Cybersecurity researchers have discovered malicious Visual Studio Code extensions targeting software developers, amassing millions of installations. Concealing their true nature, these extensions, primarily affecting JavaScript and Python developers, execute harmful code, access local files, and exfiltrate sensitive data. The sophisticated, multi-stage infection technique evades detection and raises concerns about vulnerabilities in production systems.

Hackers Actively Exploiting Critical Exchange & SharePoint Server Vulnerabilities
Microsoft has warned that cybercriminals are increasingly exploiting critical vulnerabilities in on-premises Exchange and SharePoint Servers. New techniques like NTLM relay and credential leakage enable