microsoft August 2020 Patch Tuesday fixed actively exploited zeroSecurity Affairs·Aug 12, 07:02 UTC · Aug 12, 2020Vulnerability in the wildCVE-2020-1464CVE-2020-138060
Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft's Disclosure ProcessSecurity Affairs·Jun 4, 09:13 UTC · Jun 4, 2026Exploit / PoC in the wild160
Microsoft Issues Windows Update to Patch 0The Hacker News·Dec 15, 00:00 UTC · Dec 15, 2021Vulnerability in the wildCVE-2021-43890CVE-2021-43240CVE-2021-43883+10 CVEs60
ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More StoriesThe Hacker News·Dec 4, 16:05 UTC · Dec 4, 2025Phishing & fraud55
All New Have I Been Pwned Domain Search APIs and Splunk IntegrationTroy Hunt·Aug 14, 19:55 UTC · Aug 14, 2023Data breach57
Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz DiscoveryThe Hacker News·Nov 6, 04:40 UTC · Nov 6, 2025Malware42
GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of InstallsThe Hacker News·Nov 10, 08:51 UTC · Nov 10, 2025Malware30
Simple bug could lead to RCE flaw on apps built with Electron FrameworkThe Hacker News·May 15, 00:00 UTC · May 15, 2018VulnerabilityCVE-2018-100013660
Open VSX Bug Let Malicious VS Code Extensions Bypass PreThe Hacker News·Mar 27, 13:57 UTC · Mar 27, 2026Vulnerability30
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain ChaosThe Hacker News·May 26, 04:39 UTC · May 26, 2026Malware in the wildCVE-2026-46333CVE-2026-41091CVE-2026-45498+31 CVEs60
Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and CryptoThe Hacker News·Jan 28, 13:38 UTC · Jan 28, 2026Malware30
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply ChainThe Hacker News·Apr 24, 04:35 UTC · Apr 24, 2026Malware42