The April update suppresses Copilot completions while IntelliSense is active, addressing a long-running editor conflict.
VS Code extensions since Dec 21, 2025 fuel GlassWorm v2, installing cross-IDE malware and stealing credentials.
Malicious KICS Docker tags and VS Code versions 1.17.0, 1.19.0 enabled data exfiltration, risking exposed infrastructure ...
A compromised developer's repository serves as a worm-like infection vector to spread remote access Trojans (RATs) and other ...
VS Code 1.117 adds bring-your-own model key support for Copilot Business and Enterprise users and introduces a set of chat, agent, terminal, and TypeScript updates.
Threat actors have been exploiting the BlueHammer Microsoft Defender vulnerability as a zero-day to gain System privileges.
ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian ...
As supply-chain attacks against widely-used, open-source software repositories continue, experts are urging developers to not ...
Users of GitHub's command-line interface (CLI) who value privacy, beware. The Microsoft-owned code-hosting platform has quietly begun collecting pseudonymous client-side telemetry from CLI users and ...
Snowflake (NYSE:SNOW) has expanded Snowflake Intelligence and Cortex Code with new features aimed at supporting an agentic ...
IntroductionOn March 12, 2026, Zscaler ThreatLabz discovered a malicious ZIP archive containing military-themed document lures targeting Chinese-speaking individuals. Our analysis of this sample ...
The fight between OnlyOffice and Nextcloud is not over, as OnlyOffice has now published an open letter with its demands.