GlassWorm hides malware in VS Code theme extensions, targeting developers through Visual Studio Marketplace and Open VSX.
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both.
A serious VS Code flaw lets attackers gain persistent workstation access with one click in a malicious project, bypassing Workspace Trust via clickable editor links.