Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical VS Code Flaw Enables GitHub Token Theft

Critical VS Code Flaw Enables GitHub Token Theft

Posted on June 4, 2026 By CWS

A severe vulnerability in Visual Studio Code (VS Code) has been made public by security researcher Ammar Askar, highlighting the risk of unauthorized access to GitHub tokens and repositories. This revelation underscores significant concerns for developers using Microsoft’s widely utilized code editor.

Background of the VS Code Vulnerability

The flaw was uncovered by Askar, who opted to disclose the details and a proof-of-concept (PoC) exploit without prior notification to Microsoft. This decision stemmed from a previous incident where Askar reported a vulnerability that was patched without acknowledgement of his contribution. On June 2, Askar released his findings shortly after informing a member of GitHub’s security team, a subsidiary of Microsoft.

Despite the disclosure being a zero-day, Microsoft acted swiftly, implementing a fix on June 3. The vulnerability’s exploitation involves a specially crafted Jupyter notebook, which, when opened in github.dev—a browser-based version of VS Code—executes hidden code to install a malicious extension.

Mechanism and Impact of the Exploit

This malicious extension covertly captures the user’s GitHub token, granting attackers full access to all repositories, including private ones. The attack initiates when a user interacts with a link leading to the compromised notebook. Notifications about extension access only appear if github.dev is being used for the first time, leaving experienced users potentially unaware.

While the exploit can also target the desktop version of VS Code, it necessitates additional user actions, making it less straightforward. However, the desktop attack variant poses a risk of remote code execution, and at the time of disclosure, it remained unpatched.

Industry Reactions and Previous Incidents

This incident is part of a broader pattern of researchers disclosing Microsoft product vulnerabilities without prior vendor notification. Recently, researchers known as Chaotic Eclipse and Nightmare Eclipse released PoC exploits for multiple zero-day vulnerabilities after disputes during the disclosure process with Microsoft. These vulnerabilities, named RedSun, UnDefend, BlueHammer, among others, have reportedly been exploited.

Microsoft has responded to these disclosures with threats of legal action, though it has since attempted to address community concerns following backlash. The ongoing tension highlights the challenges in vulnerability disclosure and the need for improved collaboration between researchers and vendors.

As this situation evolves, security experts advise developers to stay informed about updates and to apply patches promptly to mitigate risks. The cybersecurity community continues to monitor the implications of such vulnerabilities closely, emphasizing the need for vigilance and timely responses to emerging threats.

Security Week News Tags:Cybersecurity, GitHub, Jupyter notebook, Microsoft, remote code execution, Security, token theft, VS Code, Vulnerability, zero-day

Post navigation

Previous Post: Critical Magento RCE Flaw Added to CISA Vulnerability List
Next Post: Cisco Alerts on PoC for Critical Unified CM Flaw

Related Posts

SecurityWeek to Host 2025 ICS Cybersecurity Conference October 27-30 in Atlanta SecurityWeek to Host 2025 ICS Cybersecurity Conference October 27-30 in Atlanta Security Week News
Hackers Exploit BeyondTrust Flaw Within 24 Hours of PoC Hackers Exploit BeyondTrust Flaw Within 24 Hours of PoC Security Week News
CISA Demands Urgent Fix for Exploited LiteSpeed Flaw CISA Demands Urgent Fix for Exploited LiteSpeed Flaw Security Week News
Gambit Security Secures M for AI Cyber Resilience Gambit Security Secures $61M for AI Cyber Resilience Security Week News
Workday Data Breach Bears Signs of Widespread Salesforce Hack Workday Data Breach Bears Signs of Widespread Salesforce Hack Security Week News
Coruna Exploit Kit Targets iOS in Global Attacks Coruna Exploit Kit Targets iOS in Global Attacks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fake Open-Source Tool Sites Exploit Google Rankings for Malware
  • Cisco Alerts on PoC for Critical Unified CM Flaw
  • Critical VS Code Flaw Enables GitHub Token Theft
  • Critical Magento RCE Flaw Added to CISA Vulnerability List
  • Malicious Code Stealer Deployed via Google Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fake Open-Source Tool Sites Exploit Google Rankings for Malware
  • Cisco Alerts on PoC for Critical Unified CM Flaw
  • Critical VS Code Flaw Enables GitHub Token Theft
  • Critical Magento RCE Flaw Added to CISA Vulnerability List
  • Malicious Code Stealer Deployed via Google Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark