Information security
fromSecurityWeek
4 days agoVS Code Configs Expose GitHub Codespaces to Attacks
Automatic execution of VS Code configuration files in GitHub Codespaces can enable repository-based supply chain attacks that execute malicious commands and exfiltrate secrets.