Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
VS Code Introduces Delay for Extension Updates to Enhance Security

VS Code Introduces Delay for Extension Updates to Enhance Security

Posted on June 8, 2026 By CWS

Microsoft is taking a significant step to bolster security in its Visual Studio Code (VS Code) environment by implementing a two-hour delay on automatic updates of extensions. This new measure aims to mitigate risks associated with software supply chain attacks.

The newly introduced delay will ensure that updates for VS Code extensions are automatically applied two hours after their release. Microsoft states that this precaution adds a crucial layer of security, helping to prevent the installation of compromised or problematic versions.

How the Delay Affects Extension Updates

Available with VS Code version 1.123, the update delay feature allows users to manually update extensions at any time via the ‘Update’ button. Additionally, the details view will provide users with information on pending updates and the scheduled automatic update time.

Importantly, this update delay does not affect extensions from trusted publishers, including Microsoft, GitHub, and OpenAI. Extensions from these sources will continue to receive immediate updates, maintaining their regular update schedule.

Comparison with Other Development Tools

This move by Microsoft follows a similar path taken by RubyGems, which recently introduced an optional cooldown feature in Bundler 4.0.13, allowing developers to set a delay for installing new gem versions. This feature aims to reduce the risk of exposure to malicious versions.

Other development tools have also adopted similar strategies. For instance, Bun, npm, pnpm, and Yarn have all implemented controls to delay installations of new package versions. These measures collectively aim to curb the spread of malicious software within developer ecosystems.

Why These Measures Matter

The introduction of these update delays comes amid a rise in software supply chain attacks that target development environments to distribute malware. By enforcing a waiting period before new package versions can be installed, developers have a better chance to identify and mitigate potential threats before they cause widespread harm.

These protective steps are essential in maintaining the integrity of developer tools and ensuring that malicious software does not compromise downstream users. With these changes, Microsoft and other tech giants are demonstrating a proactive approach to safeguarding their ecosystems against evolving security threats.

The Hacker News Tags:automatic updates, developer tools, extension updates, IDE, Microsoft, security enhancement, Software Security, software supply chain, supply chain attacks, trusted publishers, VS Code

Post navigation

Previous Post: Microsoft Highlights Security Risks in Claude Code GitHub Action
Next Post: Instagram Accounts Hacked Due to AI Tool Vulnerability

Related Posts

Apple Patches WebKit Flaw in iOS and macOS Apple Patches WebKit Flaw in iOS and macOS The Hacker News
Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware Attacks Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware Attacks The Hacker News
New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024-7344 Exploit New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024-7344 Exploit The Hacker News
Anthropic’s AI Model Uncovers Major Security Flaws Anthropic’s AI Model Uncovers Major Security Flaws The Hacker News
Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens The Hacker News
OpenAI Unveils GPT-5.6 Sol with Enhanced Security OpenAI Unveils GPT-5.6 Sol with Enhanced Security The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark