<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Vscode on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/vscode/</link><description>Recent content in Vscode on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 03 Jun 2026 17:58:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/vscode/index.xml" rel="self" type="application/rss+xml"/><item><title>One-Click GitHub OAuth Token Theft via VS Code</title><link>https://zxcloudsecurity.co.uk/posts/one-click-github-dev-oauth-token-theft-vscode/</link><pubDate>Wed, 03 Jun 2026 17:58:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/one-click-github-dev-oauth-token-theft-vscode/</guid><description>A one-click attack exploiting GitHub.dev and VS Code lets attackers steal GitHub OAuth tokens, exposing private repositories to full read/write access.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html">The Hacker News</a></p>
<hr>
<p>A one-click attack targeting GitHub.dev, the browser-based VS Code environment, allows an attacker to steal a victim&rsquo;s GitHub OAuth token simply by having them click a crafted link. The stolen token grants full read and write access to both public and private repositories. This is particularly dangerous because it requires no malware installation and exploits a legitimate GitHub feature.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Audit OAuth token scopes granted to GitHub.dev within your organisation and consider enforcing fine-grained personal access tokens with minimal repository permissions instead of broad OAuth tokens. Ensure developer awareness training covers the risk of clicking unsolicited GitHub.dev links, and review whether your GitHub organisation policies can restrict OAuth app access.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html">One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens</a></p>
]]></content:encoded></item><item><title>One-Click VS Code Attack Steals GitHub OAuth Tokens</title><link>https://zxcloudsecurity.co.uk/posts/one-click-vscode-githubdev-attack-github-oauth-token-theft/</link><pubDate>Wed, 03 Jun 2026 17:58:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/one-click-vscode-githubdev-attack-github-oauth-token-theft/</guid><description>A one-click attack via VS Code&amp;#39;s GitHub.dev feature can steal full GitHub OAuth tokens, exposing private repos to read/write access.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html">The Hacker News</a></p>
<hr>
<p>A one-click attack targeting Microsoft VS Code&rsquo;s GitHub.dev feature allows an attacker to steal a victim&rsquo;s GitHub OAuth token simply by tricking them into clicking a crafted link. The stolen token grants read and write access to all repositories the victim can access, including private ones. This poses a significant supply chain risk, as compromised tokens could be used to inject malicious code into codebases.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Enforce short-lived, scoped OAuth tokens across your organisation and audit any GitHub Apps or integrations permitted in VS Code. Consider restricting or monitoring use of GitHub.dev in your developer environment policy, and enable GitHub token scanning and push protection to limit the blast radius of any token compromise.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html">One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens</a></p>
]]></content:encoded></item></channel></rss>