Vulnerable VS Code extensions put millions of developers at risk

Security researchers at OX Security have found serious vulnerabilities in four widely used Visual Studio Code extensions downloaded over 120 million times, revealing that even “verified” extensions can be manipulated to perform harmful operations at the operating-system level and expose sensitive developer data and credentials, potentially enabling lateral movement across networks and full compromise of development environments. The maintainers have so far not responded to responsible disclosures, prompting calls for mandatory security assessments, automated vulnerability scanning, and enforceable response requirements to protect developers as reliance on IDE extensions and AI coding tools grows. 

https://www.techzine.eu/news/devops/138878/vulnerable-vs-code-extensions-affect-tens-of-millions-of-developers/

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

KEVIntel: Real-Time Intelligence on Exploited Vulnerabilities