News

VS Code flaw lets attackers reuse deleted extension names, enabling ransomware payload delivery and supply chain risks.
Jun 11, 2024 15:39:00 A report that a fake VSCode extension was created and downloaded and that a flaw in the VSCode extension system that makes it easy to insert malicious code was also revealed ...
The extension can be tricked by invisible Unicode Tag Characters-special symbols unseen by humans but obeyed by AI.
VS Code team open‑sourced GitHub Copilot Chat (MIT licence) and invites developers to explore, contribute and shape the AI editor.