logo

Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures

ID: e28ad79c-e2cb-5112-ac1a-29a21595e3e6

STIX ID: report--e28ad79c-e2cb-5112-ac1a-29a21595e3e6

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-04

...
...

A security researcher published a proof-of-concept showing how attackers can abuse github.dev and VS Code Workspace Recommendations to push a malicious extension that auto-accepts its install (via a Jupyter Notebook Webview trick) and steals OAuth tokens, enabling access to any public or private GitHub repos the victim can access; the author publicly released the PoC after dissatisfaction with Microsoft’s handling of vulnerability reports.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.