<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Github.dev on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/github.dev/</link><description>Recent content in Github.dev on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 03 Jun 2026 17:58:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/github.dev/index.xml" rel="self" type="application/rss+xml"/><item><title>One-Click VS Code Attack Steals GitHub OAuth Tokens</title><link>https://zxcloudsecurity.co.uk/posts/one-click-vscode-githubdev-attack-github-oauth-token-theft/</link><pubDate>Wed, 03 Jun 2026 17:58:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/one-click-vscode-githubdev-attack-github-oauth-token-theft/</guid><description>A one-click attack via VS Code&amp;#39;s GitHub.dev feature can steal full GitHub OAuth tokens, exposing private repos to read/write access.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html">The Hacker News</a></p>
<hr>
<p>A one-click attack targeting Microsoft VS Code&rsquo;s GitHub.dev feature allows an attacker to steal a victim&rsquo;s GitHub OAuth token simply by tricking them into clicking a crafted link. The stolen token grants read and write access to all repositories the victim can access, including private ones. This poses a significant supply chain risk, as compromised tokens could be used to inject malicious code into codebases.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Enforce short-lived, scoped OAuth tokens across your organisation and audit any GitHub Apps or integrations permitted in VS Code. Consider restricting or monitoring use of GitHub.dev in your developer environment policy, and enable GitHub token scanning and push protection to limit the blast radius of any token compromise.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html">One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens</a></p>
]]></content:encoded></item></channel></rss>