Security Feed
  1. Archives

Jan 05 2026 VSCode IDE forks expose users to "recommended extension" attacks

Source

Popular AI-powered integrated development environment solutions, such as Cursor, Windsurf, Google Antigravity, and Trae, recommend extensions that are non-existent in the OpenVSX registry, allowing threat actors to claim the namespace and upload malicious extensions. [...]

Posted by Bill Toulas on Mon 05 January 2026 in BleepingComputer.

Tags: Security, Artificial Intelligence.

Categories

  1. Ars Technica
  2. AWS Security
  3. BleepingComputer
  4. Brian Krebs
  5. Bruce Schneier
  6. GCP Security
  7. Google Project Zero
  8. The Daily Swig
  9. The Guardian
  10. The Register
  11. Threatpost

Tag cloud

  • Security
  • Uncategorized
  • Security, Identity, & Compliance
  • Biz & IT
  • Security Blog
  • Microsoft
  • Security & Identity
  • AI
  • google
  • CryptoCurrency
  • Announcements
  • A Little Sunshine
  • Foundational (100)
  • Legal
  • privacy
  • Artificial Intelligence
  • Mobile
  • Apple
  • squid
  • Intermediate (200)
  • Advanced (300)
  • hacking
  • Technical How-to
  • The Coming Storm
  • Best Practices

Security Feed. Powered by Pelican and m.css. Code is available on GitLab.