Critical vulnerabilities in four widely used VS Code extensions could enable file theft and remote code execution across 125M installs.
Experts claim Amazon Q Developer Extension for VSC v1.84.0 had some dodgy code This has now been removed, with version 1.85.0 offering a clean fix Around 5.6% of VSC extensions have been compromised A ...