Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Defending the Dev Environment: Analyzing VS Code's 2-Hour Extension Update Delay
Defending the Dev Environment: Analyzing VS Code's 2-Hour Extension Update Delay Introduction On June 2026, Microsoft announced a significan...
VS Code Zero-Day: Detecting and Blocking GitHub Token Theft via Malicious Links
Introduction A critical security vulnerability has been disclosed in Visual Studio Code (VS Code) that allows attackers to steal GitHub auth...
GitHub Breach via Malicious Nx Console VS Code Extension: Detection & Hardening
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension: Detection and Remediation Introduction On Wednesday, GitHu...
Compromised Nx Console v18.95.0: VS Code Supply Chain Attack and Credential Theft
Compromised Nx Console v18.95.0: VS Code Supply Chain Attack and Credential Theft Introduction Security teams need to be on immediate alert ...
GlassWorm Supply Chain: Detecting Malicious Open VSX Extensions
Introduction The latest Security Affairs Malicious Software Newsletter (Round 95) highlights a concerning development in the software supply...
Defending Against Malicious VS Code Extensions: Open VSX Vulnerability Analysis
Introduction A recently disclosed vulnerability in the Open VSX Registry has highlighted a critical supply chain risk for organizations rely...
Defending Against VS Code Auto-Run Attacks: Mitigating StoatWaffle Malware
Defending Against VS Code Auto-Run Attacks: Mitigating StoatWaffle Malware Introduction Software development environments have become a prim...