VS Code flaw exposes GitHub OAuth tokens via one-click attack on GitHub.dev, enabling private repo access and token theft.

A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking…

Una vulnerabilità di VS Code consente il furto dei token GitHub tramite github.dev e notebook malevoli. Perché è importante.