A security researcher has publicly disclosed a new Visual Studio Code zero-day vulnerability that can reportedly let ...
VS Code flaw exposes GitHub OAuth tokens via one-click attack on GitHub.dev, enabling private repo access and token theft.
A single browser tab, a single click on “Install,” and a cybercriminal group called TeamPCP was inside GitHub’s own house.
GitHub says hackers stole about 3,800 internal repos after a poisoned VS Code extension hit an employee device ...
The code hosting giant GitHub said it was investigating a breach but said there was no evidence of customer data theft.
A major cyber scare has hit GitHub, with hackers from TeamPCP claiming they accessed nearly 4,000 private repositories, including internal source code.
GitHub has said it found about 3,800 internal repositories accessed in the breach and stressed that these contained its own code rather than customer projects. The ...
On May 20, 2026, GitHub announced that employee devices had been compromised by a 'VS Code extension containing malicious code,' resulting in data from internal GitHub repositories being transmitted ...