[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvszhKY65KGQn10IYvOjy8giMsKratA3BZmmUDGOt0SY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"a3b6fb1b-4c25-4fb2-971d-550b95b4ecd8","vs-code-zero-day-exploits-user-trust-to-steal-github-tokens","b9920a1b-ad82-46f6-a268-5e83b5d837d8","VS Code Zero-Day Exploits User Trust to Steal GitHub Tokens","A zero-day vulnerability in Visual Studio Code's webview message-passing system allowed attackers to steal GitHub OAuth tokens by tricking users into clicking malicious links that automatically install malicious extensions. The attack exploited the trust relationship between VS Code and github.dev to extract authentication tokens, providing full access to victims' private repositories. This incident highlights how social engineering combined with application vulnerabilities can bypass technical security controls, and demonstrates the critical importance of user education about suspicious links and extension installations.","**Immediate actions:**\n- Review and audit all installed VS Code extensions for legitimacy and necessity\n- Implement browser security policies to restrict automatic extension installations\n- Educate users to verify extension sources before installation and report suspicious links\n\n**Long-term improvements:**\n- Establish application security testing for all development tools used in the organization\n- Implement OAuth token rotation policies and monitoring for unauthorized access\n- Create security awareness training focused on social engineering attacks targeting developer tools\n\n**Detection measures:**\n- Monitor GitHub access patterns for unusual repository access or API usage\n- Deploy endpoint detection tools to identify suspicious extension installations\n- Implement alerting for OAuth token usage from unexpected locations or applications",[12,13,14,15,16],"CIS Control 7","CIS Control 16","NIST AC-6","NIST AT-2","NIST SI-3","published","2026-06-03T08:06:24.721363+00:00","2026-06-03T08:06:24.654+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fvs-code-zero-day-lets-hackers-steal-github-tokens-in-one-click\u002F","vs-code-zero-day-lets-hackers-steal-github-tokens-in-one-click-a7336a","VS Code zero-day lets hackers steal GitHub tokens in one click",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[38],{"id":39,"date":40,"edition":41,"title":42,"audio_url":43},"1dc1f669-6555-4116-bc32-dda32199dd59","2026-06-03","afternoon","ThreatNoir Afternoon Brief — June 3","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-03\u002Fthreatnoir-afternoon-brief-2026-06-03.mp3"]