Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical VS Code Flaw Enables GitHub Token Theft

Critical VS Code Flaw Enables GitHub Token Theft

Posted on June 4, 2026 By CWS

A severe vulnerability in Visual Studio Code (VS Code) has been made public by security researcher Ammar Askar, highlighting the risk of unauthorized access to GitHub tokens and repositories. This revelation underscores significant concerns for developers using Microsoft’s widely utilized code editor.

Background of the VS Code Vulnerability

The flaw was uncovered by Askar, who opted to disclose the details and a proof-of-concept (PoC) exploit without prior notification to Microsoft. This decision stemmed from a previous incident where Askar reported a vulnerability that was patched without acknowledgement of his contribution. On June 2, Askar released his findings shortly after informing a member of GitHub’s security team, a subsidiary of Microsoft.

Despite the disclosure being a zero-day, Microsoft acted swiftly, implementing a fix on June 3. The vulnerability’s exploitation involves a specially crafted Jupyter notebook, which, when opened in github.dev—a browser-based version of VS Code—executes hidden code to install a malicious extension.

Mechanism and Impact of the Exploit

This malicious extension covertly captures the user’s GitHub token, granting attackers full access to all repositories, including private ones. The attack initiates when a user interacts with a link leading to the compromised notebook. Notifications about extension access only appear if github.dev is being used for the first time, leaving experienced users potentially unaware.

While the exploit can also target the desktop version of VS Code, it necessitates additional user actions, making it less straightforward. However, the desktop attack variant poses a risk of remote code execution, and at the time of disclosure, it remained unpatched.

Industry Reactions and Previous Incidents

This incident is part of a broader pattern of researchers disclosing Microsoft product vulnerabilities without prior vendor notification. Recently, researchers known as Chaotic Eclipse and Nightmare Eclipse released PoC exploits for multiple zero-day vulnerabilities after disputes during the disclosure process with Microsoft. These vulnerabilities, named RedSun, UnDefend, BlueHammer, among others, have reportedly been exploited.

Microsoft has responded to these disclosures with threats of legal action, though it has since attempted to address community concerns following backlash. The ongoing tension highlights the challenges in vulnerability disclosure and the need for improved collaboration between researchers and vendors.

As this situation evolves, security experts advise developers to stay informed about updates and to apply patches promptly to mitigate risks. The cybersecurity community continues to monitor the implications of such vulnerabilities closely, emphasizing the need for vigilance and timely responses to emerging threats.

Security Week News Tags:Cybersecurity, GitHub, Jupyter notebook, Microsoft, remote code execution, Security, token theft, VS Code, Vulnerability, zero-day

Post navigation

Previous Post: Critical Magento RCE Flaw Added to CISA Vulnerability List
Next Post: Cisco Alerts on PoC for Critical Unified CM Flaw

Related Posts

US Sanctions Myanmar Militia Involved in Cyber Scams  US Sanctions Myanmar Militia Involved in Cyber Scams  Security Week News
Google Warns of Quantum Threats to Cryptocurrency Security Google Warns of Quantum Threats to Cryptocurrency Security Security Week News
US-Israel Cyber Operations Intensify Amid Iran Tensions US-Israel Cyber Operations Intensify Amid Iran Tensions Security Week News
Ransomware Group Exploits Hybrid Cloud Gaps, Gains Full Azure Control in Enterprise Attacks Ransomware Group Exploits Hybrid Cloud Gaps, Gains Full Azure Control in Enterprise Attacks Security Week News
Managing Technical Debt in AI-Driven Software Development Managing Technical Debt in AI-Driven Software Development Security Week News
Possible Zero-Day Patched in SonicWall SMA Appliances Possible Zero-Day Patched in SonicWall SMA Appliances Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Qilin Ransomware Exploits PAN-OS Vulnerability for Access
  • Microsoft to End Copilot Podcasts in 2026
  • Empirical Secures $25M for AI Cybersecurity Expansion
  • Android AI Agents Vulnerable to Covert Code Execution
  • Microsoft Defender XDR Vulnerability in Network Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Qilin Ransomware Exploits PAN-OS Vulnerability for Access
  • Microsoft to End Copilot Podcasts in 2026
  • Empirical Secures $25M for AI Cybersecurity Expansion
  • Android AI Agents Vulnerable to Covert Code Execution
  • Microsoft Defender XDR Vulnerability in Network Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark