Nuacht

Jun 11, 2024 15:39:00 A report that a fake VSCode extension was created and downloaded and that a flaw in the VSCode extension system that makes it easy to insert malicious code was also revealed ...
VS Code flaw lets attackers reuse deleted extension names, enabling ransomware payload delivery and supply chain risks.
The extension can be tricked by invisible Unicode Tag Characters-special symbols unseen by humans but obeyed by AI.
Microsoft updates its Python extension for VS Code with fixes for two security flaws and easier interpreter selection.